

spiderman2005
Membres-
Compteur de contenus
45 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par spiderman2005
-
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Bon alors fausse alerte... Merci à toi pour ta disponibilité et ton efficacité. Longue vie à ce forum que je ne cesse de recommander dès que j'en ai l'occasion. A plus et bonne année. -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Désolé Charles Ingals, à mon tour de me tromper mais voici le log : "Silent Runners.vbs", revision 49, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "Winpooch" = "C:\Program Files\Winpooch\Winpooch.exe" [null data] "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {0055C089-8582-441B-A0BF-17B458C2A3A8}\(Default) = "IDM Helper" -> {HKLM...CLSID} = "IDMIEHlprObj Class" \InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMIECC.dll" ["Tonec Inc."] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll" ["Sun Microsystems, Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal" -> {HKLM...CLSID} = "HyperTerminal Icon Ext" \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS] "{5E44E225-A408-11CF-B581-008029601108}" = "Adaptec DirectCD Shell Extension" -> {HKLM...CLSID} = "Adaptec DirectCD Shell Extension" \InProcServer32\(Default) = "C:\PROGRA~1\Roxio\EASYCD~1\DirectCD\Shellex.dll" ["Roxio"] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler" -> {HKLM...CLSID} = "Outlook File Icon Extension" \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS] "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player" -> {HKLM...CLSID} = "RealOne Player Context Menu Class" \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."] "{40950107-FEA6-4d53-A65F-B2DCBA57DD58}" = "Nokia Phone Browser" -> {HKLM...CLSID} = "Nokia Phone Browser" \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\Components\PhoneBrowserComponents\NokiaPhoneBrowser.dll" ["Nokia"] "{FBFE7864-D495-41f0-B7DC-4BB601CC295E}" = "Contact View" -> {HKLM...CLSID} = "Contact View" \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\Components\PhoneBrowserComponents\ContactView.dll" ["Nokia"] "{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places" -> {HKLM...CLSID} = "Favoris Bluetooth" \InProcServer32\(Default) = "C:\WINDOWS\system32\BTNEIG~1.DLL" ["WIDCOMM, Inc."] "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast" -> {HKLM...CLSID} = "avast" \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] "{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" = "My Logitech Pictures" -> {HKLM...CLSID} = "My Logitech Pictures" \InProcServer32\(Default) = "C:\Program Files\Logitech\Video\Namespc2.dll" ["Logitech Inc."] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes" -> {HKLM...CLSID} = "iTunes" \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5" -> {HKLM...CLSID} = "CShellExecuteHookImpl Object" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."] HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" -> {HKLM...CLSID} = "WPDShServiceObj Class" \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS] HKLM\System\CurrentControlSet\Control\Session Manager\ <<!>> "BootExecute" = "autocheck autochk *"|"SsiEfr.e" [file not found] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" -> {HKLM...CLSID} = "avast" \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}" -> {HKLM...CLSID} = "CContextScan Object" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."] Qzip3\(Default) = "{4C156620-A582-11D5-858B-444553540000}" -> {HKLM...CLSID} = "Qzip Shell Extension 3.0" \InProcServer32\(Default) = "C:\PROGRA~1\QuickZip\QzShlExt.dll" [null data] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}" -> {HKLM...CLSID} = "CContextScan Object" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."] Qzip3\(Default) = "{4C156620-A582-11D5-858B-444553540000}" -> {HKLM...CLSID} = "Qzip Shell Extension 3.0" \InProcServer32\(Default) = "C:\PROGRA~1\QuickZip\QzShlExt.dll" [null data] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" -> {HKLM...CLSID} = "avast" \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] Default executables: -------------------- HKCU\Software\Classes\.bat\(Default) = (value not set) HKCU\Software\Classes\.cmd\(Default) = (value not set) HKCU\Software\Classes\.com\(Default) = (value not set) HKCU\Software\Classes\.exe\(Default) = (value not set) HKCU\Software\Classes\.hta\(Default) = (value not set) Group Policies {policy setting}: -------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "DisableRegistryTools" = (REG_DWORD) hex:0x00000000 {Prevent access to registry editing tools} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 {Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) hex:0x00000001 {Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Mes documents\Mes images\Picture.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\David BENAYOUN\Mes documents\Mes images\Picture.bmp" Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS] Enabled Scheduled Tasks: ------------------------ "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task" ["Apple Computer, Inc."] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000004\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 30 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID\{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}\(Default) = "Volet Wanadoo" Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string] HKLM\Software\Classes\CLSID\{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}\(Default) = "ToolBand Class" Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string] HKLM\Software\Classes\CLSID\{5BF498C0-931E-4A4F-B33F-456D07137EAA}\(Default) = "Volet Wanadoo" Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Console Java (Sun)" "CLSIDExtension" = "{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}" -> {HKLM...CLSID} = "Java Plug-in 1.5.0_10" \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll" ["Sun Microsystems, Inc."] Miscellaneous IE Hijack Points ------------------------------ C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings") Added lines (compared with English-language version): [strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/" Missing lines (compared with English-language version): [strings]: 1 line Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data] avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data] avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"] avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"] AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."] Kerio Personal Firewall 4, KPF4, ""C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe"" ["Kerio Technologies"] ---------- <<!>>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 759 seconds. ---------- (total run time: 2352 seconds) En fait, j'ai eu un premier résultat puis celui-ci quelques...minutes après. -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
