infections multiples(resolu,merci egwene) - Page 2
Forum Sécurité - Virus : infections multiples(resolu,merci egwene)
Reprise du message précédent :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:18:09, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eye On Network\Eye On Network.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo009a11f4.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-436374069-1960408961-839522115-1007\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'marie josée')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: (PopUpCop) Allow images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/allowimages
O8 - Extra context menu item: (PopUpCop) Block images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/blockimages
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Laura%20Jones%20and%20the%20Gates%20of%20Good%20and%20Evil/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9236 bytes
bonjour frederix. ya rien de changé coté windows security center...
Répondre à tinomme1969
| tinomme1969 a écrit : > est-ce que mes explications sont claires??? |
Bonsoir tinomme1969,
> Non...
A+ tard
.
Bonjour,
| Citation : bonjour frederix. ya rien de changé coté windows security center... |
tinomme1969, peux-tu être plus précis sur la nature du problème qui persiste ? Symptômes etc. Sois précis et détaille bien.
Je poste pour suivre.
Sécurité / Prévention
Répondre à Egwene
c est ça mon problème!! xp security center a remplacé mon centre de securité xp dans le panneau de configuration.j ai pas de probleme de pop up TANT ET AUSSI LONGTEMPS que je ne dois pas aller y voir quoi que ce soit.
des que je clic dessus,ya un bouclier rouge ayant un x blanc qui s installe dans ma barre des taches.
SI je clic dessus,il m emmène dans un faux centre de sécurité xp,(situé dans mon panneau de configuration)et la,tout semble normal mis a part l onglet ayant rapport a mon antivirus qui est rouge.
LA, si je clic ,je suis redirigé sur le lien en haut de page.
en bref, centre de securité xp est remplacé par windows security center.
en as-tu assé pour un diagnostic?
merci d aider frederix. j suis certain qu on va y arriver.
Message édité par tinomme1969 le 16-08-2008 à 21:13:10
Répondre à tinomme1969
Bonjour,
Enlève le lien de ton dernier message
Frederix devrait bientôt s'occuper de toi.
Sécurité / Prévention
Répondre à Egwene
Bonjour,
Tu es toujours avec nous ? Désolé pour l'attente, mais je pensais que Frederix allait continuer. Il m'a finalement demandé de prendre la relève, tout en continuant à suivre le sujet.
Je suis fatigué là
Je te réponds demain.
Fais un "up" du sujet dès que possible.
Message édité par Egwene le 18-08-2008 à 00:32:19
Sécurité / Prévention
Répondre à Egwene
bon,pas d problème.repose toi et moi j attendrai les directives. merci de prendre la relève.
Répondre à tinomme1969
Bonjour,
Merci de ta patience
Désactive toute protection résidente ( antivirus…) ! <------- Pense-y !
Copie le texte se situant dans le cadre ci-dessous : ( Ctrl + C )
| Citation : File::
|
=> Ouvre le Bloc Notes : Démarrer > Tous les programmes > Accessoires > Bloc notes
- Colles y le texte (CTRL + V)
- Enregistre ce fichier dans : Bureau
- Nom du fichier : CFScript
- Type du fichier : tous les fichiers !!
- Clique sur Enregistrer
- Quitte le Bloc Notes
Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
* Cela va relancer Combofix : au message qui apparaît ( Type 1 to continue, or 2 to abort), tape 1 puis valide.
* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
* Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher : Copie/Colle son contenue sur le forum.
Si le fichier ne s'ouvre pas, il se trouve ici : C:\ComboFix.txt
* Poste un nouveau rapport hijackthis.
Sécurité / Prévention
Répondre à Egwene
ComboFix 08-08-11.01 - Mario Després 2008-08-19 9:06:02.7 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1505 [GMT -4:00]
Endroit: C:\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mario Després\Bureau\cfscript.txt
* Création d'un nouveau point de restauration
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
FILE ::
C:\WINDOWS\ssconf2.bin
C:\WINDOWS\system32\_scui.cpl
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\ssconf2.bin
C:\WINDOWS\system32\_scui.cpl
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-19 to 2008-08-19 ))))))))))))))))))))))))))))))))))))
.
2008-08-19 06:15 . 2008-08-19 06:18 <REP> d-------- C:\Program Files\Hawaiian Explorer - Lost Island
2008-08-17 14:56 . 2008-08-17 14:56 <REP> d-------- C:\Program Files\Conduit
2008-08-17 14:55 . 2008-08-17 14:56 <REP> d-------- C:\Program Files\free-downloads.net
2008-08-15 20:23 . 2008-08-15 20:52 <REP> d-------- C:\Program Files\Wild West Quest
2008-08-13 08:53 . 2008-08-13 08:53 <REP> d-------- C:\Documents and Settings\antoine\Application Data\Skinux
2008-08-12 07:15 . 2008-08-12 07:15 2,710,613 --a------ C:\ComboFix.exe
2008-08-11 13:22 . 2008-08-11 13:30 <REP> d-------- C:\d3temp
2008-08-11 11:46 . 2008-08-11 11:46 <REP> d-------- C:\Documents and Settings\Mario Després\Application Data\Skinux
2008-08-10 06:41 . 2008-08-10 06:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Slapdash Games
2008-08-09 15:49 . 2008-08-09 15:49 230,776 --a------ C:\aswclear.exe
2008-08-07 20:41 . 2008-08-13 19:01 <REP> d-------- C:\WINDOWS\SmitfraudFix
2008-08-07 11:04 . 2008-08-07 11:04 <REP> d-------- C:\Program Files\Avira
2008-08-07 11:04 . 2008-08-07 11:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-06 22:06 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 22:06 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-06 07:38 . 2008-08-06 07:38 <REP> d-------- C:\Program Files\Sun
2008-08-05 07:04 . 2008-08-05 07:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TheRace_dev
2008-08-03 12:55 . 2008-08-03 12:55 <REP> d-------- C:\Documents and Settings\Mario Després\Application Data\Malwarebytes
2008-08-03 12:55 . 2008-08-03 12:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-03 11:44 . 2008-08-03 11:45 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-03 10:43 . 2008-08-03 10:43 <REP> d-------- C:\Program Files\Trend Micro
2008-08-02 21:19 . 2008-08-02 21:19 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 21:14 . 2008-08-02 21:17 15,083,520 --a------ C:\spybotsd160.exe
2008-08-02 15:58 . 2008-08-02 15:58 <REP> d-------- C:\Documents and Settings\marie josée\Application Data\Skinux
2008-08-02 13:13 . 2008-08-02 13:48 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-08-02 13:06 . 2008-08-02 14:01 <REP> d-------- C:\Program Files\Kodak
2008-08-02 08:10 . 2008-08-02 08:12 <REP> d-------- C:\Program Files\Cactus Bruce and the Corporate Monkeys
2008-08-02 08:03 . 2008-08-02 08:03 <REP> d-------- C:\Program Files\Nemo's Aquarium 3D
2008-08-02 08:03 . 2004-01-30 15:31 3,594,576 --a------ C:\WINDOWS\Nemo's Aquarium 3D Anemonen-Feld.scr
2008-08-02 08:03 . 2004-01-30 15:31 3,494,207 --a------ C:\WINDOWS\Nemo's Aquarium 3D Korallenriff.scr
2008-08-01 20:33 . 2008-08-04 12:20 <REP> d-------- C:\Program Files\The Mystery Of The Crystal Portal
2008-07-30 08:53 . 2008-07-30 08:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\The Revills Games
2008-07-22 09:43 . 2008-07-22 09:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Media Art
2008-07-19 06:33 . 2008-07-19 06:33 <REP> d-------- C:\Documents and Settings\marie josée\Application Data\Gold Casual Games
2008-07-19 06:33 . 2008-07-19 06:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Gold Casual Games
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-19 13:09 --------- d-----w C:\Program Files\Eye On Network
2008-08-19 13:01 --------- d-----w C:\Program Files\X-masTree
2008-08-19 10:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-18 16:18 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\uTorrent
2008-08-17 22:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-17 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-15 15:45 --------- d-----w C:\Program Files\GameHouse
2008-08-15 15:45 --------- d-----w C:\Program Files\GameFiesta
2008-08-13 13:51 --------- d-----w C:\Program Files\iWin.com
2008-08-11 15:40 3,870 ----a-w C:\WINDOWS\system32\tmp.reg
2008-08-09 23:27 --------- d-----w C:\Program Files\Zylom Games
2008-08-09 13:25 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Zylom
2008-08-07 15:38 --------- d-----w C:\Program Files\iWin Games
2008-08-06 14:19 --------- d-----w C:\Program Files\Java
2008-08-06 11:45 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-05 19:40 --------- d-----w C:\Program Files\Blood Ties
2008-08-04 17:23 --------- d-----w C:\Program Files\Unicorn Castle
2008-08-02 17:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-07-23 17:41 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-22 10:51 --------- d-----w C:\Program Files\SuperMarioPac
2008-07-20 00:33 --------- d-----w C:\Documents and Settings\marie josée\Application Data\ForgottenRiddles2
2008-07-15 18:43 --------- d-----w C:\Program Files\RealArcade
2008-07-15 18:42 --------- d-----w C:\Program Files\Oberon Media
2008-07-14 20:05 --------- d-----w C:\Documents and Settings\marie josée\Application Data\EnchantedCavern
2008-07-13 16:49 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\LimeWire
2008-07-12 12:46 --------- d-----w C:\Program Files\Lavasoft
2008-07-12 12:44 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\Lavasoft
2008-07-12 12:42 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-12 12:00 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\AlauxSoft
2008-07-08 22:42 --------- d-----w C:\Program Files\The Pini Society
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-04 12:29 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\Meridian93
2008-07-04 11:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Arkadium
2008-07-02 13:08 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Meridian93
2008-07-02 10:37 --------- d-----w C:\Program Files\Turtix Rescue Adventure
2008-07-01 14:12 --------- d-----w C:\Program Files\Turtix 2 - Rescue Adventures
2008-06-28 14:13 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Ancient Quest of Saqqarah__bfg
2008-06-28 01:21 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Reflexive
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 01:49 --------- d-----w C:\Program Files\The Lost Cases Of Sherlock Holmes
2008-06-20 01:35 --------- d-----w C:\Documents and Settings\marie josée\Application Data\MysteryStudio
2008-06-19 16:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2008-06-19 00:49 --------- d-----w C:\Documents and Settings\marie josée\Application Data\BigFish
2008-06-19 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFish
2008-03-21 07:05 7,407,104 ----a-w C:\Program Files\Limewire PRO 4.17.5.EXE
2008-03-01 12:30 0 ----a-w C:\Program Files\temp01
2007-10-29 15:29 7,467,056 ----a-w C:\Program Files\spybotsd15.exe
2007-01-09 02:14 4,049,311 ----a-w C:\Program Files\liveupdate.exe
2006-12-05 02:07 497 ----a-w C:\Program Files\Raccourci vers lumieres.lnk
2006-12-05 01:58 9,440 ----a-w C:\Program Files\lumieres.zip
2006-11-29 02:35 817 -c--a-w C:\Program Files\recoil.err
2006-08-28 23:39 983,745 ----a-w C:\Program Files\PowerpointImageExtractor.zip
2006-03-07 03:07 31,944 ----a-w C:\Program Files\Uninst.isu
2006-02-03 16:53 243,512 ----a-w C:\Program Files\jre-1_5_0_06-windows-i586-p-iftw.exe
2005-10-29 02:45 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2004-03-11 17:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
1999-10-06 21:40 1,765,376 ------w C:\Documents and Settings\Mario Després\SETUPENU.DLL
1999-10-06 21:40 1,765,376 ------w C:\Documents and Settings\Mario Després\SETUPENU.DLL
1999-01-12 21:19 75,776 ----a-w C:\Program Files\messages.dll
1998-11-06 19:50 57,344 ----a-w C:\Program Files\Uninst.dll
1998-11-04 16:41 201,216 ----a-w C:\Program Files\a3dapi.dll
1997-10-09 20:54 30,720 ----a-w C:\Program Files\regsvr32.exe
2008-03-31 16:12 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
2007-10-01 18:17 1,199,508 --sha-w C:\WINDOWS\system32\wbem\mof\good\mirc.exe
2008-03-13 12:08 172 --sha-w C:\WINDOWS\system32\wbem\mof\good\start.bat
2007-09-23 19:05 147 --sha-w C:\WINDOWS\system32\wbem\mof\good\start.reg
2008-03-12 14:56 107 --sha-w C:\WINDOWS\system32\wbem\mof\good\winhelp.vbe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\_detmp.1 -- Not a PE file.
MD5: 814ae959c53770f8e10b763da90da6d8
C:\WINDOWS\_detmp.2 -- Unable to find file version info.
MD5: 4a4718e2b4d65c0e6e93a066d55d449c
---- Directory of C:\d3temp ----
2008-08-11 13:22 176218 --a------ C:\d3temp\bubles-804.wav
Répondre à tinomme1969
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:19, on 2008-08-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eye On Network\Eye On Network.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo00025f0e.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: (PopUpCop) Allow images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/allowimages
O8 - Extra context menu item: (PopUpCop) Block images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/blockimages
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Hawaiian%20Explorer%20-%20Lost%20Island/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9661 bytes
bonjour toi.j te laisse le temps d analyser tout ca.merci,j attend de tes nouvelles
Répondre à tinomme1969
Re,
Le rapport de Combofix était incomplet, peux-tu me le poster stp ?
Et j'ai oublié un fichier à supprimer.
Téléchargez ATF Cleaner sur votre Bureau.
- Faites un double clic sur ATF-Cleaner.exe pour lancer le programme.
- Cliquez sur Select All situé en bas de la liste.
- Cliquez sur le bouton Empty Selected.
Si vous utilisez le navigateur Firefox, faites aussi ceci :
- Cliquez sur Firefox en haut et choisissez Select All dans la liste.
- Cliquez sur le bouton Empty Selected.
- NOTE : Si vous désirez conserver vos mots de passe enregistrés, cliquez sur No dans le message d'avertissement.
Si vous utilisez le navigateur Opera, faites aussi ceci :
- Cliquez sur Opera en haut et choisissez Select All dans la liste.
- Fermez TOUS les navigateurs Internet (très important).
- Cliquez sur le bouton Empty Selected.
- NOTE : Si vous désirez conserver vos mots de passe enregistrés, cliquez sur No dans le message d'avertissement.
Cliquez sur Exit dans le menu principal pour fermer le programme.
Et ensuite redémarre le PC et poste-moi un nouveau rapports HijackThis.
Et dis-moi où tu en es de tes problèmes.
Sécurité / Prévention
Répondre à Egwene
re-voila combofix.
windows security center est disparu du panneau de configuration mais ya pas le centre de sécurité xp,j imagine que ca reviendra plus tard...
ComboFix 08-08-11.01 - Mario Després 2008-08-19 19:02:04.8 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1544 [GMT -4:00]
Endroit: C:\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mario Després\Bureau\cfscript.txt
* Création d'un nouveau point de restauration
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
FILE ::
C:\WINDOWS\ssconf2.bin
C:\WINDOWS\system32\_scui.cpl
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\ssconf2.bin
C:\WINDOWS\system32\_scui.cpl
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-19 to 2008-08-19 ))))))))))))))))))))))))))))))))))))
.
2008-08-19 06:15 . 2008-08-19 06:18 <REP> d-------- C:\Program Files\Hawaiian Explorer - Lost Island
2008-08-17 14:56 . 2008-08-17 14:56 <REP> d-------- C:\Program Files\Conduit
2008-08-17 14:55 . 2008-08-17 14:56 <REP> d-------- C:\Program Files\free-downloads.net
2008-08-15 20:23 . 2008-08-15 20:52 <REP> d-------- C:\Program Files\Wild West Quest
2008-08-13 08:53 . 2008-08-13 08:53 <REP> d-------- C:\Documents and Settings\antoine\Application Data\Skinux
2008-08-12 07:15 . 2008-08-12 07:15 2,710,613 --a------ C:\ComboFix.exe
2008-08-11 13:22 . 2008-08-11 13:30 <REP> d-------- C:\d3temp
2008-08-11 11:46 . 2008-08-11 11:46 <REP> d-------- C:\Documents and Settings\Mario Després\Application Data\Skinux
2008-08-10 06:41 . 2008-08-10 06:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Slapdash Games
2008-08-09 15:49 . 2008-08-09 15:49 230,776 --a------ C:\aswclear.exe
2008-08-07 20:41 . 2008-08-13 19:01 <REP> d-------- C:\WINDOWS\SmitfraudFix
2008-08-07 11:04 . 2008-08-07 11:04 <REP> d-------- C:\Program Files\Avira
2008-08-07 11:04 . 2008-08-07 11:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-06 22:06 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 22:06 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-06 07:38 . 2008-08-06 07:38 <REP> d-------- C:\Program Files\Sun
2008-08-05 07:04 . 2008-08-05 07:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TheRace_dev
2008-08-03 12:55 . 2008-08-03 12:55 <REP> d-------- C:\Documents and Settings\Mario Després\Application Data\Malwarebytes
2008-08-03 12:55 . 2008-08-03 12:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-03 11:44 . 2008-08-03 11:45 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-03 10:43 . 2008-08-03 10:43 <REP> d-------- C:\Program Files\Trend Micro
2008-08-02 21:19 . 2008-08-02 21:19 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 21:14 . 2008-08-02 21:17 15,083,520 --a------ C:\spybotsd160.exe
2008-08-02 15:58 . 2008-08-02 15:58 <REP> d-------- C:\Documents and Settings\marie josée\Application Data\Skinux
2008-08-02 13:13 . 2008-08-02 13:48 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-08-02 13:06 . 2008-08-02 14:01 <REP> d-------- C:\Program Files\Kodak
2008-08-02 08:10 . 2008-08-02 08:12 <REP> d-------- C:\Program Files\Cactus Bruce and the Corporate Monkeys
2008-08-02 08:03 . 2008-08-02 08:03 <REP> d-------- C:\Program Files\Nemo's Aquarium 3D
2008-08-02 08:03 . 2004-01-30 15:31 3,594,576 --a------ C:\WINDOWS\Nemo's Aquarium 3D Anemonen-Feld.scr
2008-08-02 08:03 . 2004-01-30 15:31 3,494,207 --a------ C:\WINDOWS\Nemo's Aquarium 3D Korallenriff.scr
2008-08-01 20:33 . 2008-08-04 12:20 <REP> d-------- C:\Program Files\The Mystery Of The Crystal Portal
2008-07-30 08:53 . 2008-07-30 08:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\The Revills Games
2008-07-22 09:43 . 2008-07-22 09:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Media Art
2008-07-19 06:33 . 2008-07-19 06:33 <REP> d-------- C:\Documents and Settings\marie josée\Application Data\Gold Casual Games
2008-07-19 06:33 . 2008-07-19 06:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Gold Casual Games
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-19 23:03 --------- d-----w C:\Program Files\Eye On Network
2008-08-19 21:50 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\uTorrent
2008-08-19 13:01 --------- d-----w C:\Program Files\X-masTree
2008-08-19 10:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-17 22:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-17 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-15 15:45 --------- d-----w C:\Program Files\GameHouse
2008-08-15 15:45 --------- d-----w C:\Program Files\GameFiesta
2008-08-13 13:51 --------- d-----w C:\Program Files\iWin.com
2008-08-11 15:40 3,870 ----a-w C:\WINDOWS\system32\tmp.reg
2008-08-09 23:27 --------- d-----w C:\Program Files\Zylom Games
2008-08-09 13:25 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Zylom
2008-08-07 15:38 --------- d-----w C:\Program Files\iWin Games
2008-08-06 14:19 --------- d-----w C:\Program Files\Java
2008-08-06 11:45 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-05 19:40 --------- d-----w C:\Program Files\Blood Ties
2008-08-04 17:23 --------- d-----w C:\Program Files\Unicorn Castle
2008-08-02 17:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-07-23 17:41 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-22 10:51 --------- d-----w C:\Program Files\SuperMarioPac
2008-07-20 00:33 --------- d-----w C:\Documents and Settings\marie josée\Application Data\ForgottenRiddles2
2008-07-15 18:43 --------- d-----w C:\Program Files\RealArcade
2008-07-15 18:42 --------- d-----w C:\Program Files\Oberon Media
2008-07-14 20:05 --------- d-----w C:\Documents and Settings\marie josée\Application Data\EnchantedCavern
2008-07-13 16:49 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\LimeWire
2008-07-12 12:46 --------- d-----w C:\Program Files\Lavasoft
2008-07-12 12:44 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\Lavasoft
2008-07-12 12:42 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-12 12:00 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\AlauxSoft
2008-07-08 22:42 --------- d-----w C:\Program Files\The Pini Society
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-04 12:29 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\Meridian93
2008-07-04 11:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Arkadium
2008-07-02 13:08 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Meridian93
2008-07-02 10:37 --------- d-----w C:\Program Files\Turtix Rescue Adventure
2008-07-01 14:12 --------- d-----w C:\Program Files\Turtix 2 - Rescue Adventures
2008-06-28 14:13 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Ancient Quest of Saqqarah__bfg
2008-06-28 01:21 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Reflexive
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 01:49 --------- d-----w C:\Program Files\The Lost Cases Of Sherlock Holmes
2008-06-20 01:35 --------- d-----w C:\Documents and Settings\marie josée\Application Data\MysteryStudio
2008-06-19 16:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2008-06-19 00:49 --------- d-----w C:\Documents and Settings\marie josée\Application Data\BigFish
2008-06-19 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFish
2008-03-21 07:05 7,407,104 ----a-w C:\Program Files\Limewire PRO 4.17.5.EXE
2008-03-01 12:30 0 ----a-w C:\Program Files\temp01
2007-10-29 15:29 7,467,056 ----a-w C:\Program Files\spybotsd15.exe
2007-01-09 02:14 4,049,311 ----a-w C:\Program Files\liveupdate.exe
2006-12-05 02:07 497 ----a-w C:\Program Files\Raccourci vers lumieres.lnk
2006-12-05 01:58 9,440 ----a-w C:\Program Files\lumieres.zip
2006-11-29 02:35 817 -c--a-w C:\Program Files\recoil.err
2006-08-28 23:39 983,745 ----a-w C:\Program Files\PowerpointImageExtractor.zip
2006-03-07 03:07 31,944 ----a-w C:\Program Files\Uninst.isu
2006-02-03 16:53 243,512 ----a-w C:\Program Files\jre-1_5_0_06-windows-i586-p-iftw.exe
2005-10-29 02:45 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2004-03-11 17:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
1999-10-06 21:40 1,765,376 ------w C:\Documents and Settings\Mario Després\SETUPENU.DLL
1999-10-06 21:40 1,765,376 ------w C:\Documents and Settings\Mario Després\SETUPENU.DLL
1999-01-12 21:19 75,776 ----a-w C:\Program Files\messages.dll
1998-11-06 19:50 57,344 ----a-w C:\Program Files\Uninst.dll
1998-11-04 16:41 201,216 ----a-w C:\Program Files\a3dapi.dll
1997-10-09 20:54 30,720 ----a-w C:\Program Files\regsvr32.exe
2008-03-31 16:12 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
2007-10-01 18:17 1,199,508 --sha-w C:\WINDOWS\system32\wbem\mof\good\mirc.exe
2008-03-13 12:08 172 --sha-w C:\WINDOWS\system32\wbem\mof\good\start.bat
2007-09-23 19:05 147 --sha-w C:\WINDOWS\system32\wbem\mof\good\start.reg
2008-03-12 14:56 107 --sha-w C:\WINDOWS\system32\wbem\mof\good\winhelp.vbe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\_detmp.1 -- Not a PE file.
