Le forum de la TAI8
Vous souhaitez réagir à ce message ? Créez un compte en quelques clics ou connectez-vous pour continuer.
Le deal à ne pas rater :
Cartes Pokémon 151 : où trouver le coffret Collection Alakazam-ex ?
Voir le deal

va s y francky

2 participants

Aller en bas

va s y francky Empty va s y francky

Message par mushu14 Ven 7 Nov - 20:30

je t attend
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par Noctambule Ven 7 Nov - 20:36

commence par rsit, envoie fidykill option1 , nous verrons pour elibaglia si nécessaire

c'est un hijack-this amelioré
Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<ainsi que de info.txt (<
NB : Les rapports sont sauvegardés dans le dossier C:\rsit

==============================

ça , ça traite bagle en parti
Rends toi sur ce site :
http://www.zonavirus.com/datos/descargas/95/elibagla.asp
tout en bas de cette page tu trouveras un outil
à télécharger,clique sur "escargar Elibagla" (le numéro de version change au fur et à mesure des mises à jour)
installe ce fichier sur le bureau.
ensuite double-clic sur Elibagla.exe
>laisse la case "eliminar ficheros automaticamente" coché
>clique sur"explorar"
>laisse-le travailler
>poste le rapport final qui sera dans c:\infosat.txt

Si, dans le rapport, tu vois un texte semblable à celui-ci

Por favor, envienos una muestra del fichero
C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.24
a "virus@satinfo.es". Gracias;

envoie ce(s) fichier(s) (dans l'exemple C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.24 ) à l'adresse e-mail indiquée (virus@satinfo.es).

================================
ça , ça traite bagle aussi, ( mais j'ai pas encore testé, c'estchiquitine29 qui a fait le tools)
Noctambule
Noctambule
posteur d'argent
posteur d'argent

Nombre de messages : 90
Age : 54
Date d'inscription : 21/10/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 20:38

ok, je lance la machine
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 20:40

on commence par une erreur 1 sur findykill
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par Noctambule Ven 7 Nov - 20:54

Telecharge FindyKill sur ton Bureau :

https://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

--> Lance l installation avec les parametres par default

--> Branche tes sources de données externes à ton PC, (clé USB,
disque dur externe, etc...) suceptible d avoir été infectés sans les
ouvrir


--> Double clic sur le raccourci FindyKill sur ton bureau

--> Au menu principal,choisis l'option 1 (Recherche)

--> Poste le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

----------------

Relance FindyKill :

(vérifie que les supports amovibles susceptibles d'avoir été infectés sont branchés)

-> choisis cette fois-ci l'option 2 .

/!\ durant la procédure, l'ordinateur va redémarrer !... Laisses travailler l'outil jusqu' à l'apparition du message :
"nettoyage terminé" .

Note : lors du message d'avertissement , cliques sur " Ok " .

--> ensuite poste le nouveau rapport FindyKill.txt qui est généré et attends la suite ...

( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )


PS : Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier"-> "Nouvelle tâche":
tape explorer.exe et valide .
Noctambule
Noctambule
posteur d'argent
posteur d'argent

Nombre de messages : 90
Age : 54
Date d'inscription : 21/10/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:03

Fri Nov 07 18:46:58 2008
EliBagle v11.93 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 4 de Noviembre del 2008)
----------------------------------------------
Lista de Acciones (por Acción Directa):

Fri Nov 07 18:47:12 2008
EliBagle v11.93 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 4 de Noviembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\

Nº Total de Directorios: 22911
Nº Total de Ficheros: 141544
Nº de Ficheros Analizados: 20079
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:07

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:07:18, on 07/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Artificial Dynamics\SafeSpace\SafeSpaceSysTray.exe
C:\Program Files\Artificial Dynamics\SafeSpace\WaveFramer.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceService.exe
C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\FileZilla Server\FileZilla Server Interface.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\JetAudio\JetAudio.exe
C:\Program Files\JetMailMonitor\JetMM.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\procexp.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceHost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Users\mushu\Desktop\My Mobile\MyMobiler\MyMobiler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\mushu\Desktop\ultrasurf\u.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Program Files\Power Translator 11\Applications\LEC IE Translation Extension.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SafeSpace] C:\Program Files\Artificial Dynamics\SafeSpace\SafeSpaceSysTray.exe
O4 - HKLM\..\Run: [WaveFramer] C:\Program Files\Artificial Dynamics\SafeSpace\WaveFramer.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KnexStarter] C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe
O4 - HKLM\..\Run: [RunTasktray] "C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" --regkeypath=Software\Hewlett-Packard\HP Easy Printer Care\HPPRun --valuename=InstallTTM
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: jetAudio.lnk = ?
O4 - Global Startup: jetMailMonitor.lnk = C:\Program Files\JetMailMonitor\JetMM.exe
O4 - Global Startup: procexp.exe
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.hp.com (HKLM)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_0.cab
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{48F038D0-81E7-4D07-ADC6-133DCD82CFB5}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CCS\Services\Tcpip\..\{9BF71126-3B03-4217-8CEF-182CC54742CA}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CCS\Services\Tcpip\..\{BB3754D3-448B-4AA7-A230-5D30B64AFA5F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol: HPDCS - {BA135F49-A12C-4E26-A2C4-6EA945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
O18 - Protocol: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 - Protocol: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 - Protocol: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: ,AS_WAVEHook.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Artificial Dynamics SafeSpace Agent - Unknown owner - C:\Program Files\Artificial Dynamics\SafeSpace\SafeSpace_Agent.EXE
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Cobian Backup 8 service (CobBMService) - Unknown owner - C:\Program Files\Cobian Backup 8\cbService.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Program Files\Power Translator 11\LogoMedia TranslateDotNet Server.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Artificial Dynamics WAVE Launcher Service (Wave Launcher Service) - Artificial Dynamics Ltd. - C:\Program Files\Artificial Dynamics\SafeSpace\LauncherService.exe

--
End of file - 8422 bytes
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:22

Rapport de ZHPDiag v1.1.3.7 par Nicolas Coolman
Enregistré le 07/11/2008 19:12:17
Platform : Windows Vista (TM) Business (6.0.6001) Service Pack 1
MSIE: Internet Explorer v7.0.6001.18000
OPIE: Opera 9.52
MFIE: Mozilla Firefox (3.0.3)

---\\\\\\\\\\\\\\\\ Processus lancés
C:\\\\\\\\Program Files\\\\\\\\Artificial Dynamics\\\\\\\\SafeSpace\\\\\\\\SafeSpaceSysTray.exe
C:\\\\\\\\Program Files\\\\\\\\Artificial Dynamics\\\\\\\\SafeSpace\\\\\\\\WaveFramer.exe
C:\\\\\\\\Program Files\\\\\\\\Java\\\\\\\\jre6\\\\\\\\bin\\\\\\\\jusched.exe
C:\\\\\\\\Program Files\\\\\\\\Common Files\\\\\\\\Hewlett-Packard\\\\\\\\HP Device Communication Services\\\\\\\\Appinterfaces\\\\\\\\HPDeviceService.exe
C:\\\\\\\\Program Files\\\\\\\\Hp\\\\\\\\HP Software Update\\\\\\\\HPWuSchd2.exe
C:\\\\\\\\Program Files\\\\\\\\FileZilla Server\\\\\\\\FileZilla Server Interface.exe
%windir%\\\\\\\\WindowsMobile\\\\\\\\wmdc.exe
C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe
C:\\\\\\\\Program Files\\\\\\\\Avira\\\\\\\\AntiVir PersonalEdition Classic\\\\\\\\sched.exe
C:\\\\\\\\Program Files\\\\\\\\Avira\\\\\\\\AntiVir PersonalEdition Classic\\\\\\\\avguard.exe
C:\\\\\\\\Program Files\\\\\\\\Artificial Dynamics\\\\\\\\SafeSpace\\\\\\\\SafeSpace_Agent.EXE
C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\Ati2evxx.exe
C:\\\\\\\\Program Files\\\\\\\\Cobian Backup 8\\\\\\\\cbService.exe
C:\\\\\\\\Program Files\\\\\\\\FileZilla Server\\\\\\\\FileZilla Server.exe
%windir%\\\\\\\\system32\\\\\\\\svchost.exe
C:\\\\\\\\Program Files\\\\\\\\Power Translator 11\\\\\\\\LogoMedia TranslateDotNet Server.exe
C:\\\\\\\\Program Files\\\\\\\\McAfee\\\\\\\\SiteAdvisor\\\\\\\\McSACore.exe
C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\lsass.exe
C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\SLsvc.exe
C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\spoolsv.exe

---\\\\\\\\\\\\\\\\ Plugin de navigateur Opéra (P1)
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\np32dsw.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npdivx32.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\nppl3260.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin2.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin3.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin4.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin5.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin6.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\npqtplugin7.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\nprpjplug.dll
P1 - OPN:Opera Plugin Navigator - C:\\\\\\\\Program Files\\\\\\\\Opera\\\\\\\\Program\\\\\\\\Plugins\\\\\\\\NPSWF32_FlashUtil.exe

---\\\\\\\\\\\\\\\\ Modification d'une valeur System.ini (F2)
F2 - REG:system.ini: UserInit=C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\userinit.exe,

---\\\\\\\\\\\\\\\\ Pages de démarrage d'Internet Explorer (R0)
R0 - HKCU\\\\\\\\Software\\\\\\\\Microsoft\\\\\\\\Internet Explorer\\\\\\\\Main,Start Page = http://google.fr/
R0 - HKLM\\\\\\\\Software\\\\\\\\Microsoft\\\\\\\\Internet Explorer\\\\\\\\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

---\\\\\\\\\\\\\\\\ Pages de recherche d'Internet Explorer (R1)
R1 - HKCU\\\\\\\\Software\\\\\\\\Microsoft\\\\\\\\Internet Explorer\\\\\\\\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\\\\\\\\Software\\\\\\\\Microsoft\\\\\\\\Internet Explorer\\\\\\\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\\\\\\\\Software\\\\\\\\Microsoft\\\\\\\\Internet Explorer\\\\\\\\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R1 - HKCU\\\\\\\\Software\\\\\\\\Microsoft\\\\\\\\Windows\\\\\\\\CurrentVersion\\\\\\\\Internet Settings,ProxyOverride = local

---\\\\\\\\\\\\\\\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\\\\\\\Program Files\\\\\\\\Common Files\\\\\\\\Adobe\\\\\\\\Acrobat\\\\\\\\ActiveX\\\\\\\\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\\\\\\\\Program Files\\\\\\\\SpywareGuard\\\\\\\\dlprotect.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\\\\\\\Program Files\\\\\\\\Java\\\\\\\\jre6\\\\\\\\bin\\\\\\\\ssv.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\\\\\\\\PROGRA~1\\\\\\\\mcafee\\\\\\\\SITEAD~1\\\\\\\\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\\\\\\\Program Files\\\\\\\\Java\\\\\\\\jre6\\\\\\\\bin\\\\\\\\jp2ssv.dll