C'est pas beaucoup plus long comme tu peux le voir : "Silent Runners.vbs", revision 49, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "Winpooch" = "C:\Program Files\Winpooch\Winpooch.exe" [null data] "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data] -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Bonjour à tous et bonne année ! Merci à toi Charles Ingals, je suis toujours impressionné par le sérieux et le professionalisme de ce forum. Bref, j'arrête sur les compliments sinon on va verser une larme... Voici le résultat (court..?) de ce rapport : "Silent Runners.vbs", revision 49, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "Winpooch" = "C:\Program Files\Winpooch\Winpooch.exe" [null data] "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data] Cela vous inspire-t-il quelquechose ? Le forum a une meilleure mémoire que moi (cf les citations de Janvier 2006), mais tout était parfait malgré Winpooch, Ewido etc... A cahque ouverture de mon système, Winpooch me bombarde d'alertes concernant des processus de lecture par des programmes inoffensifs tels que Avast ou Kerio et je passe bien 10 minutes à lui faire accepter des processus qu'il ne me signalait jamais avec l'ancienne version de Winpooch. Peut-être doit-il enregistrer les "filtres" mais je n'ai jamais eu ces alertes avec l'ancienne version... Merci à tous. -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Merci à toi Charles Ingals, Console Java mise à jour. Free est mon FAI, j'ai récemment quitté France Télécom et Wanadoo. Je me connecte donc soit en Ethernet soit en Wifi au choix mais les ralentiqqements du système existent même sans connecter l'ordinateur à internet. J'ai l'impression que depuis la mise à jour de Winpooch 0.6.3, tout est lent... Cela t'inspire-t-il ? Y a-t-il moyen d'optimiser le système ? Je fais régulièrement passer Zeb Utility et autre nettoyeurs conseillés sur le forum. Merci par avance à toi. -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Charles Ingals es-tu là ? -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Désolé pour l'attente... Voici le rapport de DiagHelp option 1 : C:\WINDOWS\System32\Uninstall.ico -->26/12/2006 21:46:59 C:\WINDOWS\System32\pavas.ico -->26/12/2006 21:46:59 C:\WINDOWS\System32\Help.ico -->26/12/2006 21:46:59 C:\WINDOWS\System32\wpa.dbl -->22/12/2006 16:05:48 C:\WINDOWS\System32\MRT.exe -->08/12/2006 00:13:44 C:\WINDOWS\System32\PerfStringBackup.INI -->06/12/2006 22:22:18 C:\WINDOWS\System32\perfh00C.dat -->06/12/2006 22:22:18 C:\WINDOWS\System32\perfh009.dat -->06/12/2006 22:22:18 C:\WINDOWS\System32\perfc00C.dat -->06/12/2006 22:22:18 C:\WINDOWS\System32\perfc009.dat -->06/12/2006 22:22:18 C:\WINDOWS\System32\nscompat.tlb -->04/12/2006 23:59:09 C:\WINDOWS\System32\amcompat.tlb -->04/12/2006 23:59:09 C:\WINDOWS\System32\results.txt -->04/12/2006 21:43:48 C:\WINDOWS\System32\inetcomm.dll -->08/11/2006 06:07:30 C:\WINDOWS\System32\RmActivate_isv.exe -->06/11/2006 11:35:46 C:\WINDOWS\System32\RmActivate.exe -->06/11/2006 11:35:44 C:\WINDOWS\System32\SecProc_isv.dll -->06/11/2006 11:35:42 C:\WINDOWS\System32\SecProc.dll -->06/11/2006 11:35:42 C:\WINDOWS\System32\RmActivate_ssp.exe -->06/11/2006 11:35:38 C:\WINDOWS\System32\RmActivate_ssp_isv.exe -->06/11/2006 11:35:36 C:\WINDOWS\System32\SecProc_ssp_isv.dll -->06/11/2006 11:35:32 C:\WINDOWS\System32\msdrm.dll -->06/11/2006 11:35:32 C:\WINDOWS\System32\SecProc_ssp.dll -->06/11/2006 11:35:30 C:\WINDOWS\System32\msxml4.dll -->04/11/2006 14:14:00 C:\WINDOWS\System32\wmploc.dll -->03/11/2006 10:03:34 C:\WINDOWS\KB916595.log -->26/12/2006 22:20:24 C:\WINDOWS\0.log -->26/12/2006 22:09:50 C:\WINDOWS\wiadebug.log -->26/12/2006 22:09:45 C:\WINDOWS\WindowsUpdate.log -->26/12/2006 22:09:40 C:\WINDOWS\wiaservc.log -->26/12/2006 22:09:35 C:\WINDOWS\bootstat.dat -->26/12/2006 22:09:19 C:\WINDOWS\setupapi.log -->26/12/2006 21:45:54 C:\WINDOWS\IDMan.INI -->26/12/2006 20:29:38 C:\WINDOWS\SchedLgU.Txt -->26/12/2006 20:00:38 C:\WINDOWS\wmsetup.log -->25/12/2006 21:34:29 C:\WINDOWS\bthservsdp.dat -->24/12/2006 15:18:33 C:\WINDOWS\setupact.log -->24/12/2006 14:39:19 C:\WINDOWS\ModemLog_Conexant 56K ACLink Modem.txt -->24/12/2006 14:05:20 C:\WINDOWS\KB925454.log -->23/12/2006 23:18:33 C:\WINDOWS\updspapi.log -->23/12/2006 23:18:31 C:\WINDOWS\adiras.exe |27/04/2005 18:47:55 C:\WINDOWS\autoclk.exe |27/04/2005 18:47:45 C:\WINDOWS\bdoscandel.exe |04/03/2005 13:10:36 C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe |14/09/2005 22:02:49 C:\WINDOWS\ciaunwdm.exe |10/12/2002 02:51:32 C:\WINDOWS\CleanUpUninstall.exe |18/01/2006 18:42:55 C:\WINDOWS\InstallDialog.exe |04/12/2006 21:43:09 C:\WINDOWS\IsUn040c.exe |10/12/2002 03:12:57 C:\WINDOWS\IsUninst.exe |10/12/2002 03:15:45 C:\WINDOWS\iun6002.exe |18/09/2005 21:07:20 C:\WINDOWS\PATCH.EXE |24/07/2005 18:48:53 C:\WINDOWS\runtsckl.exe |09/06/2004 15:56:06 C:\WINDOWS\slrundll.exe |20/08/2004 00:10:02 C:\WINDOWS\tsc.exe |24/07/2005 18:49:55 C:\WINDOWS\twunk_16.exe |30/08/2002 03:00:00 C:\WINDOWS\twunk_32.exe |30/08/2002 03:00:00 C:\WINDOWS\uneng.exe |02/02/2005 17:45:01 C:\WINDOWS\uninst.exe |10/12/2002 03:16:16 C:\WINDOWS\UNINST32.EXE |14/10/2002 17:23:22 C:\WINDOWS\UninstallDialog.exe |04/12/2006 21:43:12 C:\WINDOWS\UninstallFirefox.exe |13/01/2006 20:57:57 C:\WINDOWS\UNNeroVision.exe |29/07/2005 10:52:26 C:\WINDOWS\UNNMP.exe |29/07/2005 10:58:30 C:\WINDOWS\AuHCcup1.dll |23/07/1999 10:53:20 C:\WINDOWS\BPMNT.dll |24/07/2005 18:49:54 C:\WINDOWS\hcextoutput.dll |24/07/2005 18:49:55 C:\WINDOWS\libeay32.dll |02/01/2006 12:55:13 C:\WINDOWS\loadhttp.dll |15/10/2002 13:29:40 C:\WINDOWS\patchw32.dll |14/12/2001 12:34:46 C:\WINDOWS\ssleay32.dll |02/01/2006 12:55:12 C:\WINDOWS\TMUPDATE.DLL |24/07/2005 18:48:53 C:\WINDOWS\twain.dll |30/08/2002 03:00:00 C:\WINDOWS\twain_32.dll |30/08/2002 03:00:00 C:\WINDOWS\UNZIP.DLL |24/07/2005 18:48:53 C:\WINDOWS\vsapi32.dll |24/07/2005 18:49:54 C:\WINDOWS\WRUninstall.dll |02/01/2006 12:55:12 C:\WINDOWS\system32\append.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\asuninst.exe |22/12/2005 22:13:48 C:\WINDOWS\system32\aswBoot.exe |26/07/2005 23:08:40 C:\WINDOWS\system32\ati2evxx.exe |10/12/2002 11:47:41 C:\WINDOWS\system32\Ati2mdxx.exe |10/12/2002 11:47:41 C:\WINDOWS\system32\atiiprxx.exe |10/12/2002 11:47:43 C:\WINDOWS\system32\atiphexx.exe |10/12/2002 11:47:43 C:\WINDOWS\system32\atiprbxx.exe |10/12/2002 11:47:43 C:\WINDOWS\system32\atiptaxx.exe |10/12/2002 11:47:43 C:\WINDOWS\system32\carpserv.exe |21/05/2003 15:35:50 C:\WINDOWS\system32\debug.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\dosx.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\dvdplay.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\edlin.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\exe2bin.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\fastopen.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\HPConfig.exe |10/12/2002 03:14:56 C:\WINDOWS\system32\InstMed.exe |14/09/2005 22:05:19 C:\WINDOWS\system32\ipdetect.exe |27/04/2005 18:47:54 C:\WINDOWS\system32\java.exe |07/07/2005 23:47:49 C:\WINDOWS\system32\javaw.exe |07/07/2005 23:47:49 C:\WINDOWS\system32\javaws.exe |07/07/2005 23:47:49 C:\WINDOWS\system32\LVCOMSX.EXE |08/10/2004 10:52:32 C:\WINDOWS\system32\mem.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\MMAVILNG.exe |03/02/2005 15:08:34 C:\WINDOWS\system32\mscdexnt.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\NeroCheck.exe |29/07/2005 10:55:28 C:\WINDOWS\system32\nlsfunc.