MD5: 814ae959c53770f8e10b763da90da6d8
C:\WINDOWS\_detmp.2 -- Unable to find file version info.
MD5: 4a4718e2b4d65c0e6e93a066d55d449c
---- Directory of C:\d3temp ----
2008-08-11 13:22 176218 --a------ C:\d3temp\bubles-804.wav
((((((((((((((((((((((((((((( snapshot@2008-08-12_ 7.33.19.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-07 20:18:27 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP2QFE\es.dll
+ 2008-07-07 20:28:20 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3GDR\es.dll
+ 2008-07-07 20:24:11 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:29 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:29 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:29 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:26 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:29 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-07-14 11:03:00 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
+ 2008-07-11 12:42:28 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
+ 2008-07-11 12:51:51 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-06-24 16:30:27 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP2QFE\mscms.dll
+ 2008-06-24 16:44:02 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3GDR\mscms.dll
+ 2008-06-24 16:53:52 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-04-23 04:16:39 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
+ 2008-04-23 04:16:39 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2008-04-23 04:16:39 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
+ 2008-04-23 04:16:39 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
+ 2008-04-23 04:16:39 63,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
+ 2008-04-22 07:41:08 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2008-04-23 04:16:39 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
+ 2008-04-23 04:16:39 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
+ 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
+ 2008-04-23 04:16:39 383,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2008-04-23 04:16:39 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2008-04-23 04:16:39 6,066,176 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
+ 2008-04-23 04:16:39 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
+ 2008-04-23 04:16:39 267,776 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
+ 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
+ 2008-04-22 07:41:30 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
+ 2008-04-23 04:16:40 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
+ 2008-04-23 04:16:40 459,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
+ 2008-04-23 04:16:40 52,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
+ 2008-04-24 02:16:42 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
+ 2008-04-23 04:16:40 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
+ 2008-04-23 04:16:40 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
+ 2008-04-23 04:16:40 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
+ 2008-04-23 04:16:40 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
+ 2008-04-23 04:16:40 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
+ 2008-04-23 04:16:40 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
+ 2008-04-23 04:16:40 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
+ 2008-04-23 04:16:40 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
+ 2008-04-23 04:16:40 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
+ 2007-05-31 17:35:22 6,420,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040110900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
- 2008-07-26 10:12:22 593,920 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-08-14 10:52:30 593,920 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-07-26 10:12:23 12,288 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-08-14 10:52:30 12,288 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-07-26 10:12:23 86,016 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-08-14 10:52:30 86,016 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-07-26 10:12:22 135,168 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-08-14 10:52:30 135,168 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-07-26 10:12:23 11,264 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-08-14 10:52:30 11,264 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-07-26 10:12:23 27,136 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-08-14 10:52:30 27,136 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-07-26 10:12:23 4,096 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-08-14 10:52:30 4,096 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-07-26 10:12:23 794,624 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-08-14 10:52:30 794,624 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-07-26 10:12:22 249,856 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-08-14 10:52:30 249,856 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-07-26 10:12:22 61,440 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-08-14 10:52:30 61,440 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-07-26 10:12:23 23,040 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-08-14 10:52:31 23,040 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-07-26 10:12:22 286,720 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-08-14 10:52:30 286,720 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-07-26 10:12:22 409,600 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-08-14 10:52:30 409,600 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-04-23 04:16:39 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-06-23 16:28:17 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
- 2008-04-23 04:16:39 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-06-23 16:28:17 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2008-04-23 04:16:39 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-06-23 16:28:17 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-04-23 04:16:39 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-06-23 16:28:17 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2005-07-26 04:39:57 243,200 -c--a-w C:\WINDOWS\system32\dllcache\es.dll
+ 2008-07-07 20:31:48 253,952 -c--a-w C:\WINDOWS\system32\dllcache\es.dll
- 2008-04-23 04:16:39 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-06-23 16:28:17 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-04-23 04:16:39 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-06-23 16:28:17 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
- 2008-04-22 07:41:08 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-06-23 09:21:30 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-04-23 04:16:39 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-06-23 16:28:18 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-04-23 04:16:39 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-06-23 16:28:18 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-04-20 05:07:51 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-06-21 05:23:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-04-23 04:16:39 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-06-23 16:28:18 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-04-23 04:16:39 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-06-23 16:28:18 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-04-23 04:16:39 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-06-23 16:28:19 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-04-23 04:16:39 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-06-23 16:28:19 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-04-23 04:16:39 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-06-23 16:28:20 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-04-22 07:41:30 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-06-23 09:21:49 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-08-21 06:17:23 683,520 -c--a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:51:06 683,520 -c--a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
- 2008-04-23 04:16:40 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-23 16:28:20 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2004-08-05 12:00:00 331,776 -c--a-w C:\WINDOWS\system32\dllcache\msadce.dll
+ 2008-05-01 14:31:48 331,776 -c--a-w C:\WINDOWS\system32\dllcache\msadce.dll
- 2005-06-29 01:49:41 74,240 -c--a-w C:\WINDOWS\system32\dllcache\mscms.dll
+ 2008-06-24 16:23:56 74,240 -c--a-w C:\WINDOWS\system32\dllcache\mscms.dll
- 2008-04-23 04:16:40 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-06-23 16:28:20 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-04-23 04:16:40 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-06-23 16:28:20 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-04-24 02:16:42 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-06-24 14:28:24 3,592,192 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-04-23 04:16:40 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-06-23 16:28:22 477,696 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-04-23 04:16:40 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-06-23 16:28:22 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-04-23 04:16:40 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-06-23 16:28:22 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-04-23 04:16:40 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-06-23 16:28:22 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2008-04-23 04:16:40 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-06-23 16:28:22 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2008-04-23 04:16:40 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-06-23 16:28:22 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
- 2008-04-23 04:16:40 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-06-23 16:28:23 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-04-23 04:16:40 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-06-23 16:28:23 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-04-23 04:16:40 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-06-23 16:28:23 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2008-04-23 04:16:39 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-06-23 16:28:17 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-04-23 04:16:39 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-06-23 16:28:17 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-04-23 04:16:39 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-06-23 16:28:17 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2008-08-03 15:43:08 150,792 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-18 19:40:39 147,608 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-04-23 04:16:39 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-06-23 16:28:17 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2008-04-22 07:41:08 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-06-23 09:21:30 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2008-04-23 04:16:39 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-06-23 16:28:18 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2008-04-23 04:16:39 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-06-23 16:28:18 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2008-04-20 05:07:51 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-06-21 05:23:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
- 2008-04-23 04:16:39 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-06-23 16:28:18 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-04-23 04:16:39 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-06-23 16:28:18 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2008-04-23 04:16:39 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-06-23 16:28:19 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2008-04-23 04:16:39 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-06-23 16:28:19 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
- 2008-04-23 04:16:39 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-06-23 16:28:20 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2008-04-22 07:39:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2007-08-21 06:17:23 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 18:51:06 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2008-04-23 04:16:40 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-06-23 16:28:20 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2008-06-25 16:15:46 17,972,344 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-08-05 18:11:01 15,888,504 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-04-23 04:16:40 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-06-23 16:28:20 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2008-04-23 04:16:40 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-06-23 16:28:20 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-04-24 02:16:42 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-06-24 14:28:24 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-04-23 04:16:40 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-06-23 16:28:22 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-04-23 04:16:40 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-06-23 16:28:22 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
- 2008-04-23 04:16:40 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-06-23 16:28:22 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
- 2008-04-23 04:16:40 102,912 ----a-w C:\WINDOWS\system32\occache.dll
+ 2008-06-23 16:28:22 102,912 ----a-w C:\WINDOWS\system32\occache.dll
- 2008-04-23 04:16:40 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-06-23 16:28:22 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2007-11-30 12:39:29 18,296 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:19:06 18,296 ------w C:\WINDOWS\system32\spmsg.dll
- 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 ------w C:\WINDOWS\system32\tzchange.exe
- 2008-04-23 04:16:40 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-06-23 16:28:22 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2008-04-23 04:16:40 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-06-23 16:28:23 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2008-04-23 04:16:40 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-06-23 16:28:23 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2008-02-14 14:54 1555480 --a------ C:\Program Files\free-downloads.net\tbfree.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 08:00 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-03-14 07:55 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43 8466432]
"Eye On Network"="C:\Program Files\Eye On Network\Eye On Network.exe" [2003-09-13 13:47 1553920]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-08-21 11:15 1192336]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-08-21 11:17 1966128]
"Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe" [2007-08-20 19:20 148760]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43 81920]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 15:07 90112 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 08:00 15360]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
CoreCenter.lnk - C:\Program Files\MSI\Core Center\CoreCenter.exe [2007-07-02 17:56:45 840704]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
Logiciel Kodak EasyShare.lnk - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-05-10 07:15:28 282624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
"msacm.g723"= g723.acm
"vidc.I263"= I263_32.drv
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BlackICE PC Protection.lnk]
backup=C:\WINDOWS\pss\BlackICE PC Protection.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
backup=C:\WINDOWS\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Kodak software updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
backup=C:\WINDOWS\pss\Logiciel Kodak EasyShare.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mario Després^Menu Démarrer^Programmes^Démarrage^Enregistrement d'un produit Joint Operations Typhoon Rising.lnk]
backup=C:\WINDOWS\pss\Enregistrement d'un produit Joint Operations Typhoon Rising.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDSwitchAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaGateway
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\Sierra\\FEAR\\fpupdate.exe"=
"C:\\Program Files\\ASUS\\ASUS GameFace Live\\GameFace.exe"=
"C:\\Program Files\\Powerboat GT\\Run.exe"=
"F:\\carbon\\NFSC.exe"=
"F:\\xpandrally.exe"=
"F:\\Program Files\\Supreme Commander\\bin\\SupremeCommander.exe"=
"F:\\Program Files\\GPGNet\\GPG.Multiplayer.Client.exe"=
"E:\\mc2.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"F:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"50171:TCP"= 50171:TCP:utorrent
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys [2006-07-05 08:46]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 11:11]
R0 vIdeBus;vIdeBus;C:\WINDOWS\system32\DRIVERS\vIdeBus.sys [2007-06-25 15:12]
R0 vIdePort;VIA IDE Controller PORT Driver;C:\WINDOWS\system32\DRIVERS\vIdePort.sys [2007-06-25 15:12]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-06-25 14:45]
R3 PCAlertDriver;PCAlertDriver;C:\Program Files\MSI\Core Center\NTGLM7X.sys [2004-11-16 09:27]
R3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys [2004-11-16 11:54]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys [2004-07-06 19:56]
S0 black;black;C:\WINDOWS\system32\drivers\BlackDrv.sys []
S2 nvtvSND;nVidia WDM TVAudio Crossbar;C:\WINDOWS\system32\DRIVERS\nvtvsnd.sys []
S3 atidgllk;atidgllk;C:\Program Files\ASUS\SmartDoctor\atidgllk.sys [2004-06-16 14:34]
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 Fadpu16E;Fadpu16E;C:\WINDOWS\TEMP\Fadpu16E.sys []
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-02-25 19:26]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-02-25 19:26]
S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;C:\WINDOWS\system32\drivers\usbscan.sys [2004-08-03 23:58]
S3 SIWIO;SIWIO;C:\WINDOWS\TEMP\SiwIo.sys []
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S4 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5fc3fa98-f418-11dc-80ff-00110903e472}]
\Shell\AutoRun\command - G:\autorun.exe
*Newly Created Service* - PCALERTDRIVER
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-08-02 C:\WINDOWS\Tasks\EasyShare Registration Task.job
- C:\WINDOWS\system32\rundll32.exe [2004-08-05 08:00]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-19 19:05:51
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\temp\bwgo000251ee.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-19 19:12:28 - machine was rebooted [Mario Després]
ComboFix-quarantined-files.txt 2008-08-19 23:12:24
Pre-Run: 1,815,183,360 octets libres
Post-Run: 1,802,141,696 octets libres
507 --- E O F --- 2008-08-14 10:53:04
Répondre à tinomme1969
et voila le dernier hijachthis.merci.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31:42, on 2008-08-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eye On Network\Eye On Network.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo0000e762.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: (PopUpCop) Allow images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/allowimages
O8 - Extra context menu item: (PopUpCop) Block images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/blockimages
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Hawaiian%20Explorer%20-%20Lost%20Island/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9496 bytes
Répondre à tinomme1969
Désactive toute protection résidente ( antivirus…) ! <------- Pense-y !
Copie le texte se situant dans le cadre ci-dessous : ( Ctrl + C )
| Citation : Driver::
|
=> Ouvre le Bloc Notes : Démarrer > Tous les programmes > Accessoires > Bloc notes
- Colles y le texte (CTRL + V)
- Enregistre ce fichier dans : Bureau
- Nom du fichier : CFScript
- Type du fichier : tous les fichiers !!
- Clique sur Enregistrer
- Quitte le Bloc Notes
Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
* Cela va relancer Combofix : au message qui apparaît ( Type 1 to continue, or 2 to abort), tape 1 puis valide.
* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
* Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher : Copie/Colle son contenue sur le forum.
Si le fichier ne s'ouvre pas, il se trouve ici : C:\ComboFix.txt
* Poste un nouveau rapport hijackthis.
Sécurité / Prévention
Répondre à Egwene
ComboFix 08-08-19.02 - Mario Després 2008-08-20 13:33:52.11 - NTFSx86
Endroit: C:\Documents and Settings\Mario Després\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mario Després\Bureau\cfscript.txt
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
FILE ::
C:\DOCUME~1\MARIOD~1\LOCALS~1\temp\bwgo000251ee.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\d3temp
C:\d3temp\bubles-804.wav
.
---- Previous Run -------
.
C:\WINDOWS\jestertb.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AVFLT
-------\Legacy_BLACK
-------\Legacy_BOONTY_GAMES
-------\Legacy_FADPU16E
-------\Legacy_NVTVSND
-------\Legacy_SIWIO
-------\Service_AvFlt
-------\Service_black
-------\Service_Boonty Games
-------\Service_Fadpu16E
-------\Service_nvtvSND
-------\Service_SIWIO
((((((((((((((((((((((((((((( Fichiers créés 2008-07-20 to 2008-08-20 ))))))))))))))))))))))))))))))))))))
.