---\\\\\\\\\\\\\\\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: McAfee SiteAdvisor - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\\\\\\\\PROGRA~1\\\\\\\\mcafee\\\\\\\\SITEAD~1\\\\\\\\mcieplg.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\\\\\\\\Program Files\\\\\\\\Power Translator 11\\\\\\\\Applications\\\\\\\\LEC IE Translation Extension.dll

---\\\\\\\\\\\\\\\\ Applications démarrées automatiquement par le registre (O4)
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [avgnt] "C:\\\\\\\\Program Files\\\\\\\\Avira\\\\\\\\AntiVir PersonalEdition Classic\\\\\\\\avgnt.exe" /min
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [SafeSpace] C:\\\\\\\\Program Files\\\\\\\\Artificial Dynamics\\\\\\\\SafeSpace\\\\\\\\SafeSpaceSysTray.exe
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [WaveFramer] C:\\\\\\\\Program Files\\\\\\\\Artificial Dynamics\\\\\\\\SafeSpace\\\\\\\\WaveFramer.exe
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [SunJavaUpdateSched] "C:\\\\\\\\Program Files\\\\\\\\Java\\\\\\\\jre6\\\\\\\\bin\\\\\\\\jusched.exe"
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [KnexStarter] C:\\\\\\\\Program Files\\\\\\\\Common Files\\\\\\\\Hewlett-Packard\\\\\\\\HP Device Communication Services\\\\\\\\Appinterfaces\\\\\\\\HPDeviceService.exe
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [RunTasktray] "C:\\\\\\\\Program Files\\\\\\\\Hewlett-Packard\\\\\\\\HP Easy Printer Care\\\\\\\\HPPRun.exe" --regkeypath=Software\\\\\\\\Hewlett-Packard\\\\\\\\HP Easy Printer Care\\\\\\\\HPPRun --valuename=InstallTTM
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [HP Software Update] C:\\\\\\\\Program Files\\\\\\\\Hp\\\\\\\\HP Software Update\\\\\\\\HPWuSchd2.exe
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [FileZilla Server Interface] "C:\\\\\\\\Program Files\\\\\\\\FileZilla Server\\\\\\\\FileZilla Server Interface.exe"
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [Windows Mobile Device Center] %windir%\\\\\\\\WindowsMobile\\\\\\\\wmdc.exe
O4 - HKLM\\\\\\\\..\\\\\\\\Run: [PWRISOVM.EXE] C:\\\\\\\\Program Files\\\\\\\\PowerISO\\\\\\\\PWRISOVM.EXE
O4 - HKCU\\\\\\\\..\\\\\\\\Run: [DAEMON Tools] "C:\\\\\\\\Program Files\\\\\\\\DAEMON Tools\\\\\\\\daemon.exe" -lang 1033
O4 - HKCU\\\\\\\\..\\\\\\\\Run: [Sidebar] C:\\\\\\\\Program Files\\\\\\\\Windows Sidebar\\\\\\\\sidebar.exe /autoRun
O4 - HKLM\\\\\\\\..\\\\\\\\policies\\\\\\\\Explorer: [NoDriveTypeAutoRun] Data="227"
O4 - HKLM\\\\\\\\..\\\\\\\\policies\\\\\\\\Explorer: [NoDrives] Data="0"

---\\\\\\\\\\\\\\\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: inetcpl.cpl=no

---\\\\\\\\\\\\\\\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\\\\\\\\Windows\\\\\\\\WindowsMobile\\\\\\\\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\\\\\\\\Windows\\\\\\\\WindowsMobile\\\\\\\\INetRepl.dll,211
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\\\\\\\PROGRA~1\\\\\\\\MICROS~1\\\\\\\\Office12\\\\\\\\REFBARH.ICO

---\\\\\\\\\\\\\\\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_0.cab
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab

---\\\\\\\\\\\\\\\\ Piratage de domaine (Lop.com) (O17)
O17 - HKLM\\\\\\\\System\\\\\\\\CCS\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{48F038D0-81E7-4D07-ADC6-133DCD82CFB5}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CCS\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{9BF71126-3B03-4217-8CEF-182CC54742CA}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CCS\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{BB3754D3-448B-4AA7-A230-5D30B64AFA5F}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CS2\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{48F038D0-81E7-4D07-ADC6-133DCD82CFB5}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CS2\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{9BF71126-3B03-4217-8CEF-182CC54742CA}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CS2\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{BB3754D3-448B-4AA7-A230-5D30B64AFA5F}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CS3\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{48F038D0-81E7-4D07-ADC6-133DCD82CFB5}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CS3\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{9BF71126-3B03-4217-8CEF-182CC54742CA}: 212.27.53.252,212.27.54.252
O17 - HKLM\\\\\\\\System\\\\\\\\CS3\\\\\\\\Services\\\\\\\\Tcpip\\\\\\\\..\\\\\\\\{BB3754D3-448B-4AA7-A230-5D30B64AFA5F}: 212.27.53.252,212.27.54.252

---\\\\\\\\\\\\\\\\ Protocole additionnel et piratage de protocole (O18)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\\\\\\\\PROGRA~1\\\\\\\\MSNMES~1\\\\\\\\MSGRAP~1.DLL

---\\\\\\\\\\\\\\\\ Valeur de Registre AppInit_DLLs (O20)
O20 - AppInit_DLLs: ,AS_WAVEHook.dll

---\\\\\\\\\\\\\\\\ Clé de Registre autorun SharedTaskScheduler (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030}

---\\\\\\\\\\\\\\\\ Services NT non Microsoft et non désactivés (O23)
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - C:\\\\\\\\Program Files\\\\\\\\Avira\\\\\\\\AntiVir PersonalEdition Classic\\\\\\\\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - C:\\\\\\\\Program Files\\\\\\\\Avira\\\\\\\\AntiVir PersonalEdition Classic\\\\\\\\avguard.exe
O23 - Service: Artificial Dynamics SafeSpace Agent (Artificial Dynamics SafeSpace Agent) - C:\\\\\\\\Program Files\\\\\\\\Artificial Dynamics\\\\\\\\SafeSpace\\\\\\\\SafeSpace_Agent.EXE
O23 - Service: (Ati External Event Utility) - C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\Ati2evxx.exe
O23 - Service: Cobian Backup 8 service (CobBMService) - C:\\\\\\\\Program Files\\\\\\\\Cobian Backup 8\\\\\\\\cbService.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - C:\\\\\\\\Program Files\\\\\\\\FileZilla Server\\\\\\\\FileZilla Server.exe
O23 - Service: LEC TranslateDotNet Server (LEC TranslateDotNet Server) - C:\\\\\\\\Program Files\\\\\\\\Power Translator 11\\\\\\\\LogoMedia TranslateDotNet Server.exe
O23 - Service: McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) - C:\\\\\\\\Program Files\\\\\\\\McAfee\\\\\\\\SiteAdvisor\\\\\\\\McSACore.exe
O23 - Service: @%SystemRoot%\\\\\\\\system32\\\\\\\\SLsvc.exe,-101 (slsvc) - C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\SLsvc.exe
O23 - Service: @%systemroot%\\\\\\\\system32\\\\\\\\spoolsv.exe,-1 (Spooler) - C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\spoolsv.exe

---\\\\\\\\\\\\\\\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\\\\\\\\Windows\\\\\\\\Tasks\\\\\\\\SA.DAT
O39 - APT:Automatic Planified Task - C:\\\\\\\\Windows\\\\\\\\Tasks\\\\\\\\SCHEDLGU.TXT
O39 - APT:Automatic Planified Task - C:\\\\\\\\Windows\\\\\\\\Tasks\\\\\\\\User_Feed_Synchronization-{D0CF96B5-145E-4EAE-B9E4-F8E69EE8AE46}.job
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:24

---\\\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\\Windows\\system32\\unregmp2.exe /HideWMP
O40 - ASIC: Internet Explorer - {26923b43-4d38-484f-9b9e-de460746276c} - C:\\Windows\\system32\\ie4uinit.exe -UserIconConfig
O40 - ASIC: Browser Customizations - {60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
O40 - ASIC: (no name) - AutorunsDisabled - (not file)
O40 - ASIC: Adobe Flash Player 9 ActiveX - D27CDB6E-AE6D-11CF-96B8-444553540000 - (not file)
O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - (not file)
O40 - ASIC: Macromedia Shockwave Director 8.0 - {166B1BCA-3F9C-11CF-8075-444553540000} - C:\\Windows\\System32\\Macromed\\Director\\SwDir.dll
O40 - ASIC: (no name) - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - (not file)
O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\\Windows\\System32\\wmpdxm.dll
O40 - ASIC: Macromedia Shockwave Director 8.0 - {2A202491-F00D-11cf-87CC-0020AFEECF20} - (not file)
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\\Windows\\system32\\regsvr32.exe /s /n /i:/UserInstall C:\\Windows\\system32\\themeui.dll
O40 - ASIC: Offline Browsing Pack - {3af36230-a269-11d1-b5bf-0000f8051515} - (not file)
O40 - ASIC: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) - {411EDCF7-755D-414E-A74B-3DCD6583F589} - (not file)
O40 - ASIC: (no name) - {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - (not file)
O40 - ASIC: DirectDrawEx - {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - (not file)
O40 - ASIC: Internet Explorer Help - {45ea75a0-a269-11d1-b5bf-0000f8051515} - (not file)
O40 - ASIC: Microsoft Windows Script 5.7 - {4f645220-306d-11d2-995d-00c04f98bbc9} - (not file)
O40 - ASIC: Internet Explorer Setup Tools - {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - (not file)
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} - (not file)
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\\Windows\\system32\\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
O40 - ASIC: MSN Site Access - {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - (not file)
O40 - ASIC: Address Book 7 - {7790769C-0471-11d2-AF11-00C04FA35D02} - (not file)
O40 - ASIC: .NET Framework - {7C028AF8-F614-47B3-82DA-BA94E41B1089} - (not file)
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\\Windows\\system32\\ie4uinit.exe -BaseSettings
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\\Windows\\system32\\Rundll32.exe C:\\Windows\\system32\\mscories.dll,Install
O40 - ASIC: Dynamic HTML Data Binding - {9381D8F2-0288-11D0-9501-00AA00B911A5} - (not file)
O40 - ASIC: .NET Framework - {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - (not file)
O40 - ASIC: Internet Explorer Core Fonts - {C9E9A340-D1F1-11D0-821E-444553540600} - (not file)
O40 - ASIC: .NET Framework - {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - (not file)
O40 - ASIC: (no name) - {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - (not file)
O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\\Windows\\system32\\Macromed\\Flash\\Flash9f.ocx
O40 - ASIC: HTML Help - {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - (not file)
O40 - ASIC: Active Directory Service Interface - {E92B03AB-B707-11d2-9CBD-0000F87A369E} - (not file)