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\Process.exe |05/05/2006 20:56:26 C:\WINDOWS\system32\pxhpinst.exe |17/02/2005 19:03:42 C:\WINDOWS\system32\redir.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\setver.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\share.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\slrundll.exe |20/08/2004 00:10:02 C:\WINDOWS\system32\slserv.exe |20/08/2004 00:10:02 C:\WINDOWS\system32\SrchSTS.exe |05/05/2006 20:56:29 C:\WINDOWS\system32\swreg.exe |05/05/2006 20:56:27 C:\WINDOWS\system32\swsc.exe |05/05/2006 20:56:28 C:\WINDOWS\system32\unaddrv.exe |27/04/2005 18:47:47 C:\WINDOWS\system32\usrmlnka.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\usrprbda.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\usrshuta.exe |30/08/2002 03:00:00 C:\WINDOWS\system32\adadix16.dll |27/04/2005 18:47:47 C:\WINDOWS\system32\adadix2k.dll |27/04/2005 18:47:47 C:\WINDOWS\system32\AdADIx32.dll |27/04/2005 18:47:47 C:\WINDOWS\system32\amstream.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\ati2cqag.dll |15/05/2004 18:14:40 C:\WINDOWS\system32\ati2dvaa.dll |20/08/2004 00:09:19 C:\WINDOWS\system32\ati2dvag.dll |15/05/2004 18:29:34 C:\WINDOWS\system32\ati3d1ag.dll |15/05/2004 18:21:00 C:\WINDOWS\system32\ati3d2ag.dll |10/12/2002 11:47:41 C:\WINDOWS\system32\ati3duag.dll |15/05/2004 18:27:00 C:\WINDOWS\system32\ATIDDC.DLL |10/12/2002 11:47:42 C:\WINDOWS\system32\atidrab.dll |23/08/2001 12:46:44 C:\WINDOWS\system32\atiicdxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atiicpxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atiiiexx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atioglxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atipdlxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atipdsxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atippaxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atipuixx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\atitvo32.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\ativcoxx.dll |10/12/2002 11:47:43 C:\WINDOWS\system32\ativtmxx.dll |20/08/2004 00:09:19 C:\WINDOWS\system32\ativvaxx.dll |15/05/2004 18:18:32 C:\WINDOWS\system32\atmfd.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\atmlib.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\avisynth.dll |07/10/2005 18:14:52 C:\WINDOWS\system32\AW32n50.dll |04/12/2006 21:42:56 C:\WINDOWS\system32\BASSMOD.dll |09/09/2006 11:29:33 C:\WINDOWS\system32\bt2k_ins.dll |01/12/2003 15:10:00 C:\WINDOWS\system32\BtAudioHelper.dll |01/12/2003 15:15:00 C:\WINDOWS\system32\btbigbmp.dll |14/08/2003 12:38:00 C:\WINDOWS\system32\btcss.dll |01/12/2003 15:24:00 C:\WINDOWS\system32\btdev.dll |01/12/2003 15:18:00 C:\WINDOWS\system32\bthcrp.dll |14/08/2003 12:48:00 C:\WINDOWS\system32\bthcrpui.dll |14/08/2003 12:49:00 C:\WINDOWS\system32\btins.dll |01/12/2003 15:19:00 C:\WINDOWS\system32\BTNCopy.dll |01/12/2003 15:10:00 C:\WINDOWS\system32\BTNeighborhood.dll |01/12/2003 15:27:00 C:\WINDOWS\system32\btosif.dll |01/12/2003 15:14:00 C:\WINDOWS\system32\btosif_notes.dll |01/12/2003 15:14:00 C:\WINDOWS\system32\btosif_ol.dll |01/12/2003 15:14:00 C:\WINDOWS\system32\btosif_olx.dll |01/12/2003 15:20:00 C:\WINDOWS\system32\btprn2k.dll |14/08/2003 12:50:00 C:\WINDOWS\system32\btrez.dll |24/03/2003 10:38:00 C:\WINDOWS\system32\btrezxp.dll |01/12/2003 15:20:00 C:\WINDOWS\system32\btsec.dll |01/12/2003 15:20:00 C:\WINDOWS\system32\btsendto.dll |14/08/2003 12:48:00 C:\WINDOWS\system32\btsendto_ie.dll |14/08/2003 13:17:00 C:\WINDOWS\system32\btsendto_notes.dll |14/08/2003 13:13:00 C:\WINDOWS\system32\btsendto_office.dll |14/08/2003 13:16:00 C:\WINDOWS\system32\btsendto_wab.dll |14/08/2003 13:16:00 C:\WINDOWS\system32\BtWizard.dll |01/12/2003 15:29:00 C:\WINDOWS\system32\btwpimif.dll |01/12/2003 15:15:00 C:\WINDOWS\system32\BTXPPanel.dll |01/12/2003 15:11:00 C:\WINDOWS\system32\BtXpShell.dll |01/12/2003 15:29:00 C:\WINDOWS\system32\carpdll.dll |21/05/2003 15:35:54 C:\WINDOWS\system32\CDDBControlRoxio.dll |31/07/2002 13:32:18 C:\WINDOWS\system32\CddbLangFR.dll |10/05/2002 09:58:10 C:\WINDOWS\system32\CDDBUIRoxio.dll |31/07/2002 13:32:18 C:\WINDOWS\system32\cdral.dll |01/08/2002 00:23:58 C:\WINDOWS\system32\cdrtc.dll |01/08/2002 00:24:46 C:\WINDOWS\system32\cnxci.dll |01/01/2006 03:06:45 C:\WINDOWS\system32\coclassfast.dll |27/04/2005 18:47:48 C:\WINDOWS\system32\compatui.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\Cpq32.dll |10/12/2002 03:22:54 C:\WINDOWS\system32\cpuinf32.dll |03/02/2005 15:13:14 C:\WINDOWS\system32\CSH.DLL |15/07/2002 15:58:00 C:\WINDOWS\system32\devil.dll |22/02/2004 09:11:09 C:\WINDOWS\system32\dgrpsetu.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\dgsetup.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\divx.dll |04/09/2006 21:28:11 C:\WINDOWS\system32\DivXc32.dll |11/12/2001 13:17:12 C:\WINDOWS\system32\DivXc32f.dll |27/11/2001 01:19:54 C:\WINDOWS\system32\divxdec_0407.dll |04/09/2004 00:34:08 C:\WINDOWS\system32\divxdec_040c.dll |04/09/2004 00:34:08 C:\WINDOWS\system32\divxdec_0411.dll |04/09/2004 00:25:12 C:\WINDOWS\system32\dpl100.dll |04/09/2006 21:28:12 C:\WINDOWS\system32\dpu10.dll |03/09/2004 18:33:33 C:\WINDOWS\system32\dpuGUI10.dll |03/09/2004 18:37:38 C:\WINDOWS\system32\dpus10.dll |01/09/2004 16:49:16 C:\WINDOWS\system32\dpv10.dll |01/09/2004 16:49:16 C:\WINDOWS\system32\dtu100.dll |04/09/2006 21:28:13 C:\WINDOWS\system32\encdec.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\EqnClass.Dll |30/08/2002 03:00:00 C:\WINDOWS\system32\ffJmpWeb.dll |02/01/2006 15:55:32 C:\WINDOWS\system32\ff_vfw.dll |04/09/2006 21:28:07 C:\WINDOWS\system32\FreeImage.dll |25/01/2006 20:34:50 C:\WINDOWS\system32\GEARAspi.dll |19/09/2006 15:43:58 C:\WINDOWS\system32\HPUNINST.DLL |10/12/2002 03:09:47 C:\WINDOWS\system32\HSFCI006.dll |14/04/2003 18:53:54 C:\WINDOWS\system32\hsfcisp2.dll |20/08/2004 00:09:27 C:\WINDOWS\system32\hsfinst.dll |10/12/2002 11:47:49 C:\WINDOWS\system32\hticons.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\huffyuv.dll |04/09/2006 21:28:24 C:\WINDOWS\system32\hypertrm.dll |17/11/2004 18:57:39 C:\WINDOWS\system32\Iacenc.dll |18/11/1998 14:33:16 C:\WINDOWS\system32\iccvid.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\idmmbc.dll |19/02/2004 16:42:46 C:\WINDOWS\system32\ieencode.dll |20/08/2004 00:09:27 C:\WINDOWS\system32\ImagX7.dll |29/07/2005 10:51:34 C:\WINDOWS\system32\ImagXpr7.dll |29/07/2005 10:51:34 C:\WINDOWS\system32\ImagXR7.dll |29/07/2005 10:51:34 C:\WINDOWS\system32\ImagXRA7.dll |29/07/2005 10:51:35 C:\WINDOWS\system32\indounin.dll |27/01/1999 12:39:06 C:\WINDOWS\system32\INETWH32.dll |04/08/2000 15:25:30 C:\WINDOWS\system32\InstHpci.dll |10/12/2002 03:14:53 C:\WINDOWS\system32\ir32_32.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\ir41_qc.dll |20/08/2004 00:09:30 C:\WINDOWS\system32\ir41_qcx.dll |20/08/2004 00:09:30 C:\WINDOWS\system32\ir50_32.dll |20/08/2004 00:09:30 C:\WINDOWS\system32\ir50_qc.dll |20/08/2004 00:09:30 C:\WINDOWS\system32\ir50_qcx.dll |20/08/2004 00:09:30 C:\WINDOWS\system32\isrdbg32.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\Iyvu9_32.dll |13/06/1997 06:56:08 C:\WINDOWS\system32\jgaw400.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\jgdw400.