2008-08-19 06:15 . 2008-08-19 06:18 <REP> d-------- C:\Program Files\Hawaiian Explorer - Lost Island
2008-08-17 14:56 . 2008-08-17 14:56 <REP> d-------- C:\Program Files\Conduit
2008-08-17 14:55 . 2008-08-17 14:56 <REP> d-------- C:\Program Files\free-downloads.net
2008-08-15 20:23 . 2008-08-15 20:52 <REP> d-------- C:\Program Files\Wild West Quest
2008-08-13 08:53 . 2008-08-13 08:53 <REP> d-------- C:\Documents and Settings\antoine\Application Data\Skinux
2008-08-11 11:46 . 2008-08-11 11:46 <REP> d-------- C:\Documents and Settings\Mario Després\Application Data\Skinux
2008-08-10 06:41 . 2008-08-10 06:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Slapdash Games
2008-08-09 15:49 . 2008-08-09 15:49 230,776 --a------ C:\aswclear.exe
2008-08-07 20:41 . 2008-08-13 19:01 <REP> d-------- C:\WINDOWS\SmitfraudFix
2008-08-07 11:04 . 2008-08-07 11:04 <REP> d-------- C:\Program Files\Avira
2008-08-07 11:04 . 2008-08-07 11:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-06 22:06 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 22:06 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-06 07:38 . 2008-08-06 07:38 <REP> d-------- C:\Program Files\Sun
2008-08-05 07:04 . 2008-08-05 07:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TheRace_dev
2008-08-03 12:55 . 2008-08-03 12:55 <REP> d-------- C:\Documents and Settings\Mario Després\Application Data\Malwarebytes
2008-08-03 12:55 . 2008-08-03 12:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-03 11:44 . 2008-08-03 11:45 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-03 10:43 . 2008-08-03 10:43 <REP> d-------- C:\Program Files\Trend Micro
2008-08-02 21:19 . 2008-08-02 21:19 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 21:14 . 2008-08-02 21:17 15,083,520 --a------ C:\spybotsd160.exe
2008-08-02 15:58 . 2008-08-02 15:58 <REP> d-------- C:\Documents and Settings\marie josée\Application Data\Skinux
2008-08-02 13:13 . 2008-08-02 13:48 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-08-02 13:06 . 2008-08-02 14:01 <REP> d-------- C:\Program Files\Kodak
2008-08-02 08:10 . 2008-08-02 08:12 <REP> d-------- C:\Program Files\Cactus Bruce and the Corporate Monkeys
2008-08-02 08:03 . 2008-08-02 08:03 <REP> d-------- C:\Program Files\Nemo's Aquarium 3D
2008-08-02 08:03 . 2004-01-30 15:31 3,594,576 --a------ C:\WINDOWS\Nemo's Aquarium 3D Anemonen-Feld.scr
2008-08-02 08:03 . 2004-01-30 15:31 3,494,207 --a------ C:\WINDOWS\Nemo's Aquarium 3D Korallenriff.scr
2008-08-01 20:33 . 2008-08-04 12:20 <REP> d-------- C:\Program Files\The Mystery Of The Crystal Portal
2008-07-30 08:53 . 2008-07-30 08:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\The Revills Games
2008-07-22 09:43 . 2008-07-22 09:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Media Art
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-20 17:37 --------- d-----w C:\Program Files\Eye On Network
2008-08-20 17:16 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\uTorrent
2008-08-19 13:01 --------- d-----w C:\Program Files\X-masTree
2008-08-19 10:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-17 22:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-17 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-15 15:45 --------- d-----w C:\Program Files\GameHouse
2008-08-15 15:45 --------- d-----w C:\Program Files\GameFiesta
2008-08-13 13:51 --------- d-----w C:\Program Files\iWin.com
2008-08-11 15:40 3,870 ----a-w C:\WINDOWS\system32\tmp.reg
2008-08-09 23:27 --------- d-----w C:\Program Files\Zylom Games
2008-08-09 13:25 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Zylom
2008-08-07 15:38 --------- d-----w C:\Program Files\iWin Games
2008-08-06 14:19 --------- d-----w C:\Program Files\Java
2008-08-06 11:45 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-05 19:40 --------- d-----w C:\Program Files\Blood Ties
2008-08-04 17:23 --------- d-----w C:\Program Files\Unicorn Castle
2008-08-02 17:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-07-23 17:41 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-22 10:51 --------- d-----w C:\Program Files\SuperMarioPac
2008-07-20 00:33 --------- d-----w C:\Documents and Settings\marie josée\Application Data\ForgottenRiddles2
2008-07-19 10:33 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Gold Casual Games
2008-07-19 10:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Gold Casual Games
2008-07-15 18:43 --------- d-----w C:\Program Files\RealArcade
2008-07-15 18:42 --------- d-----w C:\Program Files\Oberon Media
2008-07-14 20:05 --------- d-----w C:\Documents and Settings\marie josée\Application Data\EnchantedCavern
2008-07-13 16:49 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\LimeWire
2008-07-12 12:46 --------- d-----w C:\Program Files\Lavasoft
2008-07-12 12:44 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\Lavasoft
2008-07-12 12:42 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-12 12:00 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\AlauxSoft
2008-07-08 22:42 --------- d-----w C:\Program Files\The Pini Society
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-04 12:29 --------- d-----w C:\Documents and Settings\Mario Després\Application Data\Meridian93
2008-07-04 11:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Arkadium
2008-07-02 13:08 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Meridian93
2008-07-02 10:37 --------- d-----w C:\Program Files\Turtix Rescue Adventure
2008-07-01 14:12 --------- d-----w C:\Program Files\Turtix 2 - Rescue Adventures
2008-06-28 14:13 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Ancient Quest of Saqqarah__bfg
2008-06-28 01:21 --------- d-----w C:\Documents and Settings\marie josée\Application Data\Reflexive
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 01:49 --------- d-----w C:\Program Files\The Lost Cases Of Sherlock Holmes
2008-06-20 01:35 --------- d-----w C:\Documents and Settings\marie josée\Application Data\MysteryStudio
2008-03-21 07:05 7,407,104 ----a-w C:\Program Files\Limewire PRO 4.17.5.EXE
2008-03-01 12:30 0 ----a-w C:\Program Files\temp01
2007-10-29 15:29 7,467,056 ----a-w C:\Program Files\spybotsd15.exe
2007-01-09 02:14 4,049,311 ----a-w C:\Program Files\liveupdate.exe
2006-12-05 02:07 497 ----a-w C:\Program Files\Raccourci vers lumieres.lnk
2006-12-05 01:58 9,440 ----a-w C:\Program Files\lumieres.zip
2006-11-29 02:35 817 -c--a-w C:\Program Files\recoil.err
2006-08-28 23:39 983,745 ----a-w C:\Program Files\PowerpointImageExtractor.zip
2006-03-07 03:07 31,944 ----a-w C:\Program Files\Uninst.isu
2006-02-03 16:53 243,512 ----a-w C:\Program Files\jre-1_5_0_06-windows-i586-p-iftw.exe
2005-10-29 02:45 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2004-03-11 17:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
1999-10-06 21:40 1,765,376 ------w C:\Documents and Settings\Mario Després\SETUPENU.DLL
1999-10-06 21:40 1,765,376 ------w C:\Documents and Settings\Mario Després\SETUPENU.DLL
1999-01-12 21:19 75,776 ----a-w C:\Program Files\messages.dll
1998-11-06 19:50 57,344 ----a-w C:\Program Files\Uninst.dll
1998-11-04 16:41 201,216 ----a-w C:\Program Files\a3dapi.dll
1997-10-09 20:54 30,720 ----a-w C:\Program Files\regsvr32.exe
2008-03-31 16:12 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
2007-10-01 18:17 1,199,508 --sha-w C:\WINDOWS\system32\wbem\mof\good\mirc.exe
2008-03-13 12:08 172 --sha-w C:\WINDOWS\system32\wbem\mof\good\start.bat
2007-09-23 19:05 147 --sha-w C:\WINDOWS\system32\wbem\mof\good\start.reg
2008-03-12 14:56 107 --sha-w C:\WINDOWS\system32\wbem\mof\good\winhelp.vbe
.
((((((((((((((((((((((((((((( snapshot_2008-08-19_19.12.05.39 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-18 19:40:39 147,608 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-20 17:24:38 147,608 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2008-02-14 14:54 1555480 --a------ C:\Program Files\free-downloads.net\tbfree.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 08:00 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-03-14 07:55 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43 8466432]
"Eye On Network"="C:\Program Files\Eye On Network\Eye On Network.exe" [2003-09-13 13:47 1553920]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-08-21 11:15 1192336]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-08-21 11:17 1966128]
"Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe" [2007-08-20 19:20 148760]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43 81920]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 15:07 90112 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 08:00 15360]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
CoreCenter.lnk - C:\Program Files\MSI\Core Center\CoreCenter.exe [2007-07-02 17:56:45 840704]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
Logiciel Kodak EasyShare.lnk - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-05-10 07:15:28 282624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
"msacm.g723"= g723.acm
"vidc.I263"= I263_32.drv
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BlackICE PC Protection.lnk]
backup=C:\WINDOWS\pss\BlackICE PC Protection.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
backup=C:\WINDOWS\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Kodak software updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
backup=C:\WINDOWS\pss\Logiciel Kodak EasyShare.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mario Després^Menu Démarrer^Programmes^Démarrage^Enregistrement d'un produit Joint Operations Typhoon Rising.lnk]
backup=C:\WINDOWS\pss\Enregistrement d'un produit Joint Operations Typhoon Rising.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDSwitchAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaGateway
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\Sierra\\FEAR\\fpupdate.exe"=
"C:\\Program Files\\ASUS\\ASUS GameFace Live\\GameFace.exe"=
"C:\\Program Files\\Powerboat GT\\Run.exe"=
"F:\\carbon\\NFSC.exe"=
"F:\\xpandrally.exe"=
"F:\\Program Files\\Supreme Commander\\bin\\SupremeCommander.exe"=
"F:\\Program Files\\GPGNet\\GPG.Multiplayer.Client.exe"=
"E:\\mc2.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"F:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"50171:TCP"= 50171:TCP:utorrent
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys [2006-07-05 08:46]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 11:11]
R0 vIdeBus;vIdeBus;C:\WINDOWS\system32\DRIVERS\vIdeBus.sys [2007-06-25 15:12]
R0 vIdePort;VIA IDE Controller PORT Driver;C:\WINDOWS\system32\DRIVERS\vIdePort.sys [2007-06-25 15:12]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-06-25 14:45]
R3 PCAlertDriver;PCAlertDriver;C:\Program Files\MSI\Core Center\NTGLM7X.sys [2004-11-16 09:27]
R3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys [2004-11-16 11:54]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys [2004-07-06 19:56]
S3 atidgllk;atidgllk;C:\Program Files\ASUS\SmartDoctor\atidgllk.sys [2004-06-16 14:34]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-02-25 19:26]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-02-25 19:26]
S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;C:\WINDOWS\system32\drivers\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5fc3fa98-f418-11dc-80ff-00110903e472}]
\Shell\AutoRun\command - G:\autorun.exe
*Newly Created Service* - PCALERTDRIVER
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-08-02 C:\WINDOWS\Tasks\EasyShare Registration Task.job
- C:\WINDOWS\system32\rundll32.exe [2004-08-05 08:00]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-20 13:40:43
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\temp\bwgo00030706.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-20 13:48:41 - machine was rebooted [Mario Després]
ComboFix-quarantined-files.txt 2008-08-20 17:48:37
ComboFix2.txt 2008-08-19 23:12:29
Pre-Run: 1,737,019,392 octets libres
Post-Run: 1,718,894,592 octets libres
289 --- E O F --- 2008-08-14 10:53:04
Répondre à tinomme1969
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:50:54, on 2008-08-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Eye On Network\Eye On Network.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo00030706.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: (PopUpCop) Allow images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/allowimages
O8 - Extra context menu item: (PopUpCop) Block images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/blockimages
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Hawaiian%20Explorer%20-%20Lost%20Island/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9677 bytes
salut,ya tout ce que tu m as demandé! a+
Répondre à tinomme1969
Re,
Ouvre le gestionnaire des tâches, ( Ctrl + Alt + Suppr ), onglet processus et stoppe toutes les occurrences du processus suivant :
C:\DOCUME~1\MARIOD~1\LOCALS~1\temp\bwgo00030706.exe
Ensuite :
[~]Aller dans poste de travail/outils/option des dossiers/affichage/afficher les fichiers et dossiers cachés/Appliquer - - > OK
[~]Aller dans poste de travail/outils/option des dossiers/affichage/décocher masquer les fichiers protégés du système d'exploitation./Appliquer - - > OK
Tu recocheras après.
[~] Poste de travail/outils/option des dossiers/affichage/décocher masquer les extensions dont le type est connu./Appliquer - - > OK
Puis supprime le fichier suivant en gras manuellement : ( clic droit, supprimer )
C:\DOCUME~1\MARIOD~1\LOCALS~1\temp\bwgo00030706.exe
Redémarre le PC et poste un nouveau rapport HijackThis.
Sécurité / Prévention
Répondre à Egwene
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:18:14, on 2008-08-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eye On Network\Eye On Network.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo00011f5a.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: (PopUpCop) Allow images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/allowimages
O8 - Extra context menu item: (PopUpCop) Block images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/blockimages
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Hawaiian%20Explorer%20-%20Lost%20Island/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9668 bytes
Répondre à tinomme1969
Puis supprime le fichier suivant en gras manuellement : ( clic droit, supprimer )
C:\DOCUME~1\MARIOD~1\LOCALS~1\temp\bwgo00030706.exe
supprimé a partir du gestionnaire des taches puis a partir d une recherche de dossier.est-ce ok comme ca?
Répondre à tinomme1969
Bonjour,
Oui tu supprimes le processus à partir du gestionnaire des tâches puis le fichier à l'aide de windows explorer, c'est-à-dire en naviguant jusqu'au fichier en question.
Il y a un problème ou c'est bon ?
Sécurité / Prévention
Répondre à Egwene
c est bon. j crois avoir tout supprimé.
que fait-on maintenant?
Répondre à tinomme1969
Re,
Tu me postes un nouveau rapport HijackThis.
Sécurité / Prévention
Répondre à Egwene
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:17, on 2008-08-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eye On Network\Eye On Network.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo038b809e.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-436374069-1960408961-839522115-1007\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'marie josée')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: (PopUpCop) Allow images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/allowimages
O8 - Extra context menu item: (PopUpCop) Block images... - res://C:\PROGRA~1\PopUpCop\PopUpCop.dll/blockimages
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Hawaiian%20Explorer%20-%20Lost%20Island/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9910 bytes
Répondre à tinomme1969
Re,
Hum... on va procéder autrement, il reste un truc pas net.
Téléchargez OTScanIt.exe sur votre Bureau, et faites un double clic dessus pour extraire les fichiers. Ceci va créer un dossier nommé OTScanIt sur votre Bureau.
N.B : Si pendant le téléchargement et/ou l’installation tu reçois une alerte de ton antivirus, ignore-là. Certains composants de OTscanIT peuvent être détectés comme un virus par certains antivirus. Pense aussi à désactiver tes protections résidentes durant la procédure.
Note : Vous devez avoir ouvert une session avec un compte ayant les droits Administrateur pour exécuter ce programme.
- Fermez TOUS LES AUTRES PROGRAMMES.
- Ouvrez le dossier OTScanIt et faites un double clic sur OTScanIt.exe pour lancer le programme (si vous êtes sous Windows Vista, faites un clic droit sur le programme et choisissez Exécuter en tant qu'Administrateur).
- Dans la section Drivers cliquez sur Non-Microsoft.
- Sous Additional Scans cochez la case située devant les éléments suivants afin de les sélectionner :
Reg - BotCheck
File - Additional Folder Scans
- Ne modifiez aucun autre paramètre.
- Ensuite, cliquez sur le bouton Run Scan dans la barre d'outils.
- Laissez le programme tourner sans intervenir.
- Lorsque l'analyse est terminée le Bloc-notes va s'ouvrir pour afficher le fichier rapport.
- Cliquez sur le menu Format et vérifiez que Retour automatique à la ligne n'est pas coché. S'il l'est, cliquez dessus afin de le décocher.
- Upload-moi le rapport sur Mediafire.
Uploader un fichier sur mediafire :
- Rends-toi sur ce lien : http://www.mediafire.com/
- Clique en haut sur "Upload files To Media fire". Choisis ensuite "I want to upload without an account"
- Une fenêtre de ton explorateur windows va s'ouvrir. Navigue jusqu'au rapport que je te demande d'uploader, sélectionne-le puis clique sur "ouvrir".
- Clique ensuite sur "Upload".
- A droite de l'écran, choisis : "upload to a new folder". Laisse le nom par défaut ( = la date )
- Valide et laisse l'upload se faire.
- Clique sur "Vieuw uploaded file" et copie-moi l'url ( = le lien ) du nouvel onglet ou de la nouvelle fenêtre qui va s'ouvrir dans ton prochain message. Ainsi, je pourrais télécharger le rapport demandé.
Sécurité / Prévention
Répondre à Egwene
ouaou!!! nouvelle manip pour moi... j aime`,-}
a+ ma puce(façon de parler)loll
Répondre à tinomme1969
et voila l travail.rapide le scan...
http://www.mediafire.com//?shareke [...] facb4f1619
Répondre à tinomme1969
Re,
1) On va maintenant devoir modifier le registre. Modifier le registre peut se révéler être très dangereux, c'est pourquoi nous allons créer une sauvegarde du registre avant d'effectuer nos modifications. Ainsi, en cas de souci, il n'y aura qu'à restaurer.
Merci de procéder EXACTEMENT comme décrit ci-dessous :
Télécharge ERUNT
( ERUNT = Emergency Recovery Utility NT, c'est un programme gratuit qui te permet de conserver une sauvegarde complète de ta base de registre et de la restaurer quand cela s'avère nécessaire )
- Installe ERUNT en suivant les instructions suivantes
( suis les directives d'installation par défaut, mais dis non quand on te demande d'ajouter ERUNT au startup folder ( dossier start up ), d'autant plus que si tu le souhaites tu pourras ajouter cette option ultérieurement )
- Lance ERUNT ( soit en double-cliquant sur l'icône présente sur ton bureau soit en choisissant de lancer le programme en fin d'installation )
- Choisis un emplacement pour la sauvegarde ( l'emplacement par défaut est : C:\WINDOWS\ERDNT ce qui est acceptable ).
- Assure-toi que les deux premières cases suivantes soient bien cochées !!!
- Clique sur OK
- Clique sur YES pour créer le dossier de sauvegarde.
2) Désactive toutes tes protections résidentes ( antivirus, etc. ) !
Ouvrez le dossier OTScanIt et faites un double clic sur OTScanIt.exe pour lancer le programme (si vous êtes sous Windows Vista, faites un clic droit sur le programme et choisissez Exécuter en tant qu'Administrateur).
Faites un copier/coller des informations de la zone Code ci-dessous dans la zone de saisie intitulée "Paste fix here" puis cliquez sur le bouton Run Fix.
[Kill Explorer]
|
L'exécution devrait être très rapide. Lorsque la correction est terminée, soit vous verrez un message vous annonçant que c'est fini (finished), soit vous serez invité à faire redémarrer le PC pour terminer l'exécution. Si c'est fini, cliquez sur le bouton Ok et le Bloc-notes va s'ouvrir pour afficher un rapport de toutes les actions réalisées. Envoyez ces informations en réponse.
Si un redémarrage est nécessaire, cliquez sur le bouton "Yes" pour faire redémarrer la machine. Après ce redémarrage, OTScanIt va finir de déplacer les fichiers qui ne pouvaient pas l'être précédemment, puis le Bloc-notes va s'ouvrir et afficher à ce moment-là les résultats finaux. Envoyez ces informations en réponse.
Sécurité / Prévention
Répondre à Egwene
et voila. c est fait
Explorer killed successfully
[Processes - Non-Microsoft Only]
Unable to kill process bwgo038b809e.exe .
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo038b809e.exe moved successfully.
[Driver Services - Non-Microsoft Only]
Service bdpredir stopped successfully.
Service bdpredir deleted successfully.
File C:\Program Files\Softwin\BitDefender10\bdpredir.sys not found.
Service GMSIPCI stopped successfully.
Service GMSIPCI deleted successfully.
File D:\INSTALL\GMSIPCI.SYS not found.
Service mohfilt stopped successfully.
Service mohfilt deleted successfully.
File C:\WINDOWS\System32\drivers\mohfilt.sys not found.
Service Profos stopped successfully.
Service Profos deleted successfully.
File C:\PROGRA~1\Softwin\BITDEF~2\profos.sys not found.
Service Trufos stopped successfully.
Service Trufos deleted successfully.
File C:\PROGRA~1\Softwin\BITDEF~2\trufos.sys not found.
[Registry - Non-Microsoft Only]
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\(PopUpCop) Allow images...\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\(PopUpCop) Block images...\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Anti-Banner\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Open Image in New Window\ deleted successfully.
[Files/Folders - Modified Within 30 days]
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo00011f5a.exe moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo0241e160.exe moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo027925c1.exe moved successfully.
File C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo038b809e.exe not found!
File C:\Documents and Settings\Mario Després\Local Settings\temp\_inst1.exe not found!
File C:\Documents and Settings\Mario Després\Local Settings\temp\_inst2.exe not found!
File C:\Documents and Settings\Mario Després\Local Settings\temp\_inst3.exe not found!
C:\WINDOWS\temp\bwgo003d0c0d.exe moved successfully.
C:\WINDOWS\temp\bwgo02ad7839.exe moved successfully.
C:\WINDOWS\temp\SIntf16.dll moved successfully.
C:\WINDOWS\temp\SIntf32.dll moved successfully.
C:\WINDOWS\temp\SIntfNT.dll moved successfully.
[Extra Files]
< Purity >
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo007dd1d6.exe scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt by OldTimer - Version 1.0.16.2 fix logfile created on 08222008_165249
Files moved on Reboot...
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo007dd1d6.exe moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\Application Data\Mozilla\Firefox\Profiles\7g53ffgl.default\XUL.mfl moved successfully.
ca semble bien ....?!?!?