---\\\\ Pilotes lancés au démarrage (O41)
O41 - Driver: AEGIS Protocol (IEEE 802.1x) v3.4.3.0 (AegisP) - C:\\WINDOWS\\system32\\DRIVERS\\AegisP.sys
O41 - Driver: ASWave (ASWave) - C:\\Windows\\system32\\drivers\\ASWave.sys
O41 - Driver: Pilote de média asynchrone RAS (AsyncMac) - C:\\WINDOWS\\system32\\DRIVERS\\asyncmac.sys
O41 - Driver: (no object) (atikmdag) - C:\\WINDOWS\\system32\\DRIVERS\\atikmdag.sys
O41 - Driver: avgio (avgio) - C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgio.sys
O41 - Driver: avgntflt (avgntflt) - C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgntflt.sys
O41 - Driver: avipbb (avipbb) - C:\\WINDOWS\\system32\\DRIVERS\\avipbb.sys
O41 - Driver: Profil AVRCP Bluetooth (BthAvrcp) - C:\\WINDOWS\\system32\\DRIVERS\\BthAvrcp.sys
O41 - Driver: Pilote de bloc de demande Bluetooth (BthEnum) - C:\\WINDOWS\\system32\\DRIVERS\\BthEnum.sys
O41 - Driver: Périphérique Bluetooth (réseau personnel) (BthPan) - C:\\WINDOWS\\system32\\DRIVERS\\bthpan.sys
O41 - Driver: Pilote de port Bluetooth (BTHPORT) - C:\\WINDOWS\\System32\\Drivers\\BTHport.sys
O41 - Driver: Pilote USB radio Bluetooth (BTHUSB) - C:\\WINDOWS\\System32\\Drivers\\BTHUSB.sys
O41 - Driver: Pilote MS IEEE-1284.4 (dot4) - C:\\WINDOWS\\system32\\DRIVERS\\Dot4.sys
O41 - Driver: Pilote de classe Imprimante pour IEEE-1284.4 (Dot4Print) - C:\\WINDOWS\\system32\\DRIVERS\\Dot4Prt.sys
O41 - Driver: Filtre Dot4USB Dot4USB Filter (dot4usb) - C:\\WINDOWS\\system32\\DRIVERS\\dot4usb.sys
O41 - Driver: Filtre de décodeur DRM (Noyau Microsoft) (drmkaud) - C:\\WINDOWS\\system32\\drivers\\drmkaud.sys
O41 - Driver: USB2.0 DVB-T Dongle (DTV5100) - C:\\WINDOWS\\SYSTEM32\\DRIVERS\\DTV5100.SYS
O41 - Driver: LITE-ON DVB-T USB adapter firmware (DTVFW) - C:\\WINDOWS\\system32\\DRIVERS\\dtvfw.sys
O41 - Driver: Intel(R) PRO/1000 NDIS 6 Adapter Driver (E1G60) - C:\\WINDOWS\\system32\\DRIVERS\\E1G60I32.sys
O41 - Driver: ElbyCDIO Driver (ElbyCDIO) - C:\\WINDOWS\\System32\\Drivers\\ElbyCDIO.sys
O41 - Driver: ENTECH (ENTECH) - C:\\Windows\\system32\\DRIVERS\\ENTECH.sys
O41 - Driver: epmntdrv (epmntdrv) - C:\\Windows\\system32\\epmntdrv.sys
O41 - Driver: EuGdiDrv (EuGdiDrv) - C:\\Windows\\system32\\EuGdiDrv.sys
O41 - Driver: Lavalys EVEREST Kernel Driver (EverestDriver) - C:\\Program Files\\Lavalys\\EVEREST Home Edition\\kerneld.wnt
O41 - Driver: (no object) (G200) - C:\\WINDOWS\\system32\\DRIVERS\\g200mini.sys
O41 - Driver: giveio (giveio) - C:\\WINDOWS\\system32\\giveio.sys
O41 - Driver: Hamachi Network Interface (hamachi) - C:\\WINDOWS\\system32\\DRIVERS\\hamachi.sys
O41 - Driver: Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio (HdAudAddService) - C:\\WINDOWS\\system32\\drivers\\HdAudio.sys
O41 - Driver: Comodo Firewall Network Driver (Inspect) - C:\\WINDOWS\\system32\\DRIVERS\\inspect.sys
O41 - Driver: Service for Realtek HD Audio (WDM) (IntcAzAudAddService) - C:\\WINDOWS\\system32\\drivers\\RTKVHDA.sys
O41 - Driver: @%systemroot%\\system32\\rascfg.dll,-32013 (IpFilterDriver) - C:\\WINDOWS\\system32\\DRIVERS\\ipfltdrv.sys
O41 - Driver: IP in IP Tunnel Driver (IpInIp) - C:\\WINDOWS\\system32\\DRIVERS\\ipinip.sys
O41 - Driver: Protocole IrDA (irda) - C:\\WINDOWS\\system32\\DRIVERS\\irda.sys
O41 - Driver: Pilote série infrarouge Microsoft (irsir) - C:\\WINDOWS\\system32\\DRIVERS\\irsir.sys
O41 - Driver: Pilote d’E/S du mappage de découverte de topologie de la couche de liaison (lltdio) - C:\\WINDOWS\\system32\\DRIVERS\\lltdio.sys
O41 - Driver: (no object) (MGAU) - C:\\WINDOWS\\system32\\DRIVERS\\mgaum.sys
O41 - Driver: Service Pilote de fonction de classe Moniteur Microsoft (monitor) - C:\\WINDOWS\\system32\\DRIVERS\\monitor.sys
O41 - Driver: Proxy de service de répartition Microsoft (MSKSSRV) - C:\\WINDOWS\\system32\\drivers\\MSKSSRV.sys
O41 - Driver: Proxy d'horloge de répartition Microsoft (MSPCLOCK) - C:\\WINDOWS\\system32\\drivers\\MSPCLOCK.sys
O41 - Driver: Proxy de gestion de qualité de répartition Microsoft (MSPQM) - C:\\WINDOWS\\system32\\drivers\\MSPQM.sys
O41 - Driver: Convertisseur en T/site-à-site de répartition Microsoft (MSTEE) - C:\\WINDOWS\\system32\\drivers\\MSTEE.sys
O41 - Driver: (no object) (MTXPAR) - C:\\WINDOWS\\system32\\DRIVERS\\mtxparm.sys
O41 - Driver: Filtre NativeWiFi (NativeWifiP) - C:\\WINDOWS\\system32\\DRIVERS\\nwifi.sys
O41 - Driver: @%systemroot%\\system32\\rascfg.dll,-32001 (NdisTapi) - C:\\WINDOWS\\system32\\DRIVERS\\ndistapi.sys
O41 - Driver: NDIS mode utilisateur E/S Protocole (Ndisuio) - C:\\WINDOWS\\system32\\DRIVERS\\ndisuio.sys
O41 - Driver: @%systemroot%\\system32\\rascfg.dll,-32002 (NdisWan) - C:\\WINDOWS\\system32\\DRIVERS\\ndiswan.sys
O41 - Driver: NetBIOS Interface (NetBIOS) - C:\\WINDOWS\\system32\\DRIVERS\\netbios.sys
O41 - Driver: Notebook Hardware Control Driver (nhcDriverDevice) - C:\\Windows\\system32\\drivers\\nhcDriver.sys
O41 - Driver: IPX Traffic Filter Driver (NwlnkFlt) - C:\\WINDOWS\\system32\\DRIVERS\\nwlnkflt.sys
O41 - Driver: IPX Traffic Forwarder Driver (NwlnkFwd) - C:\\WINDOWS\\system32\\DRIVERS\\nwlnkfwd.sys
O41 - Driver: Miniport réseau étendu WAN (PPTP) (PptpMiniport) - C:\\WINDOWS\\system32\\DRIVERS\\raspptp.sys
O41 - Driver: ProSecur (ProSecur) - C:\\Program Files\\ProSecurity\\ProSecur.sys
O41 - Driver: @%SystemRoot%\\System32\\drivers\\pacer.sys,-101 (PSched) - C:\\WINDOWS\\system32\\DRIVERS\\pacer.sys
O41 - Driver: (no object) (R300) - C:\\WINDOWS\\system32\\DRIVERS\\atikmdag.sys
O41 - Driver: Remote Access Auto Connection Driver (RasAcd) - C:\\WINDOWS\\System32\\DRIVERS\\rasacd.sys
O41 - Driver: Miniport réseau étendu WAN (L2TP) (Rasl2tp) - C:\\WINDOWS\\system32\\DRIVERS\\rasl2tp.sys
O41 - Driver: @%systemroot%\\system32\\rascfg.dll,-32007 (RasPppoe) - C:\\WINDOWS\\system32\\DRIVERS\\raspppoe.sys
O41 - Driver: @%systemroot%\\system32\\sstpsvc.dll,-202 (RasSstp) - C:\\WINDOWS\\system32\\DRIVERS\\rassstp.sys
O41 - Driver: Périphérique Bluetooth (TDI protocole RFCOMM) (RFCOMM) - C:\\WINDOWS\\system32\\DRIVERS\\rfcomm.sys
O41 - Driver: RivaTuner32 (RivaTuner32) - C:\\Program Files\\RivaTuner v2.11\\RivaTuner32.sys
O41 - Driver: Répondeur de découverte de topologie de la couche de liaison (rspndr) - C:\\WINDOWS\\system32\\DRIVERS\\rspndr.sys
O41 - Driver: Sitecom RT61 Wireless Network Driver (RT61) - C:\\WINDOWS\\system32\\DRIVERS\\RT61.sys
O41 - Driver: Sitecom RT61 Wireless Network Driver for Windows Vista (rt61x86) - C:\\WINDOWS\\system32\\DRIVERS\\netr61.sys
O41 - Driver: @%SystemRoot%\\system32\\tcpipcfg.dll,-50005 (Smb) - C:\\WINDOWS\\system32\\DRIVERS\\smb.sys
O41 - Driver: speedfan (speedfan) - C:\\WINDOWS\\system32\\speedfan.sys
O41 - Driver: (no object) (sptd) - C:\\WINDOWS\\System32\\Drivers\\sptd.sys
O41 - Driver: ssmdrv (ssmdrv) - C:\\WINDOWS\\system32\\DRIVERS\\ssmdrv.sys
O41 - Driver: (no object) (ST330) - C:\\WINDOWS\\system32\\drivers\\st330.sys
O41 - Driver: (no object) (STBUS) - C:\\WINDOWS\\system32\\drivers\\stbus.sys
O41 - Driver: Pilote de protocole IPv6 Microsoft (Tcpip6) - C:\\WINDOWS\\system32\\DRIVERS\\tcpip.sys
O41 - Driver: Teefer for NT (Teefer) - C:\\Windows\\SYSTEM32\\Drivers\\Teefer.sys
O41 - Driver: Pilote de carte miniport Microsoft Tun (tunmp) - C:\\WINDOWS\\system32\\DRIVERS\\tunmp.sys
O41 - Driver: Pilote de carte miniport Microsoft IPv6 Tunnel (tunnel) - C:\\WINDOWS\\system32\\DRIVERS\\tunnel.sys
O41 - Driver: LITE-ON DVB-T (PID=F001) receiver (usbdtv) - C:\\WINDOWS\\System32\\Drivers\\usbdtv.sys
O41 - Driver: Pilote de scanneur USB (usbscan) - C:\\WINDOWS\\system32\\DRIVERS\\usbscan.sys
O41 - Driver: Carte RNDIS USB (usb_rndisx) - C:\\WINDOWS\\system32\\DRIVERS\\usb8023x.sys
O41 - Driver: VirtualBox Service (VBoxDrv) - C:\\WINDOWS\\system32\\DRIVERS\\VBoxDrv.sys
O41 - Driver: VirtualBox USB Filter Driver (VBoxUSBFlt) - C:\\WINDOWS\\system32\\DRIVERS\\VBoxUSBFlt.sys
O41 - Driver: (no object) (vga) - C:\\WINDOWS\\system32\\DRIVERS\\vgapnp.sys
O41 - Driver: Virtual Machine Monitor (vmm) - C:\\Windows\\system32\\Drivers\\vmm.sys
O41 - Driver: Virtual Machine Network Services Driver (VPCNetS2) - C:\\WINDOWS\\system32\\DRIVERS\\VMNetSrv.sys
O41 - Driver: Remote Access IP ARP Driver (Wanarp) - C:\\WINDOWS\\system32\\DRIVERS\\wanarp.sys
O41 - Driver: Remote Access IPv6 ARP Driver (Wanarpv6) - C:\\WINDOWS\\system32\\DRIVERS\\wanarp.sys
O41 - Driver: GlobeSpan Usb ADSL WAN Modem (wanusb) - C:\\WINDOWS\\system32\\DRIVERS\\gwausb.sys
O41 - Driver: SyGate for NT, wg3n (wg3n) - C:\\Windows\\SYSTEM32\\Drivers\\wg3n.sys
O41 - Driver: wpsdrvnt (wpsdrvnt) - C:\\WINDOWS\\system32\\drivers\\wpsdrvnt.sys
O41 - Driver: (no object) (WUDFRd) - C:\\WINDOWS\\system32\\DRIVERS\\WUDFRd.sys
O41 - Driver: NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller (yukonwlh) - C:\\WINDOWS\\system32\\DRIVERS\\yk60x86.sys
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:25