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\jgmd400.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\jgpl400.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\jgsd400.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\jgsh400.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\LCamCpl.dll |14/09/2005 22:03:27 C:\WINDOWS\system32\lcppn21.dll |14/11/2001 13:56:00 C:\WINDOWS\system32\lfavi12n.dll |17/07/2005 15:39:20 C:\WINDOWS\system32\lfbmp11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lfbmp12n.dll |14/09/2005 22:03:18 C:\WINDOWS\system32\LFCMP11n.DLL |06/06/2002 22:02:00 C:\WINDOWS\system32\LFCMP12n.DLL |14/09/2005 22:03:18 C:\WINDOWS\system32\lfeps11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lffax11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lffax12n.dll |14/09/2005 22:03:18 C:\WINDOWS\system32\lfgif11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lfgif12n.dll |17/07/2005 15:39:21 C:\WINDOWS\system32\lfmpg12n.dll |17/07/2005 15:39:21 C:\WINDOWS\system32\lfpcd11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lfpcx11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\Lfpng11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lfpsd11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lftga11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lftif11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\lftif12n.dll |14/09/2005 22:03:18 C:\WINDOWS\system32\lfwmf11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\libclamav.dll |17/12/2006 11:22:29 C:\WINDOWS\system32\libdivx.dll |04/09/2006 21:28:14 C:\WINDOWS\system32\LQCUI2.dll |14/09/2005 22:03:16 C:\WINDOWS\system32\LTDIS11n.dll |06/06/2002 22:02:00 C:\WINDOWS\system32\LTDIS12n.dll |14/09/2005 22:03:19 C:\WINDOWS\system32\ltefx12n.dll |14/09/2005 22:03:19 C:\WINDOWS\system32\ltfil11n.DLL |06/06/2002 22:02:00 C:\WINDOWS\system32\ltfil12n.DLL |14/09/2005 22:03:19 C:\WINDOWS\system32\ltimg11n.dll |06/06/2002 22:02:02 C:\WINDOWS\system32\ltimg12n.dll |14/09/2005 22:03:19 C:\WINDOWS\system32\ltkrn11n.dll |06/06/2002 22:02:02 C:\WINDOWS\system32\ltkrn12n.dll |14/09/2005 22:03:19 C:\WINDOWS\system32\LTTWN12n.DLL |17/07/2005 15:39:25 C:\WINDOWS\system32\Ltwvc11n.dll |06/06/2002 22:02:02 C:\WINDOWS\system32\Ltwvc12n.dll |14/09/2005 22:03:19 C:\WINDOWS\system32\lvcodec2.dll |14/09/2005 22:17:34 C:\WINDOWS\system32\lvcoinst.dll |14/09/2005 22:17:35 C:\WINDOWS\system32\LVCOMCX.dll |08/10/2004 10:55:36 C:\WINDOWS\system32\Lvkrn12n.dll |14/09/2005 22:03:27 C:\WINDOWS\system32\LVMAENUM.dll |08/10/2004 10:52:58 C:\WINDOWS\system32\LVUI2.dll |14/09/2005 22:17:35 C:\WINDOWS\system32\LVUI2RC.dll |14/09/2005 22:17:35 C:\WINDOWS\system32\mdmxsdk.dll |09/04/2003 14:01:32 C:\WINDOWS\system32\mdwmdmsp.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\msdmo.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\msencode.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\mtxparhd.dll |20/08/2004 00:09:35 C:\WINDOWS\system32\nmwcdcls.dll |11/01/2005 11:30:50 C:\WINDOWS\system32\nmwcdlog.dll |11/01/2005 11:30:48 C:\WINDOWS\system32\Npindeo.dll |20/11/1998 12:38:58 C:\WINDOWS\system32\nv4_disp.dll |20/08/2004 00:09:36 C:\WINDOWS\system32\Oemdspif.dll |10/12/2002 11:47:44 C:\WINDOWS\system32\paqsp.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\PCDLIB32.DLL |08/12/1998 18:53:58 C:\WINDOWS\system32\picn20.dll |29/07/2005 10:51:33 C:\WINDOWS\system32\pncrt.dll |03/02/2005 15:41:00 C:\WINDOWS\system32\pndx5016.dll |03/02/2005 15:41:03 C:\WINDOWS\system32\pndx5032.dll |03/02/2005 15:41:03 C:\WINDOWS\system32\pqdvdb.dll |16/11/2005 05:38:00 C:\WINDOWS\system32\px.dll |17/02/2005 19:03:41 C:\WINDOWS\system32\pxdrv.dll |17/02/2005 19:03:42 C:\WINDOWS\system32\pxmas.dll |17/02/2005 19:03:41 C:\WINDOWS\system32\pxwave.dll |17/02/2005 19:03:42 C:\WINDOWS\system32\QCUI2.dll |14/09/2005 22:03:20 C:\WINDOWS\system32\qedwipes.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\qt-dx331.dll |04/09/2006 21:28:15 C:\WINDOWS\system32\qt-mt331.dll |01/09/2004 16:49:17 C:\WINDOWS\system32\rmoc3260.dll |03/02/2005 15:41:31 C:\WINDOWS\system32\Roboex32.dll |07/11/2000 17:36:14 C:\WINDOWS\system32\S32EVNT1.DLL |02/02/2005 20:20:18 C:\WINDOWS\system32\s3gnb.dll |20/08/2004 00:09:39 C:\WINDOWS\system32\sbe.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\slbcsp.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\slbiop.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\slbrccsp.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\slcoinst.dll |20/08/2004 00:09:41 C:\WINDOWS\system32\slextspk.dll |20/08/2004 00:09:41 C:\WINDOWS\system32\slgen.dll |20/08/2004 00:09:41 C:\WINDOWS\system32\SONYHCY.DLL |17/07/2005 15:36:58 C:\WINDOWS\system32\spnike.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\sprio600.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\sprio800.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\spxcoins.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\ssldivx.dll |04/09/2006 21:28:17 C:\WINDOWS\system32\SymNeti.dll |05/04/2005 10:17:04 C:\WINDOWS\system32\SymRedir.dll |05/04/2005 10:17:04 C:\WINDOWS\system32\SynTPAPI.dll |10/09/2002 23:22:38 C:\WINDOWS\system32\SynTPFcs.dll |10/09/2002 23:23:30 C:\WINDOWS\system32\tsd32.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\TwnLib20.dll |29/07/2005 10:51:33 C:\WINDOWS\system32\TwnLib4.dll |29/07/2005 10:51:35 C:\WINDOWS\system32\unacev2.dll |06/03/2002 00:00:00 C:\WINDOWS\system32\unrar.dll |15/10/2002 23:54:04 C:\WINDOWS\system32\UNRAR3.dll |02/02/2003 19:06:02 C:\WINDOWS\system32\usrcntra.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrcoina.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrdpa.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrdtea.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrfaxa.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrlbva.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrrtosa.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrsdpia.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrsvpia.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrv42a.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrv80a.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrvoica.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\usrvpa.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\vobsub.dll |11/12/2002 09:19:32 C:\WINDOWS\system32\vp6vfw.dll |04/09/2006 21:28:21 C:\WINDOWS\system32\vp7vfw.dll |04/09/2006 21:28:22 C:\WINDOWS\system32\VSFilter.dll |08/03/2004 00:07:06 C:\WINDOWS\system32\vxblock.dll |17/02/2005 19:03:42 C:\WINDOWS\system32\wbtapi.dll |01/12/2003 15:22:00 C:\WINDOWS\system32\WidcommSdk.dll |01/12/2003 15:28:00 C:\WINDOWS\system32\win87em.dll |30/08/2002 03:00:00 C:\WINDOWS\system32\WNASPI32.DLL |02/02/2005 20:29:57 C:\WINDOWS\system32\WooDial2000.dll |02/02/2005 18:34:06 C:\WINDOWS\system32\x264vfw.dll |04/09/2006 21:28:20 C:\WINDOWS\system32\xcomm.dll |02/06/2005 16:16:50 C:\WINDOWS\system32\xcommsvr.dll |01/10/2001 14:08:08 C:\WINDOWS\system32\xgate.dll |29/08/2001 06:37:12 C:\WINDOWS\system32\xvidcore.dll |04/09/2006 21:28:19 C:\WINDOWS\system32\xvidvfw.dll |04/09/2006 21:28:18 Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\WINDOWS\system 28/05/2003 18:53 4 672 WOWPOST.EXE 1 fichier(s) 4 672 octets 0 Rép(s) 12 985 090 048 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\WINDOWS\system32 20/08/2004 00:09 6 144 csrss.exe 1 fichier(s) 6 144 octets 0 Rép(s) 12 985 090 048 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\WINDOWS\Downloaded Program Files 26/12/2006 21:45 <REP> . 