Répondre à tinomme1969
Re,
Hum... Oui ça s'annonce bien
Peux-tu refaire un scan avec OtscanIT et m'uploader ce nouveau rapport sur mediafire ?
Sinon où en es-tu de tes problèmes ?
Sécurité / Prévention
Répondre à Egwene
le scan,je te le fait de la meme facon que dans le post plus haut?
Message édité par tinomme1969 le 23-08-2008 à 22:01:07
Répondre à tinomme1969
Re,
Oui.
Sécurité / Prévention
Répondre à Egwene
ok!!! un rapport otscan ,UN!
Répondre à tinomme1969
eh ben,j ai plus de windows security center dans le panneau de configuration mais je n ai pas de centre de securité xp non plus.
j ai certains raccourcis bureau qui ne fonctionnent plus( big fish game,etc..)
et si je clic sur le raccourci windows live mail pour atteindre la page d accueil msn,ben ya connection en cours qui s affiche mais plus rien. je dois cliquer sur maison pour qu elle s ouvre finalement dans un deuxieme onglet,mais ca n arrive pas si j ai deja ouvert une session firefox.
Répondre à tinomme1969
Re,
Le rapport n'est pas net, mais on verra ça par la suite. On va reprendre depuis le début.
D'abord j'aimerais que tu fasses la manip' ci-dessous si tu as ton CD de windows :
On va effectuer une réparation du système. Pour cela procède comme suit :
- Insère ton CD de windows dans ton lecteur ( il faut que le CD corresponde à ta version de windows ).
- Ferme toutes les programmes, fenêtres et applications en cours.
- Déconnecte-toi d'internet.
- Menu démarrer > exécuter.
- Dans la fenêtre qui apparaît, tape : sfc /scannow puis valide par entrée.
- Le PC va travailler, laisse-le tourner, cela peut prendre un bon moment.
- Reviens me dire quand cela est fait.
Sécurité / Prévention
Répondre à Egwene
c est fait.même 2 fois car avant que le premier scan soit terminé,ya eu reboot système avec message de récupération d erreur majeure ou sérieuse...enfin ça concernait 2 dossiers temp bfw.........
le deuxième s est bien passé par contre.
Répondre à tinomme1969
| Citation : enfin ça concernait 2 dossiers temp bfw......... |
Si tu as le message d'erreur je suis preneur, puisqu'il concerne des fichiers que je cherche à supprimer
Poste aussi un nouveau rapport HijackThis.
Sécurité / Prévention
Répondre à Egwene
j ai trouvé ce qui semble etre un rapport d erreur dans c:windows/minidump mais j sais pas l ouvrir.fichier .dmp.
je l ai uploadé sur mediafire:http://www.mediafire.com/?sharekey=2924aa48b154f489ab1eab3e9fa335ca257225ff66a16a2b
Répondre à tinomme1969
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:32:40, on 2008-08-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eye On Network\Eye On Network.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\MARIOD~1\LOCALS~1\Temp\bwgo0065ca0b.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/defaultf.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Eye On Network] C:\Program Files\Eye On Network\Eye On Network.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-436374069-1960408961-839522115-1007\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'marie josée')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C
Program%20Files/Hawaiian%20Explorer%20-%20Lost%20Island/Images/stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/control [...] oader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 5274281718
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab2.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com [...] 0_4_12.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C
Program%20Files/Little%20Shop%20-%20Road%20Trip/Images/armhelper.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn. [...] Atchmt.ocx
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Seagate\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9410 bytes
Répondre à tinomme1969
Bonsoir,
Toutes mes excuses pour ce délais trop long
Tu es toujours avec moi ?
J'attends ta réponse pour être sûr.
Sécurité / Prévention
Répondre à Egwene
bien sur que j suis la!!!! je n abandonne jamais. c est quand tu veux :-)
tu as eu le temps d analyser le dernier rapport?
le fichier bfg...big fish game.
Répondre à tinomme1969
Oué, je te réponds maintenant, laisse-moi le temps de te préparer une procédure
Sécurité / Prévention
Répondre à Egwene
Re,
Bon, pour tes problèmes de centre de sécurité disparu, je n'ai pas trop d'idées, mais je vais chercher. Ton rapport est plutôt bon, à part une série de fichiers vraiment bizarres qui semblent ne pas vouloir dégager
On va procéder ainsi :
!!! Pense à désactiver tes protections résidentes avant de faire les manip' ci-dessous !!! ( antivirus, anti-spyware etc. )
1) Ouvrez le dossier OTScanIt et faites un double clic sur OTScanIt.exe pour lancer le programme (si vous êtes sous Windows Vista, faites un clic droit sur le programme et choisissez Exécuter en tant qu'Administrateur).
Faites un copier/coller des informations de la zone Code ci-dessous dans la zone de saisie intitulée "Paste fix here" puis cliquez sur le bouton Run Fix.
[Kill Explorer]
|
N.B : Le bureau va disparaît c'est normal. De même l'ordinateur va redémarrer tout seul, c'est normal et attendu.
Si un redémarrage est nécessaire, cliquez sur le bouton "Yes" pour faire redémarrer la machine. Après ce redémarrage, OTScanIt va finir de déplacer les fichiers qui ne pouvaient pas l'être précédemment, puis le Bloc-notes va s'ouvrir et afficher à ce moment-là les résultats finaux. Envoyez ces informations en réponse.
2) Télécharge OTViewIt et sauvegarde-le sur ton bureau.
- Ferme toutes les fenêtres et double-clique sur l'icône d'OTviewIT pour l'ouvrir.
- Clique sur le bouton Run Scan et laisse le programme travailler sans l'interrompre.
- Il va produire deux rapports, l'un nommé OTViewIt.txt, et un autre nommé Extras qui sera sauvegardé sur ton bureau. Merci de me poster les deux rapports dans ta prochaine réponse.
- Un rapport par message ! Merci. Ils sont longs alors veille à me les poster en entier
Sécurité / Prévention
Répondre à Egwene
pour le centre de sécurité, te casse pas la tête.j ai pas l icône dans le panneau de config mais il existe.ie:le bouclier marqué d un x s affiche quand je désactive mon antivirus alors....
[Processes - Non-Microsoft Only]
Unable to kill process bwgo04eebffa.exe .
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo04eebffa.exe moved successfully.
[Files/Folders - Created Within 30 days]
C:\WINDOWS\NV29922996.TMP folder deleted successfully.
[Files/Folders - Modified Within 30 days]
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo0026abf6.exe moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo0303d8b6.exe moved successfully.
C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo03957199.exe moved successfully.
File C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo04eebffa.exe not found!
C:\WINDOWS\temp\bwgo002e4064.exe moved successfully.
C:\WINDOWS\temp\bwgo03906628.exe moved successfully.
C:\WINDOWS\temp\bwgo03e5a5d3.exe moved successfully.
< End of fix log >
OTScanIt by OldTimer - Version 1.0.16.2 fix logfile created on 08292008_083812
Files moved on Reboot...
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
Répondre à tinomme1969
OTViewIt logfile created on: 2008-08-29 08:53:26 - Run 1
OTViewIt by OldTimer - Version 1.0.1.0 Folder = C:\Documents and Settings\Mario Després\Bureau
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.55 Gb Available Physical Memory | 77.58% Memory free
2.60 Gb Paging File | 2.26 Gb Available in Paging File | 86.87% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 46.89 Gb Total Space | 1.76 Gb Free Space | 3.76% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 27.64 Gb Total Space | 18.82 Gb Free Space | 68.08% Space Free | Partition Type: NTFS
Drive F: | 149.04 Gb Total Space | 121.70 Gb Free Space | 81.66% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MARIO-884D96CE1
Current User Name: Mario Després
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
===== Processes - Non-Microsoft Only =====
[07-20-2004 02:15 PM | 00,090,112 | ---- | M] (ASUSTeK COMPUTER INC.) - C:\WINDOWS\ATKKBService.exe
[09-13-2003 01:47 PM | 01,553,920 | ---- | M] () - C:\Program Files\Eye On Network\Eye On Network.exe
[08-21-2007 11:15 AM | 01,192,336 | ---- | M] (Seagate) - C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
[12-08-2003 05:35 PM | 00,032,768 | ---- | M] (Cyberlink Corp.) - C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[10-08-2004 11:52 AM | 00,221,184 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\LVCOMSX.EXE
[01-18-2005 05:37 PM | 00,217,088 | ---- | M] (Logitech Inc.) - C:\Program Files\Logitech\Video\LogiTray.exe
[03-14-2008 07:55 AM | 00,486,856 | ---- | M] (DT Soft Ltd) - C:\Program Files\DAEMON Tools Lite\daemon.exe
[01-18-2005 05:08 PM | 00,192,512 | ---- | M] (Logitech Inc.) - C:\Program Files\Logitech\Video\FxSvr2.exe
[12-07-2004 04:42 PM | 00,840,704 | ---- | M] () - C:\Program Files\MSI\Core Center\CoreCenter.exe
[05-10-2008 07:15 AM | 00,282,624 | ---- | M] (Eastman Kodak Company) - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
[02-13-2004 02:11 PM | 00,016,384 | ---- | M] () - C:\Documents and Settings\Mario Després\Local Settings\temp\bwgo0000e6c6.exe
===== Win32 Services - Non-Microsoft Only =====
(ATKKeyboardService) ATK Keyboard Service [Auto | Running]
[07-20-2004 02:15 PM | 00,090,112 | ---- | M] (ASUSTeK COMPUTER INC.) - C:\WINDOWS\ATKKBService.exe
===== Driver Services - Non-Microsoft Only =====
(asuskbnt) Enhanced Display Driver Helper Service [System | Running]
[07-20-2004 02:19 PM | 00,020,096 | ---- | M] (ASUSTeK COMPUTER INC.) - C:\WINDOWS\system32\drivers\atkkbnt.sys
(CdaC15BA) CdaC15BA [Auto | Running]
[06-05-2007 09:17 PM | 00,012,464 | ---- | M] (Macrovision Europe Ltd) - C:\WINDOWS\system32\drivers\CdaC15BA.SYS
(EIO) EIO [Auto | Running]
[10-18-2004 11:50 PM | 00,008,576 | R--- | M] (ASUSTeK Computer Inc.) - C:\WINDOWS\system32\drivers\EIO.sys
(FETND5BV) VIA Rhine-Family Fast Ethernet Adapter Driver Service [On_Demand | Running]
[08-08-2005 02:53 PM | 00,043,008 | ---- | M] (VIA Technologies, Inc. ) - C:\WINDOWS\system32\drivers\fetnd5bv.sys
(FETNDIS) Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet [On_Demand | Stopped]
[08-17-2001 04:13 PM | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) - C:\WINDOWS\system32\drivers\fetnd5.sys
(FETNDISB) VIA Rhine Family Fast Ethernet Adapter Driver Service [On_Demand | Stopped]
[04-14-2004 10:57 PM | 00,042,496 | R--- | M] (VIA Technologies, Inc. ) - C:\WINDOWS\system32\drivers\fetnd5b.sys
(LVUSBSta) Logitech USB Monitor Filter [On_Demand | Running]
[01-31-2005 06:12 AM | 00,022,016 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\LVUSBSta.sys
(PCAlertDriver) PCAlertDriver [On_Demand | Running]
[11-16-2004 09:27 AM | 00,023,744 | R--- | M] (Your Corporation) - C:\Program Files\MSI\Core Center\NTGLM7X.SYS
(pepifilter) Volume Adapter [On_Demand | Running]
[01-31-2005 06:19 AM | 00,007,104 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\lv302af.sys
(PID_08A0) QuickCam IM(PID_08A0) [On_Demand | Running]
[01-31-2005 06:26 AM | 00,912,768 | R--- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\LV302AV.SYS
(PQNTDrv) PQNTDrv [System | Running]
[09-16-2002 07:07 PM | 00,004,228 | ---- | M] (PowerQuest Corporation) - C:\WINDOWS\System32\drivers\PQNTDRV.sys
(RapFile) RapFile [On_Demand | Stopped]
[02-25-2003 07:26 PM | 00,036,644 | ---- | M] (Internet Security Systems, Inc.) - C:\WINDOWS\system32\drivers\RapFile.sys
(RapNet) RapNet [On_Demand | Stopped]
[02-25-2003 07:26 PM | 00,024,344 | ---- | M] (Internet Security Systems, Inc.) - C:\WINDOWS\system32\drivers\RapNet.sys
(rtl8139) Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C) [On_Demand | Stopped]
[08-03-2004 10:31 PM | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) - C:\WINDOWS\system32\drivers\RTL8139.sys
(RushTopDevice) RushTopDevice [On_Demand | Running]
[11-16-2004 11:54 AM | 00,038,336 | R--- | M] (Your Corporation) - C:\Program Files\MSI\Core Center\RushTop.sys
(sfdrv01) StarForce Protection Environment Driver (version 1.x) [Boot | Running]
[08-10-2005 08:44 AM | 00,050,688 | ---- | M] (Protection Technology) - C:\WINDOWS\system32\drivers\sfdrv01.sys
(sfdrv01a) StarForce Protection Environment Driver (version 1.x.a) [Boot | Running]
[07-05-2006 08:46 AM | 00,063,352 | ---- | M] (Protection Technology (StarForce)) - C:\WINDOWS\system32\drivers\sfdrv01a.sys
(sfhlp02) StarForce Protection Helper Driver (version 2.x) [Boot | Running]
[06-14-2006 10:56 AM | 00,013,680 | ---- | M] (Protection Technology (StarForce)) - C:\WINDOWS\system32\drivers\sfhlp02.sys
(sfsync03) StarForce Protection Synchronization Driver (version 3.x) [Boot | Running]
[12-06-2005 11:11 AM | 00,035,328 | ---- | M] (Protection Technology) - C:\WINDOWS\system32\drivers\sfsync03.sys
(sfsync04) StarForce Protection Synchronization Driver (version 4.x) [Boot | Running]
[08-11-2006 09:47 AM | 00,059,776 | ---- | M] (Protection Technology (StarForce)) - C:\WINDOWS\system32\drivers\sfsync04.sys
(sptd) sptd [Boot | Running]
[03-17-2008 07:48 AM | 00,717,296 | ---- | M] () - C:\WINDOWS\system32\drivers\sptd.sys
(viaagp1) VIA AGP Filter [Boot | Running]
[07-02-2003 04:42 AM | 00,027,904 | ---- | M] (VIA Technologies, Inc.) - C:\WINDOWS\system32\drivers\VIAAGP1.SYS
(viamraid) viamraid [Boot | Running]
[06-25-2007 02:45 PM | 00,104,064 | ---- | M] (VIA Technologies inc,.ltd) - C:\WINDOWS\system32\drivers\viamraid.sys
(vIdeBus) vIdeBus [Boot | Running]
[06-25-2007 03:12 PM | 00,015,232 | ---- | M] (VIA Technologies, Inc.) - C:\WINDOWS\system32\drivers\vIdeBus.sys
(Video3D) ASUS Video3D Service [On_Demand | Running]
[07-06-2004 07:56 PM | 00,044,544 | ---- | M] (ASUSTeK COMPUTER INC.) - C:\WINDOWS\system32\drivers\Video3D.sys
(vIdePort) VIA IDE Controller PORT Driver [Boot | Running]
[06-25-2007 03:12 PM | 00,040,192 | ---- | M] (VIA Technologies, Inc.) - C:\WINDOWS\system32\drivers\vIdePort.sys
(videX32) videX32 [Boot | Running]
[06-25-2007 02:45 PM | 00,009,216 | ---- | M] (VIA Technologies, Inc.) - C:\WINDOWS\system32\drivers\videX32.sys
(vulfnths) VIA USB Host Controller Lower Filter [On_Demand | Stopped]
[08-04-2003 03:29 PM | 00,006,912 | ---- | M] (VIA Technologies, Inc.) - C:\WINDOWS\system32\drivers\vulfnth.sys
(vulfntrs) VIA USB Roothub Lower Filter [On_Demand | Stopped]
[08-04-2003 03:29 PM | 00,011,392 | ---- | M] (VIA Technologies, Inc.) - C:\WINDOWS\system32\drivers\vulfntr.sys
(WmBEnum) Logitech Virtual Bus Enumerator Driver [On_Demand | Running]
[04-14-2004 11:08 AM | 00,010,144 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\WmBEnum.sys
(WmFilter) Logitech WingMan HID Filter Driver [On_Demand | Running]
[04-14-2004 11:08 AM | 00,021,280 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\WmFilter.sys
(WmVirHid) Logitech Virtual Hid Device Driver [On_Demand | Stopped]
[04-14-2004 11:08 AM | 00,005,600 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\WmVirHid.sys
(WmXlCore) Logitech WingMan Translation Layer Driver [On_Demand | Running]
[04-14-2004 11:08 AM | 00,044,064 | ---- | M] (Logitech Inc.) - C:\WINDOWS\system32\drivers\WmXlCore.sys
========== Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acronis Scheduler2 Service" = "C:\Program Files\Fichiers communs\Seagate\Schedule2\schedhlp.exe" [08-20-2007 07:20 PM | 00,148,760 | ---- | M] (Acronis)
"AcronisTimounterMonitor" = C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe [08-21-2007 11:17 AM | 01,966,128 | ---- | M] (Acronis)
"Adobe Reader Speed Launcher" = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06-12-2008 02:38 AM | 00,034,672 | ---- | M] (Adobe Systems Incorporated)
"avgnt" = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min [06-12-2008 02:28 PM | 00,266,497 | ---- | M] (Avira GmbH)
"DiscWizardMonitor.exe" = C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe [08-21-2007 11:15 AM | 01,192,336 | ---- | M] (Seagate)
"Eye On Network" = C:\Program Files\Eye On Network\Eye On Network.exe [09-13-2003 01:47 PM | 01,553,920 | ---- | M] ()
"HP Software Update" = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [05-12-2005 12:12 AM | 00,049,152 | ---- | M] (Hewlett-Packard Co.)
"ISUSPM Startup" = C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [08-09-2004 06:03 AM | 00,221,184 | ---- | M] (InstallShield Software Corporation)
"ISUSScheduler" = "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start [08-09-2004 06:03 AM | 00,081,920 | ---- | M] (InstallShield Software Corporation)
"LogitechVideoRepair" = C:\Program Files\Logitech\Video\ISStart.exe [01-18-2005 05:47 PM | 00,458,752 | ---- | M] (Logitech Inc.)
"LogitechVideoTray" = C:\Program Files\Logitech\Video\LogiTray.exe [01-18-2005 05:37 PM | 00,217,088 | ---- | M] (Logitech Inc.)
"LVCOMSX" = C:\WINDOWS\system32\LVCOMSX.EXE [10-08-2004 11:52 AM | 00,221,184 | ---- | M] (Logitech Inc.)
"NvCplDaemon" = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [06-29-2007 12:43 AM | 08,466,432 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [06-29-2007 12:43 AM | 00,081,920 | ---- | M] (NVIDIA Corporation)
"nwiz" = nwiz.exe /install [06-29-2007 12:43 AM | 01,626,112 | ---- | M] ()
"QuickTime Task" = "C:\Program Files\QuickTime\qttask.exe" -atboottime [03-28-2008 11:37 PM | 00,413,696 | ---- | M] (Apple Inc.)
"RemoteControl" = "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [12-08-2003 05:35 PM | 00,032,768 | ---- | M] (Cyberlink Corp.)