---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player Plugin
O42 - Logiciel: Alt WAV MP3 WMA OGG Converter v3.2
O42 - Logiciel: Ant Movie Catalog
O42 - Logiciel: Ant Renamer
O42 - Logiciel: Avira AntiVir Personal - Free Antivirus
O42 - Logiciel: AnyDVD
O42 - Logiciel: Anywhere PE Viewer 0.1.7
O42 - Logiciel: CCleaner (remove only)
O42 - Logiciel: CDex extraction audio
O42 - Logiciel: Chromium BSU
O42 - Logiciel: CloneDVD2
O42 - Logiciel: Documalis Free Printer
O42 - Logiciel: Documalis Free Scanner 1.0
O42 - Logiciel: DScaler 5 Mpeg Decoders
O42 - Logiciel: EASEUS Partition Manager 2.1 Home Edition
O42 - Logiciel: EasyBCD 1.7.1
O42 - Logiciel: eMule
O42 - Logiciel: FastStone Capture 5.3 (French)
O42 - Logiciel: ffdshow [rev 2144] [2008-09-24]
O42 - Logiciel: FileZilla (remove only)
O42 - Logiciel: FileZilla Server (remove only)
O42 - Logiciel: Freeplayer
O42 - Logiciel: Gold Rush Treasure Hunt
O42 - Logiciel: GoldWave v4.19
O42 - Logiciel: GPL Ghostscript 8.50
O42 - Logiciel: GPL Ghostscript Fonts
O42 - Logiciel: Haali Media Splitter
O42 - Logiciel: HijackThis 2.0.2
O42 - Logiciel: HP Download Manager
O42 - Logiciel: HP Easy Printer Care
O42 - Logiciel: Java Advanced Imaging 1.1.3 for JRE
O42 - Logiciel: jetMailMonitor French Language Pack
O42 - Logiciel: jv16 PowerTools 2008
O42 - Logiciel: Security Update for CAPICOM (KB931906)
O42 - Logiciel: KVIrc
O42 - Logiciel: Launch Manager 1.21
O42 - Logiciel: Malwarebytes' Anti-Malware
O42 - Logiciel: Marvell Miniport Driver
O42 - Logiciel: Maxthon2 Browser (remove only)
O42 - Logiciel: Microsoft .NET Framework 1.1
O42 - Logiciel: mIRC
O42 - Logiciel: Movie Collection 5.4.9.0
O42 - Logiciel: Mozilla Firefox (3.0.3)
O42 - Logiciel: Mozilla Thunderbird (2.0.0.16)
O42 - Logiciel: Multiquence v2.54
O42 - Logiciel: MusicBrainz Picard 0.10
O42 - Logiciel: Notepad++
O42 - Logiciel: OpenAL
O42 - Logiciel: OpenSSL-0.9.7c Binaries (GnuWin32)
O42 - Logiciel: PC Wizard 2008.1.82
O42 - Logiciel: PowerISO
O42 - Logiciel: Microsoft Office Professional Plus 2007
O42 - Logiciel: Real Alternative 1.8.2
O42 - Logiciel: VNC Free Edition 4.1.2
O42 - Logiciel: Revo Uninstaller 1.34
O42 - Logiciel: Ricochet Infinity
O42 - Logiciel: RivaTuner v2.11
O42 - Logiciel: Satsuki Decoder Pack 4000
O42 - Logiciel: Shockwave
O42 - Logiciel: SoftKey Manager 1.00
O42 - Logiciel: SpywareBlaster 4.1
O42 - Logiciel: SpywareGuard v2.2
O42 - Logiciel: SSC Service Utility v4.30
O42 - Logiciel: SUPER © Version 2008.bld.32 (July 8, 2008)
O42 - Logiciel: TORCS - The Open Racing Car Simulator 1.3.0
O42 - Logiciel: Total Uninstall 4.8.0
O42 - Logiciel: jetAudio 7 - Traduction française
O42 - Logiciel: TweakVI
O42 - Logiciel: Unlocker 1.8.7
O42 - Logiciel: VLC media player 0.9.2
O42 - Logiciel: Winamp
O42 - Logiciel: Archiveur WinRAR
O42 - Logiciel: WMA Encoder Decoder
O42 - Logiciel: ZebHelpProcess 2.32
O42 - Logiciel: PDFCreator
O42 - Logiciel: Composants de communication des événements
O42 - Logiciel: Marvell CPA
O42 - Logiciel: LEC Translate
O42 - Logiciel: Debugging Tools for Windows (x86)
O42 - Logiciel: Google Earth
O42 - Logiciel: VirtualDub 1.8.6 Fr
O42 - Logiciel: EPSON TWAIN 5
O42 - Logiciel: Java(TM) 6 Update 10
O42 - Logiciel: Nero 7 Premium
O42 - Logiciel: Java(TM) 6 Update 7
O42 - Logiciel: McAfee SiteAdvisor
O42 - Logiciel: Macromedia Extension Manager
O42 - Logiciel: UltraEdit 14.10
O42 - Logiciel: HydraVision
O42 - Logiciel: HP Printer Settings Tools
O42 - Logiciel: jetMailMonitor
O42 - Logiciel: Opera 9.27
O42 - Logiciel: Macromedia Dreamweaver 8
O42 - Logiciel: Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
O42 - Logiciel: Apple Software Update
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable
O42 - Logiciel: HP Proactive Services
O42 - Logiciel: 3DMark06
O42 - Logiciel: ATI AVIVO Codecs
O42 - Logiciel: Microsoft Silverlight
O42 - Logiciel: DivX Player
O42 - Logiciel: QuickTime
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB955936)
O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB952142)
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB951338)
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB954326)
O42 - Logiciel: Security Update for Visio 2007 (KB947590)
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB955470)
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB951944)
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB951808)
O42 - Logiciel: Update for Office 2007 (KB946691)
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB950113)
O42 - Logiciel: 2007 Microsoft Office Suite Service Pack 1 (SP1)
O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (kb957258)
O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB950114)
O42 - Logiciel: Microsoft Office Access MUI (French) 2007
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007
O42 - Logiciel: Microsoft Office Word MUI (French) 2007
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007
O42 - Logiciel: Microsoft Office Proof (German) 2007
O42 - Logiciel: Microsoft Office Proof (English) 2007
O42 - Logiciel: Microsoft Office Proof (French) 2007
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007
O42 - Logiciel: Microsoft Office Proofing (French) 2007
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007
O42 - Logiciel: Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
O42 - Logiciel: Gestionnaire pour appareils Windows Mobile
O42 - Logiciel: IZArc 3.81
O42 - Logiciel: Composants de communication principaux
O42 - Logiciel: Prey
O42 - Logiciel: Application Suite
O42 - Logiciel: Sniper Elite
O42 - Logiciel: Adobe Reader 8.1.2 - Français
O42 - Logiciel: Adobe Reader 8.1.2 Security Update 1 (KB403742)
O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 8
O42 - Logiciel: DivX Converter
O42 - Logiciel: DivX Web Player
O42 - Logiciel: MSXML 4.0 SP2 (KB936181)
O42 - Logiciel: Composants de communication des données du périphérique
O42 - Logiciel: MSXML 4.0 SP2 (KB941833)
O42 - Logiciel: HP Update
O42 - Logiciel: Ma-Config.com
O42 - Logiciel: Composants de communication du système d'exploitation
O42 - Logiciel: VirtualDub Plugin Pack 1.0.0.3 Fr
O42 - Logiciel: All My Movies 5.0
O42 - Logiciel: jetAudio Plus VX
O42 - Logiciel: resident evil 4
O42 - Logiciel: Opera 9.52
O42 - Logiciel: Windows Mobile Device Center Driver Update
O42 - Logiciel: Artificial Dynamics SafeSpace 2.0.41
O42 - Logiciel: HP Printer Usage Report
O42 - Logiciel: Realtek High Definition Audio Driver
O42 - Logiciel: Nero Reloaded PlugIn Pack 2.0.4 by GEAR
O42 - Logiciel: Windows Live Messenger
O42 - Logiciel: 32 Bit HP CIO Components Installer
O42 - Logiciel: Catalyst Control Center - Branding
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:26