26/12/2006 21:45 <REP> .. 24/08/2006 08:28 141 424 asinst.dll 22/08/2006 09:06 537 asinst.inf 08/08/2006 11:45 576 kavwebscan.inf 3 fichier(s) 142 537 octets Total des fichiers listés : 3 fichier(s) 142 537 octets 2 Rép(s) 12 985 085 952 octets libres Recherche de rootkit! (Merci S!Ri) Recherche d'infections connues Liste des programmes installes Ad-Aware SE Personal Adobe Acrobat 5.0 Apple Software Update Archiveur WinRAR ATI - Utilitaire de désinstallation du logiciel ATI Display Driver µTorrent AutoUpdate avast! Antivirus AVG Anti-Spyware 7.5 AviSynth 2.5 BitLord 1.1 BitTorrent 4.0.3 CCleaner (remove only) Client Windows Rights Management avec Service Pack 2 COM One Bluetooth Software Conexant 56K ACLink Modem Conexant 56K ACLink Modem Conexant AC-Link Audio Connection Booster 4.0.0.0 DivX Audio Compressor 4.02 DivX Player Easy CD Creator 5 Basic EasyCleaner eMule EndNote Freeplayer Google Earth Gordian Knot Rip Pack 0.33.1 HijackThis 1.99.1 Hotfix for Windows XP (KB926239) ImageMixer VCD2 Inactive HP Printer Drivers (Remove only) Internet Download Manager InterVideo WinDVD Iomega Automatic Backup Iomega Automatic Backup iPod for Windows 2006-01-10 iPod for Windows 2006-01-10 ISI ResearchSoft - Export Helper iTunes iTunes iTunes J2SE Runtime Environment 5.0 Update 1 Java 2 Runtime Environment Standard Edition v1.3.1_03 jv16 PowerTools 1.3 K-Lite Codec Pack 2.75 Full Kaspersky Online Scanner Kerio Personal Firewall Lecteur Windows Media 11 Logiciel QuickCam de Logitech Logitech Desktop Messenger Logitech Print Service Macromedia Flash Player Macromedia Flash Player 8 Microsoft .NET Framework (French) Microsoft .NET Framework (French) v1.0.3705 Microsoft .NET Framework 1.0 Hotfix (KB886906) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 French Language Pack Microsoft .NET Framework 2.0 Microsoft .NET Framework 2.0 Microsoft .NET Framework 2.0 Language Pack - FRA Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office XP Professional with FrontPage Microsoft Office XP Web Components Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Works 7.0 Minitel Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398) Mise à jour de sécurité pour Windows XP (KB920213) Mise à jour de sécurité pour Windows XP (KB922760) Mise à jour de sécurité pour Windows XP (KB923694) Mise à jour de sécurité pour Windows XP (KB923980) Mise à jour de sécurité pour Windows XP (KB924270) Mise à jour de sécurité pour Windows XP (KB925454) Mise à jour de sécurité pour Windows XP (KB926255) Mise à jour pour Windows XP (KB904942) Mise à jour pour Windows XP (KB920342) Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA Mozilla Firefox (2.0.0.1) MSN Messenger 7.5 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) Nero Suite NETGEAR RangeMax Wireless PC Card WPN511 Nokia Connectivity Cable Driver Nokia Connectivity Cable Driver Nokia PC Suite 6.1 Nokia PC Suite 6.1 Notebook Utilities One-Touch Buttons OpenOffice.org 2.0 Outil de connexion Wanadoo Package de base Microsoft de service de chiffrement pour cartes à puce Picture Package Programme de gestion Camera de Logitech® Quick Zip 3.06.3 QuickTime QuickTime QuickTime Real Alternative 1.35 RealPlayer SAGEM F@st800 Security Update for Microsoft .NET Framework 2.0 (KB922770) Security Update pour Microsoft .NET Framework 2.0 (KB917283) Shareaza version 2.2.1.0 Sony USB Driver SP2 de compatibilité descendante du client Windows Rights Management Spybot - Search & Destroy 1.4 SpywareBlaster v3.5.1 Synaptics TouchPad Utilitaire de sauvegarde Windows VideoLAN VLC media player 0.8.5-freehd Videora iPod Converter 0.91 VobSub v2.23 (Remove Only) Wanadoo Messager WebFldrs XP Windows Genuine Advantage v1.3.0254.0 Windows Genuine Advantage Validation Tool (KB892130) Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 2 Winpooch 0.6.3 XLSTAT 2006 Zeb-Utility 1.2 ZTE ZXDSL852 Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\Program Files 23/12/2006 15:59 <REP> . 23/12/2006 15:59 <REP> .. 09/09/2006 08:50 <REP> Addinsoft 10/12/2002 03:18 <REP> Adobe 29/07/2005 10:58 <REP> Ahead 26/07/2005 23:08 <REP> Alwil Software 25/11/2006 23:56 <REP> Apple Software Update 10/04/2005 21:57 <REP> ATI Technologies 22/06/2006 18:04 <REP> AviSynth 2.5 04/12/2006 22:31 <REP> BitLord 02/01/2006 18:08 <REP> BitTorrent 31/01/2006 19:03 <REP> CCleaner 11/02/2005 18:43 <REP> COMOne 10/12/2002 03:19 <REP> COMPAQ 10/12/2002 03:08 <REP> CompaqNET.fr 10/12/2002 11:46 <REP> ComPlus Applications 02/02/2005 19:03 <REP> CONEXANT 12/12/2006 21:53 <REP> Connection Booster 10/07/2005 23:33 <REP> directx 04/09/2006 21:21 <REP> DivX 17/12/2006 23:58 <REP> eMule 03/09/2006 10:13 <REP> EndNote 12/07/2006 23:40 <REP> ewido anti-malware 23/12/2006 15:59 <REP> ewido anti-spyware 4.0 27/08/2006 15:28 <REP> Fichiers communs 03/12/2006 11:07 <REP> Free 06/12/2006 22:28 <REP> Freeplayer 03/02/2005 15:05 <REP> Gabest 17/07/2005 23:00 <REP> GordianKnot 23/12/2006 15:59 <REP> Grisoft 10/12/2002 03:15 <REP> HPQ 07/01/2006 21:59 <REP> Infoflash France 22/12/2006 16:22 <REP> InstallShield Installation Information 10/09/2006 22:22 <REP> Internet Download Manager 17/12/2006 22:20 <REP> Internet Explorer 02/02/2005 17:41 <REP> InterVideo 03/02/2005 16:01 <REP> Iomega 26/11/2006 00:04 <REP> iPod 26/11/2006 00:04 <REP> iTunes 07/07/2005 23:47 <REP> Java 02/02/2005 18:32 <REP> JavaSoft 06/01/2006 00:46 <REP> jv16 PowerTools 06/01/2006 19:25 <REP> Kerio 04/09/2006 21:28 <REP> K-Lite Codec Pack 20/12/2005 22:04 <REP> Lavasoft 14/09/2005 22:20 <REP> Logitech 11/04/2005 22:08 <REP> Media Player Classic 22/12/2005 22:45 <REP> Messenger 29/12/2005 18:53 <REP> Microsoft ActiveSync 10/12/2002 11:46 <REP> microsoft frontpage 10/12/2002 03:05 <REP> Microsoft Office 10/12/2002 03:16 <REP> Microsoft Works 10/12/2002 03:07 <REP> Minitel 04/09/2006 21:20 <REP> Morgan 02/02/2005 19:55 <REP> Movie Maker 26/12/2006 20:31 <REP> Mozilla Firefox 02/02/2005 21:48 <REP> MSN 10/12/2002 11:46 <REP> MSN Gaming Zone 20/11/2005 20:47 <REP> MSN Messenger 26/11/2006 11:13 <REP> MSXML 4.0 04/12/2006 21:42 <REP> NETGEAR 20/08/2005 23:41 <REP> NetMeeting 07/02/2005 18:18 <REP> Nokia 02/02/2005 17:53 <REP> Office Xp 09/09/2006 16:34 <REP> OpenOffice.org 2.0 15/12/2006 20:19 <REP> Outlook Express 17/07/2005 15:42 <REP> PIXELA 26/11/2006 00:01 <REP> QuickTime 07/02/2005 17:13 <REP> QuickZip 03/02/2005 15:40 <REP> Real 11/04/2005 22:08 <REP> Real Alternative 02/02/2005 17:44 <REP> Roxio 27/04/2005 18:47 <REP> SAGEM 10/12/2002 11:46 <REP> Services en ligne 10/01/2006 21:51 <REP> Shareaza 17/07/2005 15:39 <REP> Sony Corporation 02/04/2006 19:04 <REP> Spybot - Search & Destroy 17/12/2006 11:27 <REP> SpywareBlaster 10/12/2002 03:15 <REP> Synaptics 06/01/2006 01:13 <REP> ToniArts 22/12/2006 16:22 <REP> Uninstall Information 11/11/2006 13:48 <REP> uTorrent 03/02/2005 15:35 <REP> VideoLAN 22/06/2006 18:05 <REP> VideoraiPodConverter 24/12/2006 14:38 <REP> Wanadoo 02/01/2006 15:55 <REP> Wanadoo Messager 04/12/2006 23:47 <REP> Windows Media Connect 2 04/12/2006 23:55 <REP> Windows Media Player 02/02/2005 19:50 <REP> Windows NT 23/12/2006 16:23 <REP> Winpooch 26/08/2006 20:23 <REP> WinRAR 10/12/2002 11:46 <REP> xerox 10/12/2002 03:08 <REP> Your Application Name 07/09/2006 20:13 <REP> Zeb-Utility 01/01/2006 03:02 <REP> ZTE Corporation 0 fichier(s) 0 octets 95 Rép(s) 12 984 958 976 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\Program Files\fichiers communs 27/08/2006 15:28 <REP> . 