"SoundMan" = SOUNDMAN.EXE [11-11-2005 03:07 PM | 00,090,112 | ---- | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" = C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [06-10-2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun [03-14-2008 07:55 AM | 00,486,856 | ---- | M] (DT Soft Ltd)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
========== Startup Folders ==========
[All Users Startup Folder - C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
[12-07-2004 04:42 PM | 00,840,704 | ---- | M] () - C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
[02-13-2004 02:12 PM | 00,016,423 | ---- | M] () - C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
[05-10-2008 07:15 AM | 00,282,624 | ---- | M] (Eastman Kodak Company) - C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logiciel Kodak EasyShare.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
[Mario Després Startup Folder - C:\Documents and Settings\Mario Després\Menu Démarrer\Programmes\Démarrage]
========== BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
HKLM CLSID: (Adobe PDF Link Helper) - [06-11-2008 10:33 PM | 00,075,128 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06-10-2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
HKLM CLSID: (free-downloads.net Toolbar) - [02-14-2008 02:54 PM | 01,555,480 | ---- | M] (Conduit Ltd.) C:\Program Files\free-downloads.net\tbfree.dll
========== Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"
HKLM CLSID: (free-downloads.net Toolbar) - [02-14-2008 02:54 PM | 01,555,480 | ---- | M] (Conduit Ltd.) C:\Program Files\free-downloads.net\tbfree.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"
HKLM CLSID: (free-downloads.net Toolbar) - [02-14-2008 02:54 PM | 01,555,480 | ---- | M] (Conduit Ltd.) C:\Program Files\free-downloads.net\tbfree.dll
========== AppInit_Dlls ==========
========== HKLM Security Providers ==========
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06-13-2007 09:22 AM | 01,037,312 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08-05-2004 08:00 AM | 00,025,088 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"LogonUI.EXE" - [08-05-2004 08:00 AM | 00,515,584 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08-05-2004 08:00 AM | 00,305,152 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
========== User's Winlogon Settings ==========
========== Winlogon Notify Settings ==========
========== Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun" = 67108863
"NoDriveTypeAutoRun" = 255
"NoDrives" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
"legalnoticecaption" =
"legalnoticetext" =
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
"DisableRegistryTools" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"ForceClassicControlPanel" = 1
"NoDrives" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DISALLOWCPL]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RESTRICTCPL]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RESTRICTRUN]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
========== Lsa Authentication Packages ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages]
"relog_ap" - [08-20-2007 07:21 PM | 00,014,104 | ---- | M] (Acronis) C:\WINDOWS\system32\relog_ap.dll
========== Lsa Security Packages ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe [01-19-2007 12:55 PM | 05,674,352 | ---- | M] (Microsoft Corporation)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe [03-13-2008 03:39 PM | 00,147,456 | ---- | M] (Lime Wire, LLC)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe [08-13-2008 07:48 PM | 00,267,056 | ---- | M] (BitTorrent, Inc.)
"C:\Program Files\Sierra\FEAR\FEAR.exe" = C:\Program Files\Sierra\FEAR\FEAR.exe [09-01-2005 10:30 AM | 04,632,576 | R--- | M] (Monolith Productions, Inc.)
"C:\Program Files\Sierra\FEAR\fpupdate.exe" = C:\Program Files\Sierra\FEAR\fpupdate.exe [01-07-2005 06:01 PM | 00,224,768 | R--- | M] ()
"C:\Program Files\ASUS\ASUS GameFace Live\GameFace.exe" = C:\Program Files\ASUS\ASUS GameFace Live\GameFace.exe [11-19-2004 11:21 AM | 04,059,136 | ---- | M] (ASUSTek Computer Inc.)
"C:\Program Files\Powerboat GT\Run.exe" = C:\Program Files\Powerboat GT\Run.exe [01-23-2008 04:41 PM | 02,295,296 | ---- | M] (Hammerware)
"F:\carbon\NFSC.exe" = F:\carbon\NFSC.exe [10-17-2006 01:09 AM | 08,950,979 | ---- | M] ()
"F:\xpandrally.exe" = F:\xpandrally.exe [08-01-2005 06:50 AM | 00,092,672 | ---- | M] (Techland)
"F:\Program Files\Supreme Commander\bin\SupremeCommander.exe" = F:\Program Files\Supreme Commander\bin\SupremeCommander.exe [01-12-2007 02:07 PM | 04,048,392 | R--- | M] (Gas Powered Games)
"F:\Program Files\GPGNet\GPG.Multiplayer.Client.exe" = F:\Program Files\GPGNet\GPG.Multiplayer.Client.exe [01-12-2007 11:19 AM | 05,350,920 | ---- | M] (Gas Powered Games)
"E:\mc2.exe" = E:\mc2.exe [06-20-2003 03:29 PM | 03,911,123 | ---- | M] ()
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [02-13-2004 02:12 PM | 00,016,423 | ---- | M] ()
"F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [05-10-2008 07:15 AM | 00,282,624 | ---- | M] (Eastman Kodak Company)
"C:\Program Files\Paradox Entertainment\Airfix Dogfighter\Dogfighter.exe" = C:\Program Files\Paradox Entertainment\Airfix Dogfighter\Dogfighter.exe [02-27-2001 05:52 PM | 00,290,816 | ---- | M] ()
========== Desktop Components ==========
========== Safeboot Options ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
========== Disabled MsConfig Items ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BlackICE PC Protection.lnk]
"backup" = C:\WINDOWS\pss\BlackICE PC Protection.lnk File not found
"location" = Common Startup
"item" = BlackICE PC Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
"backup" = C:\WINDOWS\pss\Démarrage rapide du logiciel HP Image Zone.lnk File not found
"location" = Common Startup
"command" = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [05-12-2005 01:49 AM | 00,073,728 | ---- | M] (Hewlett-Packard Co.)
"item" = Démarrage rapide du logiciel HP Image Zone
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
"backup" = C:\WINDOWS\pss\HP Digital Imaging Monitor.lnk File not found
"location" = Common Startup
"command" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [05-12-2005 12:23 AM | 00,282,624 | ---- | M] (Hewlett-Packard Co.)
"item" = HP Digital Imaging Monitor
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Kodak software updater.lnk]
"backup" = C:\WINDOWS\pss\KODAK Software Updater.lnk File not found
"location" = Common Startup
"command" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [02-13-2004 02:12 PM | 00,016,423 | ---- | M] ()
"item" = KODAK Software Updater
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
"backup" = C:\WINDOWS\pss\Logiciel Kodak EasyShare.lnk File not found
"location" = Common Startup
"command" = C:\PROGRA~1\Kodak\KODAKE~1\bin\EASYSH~1.EXE File not found
"item" = Logiciel Kodak EasyShare
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
"backup" = C:\WINDOWS\pss\Logitech Desktop Messenger.lnk File not found
"location" = Common Startup
"item" = Logitech Desktop Messenger
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Mario Després^Menu Démarrer^Programmes^Démarrage^Enregistrement d'un produit Joint Operations Typhoon Rising.lnk]
"backup" = C:\WINDOWS\pss\Enregistrement d'un produit Joint Operations Typhoon Rising.lnk File not found
"location" = Startup
"item" = Enregistrement d'un produit Joint Operations Typhoon Rising
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BDSwitchAgent]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = bdswitch
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ccApp]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = ccApp
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\InCD]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = InCD
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LDM]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = LogitechDesktopMessenger
"hkey" = HKCU
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MediaGateway]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = MediaGateway
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MessengerPlus3]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = MsgPlus
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = msmsgs
"hkey" = HKCU
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = NeroCheck
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spyware Doctor]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = swdoctor
"hkey" = HKCU
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vptray]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = VPTray
"hkey" = HKLM
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
"system.ini" = 0
"win.ini" = 0
"bootini" = 0
"services" = 0
"startup" = 0
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[10-13-2005 01:31 PM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7717bb-9657-11db-9a54-00110903e472}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7717bb-9657-11db-9a54-00110903e472}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7717bb-9657-11db-9a54-00110903e472}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7717bc-9657-11db-9a54-00110903e472}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7717bc-9657-11db-9a54-00110903e472}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7717bc-9657-11db-9a54-00110903e472}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42dac02c-6d23-11dc-9b77-c29850eeab96}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42dac02c-6d23-11dc-9b77-c29850eeab96}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42dac02c-6d23-11dc-9b77-c29850eeab96}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a7f1317-8157-11dc-9b9c-f2da6b9c0a01}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a7f1317-8157-11dc-9b9c-f2da6b9c0a01}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a7f1317-8157-11dc-9b9c-f2da6b9c0a01}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{deea465a-6d2c-11dc-9b79-8d76930b6713}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{deea465a-6d2c-11dc-9b79-8d76930b6713}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{deea465a-6d2c-11dc-9b79-8d76930b6713}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebc485bc-ce98-11db-9a91-e4aa59acc71c}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebc485bc-ce98-11db-9a91-e4aa59acc71c}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10-25-2007 12:56 PM | 08,510,976 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebc485bc-ce98-11db-9a91-e4aa59acc71c}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
========== DNS Name Servers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{4B62B3B4-89ED-4F88-82C7-86BB8DBDF85D}]
Servers: | Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{7B9546DF-0DD2-4F87-B941-448E2AFAB302}]
Servers: | Description: VIA Rhine II Fast Ethernet Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{ADB3129A-26EF-464A-A80E-D56CE4B33ABA}]
Servers: | Description:
========== Hosts File ==========
HOSTS File = (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== Files/Folders - Created Within 60 days ==========
[07-02-2008 05:31 PM | 00,000,232 | -H-- | C] () - C:\sqmdata19.sqm
[07-02-2008 05:31 PM | 00,000,244 | -H-- | C] () - C:\sqmnoopt19.sqm
[07-02-2008 08:57 AM | 00,000,232 | -H-- | C] () - C:\sqmdata15.sqm
[07-02-2008 08:57 AM | 00,000,244 | -H-- | C] () - C:\sqmnoopt15.sqm
[07-02-2008 09:07 AM | 00,000,232 | -H-- | C] () - C:\sqmdata16.sqm
[07-02-2008 09:07 AM | 00,000,244 | -H-- | C] () - C:\sqmnoopt16.sqm
[07-02-2008 11:37 AM | 00,000,232 | -H-- | C] () - C:\sqmdata17.sqm
[07-02-2008 11:37 AM | 00,000,244 | -H-- | C] () - C:\sqmnoopt17.sqm
[07-02-2008 12:10 PM | 00,000,232 | -H-- | C] () - C:\sqmdata18.sqm
[07-02-2008 12:10 PM | 00,000,244 | -H-- | C] () - C:\sqmnoopt18.sqm
[08-02-2008 09:14 PM | 15,083,520 | ---- | C] (Safer Networking Limited ) - C:\spybotsd160.exe
[08-09-2008 03:49 PM | 00,230,776 | ---- | C] (Alwil Software) - C:\aswclear.exe
[08-11-2008 11:45 AM | 21,470,12608 | -HS- | C] () - C:\hiberfil.sys
[08-12-2008 07:15 AM | ---D | C] - C:\QooBox
[08-20-2008 01:31 PM | ---D | C] - C:\ComboFix
[08-20-2008 08:11 PM | -HSD | C] - C:\RECYCLER
[08-22-2008 04:41 PM | ---D | C] - C:\d3temp
[08-24-2008 01:01 PM | 00,148,352 | ---- | C] (3dfx Interactive, Inc.) - C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[08-24-2008 01:01 PM | 00,689,216 | ---- | C] (3dfx Interactive, Inc.) - C:\WINDOWS\System32\dllcache\3dfxvs.dll
[08-24-2008 01:01 PM | 00,762,780 | ---- | C] (3Com, Inc.) - C:\WINDOWS\System32\dllcache\3cwmcru.sys
[08-24-2008 01:02 PM | 00,009,472 | ---- | C] () - C:\WINDOWS\System32\dllcache\ativmdcd.sys
[08-24-2008 01:02 PM | 00,010,240 | ---- | C] () - C:\WINDOWS\System32\dllcache\atipcxxx.sys
[08-24-2008 01:02 PM | 00,010,880 | ---- | C] (Aureal, Inc.) - C:\WINDOWS\System32\dllcache\admjoy.sys
[08-24-2008 01:02 PM | 00,016,969 | ---- | C] (AmbiCom, Inc.) - C:\WINDOWS\System32\dllcache\amb8002.sys
[08-24-2008 01:02 PM | 00,017,152 | ---- | C] () - C:\WINDOWS\System32\dllcache\atitunep.sys
[08-24-2008 01:02 PM | 00,017,152 | ---- | C] () - C:\WINDOWS\System32\dllcache\atitvsnd.sys
[08-24-2008 01:02 PM | 00,019,456 | ---- | C] () - C:\WINDOWS\System32\dllcache\ativttxx.sys
[08-24-2008 01:02 PM | 00,020,160 | ---- | C] (ADMtek Incorporated) - C:\WINDOWS\System32\dllcache\adm8511.sys
[08-24-2008 01:02 PM | 00,023,552 | ---- | C] () - C:\WINDOWS\System32\dllcache\atixbar.sys
[08-24-2008 01:02 PM | 00,026,624 | ---- | C] () - C:\WINDOWS\System32\dllcache\ativxbar.sys
[08-24-2008 01:02 PM | 00,026,880 | ---- | C] () - C:\WINDOWS\System32\dllcache\atirtsnd.sys
[08-24-2008 01:02 PM | 00,046,112 | ---- | C] (Adaptec, Inc ) - C:\WINDOWS\System32\dllcache\adptsf50.sys
[08-24-2008 01:02 PM | 00,046,464 | ---- | C] () - C:\WINDOWS\System32\dllcache\atibt829.sys
[08-24-2008 01:02 PM | 00,049,920 | ---- | C] () - C:\WINDOWS\System32\dllcache\atirtcap.sys
[08-24-2008 01:02 PM | 00,061,952 | ---- | C] (Scanneur à plat couleur) - C:\WINDOWS\System32\dllcache\acerscad.dll
[08-24-2008 01:02 PM | 00,077,824 | ---- | C] (ATI Technologies, Inc.) - C:\WINDOWS\System32\dllcache\ati.sys
[08-24-2008 01:02 PM | 00,084,480 | ---- | C] (VIA Technologies, Inc.) - C:\WINDOWS\System32\dllcache\ac97via.sys
[08-24-2008 01:02 PM | 00,096,256 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\ac97intc.sys
[08-24-2008 01:02 PM | 00,097,354 | ---- | C] (Bay Networks, Inc.) - C:\WINDOWS\System32\dllcache\aspndis3.sys
[08-24-2008 01:02 PM | 00,098,304 | ---- | C] (Aureal Semiconductor) - C:\WINDOWS\System32\dllcache\a3d.dll
[08-24-2008 01:02 PM | 00,297,728 | ---- | C] (Silicon Integrated Systems Corp.) - C:\WINDOWS\System32\dllcache\ac97sis.sys
[08-24-2008 01:02 PM | 00,462,848 | ---- | C] (Aureal Inc.) - C:\WINDOWS\System32\dllcache\a3dapi.dll
[08-24-2008 01:02 PM | 00,553,984 | ---- | C] (Aureal, Inc.) - C:\WINDOWS\System32\dllcache\adm8820.sys
[08-24-2008 01:02 PM | 00,584,448 | ---- | C] (Aureal, Inc.) - C:\WINDOWS\System32\dllcache\adm8810.sys
[08-24-2008 01:02 PM | 00,747,392 | ---- | C] (Aureal, Inc.) - C:\WINDOWS\System32\dllcache\adm8830.sys
[08-24-2008 01:03 PM | 00,002,944 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brfilt.sys
[08-24-2008 01:03 PM | 00,003,168 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brparimg.sys
[08-24-2008 01:03 PM | 00,003,968 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brfiltup.sys
[08-24-2008 01:03 PM | 00,005,120 | ---- | C] (Brother Industries,Ltd.) - C:\WINDOWS\System32\dllcache\brscnrsm.dll
[08-24-2008 01:03 PM | 00,009,728 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brcoinst.dll
[08-24-2008 01:03 PM | 00,009,728 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brserif.dll
[08-24-2008 01:03 PM | 00,010,368 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brusbscn.sys
[08-24-2008 01:03 PM | 00,011,008 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brusbmdm.sys
[08-24-2008 01:03 PM | 00,012,160 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brfiltlo.sys
[08-24-2008 01:03 PM | 00,012,800 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brevif.dll
[08-24-2008 01:03 PM | 00,015,360 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brmfbidi.dll
[08-24-2008 01:03 PM | 00,019,456 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brbidiif.dll
[08-24-2008 01:03 PM | 00,021,530 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\ce2n5.sys
[08-24-2008 01:03 PM | 00,027,164 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\ce3n5.sys
[08-24-2008 01:03 PM | 00,029,696 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brmflpt.dll
[08-24-2008 01:03 PM | 00,031,529 | ---- | C] (BreezeCOM) - C:\WINDOWS\System32\dllcache\brzwlan.sys
[08-24-2008 01:03 PM | 00,032,256 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[08-24-2008 01:03 PM | 00,032,256 | ---- | C] (Eicon Technology Corporation) - C:\WINDOWS\System32\dllcache\diapi2NT.dll
[08-24-2008 01:03 PM | 00,036,128 | ---- | C] (3Dfx Interactive, Inc.) - C:\WINDOWS\System32\dllcache\banshee.sys
[08-24-2008 01:03 PM | 00,036,992 | ---- | C] (Aztech Systems Ltd) - C:\WINDOWS\System32\dllcache\aztw2320.sys
[08-24-2008 01:03 PM | 00,037,568 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\avmwan.sys
[08-24-2008 01:03 PM | 00,037,916 | ---- | C] (Fast Ethernet Controller Provider) - C:\WINDOWS\System32\dllcache\cb102.sys
[08-24-2008 01:03 PM | 00,039,680 | ---- | C] (Silicom Ltd.) - C:\WINDOWS\System32\dllcache\cb325.sys
[08-24-2008 01:03 PM | 00,039,808 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brparwdm.sys
[08-24-2008 01:03 PM | 00,041,472 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\brmfusb.dll
[08-24-2008 01:03 PM | 00,046,108 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\cben5.sys
[08-24-2008 01:03 PM | 00,060,416 | ---- | C] (Brother Industries Ltd.) - C:\WINDOWS\System32\dllcache\brserwdm.sys
[08-24-2008 01:03 PM | 00,087,552 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\avmcoxp.dll