---\\\\ Contenu des dossiers Fichiers Communs (O43)
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Adobe
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Ahead
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Apple
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\ArcSoft
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\ATI Technologies
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Borland Shared
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\COWON
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\DESIGNER
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Hewlett-Packard
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\InstallShield
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Java
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Macromedia
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\McAfee
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\microsoft shared
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\PC SOFT
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\PC Tools
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\PX Storage Engine
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Services
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\SpeechEngines
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\SWF Studio
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\System
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Ulead Systems
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\WindowsLiveInstaller
O43 - CFD:Common File Directory - C:\\Program Files\\Common Files\\Wise Installation Wizard

---\\\\ Derniers fichiers modifiés ou crées sous System32 (O44)
O44 - LFC:Last File Created - C:\\Windows\\System32\\amdpcom32.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\ati2edxx.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Ati2evxx.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Ati2evxx.exe -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atiadlxx.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\ATIDEMGX.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atioglxx.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atipdlxx.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atitmmxx.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atiumdag.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atiumdva.cap -->13/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atiumdva.dat -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\atiumdva.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\bbfceab7_z.ocx -->28/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\bdod.bin -->18/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\BootMan.exe -->15/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\CallbackOperator.dll -->07/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\cid_store.dat -->30/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\CmdLineExt.dll -->01/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\deploytk.dll -->12/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Device.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\DeviceAdapter.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\DeviceManager.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\e7b5e854-.txt -->27/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\epmntdrv.sys -->17/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\EuEpmGdi.dll -->17/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\EuGdiDrv.sys -->17/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FATFileSystemAnalyser.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FatFormat.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FatLib.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FatResizeMove.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Faultrep.dll -->18/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FileSystemAnalyser.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FileSystemCheck.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Fixup.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\FNTCACHE.DAT -->06/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\gpprefcl.dll -->17/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\ieframe.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\iertutil.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\initdebug.nfo -->28/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\java.exe -->12/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\javaw.exe -->12/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\javaws.exe -->12/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\jsproxy.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\jupdate-1.6.0_07-b06.log -->30/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\mrt.exe -->07/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\mshtml.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\mshtml.tlb -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\mstime.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\netapi32.dll -->16/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\NTFSCopy.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\NTFSFileSystemAnalyser.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\NTFSFormat.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\NTFSLib.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\ntkrnlpa.exe -->18/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\ntoskrnl.exe -->18/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Oemdspif.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\OpenAL32.dll -->16/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\Partition.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\perfc009.dat -->07/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\perfc00C.dat -->07/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\perfh009.dat -->07/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\perfh00C.dat -->07/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\PerfStringBackup.INI -->07/11/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\QuickTime.qts -->06/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\QuickTimeVR.qtx -->06/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\ResizeNTFS.dll -->25/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\setupempdrv03.exe -->17/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\tmp.reg -->27/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\urlmon.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\wersvc.dll -->18/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\win32k.sys -->18/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\win32spl.dll -->12/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\wininet.dll -->02/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\wrap_oal.dll -->09/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\ati2erec.dll -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\atikmdag.sys -->21/08/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\mbam.sys -->22/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\mbamswissarmy.sys -->22/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\Msft_User_WpdRapi2_01_00_00.Wdf -->11/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\Msft_User_WpdRapi_01_00_00.Wdf -->11/10/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\SnpShot.sys -->28/09/2008
O44 - LFC:Last File Created - C:\\Windows\\System32\\drivers\\srv.sys -->27/08/2008
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:28

---\\\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\1033DOTNETFX.EXE-247BBF77.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\ACRORD32.EXE-DE3ACCC1.pf -->04/11/2008
O45
- LFCP:Last File Created Prefetch -
C:\\Windows\\Prefetch\\AgCx_S1_S-1-5-21-1349547134-3957785052-286754442-1000.snp.db
-->24/10/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AgGlFaultHistory.db -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AgGlFgAppHistory.db -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AgGlGlobalHistory.db -->07/11/2008
O45
- LFCP:Last File Created Prefetch -
C:\\Windows\\Prefetch\\AgGlUAD_P_S-1-5-21-1349547134-3957785052-286754442-1000.db
-->07/11/2008
O45 - LFCP:Last File Created Prefetch -
C:\\Windows\\Prefetch\\AgGlUAD_S-1-5-21-1349547134-3957785052-286754442-1000.db
-->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AgRobust.db -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\ASPNET_REGIIS.EXE-B76F1AD7.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\ATBROKER.EXE-2E15A492.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AVCENTER.EXE-AF580B74.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AVCONFIG.EXE-CC95D0BD.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AVGNT.EXE-562035F4.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AVGUARD.EXE-439D869E.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\AVWSC.EXE-18A3FCA0.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\CHCP.COM-61043047.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\CMD.EXE-4A81B364.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\COMPMGMTLAUNCHER.EXE-D8C6028E.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\CONIME.EXE-9781FD5F.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\CONTROL.EXE-817F8F1D.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\CSC.EXE-A3B8D95D.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\CVTRES.EXE-069169FB.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DEFRAG.EXE-588F90AD.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DFRGNTFS.EXE-7E4077FE.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DLLHOST.EXE-5E46FA0D.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DLLHOST.EXE-766398D2.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DLLHOST.EXE-7ED62AA2.pf -->03/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DLLHOST.EXE-861F96F8.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DLLHOST.EXE-8EF34503.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DOTNETFX.EXE-47FE9BC4.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DRVINST.EXE-4CB4314A.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DW20.EXE-35F4097D.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DW20.EXE-BDC1312B.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DWM.EXE-6FFD3DA8.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\DWWIN.EXE-9FB96D25.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\EPM0.EXE-DF495288.pf -->04/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\EXPLORER.EXE-A80E4F97.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FBX-PLAYLIST.EXE-4DF68FFC.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FG677P42.EXE-D5B76E07.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FILEZILLA SERVER.EXE-35C9B02C.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FIND.EXE-E2237F6D.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FINDSTR.EXE-2E9C6FE2.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FIREFOX.EXE-A606B53C.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\FREEPLAYER-WIN32-20050905.EXE-B670033E.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\GUARDGUI.EXE-6FA03444.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\HIJACKTHIS.EXE-9FD56571.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\HJTINSTALL.EXE-F8EF39D7.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\IEUSER.EXE-7C0FE221.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\INSTALL.EXE-559EE26A.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\IZARC.EXE-432FE040.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\JAVA.EXE-E27B75C2.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\JP2LAUNCHER.EXE-7C1F11C1.pf -->04/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\KVIRC.EXE-8002D41C.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\Layout.ini -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LEC CHINESE TO ENGLISH TRANSL-8A9040F4.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LEC DUTCH TO ENGLISH TRANSLAT-9A984C68.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LEC EUROPEAN TRANSLATION ENGI-BE69070E.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LOGOMEDIA HEBREW TO ENGLISH T-4B6EBC2A.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LOGOMEDIA KOREAN TO ENGLISH T-22EE7F2F.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LOGOMEDIA TRANSLATEDOTNET SER-89517D47.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\LOGONUI.EXE-09140401.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MAIN.EXE-B3B89877.pf -->04/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MAXTHON.EXE-A91B49AF.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MCSACORE.EXE-FC549BA9.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MIGPOLWIN.EXE-79E606FC.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MMC.EXE-2074AC9E.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MOBSYNC.EXE-C5E2284F.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MOFCOMP.EXE-8FE3D558.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MSDTC.EXE-CC1DEC77.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MSFEEDSSYNC.EXE-6E6FBDF4.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MSIEXEC.EXE-A2D55CB6.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MSNMSGR.EXE-DC932D94.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MSPAINT.EXE-76E10B24.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\MYMOBILER.EXE-9D32B5F7.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\NGEN.EXE-7900743E.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\NOTEPAD++.EXE-72A5A810.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\NOTEPAD.EXE-D8414F97.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\NTOSBOOT-B00DFAAD.pf -->26/09/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\OFFDIAG.EXE-8294A01E.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\OPERA.EXE-103FF2EC.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\OUTLOOK.EXE-183FA0F0.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\OUTLOOK.EXE-56F58785.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\PfSvPerfStats.bin -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\POWERISO.EXE-9A234886.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\POWERPNT.EXE-6EC2C177.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\PREUPD.EXE-A30DA2EC.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\REG.EXE-E7E8BD26.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\REGSVCS.EXE-A54AD617.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\REGSVR32.EXE-8461DBEE.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\REGTLIB.EXE-BE025EDE.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-1ECC27CF.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-230FC512.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-27288C65.pf -->04/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-35FCABC4.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-6D2968F1.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-6E6BE871.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNDLL32.EXE-70A53FFC.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\RUNONCE.EXE-D0649312.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SAFESPACE.EXE-EC73BA78.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SAFESPACESYSTRAY.EXE-A354DF53.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SED-3.59.EXE-8AB7A108.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SETUP.EXE-0B37CAA1.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SGBHP.EXE-F6E4BFD0.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SVCHOST.EXE-0E40BB00.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SVCHOST.EXE-36511C07.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SVCHOST.EXE-7CFEDEA3.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SVCHOST.EXE-9EFC97F2.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SVCHOST.EXE-DD6406E8.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SWREG.EXE-9CC507F0.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\SWREG.EXE-B310A650.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\TASKENG.EXE-48D4E289.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\TASKLIST.EXE-11A23AF3.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\TRUSTEDINSTALLER.EXE-3CC531E5.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\TU.EXE-EC3EF26D.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\UNLOCKER.EXE-65BBA82C.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\UPDATE.EXE-6CE0A11B.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\USERINIT.EXE-2257A3E7.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\UTORRENT.EXE-1070971C.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\VDS.EXE-6E7946F9.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\VDSLDR.EXE-6B089E8B.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\VERCLSID.EXE-7C52E31C.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\VLC.EXE-8FCA47C7.pf -->05/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\VLC.EXE-A11F73EE.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\VSSVC.EXE-B8AFC319.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WAVESERVICES.EXE-D9353E64.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WERCON.EXE-E36BD04E.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WERFAULT.EXE-E69F695A.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WERMGR.EXE-0F2AC88C.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WINRAR.EXE-94E7D80C.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WINWORD.EXE-C91725A1.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WMDHOST.EXE-BF75F5BB.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WMIADAP.EXE-F8DFDFA2.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WMIPRVSE.EXE-1628051C.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WMPLAYER.EXE-BAD6BD53.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WSCRIPT.EXE-52CF1F0C.pf -->06/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WUAPP.EXE-C6167071.pf -->07/11/2008
O45 - LFCP:Last File Created Prefetch - C:\\Windows\\Prefetch\\WUDFHOST.EXE-AFFEF87C.pf -->05/11/2008
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:28

---\\ ShellExecuteHooks, Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - SpywareGuard.Handler - {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll

---\\ Export de clé d'application autorisée (O47)
O47 - AAKE:Key Export - "C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe"="C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun"
O47 - AAKE:Key Export - "C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe"="C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun"

---\\ Déni du service Local Security Authority (LSA) (O48)
O48 - LSA:Local Security Authority Authentication Packages - C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages - C:\Windows\System32\scecli.dll

---\\ Recherche d'infection de Base de Registres (O71)
O71 - BDRI:[hklm\software\microsoft\active setup\installed components\{7790769c-0471-11d2-af11-00c04fa35d02}]
O71 - BDRI:[hklm\software\conduit]
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:32

ComboFix 08-11-06.01 - mushu 2008-11-07 15:46:34.1 - NTFSx86
Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.1183 [GMT 1:00]
Lancé depuis: c:\\\\users\\\\mushu\\\\Desktop\\\\ComboFix.exe
* Un nouveau point de restauration a été créé
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\\\\windows\\\\system32\\\\fafedbddeef5_z.dll
c:\\\\windows\\\\system32\\\\txfcxulr.ini

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-07 au 2008-11-07 ))))))))))))))))))))))))))))))))))))
.