27/08/2006 15:28 <REP> .. 02/02/2005 17:45 <REP> Adaptec Shared 16/02/2005 17:21 <REP> Adobe 29/07/2005 10:54 <REP> Ahead 29/12/2005 18:53 <REP> Designer 14/09/2005 22:06 <REP> FotoWire 13/02/2005 12:28 <REP> InstallShield 07/07/2005 23:34 <REP> Java 14/09/2005 22:04 <REP> Logitech 04/12/2006 23:10 <REP> Microsoft Shared 10/12/2002 11:46 <REP> MSSoap 17/07/2005 15:38 <REP> muvee Technologies 03/02/2005 19:26 <REP> Nokia 10/12/2002 11:46 <REP> ODBC 03/02/2005 19:26 <REP> PCSuite 03/02/2005 15:41 <REP> Real 16/04/2006 18:53 <REP> Risxtd 06/01/2006 00:29 <REP> Services 22/12/2005 21:13 <REP> Softwin 10/12/2002 11:46 <REP> SpeechEngines 15/12/2006 20:19 <REP> System 03/02/2005 15:41 <REP> xing shared 0 fichier(s) 0 octets 23 Rép(s) 12 984 958 976 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders 22/09/2006 14:08 <REP> . 22/09/2006 14:08 <REP> .. 06/03/2006 15:29 <REP> 1033 06/01/2006 19:06 <REP> 1036 29/01/2004 15:08 1 277 952 MSONSEXT.DLL 13/02/2001 00:23 58 784 MSOSV.DLL 03/06/1999 11:09 122 937 MSOWS409.DLL 07/03/2001 06:00 127 033 MSOWS40c.DLL 06/08/2000 09:04 401 462 MSVCP60.DLL 29/01/2004 15:08 69 632 PKMAXCTL.DLL 29/01/2004 15:08 868 352 PKMCDO.DLL 29/01/2004 15:08 53 248 PKMCORE.DLL 29/01/2004 15:08 102 400 PKMFORMS.DLL 29/01/2004 15:08 622 592 PKMRES.DLL 29/01/2004 15:08 28 672 PKMSSTLB.DLL 22/01/2001 03:25 40 960 PKMTEMPL.DLL 29/01/2004 15:08 24 576 PKMTRACE.DLL 29/01/2004 15:08 86 016 PKMWS.DLL 29/01/2004 15:08 237 568 PROMDEMO.DLL 29/01/2004 15:08 184 320 SECMGR.DLL 29/01/2004 15:08 315 392 VAIDDMGR.DLL 29/01/2004 15:08 32 768 VAIMEM.DLL 18 fichier(s) 4 654 664 octets 4 Rép(s) 12 984 958 976 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\ 11/11/2001 00:00 68 096 diff.exe 27/08/2006 14:10 103 424 grep.exe 2 fichier(s) 171 520 octets 0 Rép(s) 12 984 958 976 octets libres c:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.0.2.16\iTunesSetupAdmin.exe c:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\Installer\{333BECA0-DED8-4139-A516-8D9E44E22669}\ARPPRODUCTICON.exe c:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\Installer\{333BECA0-DED8-4139-A516-8D9E44E22669}\NewShortcut2_8315396A5EA1419DBEC4978284BDF556.exe c:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\Installer\{333BECA0-DED8-4139-A516-8D9E44E22669}\NewShortcut3_8315396A5EA1419DBEC4978284BDF556.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\dumphive.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\GenericRenosFix.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\Process.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\Reboot.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\restart.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\SmiUpdate.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\SrchSTS.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\swreg.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\swsc.exe c:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\unzip.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ATF-Cleaner.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\avgas-setup-7.5.0.50.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup131.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup132.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup133.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup134.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup135.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ClamWinPortable.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ewido-setup_4.0.0.172a.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Setup_Zeb-Utility.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Winpooch-0.5.10.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Winpooch-0.5.9.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Winpooch-0.6.3.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\xcleaner_free.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Antivirus\Antivirus\EClea2_0.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Antivirus\Antivirus\jv16pt_setup1.3.0.195.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\diff.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\FilesInfoCmd.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\Fport.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\grep.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\LFiles.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\LISTDLLS.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\pslist.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\streams.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\swreg.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\notrace\notrace.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\Process.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\Reboot.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\restart.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\SrchSTS.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\swreg.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\swsc.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Complément Excel\xlstat2006\setup.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\eMule0.47c-Installer_2.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Firefox Setup 2.0.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Shareaza_2.2.1.0.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Thunderbird Setup 1.5.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\uTorrent-1.6-install.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\webdrive.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\wrar360fr.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Xtremsplit.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Ipod\iTunesSetup(2).exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Ipod\iTunesSetup.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Ipod\VideoraiPodConverter_Install(2).exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\BitLord_1.01.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\iTunesSetup.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\klcodec275f.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\wmp11-windowsxp-x86-fr-fr.exe c:\Documents and Settings\David BENAYOUN\Mes documents\End Note\End Note 6.exe c:\Documents and Settings\David BENAYOUN\Mes documents\End Note\EndNote602Patch.EXE c:\Documents and Settings\David BENAYOUN\Mes documents\My Shared Folder\Firefox Setup 1.5.exe c:\Documents and Settings\David BENAYOUN\Mes documents\My Shared Folder\idman501.exe c:\Documents and Settings\David BENAYOUN\Mes documents\My Shared Folder\kmd(1).exe c:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\instmsia.