[08-24-2008 01:03 PM | 00,089,952 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\b1cbase.sys
[08-24-2008 01:03 PM | 00,144,384 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\avmenum.dll
[08-24-2008 01:03 PM | 00,164,923 | ---- | C] (Eicon Technology) - C:\WINDOWS\System32\dllcache\diapi2.sys
[08-24-2008 01:03 PM | 00,342,336 | ---- | C] (3Dfx Interactive, Inc.) - C:\WINDOWS\System32\dllcache\banshee.dll
[08-24-2008 01:03 PM | 00,715,466 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[08-24-2008 01:03 PM | 00,871,388 | ---- | C] (BCM) - C:\WINDOWS\System32\dllcache\bcmdm.sys
[08-24-2008 01:04 PM | 00,003,072 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwbase.sys
[08-24-2008 01:04 PM | 00,003,072 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwbmidi.sys
[08-24-2008 01:04 PM | 00,003,584 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[08-24-2008 01:04 PM | 00,003,712 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\ctljystk.sys
[08-24-2008 01:04 PM | 00,004,096 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\ctwdm32.dll
[08-24-2008 01:04 PM | 00,006,912 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\ctlfacem.sys
[08-24-2008 01:04 PM | 00,020,864 | ---- | C] (OMNIKEY AG) - C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[08-24-2008 01:04 PM | 00,020,928 | ---- | C] (Digital Networks, LLC) - C:\WINDOWS\System32\dllcache\defpa.sys
[08-24-2008 01:04 PM | 00,021,533 | ---- | C] (Compaq Computer Corporation) - C:\WINDOWS\System32\dllcache\cpqndis5.sys
[08-24-2008 01:04 PM | 00,022,556 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\cem28n5.sys
[08-24-2008 01:04 PM | 00,022,556 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\cem33n5.sys
[08-24-2008 01:04 PM | 00,048,640 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwrwdm.sys
[08-24-2008 01:04 PM | 00,049,182 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\cem56n5.sys
[08-24-2008 01:04 PM | 00,061,194 | ---- | C] (Compaq Computer Corp.) - C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[08-24-2008 01:04 PM | 00,063,208 | ---- | C] (Intel Corporation.) - C:\WINDOWS\System32\dllcache\dc21x4.sys
[08-24-2008 01:04 PM | 00,072,832 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwbwdm.sys
[08-24-2008 01:04 PM | 00,093,952 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwcwdm.sys
[08-24-2008 01:04 PM | 00,096,256 | ---- | C] (Copyright (C) Creative Technology Ltd. 1994-2001) - C:\WINDOWS\System32\dllcache\ctlsb16.sys
[08-24-2008 01:04 PM | 00,111,872 | ---- | C] (Crystal Semiconductor Corp.) - C:\WINDOWS\System32\dllcache\cwcspud.sys
[08-24-2008 01:04 PM | 00,117,760 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\d100ib5.sys
[08-24-2008 01:04 PM | 00,216,576 | ---- | C] (COMPAQ Inc.) - C:\WINDOWS\System32\dllcache\cpscan.dll
[08-24-2008 01:04 PM | 00,252,416 | ---- | C] (Comtrol® Corporation) - C:\WINDOWS\System32\dllcache\ctmasetp.dll
[08-24-2008 01:04 PM | 00,272,640 | ---- | C] (RAVISENT Technologies Inc.) - C:\WINDOWS\System32\dllcache\cinemclc.sys
[08-24-2008 01:04 PM | 00,980,034 | ---- | C] (Xircom) - C:\WINDOWS\System32\dllcache\cicap.sys
[08-24-2008 01:05 PM | 00,006,216 | ---- | C] () - C:\WINDOWS\System32\dllcache\divaci.dll
[08-24-2008 01:05 PM | 00,006,729 | ---- | C] (Eicon Technology) - C:\WINDOWS\System32\dllcache\disrvci.dll
[08-24-2008 01:05 PM | 00,019,594 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\e100isa4.sys
[08-24-2008 01:05 PM | 00,024,064 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\devldr32.exe
[08-24-2008 01:05 PM | 00,024,648 | ---- | C] (D-Link) - C:\WINDOWS\System32\dllcache\dfe650.sys
[08-24-2008 01:05 PM | 00,024,649 | ---- | C] (D-Link) - C:\WINDOWS\System32\dllcache\dfe650d.sys
[08-24-2008 01:05 PM | 00,026,698 | ---- | C] (D-Link Corporation) - C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[08-24-2008 01:05 PM | 00,028,062 | ---- | C] (National Semiconductor Coproration) - C:\WINDOWS\System32\dllcache\dp83820.sys
[08-24-2008 01:05 PM | 00,029,696 | ---- | C] (CNet Technology, Inc. ) - C:\WINDOWS\System32\dllcache\dm9pci5.sys
[08-24-2008 01:05 PM | 00,029,768 | ---- | C] () - C:\WINDOWS\System32\dllcache\divasu.dll
[08-24-2008 01:05 PM | 00,031,817 | ---- | C] () - C:\WINDOWS\System32\dllcache\disrvpp.dll
[08-24-2008 01:05 PM | 00,037,962 | ---- | C] () - C:\WINDOWS\System32\dllcache\divaprop.dll
[08-24-2008 01:05 PM | 00,038,985 | ---- | C] (Eicon Technology) - C:\WINDOWS\System32\dllcache\disrvsu.dll
[08-24-2008 01:05 PM | 00,051,743 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\e1000nt5.sys
[08-24-2008 01:05 PM | 00,091,305 | ---- | C] (Eicon Technology) - C:\WINDOWS\System32\dllcache\dimaint.sys
[08-24-2008 01:05 PM | 00,117,760 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\e100b325.sys
[08-24-2008 01:05 PM | 00,236,060 | ---- | C] (Eicon Technology) - C:\WINDOWS\System32\dllcache\ditrace.exe
[08-24-2008 01:05 PM | 00,256,512 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\devcon32.dll
[08-24-2008 01:05 PM | 00,334,208 | ---- | C] (Yamaha Corp.) - C:\WINDOWS\System32\dllcache\ds1wdm.sys
[08-24-2008 01:05 PM | 00,952,007 | ---- | C] (Eicon Technology) - C:\WINDOWS\System32\dllcache\diwan.sys
[08-24-2008 01:06 PM | 00,016,998 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\ex10.sys
[08-24-2008 01:06 PM | 00,018,503 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\epro4.sys
[08-24-2008 01:06 PM | 00,034,816 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esuimg.dll
[08-24-2008 01:06 PM | 00,037,120 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\es1370mp.sys
[08-24-2008 01:06 PM | 00,040,704 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\es1371mp.sys
[08-24-2008 01:06 PM | 00,043,008 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esucm.dll
[08-24-2008 01:06 PM | 00,046,080 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esuni.dll
[08-24-2008 01:06 PM | 00,046,080 | ---- | C] (SEIKO EPSON CORP.) - C:\WINDOWS\System32\dllcache\esunib.dll
[08-24-2008 01:06 PM | 00,072,192 | ---- | C] (ESS Technology Inc.) - C:\WINDOWS\System32\dllcache\es1969.sys
[08-24-2008 01:06 PM | 00,283,904 | ---- | C] (Creative Technology Ltd.) - C:\WINDOWS\System32\dllcache\emu10k1m.sys
[08-24-2008 01:07 PM | 00,011,850 | ---- | C] (FUJITSU LIMITED) - C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[08-24-2008 01:07 PM | 00,012,362 | ---- | C] (FUJITSU LIMITED) - C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[08-24-2008 01:07 PM | 00,017,664 | ---- | C] (Gemplus) - C:\WINDOWS\System32\dllcache\gpr400.sys
[08-24-2008 01:07 PM | 00,024,618 | ---- | C] (NETGEAR) - C:\WINDOWS\System32\dllcache\fa410nd5.sys
[08-24-2008 01:07 PM | 00,028,672 | ---- | C] (Gemplus) - C:\WINDOWS\System32\dllcache\grserial.sys
[08-24-2008 01:07 PM | 00,034,173 | ---- | C] (Marconi Communications, Inc.) - C:\WINDOWS\System32\dllcache\forehe.sys
[08-24-2008 01:07 PM | 00,082,560 | ---- | C] (Gemplus) - C:\WINDOWS\System32\dllcache\grclass.sys
[08-24-2008 01:07 PM | 00,441,728 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\fpcmbase.sys
[08-24-2008 01:07 PM | 00,442,240 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\fpnpbase.sys
[08-24-2008 01:07 PM | 00,444,416 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\fpcibase.sys
[08-24-2008 01:07 PM | 00,454,912 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\fxusbase.sys
[08-24-2008 01:07 PM | 00,455,296 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\fusbbase.sys
[08-24-2008 01:07 PM | 00,455,680 | ---- | C] (AVM GmbH) - C:\WINDOWS\System32\dllcache\fus2base.sys
[08-24-2008 01:08 PM | 00,068,608 | ---- | C] (Avisioin) - C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[08-24-2008 01:08 PM | 00,083,968 | ---- | C] () - C:\WINDOWS\System32\dllcache\hpgt21.dll
[08-24-2008 01:08 PM | 00,089,088 | ---- | C] () - C:\WINDOWS\System32\dllcache\hpgt33.dll
[08-24-2008 01:08 PM | 00,093,696 | ---- | C] () - C:\WINDOWS\System32\dllcache\hpgt42.dll
[08-24-2008 01:08 PM | 00,101,376 | ---- | C] () - C:\WINDOWS\System32\dllcache\hpgt34.dll
[08-24-2008 01:08 PM | 00,126,976 | ---- | C] (Hewlett Packard) - C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[08-24-2008 01:08 PM | 00,165,888 | ---- | C] () - C:\WINDOWS\System32\dllcache\hpgt53.dll
[08-24-2008 01:09 PM | 00,010,240 | ---- | C] (IBM Corporation) - C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[08-24-2008 01:09 PM | 00,028,700 | ---- | C] (IBM Corp.) - C:\WINDOWS\System32\dllcache\ibmexmp.sys
[08-24-2008 01:09 PM | 00,058,592 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\i740nt5.sys
[08-24-2008 01:09 PM | 00,100,936 | ---- | C] (IBM Corporation) - C:\WINDOWS\System32\dllcache\ibmtok.sys
[08-24-2008 01:09 PM | 00,109,085 | ---- | C] (IBM Corporation) - C:\WINDOWS\System32\dllcache\ibmtrp.sys
[08-24-2008 01:09 PM | 00,353,184 | ---- | C] (Intel Corporation) - C:\WINDOWS\System32\dllcache\i740dnt5.dll
[08-24-2008 01:10 PM | 00,023,552 | ---- | C] (MKNet Corporation) - C:\WINDOWS\System32\dllcache\irmk7.sys
[08-24-2008 01:10 PM | 00,038,784 | ---- | C] (Perle Systems Ltd. ) - C:\WINDOWS\System32\dllcache\io8.sys
[08-24-2008 01:10 PM | 00,045,632 | ---- | C] (Interphase (R) Corporation a Windows (R) 2000 DDK Driver Provider) - C:\WINDOWS\System32\dllcache\ip5515.sys
[08-24-2008 01:10 PM | 00,090,200 | ---- | C] (Perle Systems Ltd. ) - C:\WINDOWS\System32\dllcache\io8ports.dll
[08-24-2008 01:10 PM | 00,372,824 | ---- | C] (Xircom) - C:\WINDOWS\System32\dllcache\iconf32.dll
[08-24-2008 01:11 PM | 00,016,384 | ---- | C] (Litronic Industries) - C:\WINDOWS\System32\dllcache\lit220p.sys
[08-24-2008 01:11 PM | 00,019,016 | ---- | C] (Kingston Technology Company ) - C:\WINDOWS\System32\dllcache\ktc111.sys
[08-24-2008 01:11 PM | 00,020,573 | ---- | C] (The Linksts Group ) - C:\WINDOWS\System32\dllcache\lne100.sys
[08-24-2008 01:11 PM | 00,020,864 | ---- | C] (Logitech Inc.) - C:\WINDOWS\System32\dllcache\lwadihid.sys
[08-24-2008 01:11 PM | 00,022,848 | ---- | C] (Logitech Inc.) - C:\WINDOWS\System32\dllcache\lwusbhid.sys
[08-24-2008 01:11 PM | 00,025,065 | ---- | C] (D-Link) - C:\WINDOWS\System32\dllcache\lmndis3.sys
[08-24-2008 01:11 PM | 00,026,922 | ---- | C] (SMSC) - C:\WINDOWS\System32\dllcache\lanepic5.sys
[08-24-2008 01:11 PM | 00,034,688 | ---- | C] (Toshiba Corp.) - C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[08-24-2008 01:11 PM | 00,070,730 | ---- | C] (Linksys Group, Inc.) - C:\WINDOWS\System32\dllcache\lne100tx.sys
[08-24-2008 01:11 PM | 00,422,528 | ---- | C] (LT) - C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[08-24-2008 01:11 PM | 00,577,514 | ---- | C] (LT) - C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[08-24-2008 01:11 PM | 00,607,452 | ---- | C] (LT) - C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[08-24-2008 01:11 PM | 00,728,554 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\ltck000c.sys
[08-24-2008 01:11 PM | 00,797,500 | ---- | C] (LT) - C:\WINDOWS\System32\dllcache\ltsmt.sys
[08-24-2008 01:11 PM | 00,802,683 | ---- | C] (Lucent Technologies) - C:\WINDOWS\System32\dllcache\ltsm.sys
[08-24-2008 01:12 PM | 00,017,280 | ---- | C] (American Megatrends Inc.) - C:\WINDOWS\System32\dllcache\mraid35x.sys
[08-24-2008 01:12 PM | 00,056,832 | ---- | C] () - C:\WINDOWS\System32\dllcache\msdvbnp.ax
[08-24-2008 01:12 PM | 00,165,066 | ---- | C] (Madge Networks Ltd) - C:\WINDOWS\System32\dllcache\mdgndis5.sys
[08-24-2008 01:13 PM | 00,007,168 | ---- | C] (Moxa Technologies Co., Ltd) - C:\WINDOWS\System32\dllcache\mxport.dll
[08-24-2008 01:13 PM | 00,013,664 | ---- | C] (Number Nine Visual Technology Corp.) - C:\WINDOWS\System32\dllcache\n9i128.sys
[08-24-2008 01:13 PM | 00,019,968 | ---- | C] (Macronix International Co., Ltd. ) - C:\WINDOWS\System32\dllcache\mxnic.sys
[08-24-2008 01:13 PM | 00,019,968 | ---- | C] (Moxa Technologies Co., Ltd) - C:\WINDOWS\System32\dllcache\mxicfg.dll
[08-24-2008 01:13 PM | 00,022,144 | ---- | C] (Moxa Technologies Co., Ltd.) - C:\WINDOWS\System32\dllcache\mxcard.sys
[08-24-2008 01:13 PM | 00,027,936 | ---- | C] (Number Nine Visual Technology Corp.) - C:\WINDOWS\System32\dllcache\n9i3d.sys
[08-24-2008 01:13 PM | 00,032,840 | ---- | C] (NETGEAR Corporation.) - C:\WINDOWS\System32\dllcache\ngrpci.sys
[08-24-2008 01:13 PM | 00,033,088 | ---- | C] (Number Nine Visual Technology Corp.) - C:\WINDOWS\System32\dllcache\n9i128v2.sys
[08-24-2008 01:13 PM | 00,035,392 | ---- | C] (Number Nine Visual Technology Corp.) - C:\WINDOWS\System32\dllcache\n9i128.dll
[08-24-2008 01:13 PM | 00,039,264 | ---- | C] (NeoMagic Corporation) - C:\WINDOWS\System32\dllcache\neo20xx.sys
[08-24-2008 01:13 PM | 00,053,791 | ---- | C] (Compaq Computer Corporation) - C:\WINDOWS\System32\dllcache\n1000nt5.sys
[08-24-2008 01:13 PM | 00,059,104 | ---- | C] (Number Nine Visual Technology Corp.) - C:\WINDOWS\System32\dllcache\n9i128v2.dll
[08-24-2008 01:13 PM | 00,060,480 | ---- | C] (NeoMagic Corporation) - C:\WINDOWS\System32\dllcache\neo20xx.dll
[08-24-2008 01:13 PM | 00,066,302 | ---- | C] (Compaq Computer Corporation) - C:\WINDOWS\System32\dllcache\netflx3.sys
[08-24-2008 01:13 PM | 00,076,928 | ---- | C] (Moxa Technologies Co., Ltd.) - C:\WINDOWS\System32\dllcache\mxport.sys
[08-24-2008 01:13 PM | 00,091,488 | ---- | C] (Number Nine Visual Technology Corp.) - C:\WINDOWS\System32\dllcache\n9i3disp.dll
[08-24-2008 01:13 PM | 00,103,296 | ---- | C] (Matrox Graphics Inc) - C:\WINDOWS\System32\dllcache\mtxvideo.sys
[08-24-2008 01:13 PM | 00,131,072 | ---- | C] (Compaq Computer Corporation) - C:\WINDOWS\System32\dllcache\n100325.sys
[08-24-2008 01:13 PM | 00,132,695 | ---- | C] (802.11b) - C:\WINDOWS\System32\dllcache\netwlan5.sys
[08-24-2008 01:14 PM | 00,027,209 | ---- | C] (Ositech Communications, Inc.) - C:\WINDOWS\System32\dllcache\otc06x5.sys
[08-24-2008 01:14 PM | 00,028,672 | ---- | C] (National Semiconductor Corporation) - C:\WINDOWS\System32\dllcache\nscirda.sys
[08-24-2008 01:14 PM | 00,044,297 | ---- | C] () - C:\WINDOWS\System32\dllcache\otceth5.sys
[08-24-2008 01:14 PM | 00,051,552 | ---- | C] (Kensington Technology Group) - C:\WINDOWS\System32\dllcache\ntgrip.sys
[08-24-2008 01:14 PM | 00,054,528 | ---- | C] (Yamaha Corp.) - C:\WINDOWS\System32\dllcache\opl3sax.sys
[08-24-2008 01:14 PM | 00,054,954 | ---- | C] (Ositech Communications, Inc.) - C:\WINDOWS\System32\dllcache\otcsercb.sys
[08-24-2008 01:14 PM | 00,087,040 | ---- | C] (NeoMagic Corporation) - C:\WINDOWS\System32\dllcache\nm6wdm.sys
[08-24-2008 01:14 PM | 00,126,080 | ---- | C] (NeoMagic Corporation) - C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[08-24-2008 01:15 PM | 00,026,153 | ---- | C] (Linksys) - C:\WINDOWS\System32\dllcache\pcmlm56.sys
[08-24-2008 01:15 PM | 00,027,904 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) - C:\WINDOWS\System32\dllcache\perm2.sys
[08-24-2008 01:15 PM | 00,028,032 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) - C:\WINDOWS\System32\dllcache\perm3.sys
[08-24-2008 01:15 PM | 00,029,502 | ---- | C] (Marconi Communications, Inc.) - C:\WINDOWS\System32\dllcache\pca200e.sys
[08-24-2008 01:15 PM | 00,029,769 | ---- | C] (AMD Inc.) - C:\WINDOWS\System32\dllcache\pcntn5m.sys
[08-24-2008 01:15 PM | 00,030,282 | ---- | C] (AMD Inc.) - C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[08-24-2008 01:15 PM | 00,030,495 | ---- | C] (Linksys) - C:\WINDOWS\System32\dllcache\pc100nds.sys
[08-24-2008 01:15 PM | 00,035,328 | ---- | C] (AMD Inc.) - C:\WINDOWS\System32\dllcache\pcntpci5.sys
[08-24-2008 01:15 PM | 00,086,016 | ---- | C] (PCtel, Inc.) - C:\WINDOWS\System32\dllcache\pctspk.exe
[08-24-2008 01:15 PM | 00,169,984 | ---- | C] (Cisco Systems) - C:\WINDOWS\System32\dllcache\pcx500.sys
[08-24-2008 01:15 PM | 00,211,712 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) - C:\WINDOWS\System32\dllcache\perm2dll.dll
[08-24-2008 01:15 PM | 00,259,328 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) - C:\WINDOWS\System32\dllcache\perm3dd.dll
[08-24-2008 01:16 PM | 00,016,512 | ---- | C] (SCM Microsystems, Inc.) - C:\WINDOWS\System32\dllcache\pscr.sys
[08-24-2008 01:16 PM | 00,033,280 | ---- | C] () - C:\WINDOWS\System32\dllcache\psisrndr.ax
[08-24-2008 01:16 PM | 00,112,574 | ---- | C] (PCTEL, INC.) - C:\WINDOWS\System32\dllcache\ptserlp.sys
[08-24-2008 01:16 PM | 00,128,286 | ---- | C] (PCTEL, INC.) - C:\WINDOWS\System32\dllcache\ptserli.sys
[08-24-2008 01:16 PM | 00,130,942 | ---- | C] (PCTEL, INC.) - C:\WINDOWS\System32\dllcache\ptserlv.sys
[08-24-2008 01:16 PM | 00,363,520 | ---- | C] () - C:\WINDOWS\System32\dllcache\psisdecd.dll
[08-24-2008 01:17 PM | 00,010,240 | ---- | C] (Brother Industries, Ltd.) - C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[08-24-2008 01:17 PM | 00,019,017 | ---- | C] (Realtek Semiconductor Corporation) - C:\WINDOWS\System32\dllcache\rtl8029.sys
[08-24-2008 01:17 PM | 00,025,088 | ---- | C] (Ricoh Co., Ltd.) - C:\WINDOWS\System32\dllcache\rw430ext.dll
[08-24-2008 01:17 PM | 00,026,624 | ---- | C] (RICOH Co., Ltd.) - C:\WINDOWS\System32\dllcache\rw450ext.dll
[08-24-2008 01:17 PM | 00,037,563 | ---- | C] (RadioLAN) - C:\WINDOWS\System32\dllcache\rlnet5.sys
[08-24-2008 01:17 PM | 00,079,360 | ---- | C] (Comtrol Corporation) - C:\WINDOWS\System32\dllcache\rocket.sys
[08-24-2008 01:17 PM | 00,081,408 | ---- | C] (Ricoh Co., Ltd.) - C:\WINDOWS\System32\dllcache\rwia430.dll
[08-24-2008 01:17 PM | 00,083,968 | ---- | C] (Ricoh Co., Ltd.) - C:\WINDOWS\System32\dllcache\rwia450.dll
[08-24-2008 01:17 PM | 00,086,097 | ---- | C] (Xircom) - C:\WINDOWS\System32\dllcache\reslog32.dll
[08-24-2008 01:17 PM | 00,715,530 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[08-24-2008 01:17 PM | 00,899,914 | ---- | C] (Xircom, Inc.) - C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[08-24-2008 01:18 PM | 00,041,216 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3mt3d.sys
[08-24-2008 01:18 PM | 00,043,136 | ---- | C] () - C:\WINDOWS\System32\dllcache\sbp2port.sys