2008-11-07 15:23 . 2008-11-07 15:26 d-------- c:\\\\program files\\\\ZebHelpProcess 2
2008-11-06 16:32 . 2008-11-06 16:32 d-------- C:\\\\TarguTrans
2008-11-06 13:50 . 2008-11-06 13:50 d-------- c:\\\\windows\\\\System32\\\\URTTEMP
2008-11-06 10:53 . 2008-11-06 10:53 d-------- c:\\\\program files\\\\Trend Micro
2008-11-05 09:56 . 2008-11-05 09:57 d-------- c:\\\\program files\\\\Freeplayer
2008-11-01 19:57 . 2008-11-01 20:00 d-------- c:\\\\program files\\\\Power Translator 11
2008-11-01 19:45 . 2008-11-01 19:49 d-------- c:\\\\program files\\\\PowerISO
2008-11-01 19:16 . 2008-11-06 13:49 d-------- c:\\\\program files\\\\PROMT5
2008-11-01 11:41 . 2008-11-01 11:41 108,144 --a------ c:\\\\windows\\\\System32\\\\CmdLineExt.dll
2008-11-01 11:35 . 2008-11-01 11:35 d-------- c:\\\\program files\\\\CAPCOM
2008-10-31 13:25 . 2008-10-31 14:47 1,766 -rah----- c:\\\\windows\\\\EPMBatch.ept
2008-10-31 13:23 . 2008-10-31 14:37 d-------- c:\\\\program files\\\\EASEUS
2008-10-29 12:40 . 2008-08-12 04:39 443,392 --a------ c:\\\\windows\\\\System32\\\\win32spl.dll
2008-10-29 12:40 . 2008-09-18 05:56 147,456 --a------ c:\\\\windows\\\\System32\\\\Faultrep.dll
2008-10-29 12:40 . 2008-09-18 05:56 125,952 --a------ c:\\\\windows\\\\System32\\\\wersvc.dll
2008-10-27 12:27 . 2008-10-27 12:27 d-------- c:\\\\program files\\\\Ant Renamer
2008-10-24 08:58 . 2004-02-02 09:51 55,891 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\Teefer.sys
2008-10-24 08:58 . 2004-02-02 09:53 18,518 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\wpsdrvnt.sys
2008-10-24 08:58 . 2004-02-02 09:37 11,914 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\wg3n.sys
2008-10-24 08:57 . 2004-02-02 11:06 83,096 --a------ c:\\\\windows\\\\System32\\\\SSSensor.dll
2008-10-24 08:52 . 2008-10-24 08:52 d-------- c:\\\\program files\\\\Microsoft Silverlight
2008-10-24 08:52 . 2008-08-17 11:33 678,408 --a------ c:\\\\windows\\\\System32\\\\gpprefcl.dll
2008-10-23 07:10 . 2008-10-23 07:10 d-------- c:\\\\program files\\\\MC2
2008-10-21 07:37 . 2005-12-27 15:02 65,536 --a------ c:\\\\windows\\\\System32\\\\StripMyRights.exe
2008-10-21 06:46 . 2008-10-21 06:46 d-------- c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Mozilla
2008-10-21 06:41 . 2008-10-21 06:41 d-------- c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Adobe
2008-10-21 06:40 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Searches
2008-10-21 06:40 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Searches
2008-10-21 06:40 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Contacts
2008-10-21 06:40 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Contacts
2008-10-21 06:40 . 2008-10-21 06:41 d-------- c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Hewlett-Packard
2008-10-21 06:40 . 2008-10-21 06:40 d-------- c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\COWON
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Videos
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Videos
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Saved Games
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Saved Games
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Pictures
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Pictures
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Music
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Music
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Links
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Links
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Favorites
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Favorites
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Downloads
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Downloads
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Documents
2008-10-21 06:39 . 2008-10-21 06:40 dr------- c:\\\\users\\\\surf sécurisé\\\\Documents
2008-10-21 06:39 . 2008-11-06 10:53 dr------- c:\\\\users\\\\surf sécurisé\\\\Desktop
2008-10-21 06:39 . 2008-11-06 10:53 dr------- c:\\\\users\\\\surf sécurisé\\\\Desktop
2008-10-21 06:39 . 2008-10-21 06:42 d---s---- c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Microsoft
2008-10-21 06:39 . 2008-10-21 06:40 d--h----- c:\\\\users\\\\surf sécurisé\\\\AppData
2008-10-21 06:39 . 2008-10-21 06:40 d--h----- c:\\\\users\\\\surf sécurisé\\\\AppData
2008-10-21 06:39 . 2008-10-21 06:40 d-------- c:\\\\users\\\\surf sécurisé
2008-10-21 06:39 . 2008-11-07 15:46 786,432 --ahs---- c:\\\\users\\\\surf sécurisé\\\\NTUSER.DAT
2008-10-21 06:39 . 2008-11-07 15:46 786,432 --ahs---- c:\\\\users\\\\surf sécurisé\\\\NTUSER.DAT
2008-10-20 15:20 . 2008-10-20 15:20 d-------- c:\\\\program files\\\\Prey
2008-10-18 02:53 . 2008-10-18 02:53 1,024 --a------ C:\\\\.rnd
2008-10-18 02:52 . 2008-10-18 02:52 d-------- c:\\\\program files\\\\GnuWin32
2008-10-17 00:56 . 2008-10-17 00:56 d-------- c:\\\\program files\\\\RivaTuner v2.11
2008-10-17 00:43 . 2008-10-17 00:43 d-------- c:\\\\program files\\\\RivaTuner v2.0 Final Release
2008-10-16 23:54 . 2008-10-16 23:54 d-------- c:\\\\windows\\\\System32\\\\Futuremark
2008-10-16 23:54 . 2004-10-25 19:02 21,664 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\Entech.sys
2008-10-16 23:54 . 1999-11-02 09:01 6,173 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\Entech.vxd
2008-10-16 23:54 . 2004-06-22 14:44 5,632 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\Entech64.sys
2008-10-16 23:54 . 2001-11-19 18:05 3,972 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\PciBus.sys
2008-10-16 23:53 . 2008-10-16 23:53 d-------- c:\\\\program files\\\\Futuremark
2008-10-16 15:02 . 2008-10-16 15:02 d-------- c:\\\\users\\\\All Users\\\\Office Genuine Advantage
2008-10-16 15:02 . 2008-10-16 15:02 d-------- c:\\\\programdata\\\\Office Genuine Advantage
2008-10-16 12:49 . 2008-10-16 12:49 d-------- c:\\\\program files\\\\Mediatwins software
2008-10-15 08:53 . 2008-09-18 06:09 3,601,464 --a------ c:\\\\windows\\\\System32\\\\ntkrnlpa.exe
2008-10-15 08:53 . 2008-09-18 06:09 3,549,240 --a------ c:\\\\windows\\\\System32\\\\ntoskrnl.exe
2008-10-15 08:53 . 2008-09-18 03:16 2,032,640 --a------ c:\\\\windows\\\\System32\\\\win32k.sys
2008-10-15 08:53 . 2008-10-02 02:32 1,383,424 --a------ c:\\\\windows\\\\System32\\\\mshtml.tlb
2008-10-15 08:53 . 2008-10-02 04:49 827,392 --a------ c:\\\\windows\\\\System32\\\\wininet.dll
2008-10-15 08:53 . 2008-08-27 02:06 288,768 --a------ c:\\\\windows\\\\System32\\\\drivers\\\\srv.sys
2008-10-14 12:27 . 2008-10-14 12:27 d-------- c:\\\\program files\\\\GoldEsel
2008-10-14 12:27 . 2008-10-14 12:27 d-------- c:\\\\program files\\\\Ahead
2008-10-13 18:12 . 2008-10-13 18:22 d-------- C:\\\\Tom tom navigator 7 europe
2008-10-12 19:03 . 2008-10-12 19:02 410,976 --a------ c:\\\\windows\\\\System32\\\\deploytk.dll
2008-10-12 17:05 . 2008-10-12 17:11 d-------- c:\\\\program files\\\\AllMyMovies
2008-10-12 15:16 . 2008-10-12 17:11 206 --a------ c:\\\\windows\\\\EurekaLog.ini
2008-10-12 14:14 . 2008-10-12 14:15 d-------- c:\\\\program files\\\\Movie Collection
2008-10-12 13:25 . 2008-10-12 13:47 d-------- c:\\\\program files\\\\Ant Movie Catalog
2008-10-11 17:45 . 2008-10-11 17:45 d-------- c:\\\\program files\\\\RealVNC
2008-10-11 17:34 . 2008-10-11 17:34 0 --ah----- c:\\\\windows\\\\System32\\\\drivers\\\\Msft_User_WpdRapi2_01_00_00.Wdf
2008-10-11 17:26 . 2008-10-11 17:26 d-------- c:\\\\program files\\\\Microsoft ActiveSync
2008-10-11 12:04 . 2008-10-11 12:04 0 --ah----- c:\\\\windows\\\\System32\\\\drivers\\\\Msft_User_WpdRapi_01_00_00.Wdf
2008-10-09 16:07 . 2008-10-09 16:09 d-------- c:\\\\program files\\\\SuperTuxKart
2008-10-09 16:07 . 2008-10-09 16:07 d-------- c:\\\\program files\\\\OpenAL
2008-10-09 16:07 . 2008-10-09 16:07 409,600 --a------ c:\\\\windows\\\\System32\\\\wrap_oal.dll
2008-10-09 16:07 . 2008-10-16 23:55 86,016 --a------ c:\\\\windows\\\\System32\\\\OpenAL32.dll
2008-10-09 15:54 . 2008-10-09 15:54 d-------- c:\\\\program files\\\\Tux4kids
2008-10-09 15:46 . 2008-10-09 15:47 d-------- c:\\\\program files\\\\torcs
2008-10-09 15:03 . 2008-10-09 15:03 d-------- c:\\\\program files\\\\Chromium BSU
2008-10-07 14:18 . 2008-10-07 14:18 d-------- C:\\\\HP-UPD4_5-PCL6-32
2008-10-07 13:49 . 2008-10-07 13:49 92 --a------ c:\\\\windows\\\\TraceSrv.ini
2008-10-07 13:45 . 2006-05-25 23:27 835,584 --a------ c:\\\\windows\\\\tls7912d.dll
2008-10-07 13:45 . 1998-10-29 15:45 306,688 --a------ c:\\\\windows\\\\IsUninst.exe
2008-10-07 13:45 . 2007-06-08 16:39 278,528 --a------ c:\\\\windows\\\\hpzjut01.dll
2008-10-07 13:45 . 2008-10-07 13:45 48,783 --a------ c:\\\\windows\\\\Uninstrq.isu
2008-10-07 13:45 . 2007-04-26 19:06 40,960 --a------ c:\\\\windows\\\\uninstallrq.exe
2008-10-07 13:45 . 2002-05-17 21:35 2,238 --a------ c:\\\\windows\\\\realquieticon.ico