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\instmsiw.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\OOo_2.0.3_Win32Intel_install_fr.exe c:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\setup.exe c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll c:\Documents and Settings\David BENAYOUN\Application Data\IDM\idmmzcc\components\idmmzcc.dll c:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll c:\Documents and Settings\David BENAYOUN\Application Data\Mozilla\Firefox\Profiles\8f05hy02.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll Quant à l'analyse antivirus Panda, Avast refuse en faisant une alerte Win 32. Mais une analyse par Kaspersky n'a rien donné. PS : Je me connecte par Free (et plus France Telecom) par Ethernet, USB ou Wifi. Merci d'avance de votre réponse. -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Help ! -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Joyeux Noel à tous ! Qui pourrait jeter un coup d'oeil à mon analyse ? -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Merci à toi Charles Ingals, Voici le résultat de l'analyse que tu m'as suggérée : FPort v2.0 - TCP/IP Process to Port Mapper Copyright 2000 by Foundstone, Inc. http://www.foundstone.com Pid Process Port Proto Path 568 -> 1031 TCP 1080 -> 135 TCP 4 System -> 445 TCP 436 ashMaiSv -> 12025 TCP C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 436 ashMaiSv -> 12110 TCP C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 436 ashMaiSv -> 12119 TCP C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 436 ashMaiSv -> 12143 TCP C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 456 ashWebSv -> 12080 TCP C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 3416 firefox -> 1040 TCP C:\Program Files\Mozilla Firefox\firefox.exe 3416 firefox -> 1041 TCP C:\Program Files\Mozilla Firefox\firefox.exe 3416 firefox -> 1042 TCP C:\Program Files\Mozilla Firefox\firefox.exe 3416 firefox -> 1043 TCP C:\Program Files\Mozilla Firefox\firefox.exe 2012 kpf4gui -> 1025 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2012 kpf4gui -> 1027 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2148 kpf4gui -> 1032 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2148 kpf4gui -> 1034 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 1824 kpf4ss -> 1029 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1824 kpf4ss -> 1036 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1824 kpf4ss -> 44334 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1824 kpf4ss -> 44501 TCP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1080 -> 445 UDP 568 -> 4500 UDP 4 System -> 500 UDP 2012 kpf4gui -> 1026 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2148 kpf4gui -> 1028 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2012 kpf4gui -> 1055 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2012 kpf4gui -> 1056 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2148 kpf4gui -> 123 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 2148 kpf4gui -> 44334 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe 1824 kpf4ss -> 1033 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1824 kpf4ss -> 1035 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1824 kpf4ss -> 1100 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe 1824 kpf4ss -> 1900 UDP C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe PsList 1.26 - Process Information Lister Copyright © 1999-2004 Mark Russinovich Sysinternals - www.sysinternals.com Process information for CPQ26051264741: Name Pid Pri Thd Hnd VM WS Priv Idle 0 0 1 0 0 16 0 System 4 8 66 1432 1912 212 0 smss 744 11 3 21 3836 312 172 csrss 792 13 12 498 25408 3920 1920 winlogon 820 13 16 440 53768 2932 6132 services 864 9 16 289 23240 2852 1912 ashMaiSv 436 8 8 105 56300 948 3372 ashWebSv 456 8 18 124 71832 3588 7952 alg 568 8 6 104 33656 2800 1340 svchost 1024 8 19 203 63348 3600 3240 svchost 1080 8 10 266 37924 3208 2044 svchost 1120 8 75 1592 136396 24540 19752 svchost 1240 8 6 90 31664 2804 1476 svchost 1368 8 15 194 39108 3092 1964 spoolsv 1484 8 10 130 52384 4980 5044 aswUpdSv 1612 8 3 28 18408 188 680 ashServ 1628 13 24 274 92820 9548 13148 avast.setup 264 6 2 138 36424 6824 1832 guard 1648 8 8 73 43328 12020 20516 svchost 1672 8 3 74 32244 2528 2344 imapi 1748 8 5 99 35740 2564 1280 kpf4ss 1824 8 20 430 142984 10772 9348 kpf4gui 2012 8 5 78 40536 5752 2344 kpf4gui 2148 8 6 99 49808 7952 3444 svchost 1932 8 7 130 38324 2828 2664 lsass 876 9 19 351 42888 1080 3936 explorer 2204 8 17 602 126552 35948 31812 cmd 2144 8 1 18 14488 1924 1652 pslist 2224 13 2 88 18440 1936 944 Winpooch 2488 8 5 159 50000 6524 4044 ashDisp 2532 8 7 72 45364 1388 2676 firefox 3416 8 16 314 152180 57868 47860 SynTPEnh 3972 8 3 41 36144 3376 1408 ListDLLs v2.25 - DLL lister for Win9x/NT Copyright © 1997-2004 Mark Russinovich Sysinternals - www.sysinternals.com ------------------------------------------------------------------------------ explorer.exe pid: 2204 Command line: C:\WINDOWS\Explorer.EXE Base Size Version Path 0x7c800000 0x104000 5.01.2600.2945 C:\WINDOWS\system32\kernel32.dll 0x77ef0000 0x47000 5.01.2600.2818 C:\WINDOWS\system32\GDI32.dll 0x77d10000 0x90000 5.01.2600.2622 C:\WINDOWS\system32\USER32.dll 0x77f40000 0x76000 6.00.2900.3020 C:\WINDOWS\system32\SHLWAPI.dll 0x7c9d0000 0x823000 6.00.2900.2951 C:\WINDOWS\system32\SHELL32.dll 0x774a0000 0x13d000 5.01.2600.2726 C:\WINDOWS\system32\ole32.dll 0x75f10000 0xfd000 6.00.2900.3020 C:\WINDOWS\system32\BROWSEUI.dll 0x77720000 0x16f000 6.00.2900.3020 C:\WINDOWS\system32\SHDOCVW.dll 0x6fee0000 0x54000 5.01.2600.2976 C:\WINDOWS\system32\NETAPI32.dll 0x77aa0000 0xa7000 6.00.2900.3020 C:\WINDOWS\system32\WININET.dll 0x77390000 0x103000 6.00.2900.2982 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll 0x5d0a0000 0x7000 5.01.2600.0000 C:\WINDOWS\system32\serwvdrv.dll 0x5b3c0000 0x7000 5.01.2600.0000 C:\WINDOWS\system32\umdmxfrm.dll 0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL 0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll 0x76920000 0x8000 5.01.2600.2751 C:\WINDOWS\system32\LINKINFO.dll 0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL 0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll 0x76d10000 0x19000 5.01.2600.2912 C:\WINDOWS\system32\iphlpapi.dll 0x7df30000 0xa0000 6.00.2900.3020 C:\WINDOWS\system32\urlmon.dll 0x01790000 0xe000 1.04.0002.0010 C:\WINDOWS\system32\btncopy.dll 0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll 0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll 0x745e0000 0x2c6000 3.01.4000.2435 C:\WINDOWS\system32\msi.dll 0x72c60000 0x8000 5.01.2600.0000 C:\WINDOWS\system32\msacm32.drv 0x77210000 0xb1000 5.01.2600.3019 C:\WINDOWS\system32\SXS.DLL 0x0ffd0000 0x28000 5.01.2600.2161 C:\WINDOWS\system32\rsaenh.dll 0x00ae0000 0x7000 3.00.0000.0001 C:\Program Files\Internet Download Manager\idmmkb.dll 0x00af0000 0xf000 2.00.0002.0001 C:\Program Files\Internet Download Manager\IDMIECC.dll 0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll 0x01e20000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll 0x02420000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll 0x63000000 0x14000 6.07.0004.0001 C:\WINDOWS\system32\SynTPFcs.dll 0x5c2e0000 0x51000 8.00.0000.9026 C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll 0x60b30000 0x18000 8.00.0000.9025 C:\Program Files\OpenOffice.org 2.0\program\uwinapi.dll 0x7c340000 0x56000 7.10.3052.0004 C:\Program Files\OpenOffice.org 2.0\program\MSVCR71.dll 0x62410000 0x8e000 4.05.2003.0120 C:\Program Files\OpenOffice.org 2.0\program\stlport_vc7145.dll 0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\OpenOffice.org 2.0\program\MSVCP71.dll 0x02440000 0x2c000 C:\Program Files\WinRAR\rarext.dll 0x03110000 0x12b000 C:\PROGRA~1\QuickZip\QzShlExt.dll 0x750b0000 0x13000 5.01.2600.0000 C:\PROGRA~1\QuickZip\cabinet.dll 0x024a0000 0x20000 7.05.0000.0049 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll 0x64f00000 0x7000 4.07.0889.