[08-24-2008 01:18 PM | 00,061,504 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[08-24-2008 01:18 PM | 00,062,496 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3mtrio.dll
[08-24-2008 01:18 PM | 00,077,824 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3sav4m.sys
[08-24-2008 01:18 PM | 00,166,720 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3m.sys
[08-24-2008 01:18 PM | 00,179,264 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3sav3d.dll
[08-24-2008 01:18 PM | 00,182,272 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3mt3d.dll
[08-24-2008 01:18 PM | 00,198,400 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3sav4.dll
[08-24-2008 01:18 PM | 00,210,496 | ---- | C] (S3 Incorporated) - C:\WINDOWS\System32\dllcache\s3mvirge.dll
[08-24-2008 01:18 PM | 00,495,616 | ---- | C] () - C:\WINDOWS\System32\dllcache\sblfx.dll
[08-23-2008 07:01 AM | ---D | C] - C:\WINDOWS\System32\CatRoot_bak
[07-02-2008 06:37 AM | ---D | C] - C:\WINDOWS\Turtix Rescue Adventure
[07-04-2008 08:28 AM | ---D | C] - C:\WINDOWS\Unicorn Castle
[07-07-2008 03:11 PM | 00,001,409 | ---- | C] () - C:\WINDOWS\QTFont.for
[07-07-2008 03:11 PM | 00,054,156 | -H-- | C] () - C:\WINDOWS\QTFont.qfn
[07-08-2008 06:42 PM | ---D | C] - C:\WINDOWS\The Pini Society
[07-15-2008 01:54 PM | 00,069,632 | ---- | C] () - C:\WINDOWS\_detmp.2
[07-15-2008 01:54 PM | 00,105,511 | ---- | C] () - C:\WINDOWS\_detmp.1
[08-02-2008 08:03 AM | 03,494,207 | ---- | C] (Digital Illusions Software - ss3d.com) - C:\WINDOWS\Nemo's Aquarium 3D Korallenriff.scr
[08-02-2008 08:03 AM | 03,594,576 | ---- | C] (Digital Illusions Software - ss3d.com) - C:\WINDOWS\Nemo's Aquarium 3D Anemonen-Feld.scr
[08-03-2008 11:44 AM | ---D | C] - C:\WINDOWS\ERUNT
[08-07-2008 08:41 PM | ---D | C] - C:\WINDOWS\SmitfraudFix
[08-19-2008 09:03 AM | 00,028,672 | ---- | C] (NirSoft) - C:\WINDOWS\Nircmd.exe
[08-19-2008 09:03 AM | 00,049,152 | ---- | C] () - C:\WINDOWS\VFind.exe
[08-19-2008 09:03 AM | 00,068,096 | ---- | C] () - C:\WINDOWS\zip.exe
[08-19-2008 09:03 AM | 00,080,412 | ---- | C] () - C:\WINDOWS\grep.exe
[08-19-2008 09:03 AM | 00,089,504 | ---- | C] (Smallfrogs Studio) - C:\WINDOWS\fdsv.exe
[08-19-2008 09:03 AM | 00,098,816 | ---- | C] () - C:\WINDOWS\sed.exe
[08-19-2008 09:03 AM | 00,136,704 | ---- | C] (SteelWerX) - C:\WINDOWS\swsc.exe
[08-19-2008 09:03 AM | 00,161,792 | ---- | C] (SteelWerX) - C:\WINDOWS\swreg.exe
[08-19-2008 09:03 AM | 00,212,480 | ---- | C] (SteelWerX) - C:\WINDOWS\swxcacls.exe
[08-20-2008 01:48 PM | ---D | C] - C:\WINDOWS\temp
[08-22-2008 04:41 PM | 00,001,312 | ---- | C] () - C:\WINDOWS\ssconf2.bin
[08-28-2008 03:19 PM | ---D | C] - C:\WINDOWS\Internet Logs
[08-02-2008 01:38 PM | 00,000,452 | ---- | C] () - C:\WINDOWS\tasks\EasyShare Registration Task.job
[07-04-2008 07:22 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Arkadium
[07-19-2008 06:33 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Gold Casual Games
[07-22-2008 09:43 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Media Art
[07-30-2008 08:53 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\The Revills Games
[08-03-2008 12:55 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[08-05-2008 07:04 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\TheRace_dev
[08-07-2008 11:04 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Avira
[08-10-2008 06:41 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Slapdash Games
[07-04-2008 08:29 AM | ---D | C] - C:\Documents and Settings\Mario Després\Application Data\Meridian93
[07-12-2008 08:00 AM | ---D | C] - C:\Documents and Settings\Mario Després\Application Data\AlauxSoft
[08-03-2008 12:55 PM | ---D | C] - C:\Documents and Settings\Mario Després\Application Data\Malwarebytes
[08-11-2008 11:46 AM | ---D | C] - C:\Documents and Settings\Mario Després\Application Data\Skinux
[08-22-2008 04:35 PM | ---D | C] - C:\Documents and Settings\Mario Després\Application Data\TMInc
[07-02-2008 06:37 AM | ---D | C] - C:\Documents and Settings\Mario Després\Local Settings\Application Data\Turtix
[08-02-2008 01:54 PM | ---D | C] - C:\Documents and Settings\Mario Després\Local Settings\Application Data\KodakGallery
[08-03-2008 10:57 AM | 02,191,856 | -H-- | C] () - C:\Documents and Settings\Mario Després\Local Settings\Application Data\IconCache.db
[08-17-2008 02:56 PM | ---D | C] - C:\Documents and Settings\Mario Després\Local Settings\Application Data\Conduit
[08-18-2008 07:43 AM | ---D | C] - C:\Documents and Settings\Mario Després\Local Settings\Application Data\free-downloads.net
[08-09-2008 09:25 AM | ---D | C] - C:\Documents and Settings\All Users\Documents\RA Distribution
[08-10-2008 06:41 AM | ---D | C] - C:\Documents and Settings\All Users\Documents\Slapdash Games
[08-03-2008 09:58 AM | 00,156,546 | ---- | C] () - C:\Documents and Settings\Mario Després\Mes documents\cc_20080803_0958.reg
[07-12-2008 08:44 AM | 00,000,841 | ---- | C] () - C:\Documents and Settings\All Users\Bureau\Ad-Aware SE Personal.lnk
[07-14-2008 08:48 AM | 00,000,378 | ---- | C] () - C:\Documents and Settings\All Users\Bureau\Midnight Club II.lnk
[08-02-2008 01:47 PM | 00,001,659 | ---- | C] () - C:\Documents and Settings\All Users\Bureau\Kodak EasyShare.lnk
[08-14-2008 12:55 PM | 00,001,729 | ---- | C] () - C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[08-16-2008 02:03 PM | 00,001,556 | ---- | C] () - C:\Documents and Settings\All Users\Bureau\Encore plus de jeux.lnk
[08-29-2008 07:24 AM | 00,001,723 | ---- | C] () - C:\Documents and Settings\All Users\Bureau\Righteous Kill.lnk
[08-02-2008 08:03 AM | 00,001,806 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\Nemo's Aquarium 3D.lnk
[08-02-2008 09:19 PM | 00,000,933 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\Spybot - Search & Destroy.lnk
[08-03-2008 10:43 AM | 00,001,734 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\HijackThis.lnk
[08-14-2008 07:17 PM | 00,000,809 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\Raccourci vers avcenter.exe.lnk
[08-15-2008 10:00 AM | 00,766,184 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\100_0847.jpg
[08-15-2008 10:00 AM | 00,815,926 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\100_0845.jpg
[08-15-2008 10:00 AM | 00,833,158 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\100_0846.jpg
[08-19-2008 07:36 PM | 00,000,682 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\Raccourci vers Eye On Network.exe.lnk
[08-20-2008 01:12 PM | 02,719,778 | R--- | C] () - C:\Documents and Settings\Mario Després\Bureau\ComboFix.exe
[08-21-2008 06:37 PM | 00,568,477 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\OTScanIt.exe
[08-21-2008 06:38 PM | ---D | C] - C:\Documents and Settings\Mario Després\Bureau\OTScanIt
[08-22-2008 04:36 PM | 00,000,649 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\Raccourci vers TMInc.lnk
[08-22-2008 04:48 PM | 00,791,393 | ---- | C] (Lars Hederer ) - C:\Documents and Settings\Mario Després\Bureau\erunt-setup.exe
[08-22-2008 04:49 PM | 00,000,592 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\ERUNT.lnk
[08-22-2008 04:49 PM | 00,000,611 | ---- | C] () - C:\Documents and Settings\Mario Després\Bureau\NTREGOPT.lnk
[08-02-2008 01:13 PM | 00,001,996 | ---- | C] () - C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Kodak software updater.lnk
[08-02-2008 01:47 PM | 00,001,667 | ---- | C] () - C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logiciel Kodak EasyShare.lnk
[08-02-2008 01:13 PM | ---D | C] - C:\Program Files\Fichiers communs\Kodak
[08-14-2008 06:47 AM | ---D | C] - C:\Program Files\Fichiers communs\ODBC
[07-01-2008 10:12 AM | ---D | C] - C:\Program Files\Turtix 2 - Rescue Adventures
[07-02-2008 06:37 AM | ---D | C] - C:\Program Files\Turtix Rescue Adventure
[07-04-2008 07:21 AM | ---D | C] - C:\Program Files\The Pini Society
[07-04-2008 08:28 AM | ---D | C] - C:\Program Files\Unicorn Castle
[08-01-2008 08:33 PM | ---D | C] - C:\Program Files\The Mystery Of The Crystal Portal
[08-02-2008 01:06 PM | ---D | C] - C:\Program Files\Kodak
[08-02-2008 08:03 AM | ---D | C] - C:\Program Files\Nemo's Aquarium 3D
[08-02-2008 08:10 AM | ---D | C] - C:\Program Files\Cactus Bruce and the Corporate Monkeys
[08-02-2008 09:19 PM | ---D | C] - C:\Program Files\Spybot - Search & Destroy
[08-03-2008 10:43 AM | ---D | C] - C:\Program Files\Trend Micro
[08-06-2008 07:38 AM | ---D | C] - C:\Program Files\Sun
[08-07-2008 11:04 AM | ---D | C] - C:\Program Files\Avira
[08-15-2008 08:23 PM | ---D | C] - C:\Program Files\Wild West Quest
[08-17-2008 02:55 PM | ---D | C] - C:\Program Files\free-downloads.net
[08-17-2008 02:56 PM | ---D | C] - C:\Program Files\Conduit
[08-19-2008 06:15 AM | ---D | C] - C:\Program Files\Hawaiian Explorer - Lost Island
[08-22-2008 04:49 PM | ---D | C] - C:\Program Files\ERUNT
[08-28-2008 03:19 PM | ---D | C] - C:\Program Files\Zone Labs
========== Files/Folders - Modified Within 60 days ==========
[07-02-2008 05:31 PM | 00,000,232 | -H-- | M] () - C:\sqmdata19.sqm
[07-02-2008 05:31 PM | 00,000,244 | -H-- | M] () - C:\sqmnoopt19.sqm
[07-02-2008 08:57 AM | 00,000,232 | -H-- | M] () - C:\sqmdata15.sqm
[07-02-2008 08:57 AM | 00,000,244 | -H-- | M] () - C:\sqmnoopt15.sqm
Répondre à tinomme1969
OTViewIt Extras logfile created on: 2008-08-29 08:53:26 - Run 1
OTViewIt by OldTimer - Version 1.0.1.0 Folder = C:\Documents and Settings\Mario Després\Bureau
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.55 Gb Available Physical Memory | 77.58% Memory free
2.60 Gb Paging File | 2.26 Gb Available in Paging File | 86.87% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 46.89 Gb Total Space | 1.76 Gb Free Space | 3.76% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 27.64 Gb Total Space | 18.82 Gb Free Space | 68.08% Space Free | Partition Type: NTFS
Drive F: | 149.04 Gb Total Space | 121.70 Gb Free Space | 81.66% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] - File not found -
.cmd [@ = cmdfile] - File not found -
.com [@ = ComFile] - File not found -
.exe [@ = exefile] - File not found -
.html [@ = FirefoxHTML] - [07-16-2008 06:45 PM | 07,667,312 | ---- | M] (Mozilla Corporation) - C:\Program Files\Mozilla Firefox\firefox.exe
.pif [@ = piffile] - File not found -
.scr [@ = scrfile] - File not found -
========== Winsock2 Catalogs ==========
========== HKEY_LOCAL_MACHINE Protocol Defaults ==========
========== HKEY_CURRENT_USER Protocol Defaults ==========
========== Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
msdaipp: [HKLM - No CLSID value]
========== Protocol Filters ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{0297C87B-CC40-446F-865A-031B4FC0CF22}" = Race Driver 3
"{0325F1C1-883A-41AB-8981-B27359ABDFAF}" = Joint Operations: Typhoon Rising
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{084A9731-D05B-4ADA-B4A0-0ADD25FD7152}" = Splinter Cell Pandora Tomorrow
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}" = Security Update for CAPICOM (KB931906)
"{12E11FBB-7CA6-4A86-834D-5E6390D51009}" = ASUS SmartDoctor
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{169E414A-37C7-434E-9021-27A03AE087CD}" = ASUS Video Security
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{21A127AE-2DAF-40B7-8374-34C3E629521C}" = Far Cry (Patch 1.3)
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{252436F1-9583-4AD7-AA11-619AFFB96543}" = Xpand Rally
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{25A1E6A4-2DBD-4AC0-8650-8EA9A45B183D}" = Supreme Commander
"{27DC856A-0916-4988-8198-8714DDD3183D}" = AGEIA PhysX v7.05.17
"{2B653229-9854-4989-B780-D978F5F13EAB}" = FEAR
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java(TM) SE Development Kit 6 Update 7
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352B2D26-26A3-468C-8295-AE2830EE0536}" = Les Chemins de la Lecture
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{37477865-A3F1-4772-AD43-AAFC6BCFF99F}" = MSXML 4.0 SP2 (KB927978)
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3AFC7779-F2B8-49A4-9689-A2EA86ABCC8A}" = Dora Sakado
"{3C662203-292F-4E9D-AE02-281071C06903}" = Far Cry (Patch 1.33)
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{58DF884F-D071-4AFA-97AC-12D6626C6E9E}" = Adiboud'chou à la campagne
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{65248369-7CB9-43A9-82C8-C438AE04DED4}" = 1500
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D8533B-9EE7-46AB-B8B2-D643F888C5DF}" = ASUS GameFace Live
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7864A8D8-095F-483C-B060-B4A1F1EB4A6E}" = Natalie Brooks - Secrets Of Treasure House
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{81A60A13-224D-4637-8203-3EAC03B121A4}" = Seagate DiscWizard
"{81E06318-EEB9-4D55-8CD5-7AC9148D5E66}" = 1500_Help
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8}" = HLPSFO
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{9011040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}" = Google Earth
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A99968BE-C155-474C-0089-33239DEE1CE2}" = NFS Underground
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1036-7B44-A90000000001}" = Adobe Reader 9 - Français
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B023185F-F1EF-4F97-B0BD-AE6D802226D1}" = NVIDIA WDM Drivers
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C04E32E0-0416-434D-AFB9-6969D703A9EF}" = MSXML 4.0 SP2 (KB936181)
"{C194D333-B84A-4BB7-B35E-060732D98DC4}" = GPGNet
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logiciel QuickCam de Logitech
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBA30674-A242-4531-82B5-586B31F90E04}" = 1500Trb
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{D13E2C9A-5E09-41C8-ABCD-C7E67525C26D}" = Voyage au Pays de la Lecture
"{D2DEA9D8-2C39-42DA-B2A8-E91AF5D09490}" = Mozaki Blocks Deluxe
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Logiciel Kodak EasyShare
"{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}" = Far Cry
"{D9C70541-ADA5-40A4-B176-6AAFCBA05C8F}" = Airfix Dogfighter
"{DA9279A7-CA49-4012-820B-1AE318ABFFCB}" = ELKPlayer
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E90DCEE9-DC27-401B-A7AC-B0AFF5B34E4D}" = Lock On: Modern Air Combat
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EE8592F6-FC2B-4AFD-B527-109D127C039F}" = Far Cry (Patch 1.31)
"{EFE6E3B6-8CA9-4837-B292-5F11A80339A9}" = PunkBuster for Joint Operations
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F3856E7C-AD71-48E1-9A95-6D7E7FCB164A}" = Midnight Club II
"{F4026ECE-9F19-43EC-9FC8-474C2DB7D2BE}" = ASUS Utilities
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}" = Windows Live Messenger
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F86FFD86-1966-4C6C-99D9-44A6E7AB97E3}" = SweetIM For Internet Explorer 1.0a
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP
"{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}" = Windows Live installer
"{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}" = ESSEMAIL
"Abra Academy_is1" = Abra Academy
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"AddressBook" =
"Adobe Acrobat 4.0" =
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AlawarGameBox" = Alawar Game Box
"Amazing Adventures The Lost Tomb_is1" = Amazing Adventures The Lost Tomb
"AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus
"Atomica Deluxe 2.5" = Atomica Deluxe 2.5
"BackWeb-8876480 Uninstaller" =
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"Bejeweled Deluxe 1.862" = Bejeweled Deluxe 1.862
"BFGC" = Big Fish Games Client
"BFG-Turtix 2 - Rescue Adventures" = Turtix 2: Rescue Adventures
"Big City Adventure San Francisco_is1" = Big City Adventure San Francisco
"Big City Adventures-Sydney Australia1.0" = Big City Adventures-Sydney Australia
"Bookworm Deluxe" = Bookworm Deluxe
"BookWorm Deluxe 1.01" = BookWorm Deluxe 1.01
"Branding" =
"Break" = Break
"Cactus Bruce and the Corporate Monkeys_is1" = Cactus Bruce and the Corporate Monkeys
"CCleaner" = CCleaner (remove only)
"Chainz_is1" = Chainz
"Christmas Tree Screensaver" = Christmas Tree Screensaver
"Christmasville_is1" = Christmasville
"Chuzzle Deluxe 1.0" = Chuzzle Deluxe 1.0
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F30&SUBSYS_205514F1" = PCI SoftV92 Modem
"Connection Manager" =
"Core Center" = Core Center
"DirectAnimation" =
"DirectDrawEx" =
"Drug Lord 2" = Drug Lord 2
"DXM_Runtime" =
"ERUNT_is1" = ERUNT 1.1j
"Eye On Network" = Eye On Network (désinstallation)
"Fontcore" =
"free-downloads.net Toolbar" = free-downloads.net Toolbar
"Happyland Adventures - Xmas Edition_is1" = Happyland Adventures - Xmas Edition v1.3
"Hawaiian Explorer - Lost Island" = Hawaiian Explorer - Lost Island
"Hawaiian Explorer Pearl Harbor_is1" = Hawaiian Explorer Pearl Harbor
"Hidden Expedition Titanic" = Hidden Expedition Titanic (remove only)
"Hidden Relics_is1" = Hidden Relics
"Hidden Secrets - The Nightmare1.0" = Hidden Secrets - The Nightmare
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"IEData" =
"InstallShield Uninstall Information" =
"InstallShield_{169E414A-37C7-434E-9021-27A03AE087CD}" = ASUS Video Security
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{252436F1-9583-4AD7-AA11-619AFFB96543}" = Xpand Rally
"InstallShield_{524C56E0-6560-45D6-8C37-34C9DDBE3BF6}" =
"InstallShield_{68D8533B-9EE7-46AB-B8B2-D643F888C5DF}" = ASUS GameFace Live
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0 Demo
"InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}" = Far Cry
"InstallShield_{F4026ECE-9F19-43EC-9FC8-474C2DB7D2BE}" = ASUS Utilities
"iWinArcade" = iWin Games (remove only)
"Jumping Jack1.0" = Jumping Jack
"KB873339" = Correctif Windows XP - KB873339
"KB884016" =
"KB885250" = Correctif Windows XP - KB885250
"KB885835" = Correctif Windows XP - KB885835
"KB885836" = Correctif Windows XP - KB885836
"KB886185" = Correctif Windows XP - KB886185
"KB887472" = Correctif Windows XP - KB887472
"KB887742" = Correctif Windows XP - KB887742
"KB887797" = Correctif Windows XP - KB887797
"KB888113" = Correctif Windows XP - KB888113
"KB888302" = Correctif Windows XP - KB888302
"KB890046" = Mise à jour de sécurité pour Windows XP (KB890046)