.
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:32

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 14:46 786,432 --sha-w c:\\\\users\\\\surf sécurisé\\\\NTUSER.DAT
2008-11-07 14:46 786,432 --sha-w c:\\\\users\\\\surf sécurisé\\\\NTUSER.DAT
2008-11-06 19:36 --------- d-----w c:\\\\program files\\\\Malwarebytes' Anti-Malware
2008-11-01 10:35 --------- d--h--w c:\\\\program files\\\\InstallShield Installation Information
2008-10-30 19:10 --------- d-----w c:\\\\program files\\\\McAfee
2008-10-22 15:10 38,496 ----a-w c:\\\\windows\\\\system32\\\\drivers\\\\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w c:\\\\windows\\\\system32\\\\drivers\\\\mbam.sys
2008-10-21 05:46 --------- d-----w c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Mozilla
2008-10-21 05:42 --------- d-s---w c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Microsoft
2008-10-21 05:41 --------- d-----w c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Hewlett-Packard
2008-10-21 05:41 --------- d-----w c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\Adobe
2008-10-21 05:40 --------- d-----w c:\\\\users\\\\surf sécurisé\\\\AppData\\\\Roaming\\\\COWON
2008-10-20 08:16 --------- d---a-w c:\\\\programdata\\\\TEMP
2008-10-20 08:15 --------- d-----w c:\\\\program files\\\\SpywareBlaster
2008-10-18 12:34 --------- d-----w c:\\\\program files\\\\The GodFather
2008-10-17 17:35 86,408 ----a-w c:\\\\windows\\\\System32\\\\setupempdrv03.exe
2008-10-17 15:59 9,728 ----a-w c:\\\\windows\\\\System32\\\\epmntdrv.sys
2008-10-17 15:59 3,072 ----a-w c:\\\\windows\\\\System32\\\\EuGdiDrv.sys
2008-10-17 15:58 14,848 ----a-w c:\\\\windows\\\\System32\\\\EuEpmGdi.dll
2008-10-16 11:27 --------- d-----w c:\\\\program files\\\\CDex_170b2
2008-10-16 09:52 --------- d-----w c:\\\\program files\\\\Windows Mail
2008-10-15 21:29 --------- d-----w c:\\\\programdata\\\\Microsoft Help
2008-10-15 13:06 171,008 ----a-w c:\\\\windows\\\\System32\\\\BootMan.exe
2008-10-12 18:02 --------- d-----w c:\\\\program files\\\\Java
2008-10-08 17:22 --------- d-----w c:\\\\program files\\\\FileZilla Server
2008-10-07 14:02 6,144 ----a-w c:\\\\windows\\\\System32\\\\CallbackOperator.dll
2008-10-07 12:45 --------- d-----w c:\\\\program files\\\\Hewlett-Packard
2008-10-05 07:11 --------- d-----w c:\\\\program files\\\\Microsoft CAPICOM 2.1.0.2
2008-10-04 12:36 --------- d-----w c:\\\\program files\\\\Hp
2008-10-04 12:35 --------- d-----w c:\\\\program files\\\\Common Files\\\\Hewlett-Packard
2008-10-04 12:29 --------- d-----w c:\\\\programdata\\\\Hewlett-Packard
2008-10-04 10:52 --------- d-----w c:\\\\program files\\\\Anywhere PE Viewer 0.1.7
2008-10-02 11:29 --------- d-----w c:\\\\program files\\\\IDM Computer Solutions
2008-10-02 09:34 --------- d-----w c:\\\\program files\\\\Common Files\\\\SWF Studio
2008-10-01 05:57 --------- d-----w c:\\\\program files\\\\TweakVI
2008-10-01 04:52 --------- d-----w c:\\\\program files\\\\jv16 PowerTools 2008
2008-10-01 04:37 --------- d-----w c:\\\\program files\\\\Alt WAV MP3 WMA OGG Converter
2008-10-01 03:23 --------- d-----w c:\\\\programdata\\\\SiteAdvisor
2008-10-01 03:23 --------- d-----w c:\\\\programdata\\\\McAfee
2008-10-01 03:23 --------- d-----w c:\\\\program files\\\\Common Files\\\\McAfee
2008-09-30 02:40 --------- d-----w c:\\\\program files\\\\Opera
2008-09-30 02:39 --------- d-----w c:\\\\program files\\\\QuickTime
2008-09-30 02:39 --------- d-----w c:\\\\program files\\\\Common Files\\\\Apple
2008-09-30 02:36 --------- d-----w c:\\\\programdata\\\\Apple
2008-09-30 02:36 --------- d-----w c:\\\\program files\\\\Apple Software Update
2008-09-28 19:32 --------- d-----w c:\\\\programdata\\\\comodo
2008-09-28 18:38 --------- d-----w c:\\\\program files\\\\Common Files\\\\Wise Installation Wizard
2008-09-28 14:30 --------- d-----w c:\\\\programdata\\\\Avira
2008-09-28 14:30 --------- d-----w c:\\\\program files\\\\Avira
2008-09-28 14:11 --------- d-----w c:\\\\program files\\\\Common Files\\\\PC Tools
2008-09-28 14:07 --------- d-----w c:\\\\program files\\\\Sandboxie
2008-09-28 14:03 --------- d-----w c:\\\\program files\\\\MSN Messenger
2008-09-28 13:06 28,416 ----a-w c:\\\\windows\\\\system32\\\\drivers\\\\SnpShot.sys
2008-09-28 00:27 --------- d-----w c:\\\\program files\\\\VideoLAN
2008-09-27 23:39 --------- d-----w c:\\\\programdata\\\\WLInstaller
2008-09-27 22:58 --------- d-----w c:\\\\program files\\\\Winamp
2008-09-27 22:45 --------- d-----w c:\\\\programdata\\\\Artificial Dynamics
2008-09-27 22:43 --------- d-----w c:\\\\program files\\\\Artificial Dynamics
2008-09-27 15:36 --------- d-----w c:\\\\program files\\\\VirtualDub
2008-09-27 15:26 --------- d-----w c:\\\\program files\\\\DScaler5
2008-09-27 15:20 --------- d-----w c:\\\\program files\\\\Satsuki Decoder Pack
2008-09-27 14:56 --------- d-----w c:\\\\program files\\\\ATI Technologies
2008-09-27 14:54 --------- d-----w c:\\\\program files\\\\Common Files\\\\ATI Technologies
2008-09-27 14:51 --------- d-----w c:\\\\programdata\\\\ATI
2008-09-27 14:45 --------- d-----w c:\\\\program files\\\\ATI
2008-09-27 02:16 1,612 ----a-w c:\\\\windows\\\\System32\\\\tmp.reg
2008-09-26 23:49 --------- d-----w c:\\\\programdata\\\\Martau
2008-09-26 23:48 --------- d-----w c:\\\\program files\\\\Total Uninstall 4
2008-09-26 22:47 --------- d-----w c:\\\\program files\\\\Unlocker
2008-09-26 17:19 --------- d-----w c:\\\\program files\\\\Debugging Tools for Windows (x86)
2008-09-26 14:51 --------- d-----w c:\\\\program files\\\\Microsoft Works
2008-09-26 14:06 --------- d-----w c:\\\\program files\\\\mIRC
2008-09-26 10:49 --------- d-----w c:\\\\programdata\\\\Malwarebytes
2008-09-26 08:50 --------- d-----w c:\\\\program files\\\\EPSON
2008-09-25 16:42 92,672 ----a-w c:\\\\windows\\\\System32\\\\Partition.dll
2008-09-25 16:42 61,952 ----a-w c:\\\\windows\\\\System32\\\\FatResizeMove.dll
2008-09-25 16:42 472,576 ----a-w c:\\\\windows\\\\System32\\\\NTFSFormat.dll
2008-09-25 16:42 31,744 ----a-w c:\\\\windows\\\\System32\\\\FatLib.dll
2008-09-25 16:42 22,016 ----a-w c:\\\\windows\\\\System32\\\\FatFormat.dll
2008-09-25 16:42 179,200 ----a-w c:\\\\windows\\\\System32\\\\DeviceManager.dll
2008-09-25 16:42 124,416 ----a-w c:\\\\windows\\\\System32\\\\NTFSCopy.dll
2008-09-25 16:41 86,528 ----a-w c:\\\\windows\\\\System32\\\\NTFSLib.dll
2008-09-25 16:41 86,016 ----a-w c:\\\\windows\\\\System32\\\\ResizeNTFS.dll
2008-09-25 16:41 68,096 ----a-w c:\\\\windows\\\\System32\\\\Device.dll
2008-09-25 16:41 44,032 ----a-w c:\\\\windows\\\\System32\\\\FileSystemCheck.dll
2008-09-25 16:41 25,088 ----a-w c:\\\\windows\\\\System32\\\\FATFileSystemAnalyser.dll
2008-09-25 16:41 24,576 ----a-w c:\\\\windows\\\\System32\\\\NTFSFileSystemAnalyser.dll
2008-09-25 16:41 21,504 ----a-w c:\\\\windows\\\\System32\\\\Fixup.dll
2008-09-25 16:41 14,848 ----a-w c:\\\\windows\\\\System32\\\\FileSystemAnalyser.dll
2008-09-25 16:41 10,752 ----a-w c:\\\\windows\\\\System32\\\\DeviceAdapter.dll
2008-09-25 07:09 --------- d-----w c:\\\\program files\\\\PDFCreator
2008-09-23 17:15 --------- d-----w c:\\\\program files\\\\Documalis Free
2008-09-21 19:14 --------- d-----w c:\\\\program files\\\\CCleaner
2008-09-21 13:09 --------- d-----w c:\\\\program files\\\\adslTV
2008-09-19 18:44 2,788,800 ----a-w c:\\\\program files\\\\FLV PlayerFCSetup.exe
2008-09-18 08:30 81,984 ----a-w c:\\\\windows\\\\System32\\\\bdod.bin
2008-09-16 18:02 --------- d-----w c:\\\\program files\\\\Gold Rush Treasure Hunt
2008-08-21 02:14 425,984 ----a-w c:\\\\windows\\\\System32\\\\ATIDEMGX.dll
2008-08-21 02:13 159,744 ----a-w c:\\\\windows\\\\System32\\\\atitmmxx.dll
2008-08-21 02:12 43,520 ----a-w c:\\\\windows\\\\System32\\\\ati2edxx.dll
2006-05-03 09:06 163,328 --sh--r c:\\\\windows\\\\System32\\\\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\\\\windows\\\\System32\\\\msfDX.dll
2008-03-16 12:30 216,064 --sh--r c:\\\\windows\\\\System32\\\\nbDX.dll
2008-03-11
23:53 32,768 --sha-w
c:\\\\windows\\\\System32\\\\config\\\\systemprofile\\\\AppData\\\\Local\\\\Microsoft\\\\Windows\\\\History\\\\History.IE5\\\\MSHist012008031220080313\\\\index.dat
2007-12-09
02:24 397,312 --sha-w
c:\\\\windows\\\\winsxs\\\\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6000.16480_none_ef1b6bb652cf8744\\\\WinMail.exe
.
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:33