"KB890859" = Correctif Windows XP - KB890859
"KB891781" = Correctif Windows XP - KB891781
"KB892130" = Windows Genuine Advantage Validation Tool (KB892130)
"KB893066" = Mise à jour de sécurité pour Windows XP (KB893066)
"KB893756" = Mise à jour de sécurité pour Windows XP (KB893756)
"KB893803" =
"KB893803v2" = Windows Installer 3.1 (KB893803)
"KB894391" = Mise à jour pour Windows XP (KB894391)
"KB896358" = Mise à jour de sécurité pour Windows XP (KB896358)
"KB896422" = Mise à jour de sécurité pour Windows XP (KB896422)
"KB896423" = Mise à jour de sécurité pour Windows XP (KB896423)
"KB896424" = Mise à jour de sécurité pour Windows XP (KB896424)
"KB896428" = Mise à jour de sécurité pour Windows XP (KB896428)
"KB896688" = Mise à jour de sécurité pour Windows XP (KB896688)
"KB898461" = Mise à jour pour Windows XP (KB898461)
"KB899587" = Mise à jour de sécurité pour Windows XP (KB899587)
"KB899588" = Mise à jour de sécurité pour Windows XP (KB899588)
"KB899591" = Mise à jour de sécurité pour Windows XP (KB899591)
"KB900485" = Mise à jour pour Windows XP (KB900485)
"KB900725" = Mise à jour de sécurité pour Windows XP (KB900725)
"KB900930" = Mise à jour pour Windows XP (KB900930)
"KB901017" = Mise à jour de sécurité pour Windows XP (KB901017)
"KB901214" = Mise à jour de sécurité pour Windows XP (KB901214)
"KB902400" = Mise à jour de sécurité pour Windows XP (KB902400)
"KB904706" = Mise à jour de sécurité pour Windows XP (KB904706)
"KB904942" = Mise à jour pour Windows XP (KB904942)
"KB905414" = Mise à jour de sécurité pour Windows XP (KB905414)
"KB905749" = Mise à jour de sécurité pour Windows XP (KB905749)
"KB905915" = Mise à jour de sécurité pour Windows XP (KB905915)
"KB908519" = Mise à jour de sécurité pour Windows XP (KB908519)
"KB908531" = Mise à jour de sécurité pour Windows XP (KB908531)
"KB910437" = Mise à jour pour Windows XP (KB910437)
"KB911280" = Mise à jour de sécurité pour Windows XP (KB911280)
"KB911562" = Mise à jour de sécurité pour Windows XP (KB911562)
"KB911564" = Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
"KB911565" = Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)
"KB911567" = Mise à jour de sécurité pour Windows XP (KB911567)
"KB911927" = Mise à jour de sécurité pour Windows XP (KB911927)
"KB912812" = Mise à jour de sécurité pour Windows XP (KB912812)
"KB912919" = Mise à jour de sécurité pour Windows XP (KB912919)
"KB913446" = Mise à jour de sécurité pour Windows XP (KB913446)
"KB913580" = Mise à jour de sécurité pour Windows XP (KB913580)
"KB914388" = Mise à jour de sécurité pour Windows XP (KB914388)
"KB914389" = Mise à jour de sécurité pour Windows XP (KB914389)
"KB915865" = Hotfix for Windows XP (KB915865)
"KB916281" = Mise à jour de sécurité pour Windows XP (KB916281)
"KB916595" = Mise à jour pour Windows XP (KB916595)
"KB917159" = Mise à jour de sécurité pour Windows XP (KB917159)
"KB917344" = Mise à jour de sécurité pour Windows XP (KB917344)
"KB917422" = Mise à jour de sécurité pour Windows XP (KB917422)
"KB917734_WMP10" = Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)
"KB917953" = Mise à jour de sécurité pour Windows XP (KB917953)
"KB918118" = Mise à jour de sécurité pour Windows XP (KB918118)
"KB918439" = Mise à jour de sécurité pour Windows XP (KB918439)
"KB918899" = Mise à jour de sécurité pour Windows XP (KB918899)
"KB919007" = Mise à jour de sécurité pour Windows XP (KB919007)
"KB920213" = Mise à jour de sécurité pour Windows XP (KB920213)
"KB920214" = Mise à jour de sécurité pour Windows XP (KB920214)
"KB920670" = Mise à jour de sécurité pour Windows XP (KB920670)
"KB920683" = Mise à jour de sécurité pour Windows XP (KB920683)
"KB920685" = Mise à jour de sécurité pour Windows XP (KB920685)
"KB920872" = Mise à jour pour Windows XP (KB920872)
"KB921398" = Mise à jour de sécurité pour Windows XP (KB921398)
"KB921503" = Mise à jour de sécurité pour Windows XP (KB921503)
"KB921883" = Mise à jour de sécurité pour Windows XP (KB921883)
"KB922582" = Mise à jour pour Windows XP (KB922582)
"KB922616" = Mise à jour de sécurité pour Windows XP (KB922616)
"KB922760" = Mise à jour de sécurité pour Windows XP (KB922760)
"KB922819" = Mise à jour de sécurité pour Windows XP (KB922819)
"KB923191" = Mise à jour de sécurité pour Windows XP (KB923191)
"KB923414" = Mise à jour de sécurité pour Windows XP (KB923414)
"KB923689" = Mise à jour de sécurité pour Windows XP (KB923689)
"KB923980" = Mise à jour de sécurité pour Windows XP (KB923980)
"KB924191" = Mise à jour de sécurité pour Windows XP (KB924191)
"KB924270" = Mise à jour de sécurité pour Windows XP (KB924270)
"KB924496" = Mise à jour de sécurité pour Windows XP (KB924496)
"KB924667" = Mise à jour de sécurité pour Windows XP (KB924667)
"KB925398_WMP64" = Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
"KB925486" = Mise à jour de sécurité pour Windows XP (KB925486)
"KB925902" = Mise à jour de sécurité pour Windows XP (KB925902)
"KB926239" = Hotfix for Windows XP (KB926239)
"KB926255" = Mise à jour de sécurité pour Windows XP (KB926255)
"KB926436" = Mise à jour de sécurité pour Windows XP (KB926436)
"KB927779" = Mise à jour de sécurité pour Windows XP (KB927779)
"KB927802" = Mise à jour de sécurité pour Windows XP (KB927802)
"KB927891" = Mise à jour pour Windows XP (KB927891)
"KB928255" = Mise à jour de sécurité pour Windows XP (KB928255)
"KB928843" = Mise à jour de sécurité pour Windows XP (KB928843)
"KB929123" = Mise à jour de sécurité pour Windows XP (KB929123)
"KB929338" = Mise à jour pour Windows XP (KB929338)
"KB929399" = Hotfix for Windows Media Format 11 SDK (KB929399)
"KB930178" = Mise à jour de sécurité pour Windows XP (KB930178)
"KB930916" = Mise à jour pour Windows XP (KB930916)
"KB931261" = Mise à jour de sécurité pour Windows XP (KB931261)
"KB931784" = Mise à jour de sécurité pour Windows XP (KB931784)
"KB931836" = Mise à jour pour Windows XP (KB931836)
"KB931906" = Security Update for CAPICOM (KB931906)
"KB932168" = Mise à jour de sécurité pour Windows XP (KB932168)
"KB932823-v3" = Mise à jour pour Windows XP (KB932823-v3)
"KB933360" = Mise à jour pour Windows XP (KB933360)
"KB933729" = Mise à jour de sécurité pour Windows XP (KB933729)
"KB935839" = Mise à jour de sécurité pour Windows XP (KB935839)
"KB935840" = Mise à jour de sécurité pour Windows XP (KB935840)
"KB936021" = Mise à jour de sécurité pour Windows XP (KB936021)
"KB936782_WMP10" = Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)
"KB938127-IE7" = Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
"KB938828" = Mise à jour pour Windows XP (KB938828)
"KB938829" = Mise à jour de sécurité pour Windows XP (KB938829)
"KB939653-IE7" = Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)
"KB941202" = Mise à jour de sécurité pour Windows XP (KB941202)
"KB941568" = Mise à jour de sécurité pour Windows XP (KB941568)
"KB941569" = Mise à jour de sécurité pour Windows XP (KB941569)
"KB941644" = Mise à jour de sécurité pour Windows XP (KB941644)
"KB941693" = Mise à jour de sécurité pour Windows XP (KB941693)
"KB942615-IE7" = Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)
"KB942763" = Mise à jour pour Windows XP (KB942763)
"KB943055" = Mise à jour de sécurité pour Windows XP (KB943055)
"KB943460" = Mise à jour de sécurité pour Windows XP (KB943460)
"KB943485" = Mise à jour de sécurité pour Windows XP (KB943485)
"KB944533-IE7" = Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)
"KB944653" = Mise à jour de sécurité pour Windows XP (KB944653)
"KB945553" = Mise à jour de sécurité pour Windows XP (KB945553)
"KB946026" = Mise à jour de sécurité pour Windows XP (KB946026)
"KB947864-IE7" = Correctif pour Windows Internet Explorer 7 (KB947864)
"KB948590" = Mise à jour de sécurité pour Windows XP (KB948590)
"KB948881" = Mise à jour de sécurité pour Windows XP (KB948881)
"KB950749" = Mise à jour de sécurité pour Windows XP (KB950749)
"KB950759-IE7" = Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)
"KB950760" = Mise à jour de sécurité pour Windows XP (KB950760)
"KB950762" = Mise à jour de sécurité pour Windows XP (KB950762)
"KB950974" = Mise à jour de sécurité pour Windows XP (KB950974)
"KB951066" = Mise à jour de sécurité pour Windows XP (KB951066)
"KB951072-v2" = Mise à jour pour Windows XP (KB951072-v2)
"KB951376-v2" = Mise à jour de sécurité pour Windows XP (KB951376-v2)
"KB951698" = Mise à jour de sécurité pour Windows XP (KB951698)
"KB951748" = Mise à jour de sécurité pour Windows XP (KB951748)
"KB952287" = Correctif pour Windows XP (KB952287)
"KB952954" = Mise à jour de sécurité pour Windows XP (KB952954)
"KB953838-IE7" = Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)
"KB953839" = Mise à jour de sécurité pour Windows XP (KB953839)
"Language pack for Ad-Aware SE" = Language pack for Ad-Aware SE
"Lapin Malin Maternelle 2" = Lapin Malin Maternelle 2
"LEGO Racers" = LEGO Racers
"LEGO Stunt Rally" = LEGO Stunt Rally
"LimeWire" = LimeWire PRO 4.17.5
"M928366" = Microsoft .NET Framework 1.1 Hotfix (KB928366)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mario Forever v 2.16 !" = Mario Forever v 2.16 !
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"MobileOptionPack" =
"Mozilla Firefox (2.0.0.16)" = Mozilla Firefox (2.0.0.16)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI Live Update 3" = MSI Live Update 3
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"MsJavaVM" =
"MSN Adder_is1" = MSN Adder 7.0
"MSNINST" = MSN
"Nemo's Aquarium 3D_is1" = Nemo's Aquarium 3D
"NetMeeting" =
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"OutlookExpress" =
"PCHealth" =
"Pirateville_is1" = Pirateville
"Powerboat GT_is1" = Powerboat GT 1.0.8
"PowerpointImageExtractor_is1" = PowerpointImageExtractor
"Process Master_is1" = Process Master 1.1
"Puzzle Master 5" = Puzzle Master 5
"QcDrv" = Programme de gestion Camera de Logitech®
"RealArcade" = RealArcade
"RealArcade 1.2" = RealArcade
"RECOIL" = RECOIL
"Registry Mechanic_is1" = Registry Mechanic 5.2
"Righteous Kill" = Righteous Kill (supprimer seulement)
"SchedulingAgent" =
"Shockwave" =
"Slingo Quest Hawaii [h33t] [oi812heet]" = Slingo Quest Hawaii [h33t] [oi812heet]
"Stuart Little 2" = Stuart Little 2
"Super Mario Pac_is1" = Super Mario Pac v1.1
"SystemRequirementsLab" = System Requirements Lab
"The Game Of Life" = The Game Of Life
"The Hedgehogs" = The Hedgehogs (remove only)
"The Hidden Object Show1.0" = The Hidden Object Show
"The Pini Society_is1" = The Pini Society
"The Pini Society1.0" = The Pini Society
"Tonka Raceway" = Tonka Raceway
"Tonka Search and Rescue" = Tonka Search and Rescue
"Treasure Masters Inc" = Treasure Masters Inc (supprimer seulement)
"Trophy Bass 2007 Demo" = Trophy Bass 2007 Demo
"Turtix Rescue Adventure1.2" = Turtix Rescue Adventure
"Turtix_is1" = Turtix
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"WGA" = Windows Genuine Advantage Validation Tool (KB892130)
"WgaNotify" = Windows Genuine Advantage Notifications (KB905474)
"WIC" = Windows Imaging Component
"Wild West Quest_is1" = Wild West Quest
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"WOLAPI" = Westwood Shared Internet Components
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X-mas Tree 1.2.0.0" = X-mas Tree 1.2.0.0
"Zuma Deluxe 1.0" = Zuma Deluxe 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"MétéoIMédia" = MétéoIMédia
"uTorrent" = µTorrent
========== Event Log Warnings and Errors ==========
[ Application Events ]
Application - Error - 2008-08-22 09:14:10 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-22 09:14:14 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-22 09:14:24 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-23 05:58:33 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-24 10:55:31 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 06:38:43 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 06:58:08 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 06:58:13 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 06:58:20 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 07:06:08 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Application Error
Description =
Application - Error - 2008-08-25 07:06:24 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 07:06:29 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-25 07:06:40 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-26 09:18:52 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-26 12:01:43 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-27 09:10:50 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = nview_info
Description =
Application - Error - 2008-08-28 14:19:24 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = TrueVector Service
Description =
Application - Error - 2008-08-28 14:19:24 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = TrueVector Service
Description =
Application - Error - 2008-08-28 14:19:24 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = TrueVector Service
Description =
[ System Events ]
System - Error - 2008-08-22 13:21:35 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le service Services IPSEC sest arrt avec lerreur 1747
System - Error - 2008-08-22 13:21:39 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le pilote de dmarrage systme ou damorage suivant na pas pu se charger
bdpredir
System - Error - 2008-08-22 13:54:20 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = System Error
Description = Code erreur 000000a7 paramtre 1 00000280 paramtre 2 e1b1c310 paramtre
3 89328229 paramtre 4 89328229
System - Error - 2008-08-22 15:55:51 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le service Services IPSEC sest arrt avec lerreur 1747
System - Error - 2008-08-23 16:40:30 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = sr
Description =
System - Error - 2008-08-23 16:40:35 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le service Services IPSEC sest arrt avec lerreur 1747
System - Error - 2008-08-23 16:41:38 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = System Error
Description = Code erreur 000000a7 paramtre 1 00000280 paramtre 2 e1002bb8 paramtre
3 896d21a9 paramtre 4 896d21a9
System - Error - 2008-08-24 12:19:51 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le service Services IPSEC sest arrt avec lerreur 1747
System - Error - 2008-08-24 12:21:01 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = System Error
Description = Code erreur 000000a7 paramtre 1 00000280 paramtre 2 e1b515d8 paramtre
3 8957e011 paramtre 4 8957e011
System - Error - 2008-08-26 18:21:58 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = W32Time
Description = Fournisseur de temps NtpClient une erreur sest produite lors de l
a recherche DNS delhomologue manuellement configur timewindowscom0x1 NtpClient v
a essayer nouveaula recherche DNS dans 15 minutesLerreur tait Une opration a t
tente sur un hte impossible atteindre (0x80072751)
System - Error - 2008-08-26 18:21:58 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = W32Time
Description = Le fournisseur de temps NtpClient est configur pour acqurir le temps
partir duneou plusieurs sources de temps cependant aucune source nest actuellement
accessibleAucune tentative pour en contacter une ne sera effectue dici 14 minutesNtpClient
na pas de source de temps prcis
System - Error - 2008-08-28 12:44:37 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le service Services IPSEC sest arrt avec lerreur 1747
System - Error - 2008-08-28 12:50:21 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Dhcp
Description = Le bail de ladresse IP 1921681254 pour la carte rseau dont ladresse
rseau est 00110903E472a t refus par le serveur DHCP 19216801 (celui-ci a envoy un
message DHCPNACK)
System - Error - 2008-08-28 12:50:21 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = ipnathlp
Description = Le traducteur dadresses rseau (NAT) na pas pu demander une oprationdu
module de traduction en mode noyauCeci peut indiquer une configuration incorrecte
des ressources insuffisantesou une erreur interneLa donne est le code de lerreur
System - Error - 2008-08-28 13:13:32 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Dhcp
Description = Le bail de ladresse IP 1921680101 pour la carte rseau dont ladresse
rseau est 00110903E472a t refus par le serveur DHCP 19216811 (celui-ci a envoy un
message DHCPNACK)
System - Error - 2008-08-28 13:14:27 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Dhcp
Description = Le bail de ladresse IP 1921681254 pour la carte rseau dont ladresse
rseau est 00110903E472a t refus par le serveur DHCP 19216801 (celui-ci a envoy un
message DHCPNACK)
System - Error - 2008-08-28 13:17:37 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Dhcp
Description = Le bail de ladresse IP 1921680101 pour la carte rseau dont ladresse
rseau est 00110903E472a t refus par le serveur DHCP 19216811 (celui-ci a envoy un
message DHCPNACK)
System - Error - 2008-08-28 14:07:13 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Dhcp
Description = Le bail de ladresse IP 1921681254 pour la carte rseau dont ladresse
rseau est 00110903E472a t refus par le serveur DHCP 19216801 (celui-ci a envoy un
message DHCPNACK)
System - Error - 2008-08-29 07:41:07 - Computer Name = MARIO-884D96CE1 - User Name = (blank) - Source = Service Control Manager
Description = Le service Services IPSEC sest arrt avec lerreur 1747
[ Security Events ]
[ Anti-Virus Events ]
< End of report >
Répondre à tinomme1969
Re,
Ok j'ai compris ce qui bloque, je vais me renseigner.
Sinon pour le centre de sécurité, ça doit pouvoir se corriger, mais faut trouver la bonne clé de registre.
Ton pc doit marcher convenablement là non ?
Je reviens vers toi dès que j'en sais plus, et pas au bout de trois jours cette fois-ci.
Fais un up du sujet, histoire que je ne l'oublie pas.
Sécurité / Prévention
Répondre à Egwene
ya pas d problème,je t attendrai.merci.
Répondre à tinomme1969
Bonjour,
Il me faudrait un nouveau rapport OtscanIT de base avant de poursuivre.
Sécurité / Prévention
Répondre à Egwene
Il y a 2907 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Par Destrio5 il y a 6 jours :