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Wave Tag]
@="{B19BA1A8-02E5-4283-9DEF-C7DC97E570B7}"
[HKEY_CLASSES_ROOT\CLSID\{B19BA1A8-02E5-4283-9DEF-C7DC97E570B7}]
2008-05-06 10:47 303104 --a------ c:\program files\Artificial Dynamics\SafeSpace\WaveShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SafeSpace"="c:\program files\Artificial Dynamics\SafeSpace\SafeSpaceSysTray.exe" [2008-05-06 143360]
"WaveFramer"="c:\program files\Artificial Dynamics\SafeSpace\WaveFramer.exe" [2008-05-06 303104]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-12 140696]
"KnexStarter"="c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe" [2008-08-28 159744]
"RunTasktray"="c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" [2008-08-28 101376]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"FileZilla Server Interface"="c:\program files\FileZilla Server\FileZilla Server Interface.exe" [2008-07-30 942080]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 167936]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
jetAudio.lnk - c:\program files\JetAudio\JetAudio.exe [2008-03-14 2617412]
jetMailMonitor.lnk - c:\program files\JetMailMonitor\JetMM.exe [2008-08-04 651264]
procexp.exe [2008-08-06 3520552]

c:\users\mushu\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= ,AS_WAVEHook.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PDFCreator.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PDFCreator.lnk
backup=c:\windows\pss\PDFCreator.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^mushu^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DeliveryManager.lnk]
path=c:\users\mushu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeliveryManager.lnk
backup=c:\windows\pss\DeliveryManager.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^mushu^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GigaTribe.lnk]
path=c:\users\mushu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GigaTribe.lnk
backup=c:\windows\pss\GigaTribe.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^mushu^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
path=c:\users\mushu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Matrox Powerdesk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-12-17 11:02 4718592 c:\windows\RtHDVCpl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1349547134-3957785052-286754442-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"= c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{73DAB171-38D8-48B2-B94E-E9CC4EEB20B6}"= Profile=Public|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4D195293-5153-4886-AD78-B8D482A19595}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{0F8D9043-A0C4-425F-A3FE-B63651A7A274}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{DEF5D945-49D5-4600-BA85-A982DCC79678}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{EE075258-DA4C-4625-8BEC-FAA373AF6069}c:\\program files\\tribalweb\\tribalweb.exe"= UDP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"UDP Query User{95F6D944-DFDE-42B5-B977-A386E3BE8F06}c:\\program files\\tribalweb\\tribalweb.exe"= TCP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"TCP Query User{20226E1F-9405-4A0F-88C4-F168355D687A}c:\\program files\\tribalweb\\tribalweb.exe"= UDP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"UDP Query User{9F6F20C3-877E-4AA1-A5DF-67B9B5056A17}c:\\program files\\tribalweb\\tribalweb.exe"= TCP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"{9EBB80A8-3EC5-4726-BA70-E74664BD0DBC}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{1EB07C96-F472-4E41-A1D9-535A2C29474B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{D0CB7E01-D87F-4B5A-9E53-6A4C9DB6415E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{C1D0128A-2876-473A-838E-598CD1AFCBE1}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{F6AEE648-948B-4FEB-B248-CA05D431C698}c:\\program files\\nero\\nero sipps\\phone.exe"= UDP:c:\program files\nero\nero sipps\phone.exe:Phone
"UDP Query User{F5BC1155-80D9-4120-B0F3-9EEBF95AE816}c:\\program files\\nero\\nero sipps\\phone.exe"= TCP:c:\program files\nero\nero sipps\phone.exe:Phone
"TCP Query User{568346E5-1CF7-4C82-ABE0-00162FCD6BE5}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"UDP Query User{A9A4CA65-07FA-4179-A114-CF691FD64C57}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"{45A5AA8A-E5B3-463A-80B9-A14306DCA0D2}"= c:\program files\Windows Live\Messenger\wlcsdk.exe:Windows Live Messenger (Phone)
"{AFD1FDAF-FB8D-424F-B7D4-F49CE5840277}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FCA74639-4DB3-481B-B0CC-D6686E700924}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2970779B-137E-4F20-8B0D-39DF94312944}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{84A454EE-68FB-4468-B39E-63FADB757C5F}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{B6F49D65-D13A-4AF9-9D8C-F9E2CD72FF11}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{511FBF2E-EC94-426B-A913-CC73C6B328B7}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{F8F72660-F045-44A1-A1EE-2DA7245D0628}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{DCACBF02-3E40-47F1-BF43-298420B1433F}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par mushu14 Ven 7 Nov - 21:34

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"= c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun

R0 snpshot;snpshot;c:\windows\system32\drivers\snpshot.sys [2008-09-28 28416]
R1 ASWave;ASWave;c:\windows\system32\drivers\ASWave.sys [2008-05-06 326784]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2007-03-13 24512]
R2 Artificial Dynamics SafeSpace Agent;Artificial Dynamics SafeSpace Agent;c:\program files\Artificial Dynamics\SafeSpace\SafeSpace_Agent.EXE [2008-05-06 155648]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-10-08 203280]
R2 Wave Launcher Service;Artificial Dynamics WAVE Launcher Service;c:\program files\Artificial Dynamics\SafeSpace\LauncherService.exe [2008-05-06 274432]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-08-21 3928576]
R3 VBoxUSBFlt;VirtualBox USB Filter Driver;c:\windows\system32\DRIVERS\VBoxUSBFlt.sys [2007-03-13 18720]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x86.sys [2007-12-06 298496]
S3 BthAvrcp;Profil AVRCP Bluetooth;c:\windows\system32\DRIVERS\BthAvrcp.sys [2008-07-10 15872]
S3 DTV5100;USB2.0 DVB-T Dongle;c:\windows\system32\DRIVERS\DTV5100.SYS [2006-05-06 198272]
S3 DTVFW;LITE-ON DVB-T USB adapter firmware;c:\windows\system32\DRIVERS\dtvfw.sys [2006-11-02 22272]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2008-10-17 9728]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2008-10-17 3072]
S3 G200;G200;c:\windows\system32\DRIVERS\g200mini.sys [2007-04-13 261376]
S3 MGAU;MGAU;c:\windows\system32\DRIVERS\mgaum.sys [2002-02-14 275456]
S3 MTXPAR;MTXPAR;c:\windows\system32\DRIVERS\mtxparm.sys [2007-09-11 1484416]
S3 rt61x86;Sitecom RT61 Wireless Network Driver for Windows Vista;c:\windows\system32\DRIVERS\netr61.sys [2007-05-11 357376]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2005-10-26 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2005-10-26 12672]
S3 usbdtv;LITE-ON DVB-T (PID=F001) receiver;c:\windows\system32\Drivers\usbdtv.sys [2006-11-08 35584]
S4 ATIWebPAM;ATI WebPAM;c:\users\mushu\WebPAM\jetty\extra\win32\Wrapper.exe [2003-09-29 110592]
S4 freenet-darknet-8888;Freenet 0.7 darknet-8888;c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [ ]
S4 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-07-25 191656]
S4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [ ]
S4 ShadowSystemService;Shadow System Service;c:\windows\system32\shadow\ShadowService.exe [2008-09-28 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bdx REG_MULTI_SZ scan
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9bb32aa4-dc96-11dc-86df-000129d7fc87}]
\shell\AutoRun\command - S:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bab5dbdb-a667-11dc-81da-000129d7fc95}]
\shell\AutoRun\command - D:\LaunchU3.exe -a

*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'

2008-11-07 c:\windows\Tasks\User_Feed_Synchronization-{D0CF96B5-145E-4EAE-B9E4-F8E69EE8AE46}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 22:33]
.
- - - - ORPHELINS SUPPRIMES - - - -

ShellIconOverlayIdentifiers-{37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF} - (no file)
ShellIconOverlayIdentifiers-{F594B094-8768-4632-8143-12852EBBD688} - (no file)
ShellIconOverlayIdentifiers-{F1A1DA12-E651-4AD0-A1A0-6214546B2F9D} - (no file)
ShellIconOverlayIdentifiers-{E4FC4B31-8A4F-45E6-BDAC-28F612371FE3} - (no file)


.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\users\mushu\AppData\Roaming\Mozilla\Firefox\Profiles\u6q7q5ww.default\
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\ma-config.com\nphardwaredetection.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Opera\program\plugins\np32dsw.dll
FF -: plugin - c:\program files\Opera\program\plugins\npdivx32.dll
FF -: plugin - c:\program files\Opera\program\plugins\nppl3260.dll
FF -: plugin - c:\program files\Opera\program\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 15:50:09
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

PROCESSUS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\detoured.dll

PROCESSUS: c:\windows\system32\lsass.exe
-> c:\windows\system32\detoured.dll
.
Heure de fin: 2008-11-07 15:52:10
ComboFix-quarantined-files.txt 2008-11-07 14:51:34

Avant-CF: 45 161 558 016 octets libres
Après-CF: 44,903,321,600 octets libres

419 --- E O F --- 2008-11-07 11:43:51
mushu14
mushu14
posteur ultime
posteur ultime

Nombre de messages : 698
Age : 56
Localisation : Caen les bains
Date d'inscription : 10/01/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par Noctambule Ven 7 Nov - 22:37

Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
http://eric.71.mespages.googlepages.com/ToolBarSD.exe

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)

Suppression

Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.

NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.

Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le scrïpt.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Noctambule
Noctambule
posteur d'argent
posteur d'argent

Nombre de messages : 90
Age : 54
Date d'inscription : 21/10/2007

Revenir en haut Aller en bas

va s y francky Empty Re: va s y francky

Message par Contenu sponsorisé


Contenu sponsorisé


Revenir en haut Aller en bas

Revenir en haut


 
Permission de ce forum:
Vous ne pouvez pas répondre aux sujets dans ce forum