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll 0x14070000 0x1b000 11.00.5721.5145 C:\WINDOWS\system32\wmpshell.dll 0x73a80000 0x15000 5.01.2600.2709 C:\WINDOWS\system32\mscms.dll 0x15110000 0x25a000 11.00.5721.5145 C:\WINDOWS\system32\wmvcore.dll 0x11c70000 0x39000 11.00.5721.5145 C:\WINDOWS\system32\WMASF.DLL 0x10af0000 0x37000 11.00.5721.5145 C:\WINDOWS\system32\qasf.dll 0x04010000 0x16d000 6.05.2600.2749 C:\WINDOWS\system32\quartz.dll 0x30d30000 0x288000 1.00.0002.1999 C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax 0x041e0000 0xe5000 1.00.0001.0003 C:\Program Files\K-Lite Codec Pack\filters\vsfilter.dll 0x15380000 0x17e000 11.00.5721.5145 C:\WINDOWS\system32\WMVDECOD.dll 0x0bef0000 0x37000 11.00.5721.5145 C:\WINDOWS\system32\MFPlat.DLL 0x03b20000 0x3c000 3.04.0000.0000 C:\WINDOWS\system32\l3codecp.acm 0x10000000 0x13000 7.05.0000.0047 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll 0x41f00000 0x7000 1.01.0000.3917 C:\WINDOWS\system32\asfsipc.dll 0x60980000 0x7000 3.01.4000.1823 C:\WINDOWS\system32\MSISIP.DLL 0x74e10000 0x10000 5.06.0000.8820 C:\WINDOWS\System32\wshext.dll 0x73d20000 0xfe000 6.02.4131.0000 C:\WINDOWS\system32\MFC42.DLL 0x61d70000 0xe000 6.00.8665.0000 C:\WINDOWS\system32\MFC42LOC.DLL 0x59000000 0xe000 5.06.0000.6626 C:\WINDOWS\System32\wshFR.DLL 0x365a0000 0x16000 10.00.6313.0000 C:\PROGRA~1\MICROS~2\Office10\MCPS.DLL ListDLLs v2.25 - DLL lister for Win9x/NT Copyright © 1997-2004 Mark Russinovich Sysinternals - www.sysinternals.com No matching processes were found. ListDLLs v2.25 - DLL lister for Win9x/NT Copyright © 1997-2004 Mark Russinovich Sysinternals - www.sysinternals.com ------------------------------------------------------------------------------ winlogon.exe pid: 820 Command line: winlogon.exe Base Size Version Path 0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe 0x7c800000 0x104000 5.01.2600.2945 C:\WINDOWS\system32\kernel32.dll 0x77680000 0x11000 5.01.2600.2622 C:\WINDOWS\system32\AUTHZ.dll 0x77d10000 0x90000 5.01.2600.2622 C:\WINDOWS\system32\USER32.dll 0x77ef0000 0x47000 5.01.2600.2818 C:\WINDOWS\system32\GDI32.dll 0x6fee0000 0x54000 5.01.2600.2976 C:\WINDOWS\system32\NETAPI32.dll 0x7c9d0000 0x823000 6.00.2900.2951 C:\WINDOWS\system32\SHELL32.dll 0x77f40000 0x76000 6.00.2900.3020 C:\WINDOWS\system32\SHLWAPI.dll 0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll 0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll 0x77390000 0x103000 6.00.2900.2982 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll 0x774a0000 0x13d000 5.01.2600.2726 C:\WINDOWS\system32\ole32.dll 0x77210000 0xb1000 5.01.2600.3019 C:\WINDOWS\system32\sxs.dll 0x5d0a0000 0x7000 5.01.2600.0000 C:\WINDOWS\system32\serwvdrv.dll 0x5b3c0000 0x7000 5.01.2600.0000 C:\WINDOWS\system32\umdmxfrm.dll 0x0ffd0000 0x28000 5.01.2600.2161 C:\WINDOWS\system32\rsaenh.dll 0x76d10000 0x19000 5.01.2600.2912 C:\WINDOWS\system32\iphlpapi.dll 0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll 0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL 0x72c60000 0x8000 5.01.2600.0000 C:\WINDOWS\system32\msacm32.drv ListDLLs v2.25 - DLL lister for Win9x/NT Copyright © 1997-2004 Mark Russinovich Sysinternals - www.sysinternals.com ------------------------------------------------------------------------------ services.exe pid: 864 Command line: C:\WINDOWS\system32\services.exe Base Size Version Path 0x7c800000 0x104000 5.01.2600.2945 C:\WINDOWS\system32\kernel32.dll 0x77d10000 0x90000 5.01.2600.2622 C:\WINDOWS\system32\USER32.dll 0x77ef0000 0x47000 5.01.2600.2818 C:\WINDOWS\system32\GDI32.dll 0x77680000 0x11000 5.01.2600.2622 C:\WINDOWS\system32\AUTHZ.dll 0x7dbc0000 0x21000 5.01.2600.2744 C:\WINDOWS\system32\umpnpmgr.dll 0x6fee0000 0x54000 5.01.2600.2976 C:\WINDOWS\system32\NETAPI32.dll 0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll 0x47260000 0xf000 5.01.2600.3008 C:\WINDOWS\AppPatch\AcAdProc.dll Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 5D96-7AAE Répertoire de C:\Program Files 23/12/2006 15:59 <REP> . 23/12/2006 15:59 <REP> .. 09/09/2006 08:50 <REP> Addinsoft 10/12/2002 03:18 <REP> Adobe 29/07/2005 10:58 <REP> Ahead 26/07/2005 23:08 <REP> Alwil Software 25/11/2006 23:56 <REP> Apple Software Update 10/04/2005 21:57 <REP> ATI Technologies 22/06/2006 18:04 <REP> AviSynth 2.5 04/12/2006 22:31 <REP> BitLord 02/01/2006 18:08 <REP> BitTorrent 31/01/2006 19:03 <REP> CCleaner 11/02/2005 18:43 <REP> COMOne 10/12/2002 03:19 <REP> COMPAQ 10/12/2002 03:08 <REP> CompaqNET.fr 10/12/2002 11:46 <REP> ComPlus Applications 02/02/2005 19:03 <REP> CONEXANT 12/12/2006 21:53 <REP> Connection Booster 10/07/2005 23:33 <REP> directx 04/09/2006 21:21 <REP> DivX 17/12/2006 23:58 <REP> eMule 03/09/2006 10:13 <REP> EndNote 12/07/2006 23:40 <REP> ewido anti-malware 23/12/2006 15:59 <REP> ewido anti-spyware 4.0 27/08/2006 15:28 <REP> Fichiers communs 03/12/2006 11:07 <REP> Free 06/12/2006 22:28 <REP> Freeplayer 03/02/2005 15:05 <REP> Gabest 17/07/2005 23:00 <REP> GordianKnot 23/12/2006 15:59 <REP> Grisoft 10/12/2002 03:15 <REP> HPQ 07/01/2006 21:59 <REP> Infoflash France 22/12/2006 16:22 <REP> InstallShield Installation Information 10/09/2006 22:22 <REP> Internet Download Manager 17/12/2006 22:20 <REP> Internet Explorer 02/02/2005 17:41 <REP> InterVideo 03/02/2005 16:01 <REP> Iomega 26/11/2006 00:04 <REP> iPod 26/11/2006 00:04 <REP> iTunes 07/07/2005 23:47 <REP> Java 02/02/2005 18:32 <REP> JavaSoft 06/01/2006 00:46 <REP> jv16 PowerTools 04/09/2006 21:28 <REP> K-Lite Codec Pack 06/01/2006 19:25 <REP> Kerio 20/12/2005 22:04 <REP> Lavasoft 14/09/2005 22:20 <REP> Logitech 11/04/2005 22:08 <REP> Media Player Classic 22/12/2005 22:45 <REP> Messenger 29/12/2005 18:53 <REP> Microsoft ActiveSync 10/12/2002 11:46 <REP> microsoft frontpage 10/12/2002 03:05 <REP> Microsoft Office 10/12/2002 03:16 <REP> Microsoft Works 10/12/2002 03:07 <REP> Minitel 04/09/2006 21:20 <REP> Morgan 02/02/2005 19:55 <REP> Movie Maker 24/12/2006 12:32 <REP> Mozilla Firefox 02/02/2005 21:48 <REP> MSN 10/12/2002 11:46 <REP> MSN Gaming Zone 20/11/2005 20:47 <REP> MSN Messenger 26/11/2006 11:13 <REP> MSXML 4.0 04/12/2006 21:42 <REP> NETGEAR 20/08/2005 23:41 <REP> NetMeeting 07/02/2005 18:18 <REP> Nokia 02/02/2005 17:53 <REP> Office Xp 09/09/2006 16:34 <REP> OpenOffice.org 2.0 15/12/2006 20:19 <REP> Outlook Express 17/07/2005 15:42 <REP> PIXELA 26/11/2006 00:01 <REP> QuickTime 07/02/2005 17:13 <REP> QuickZip 03/02/2005 15:40 <REP> Real 11/04/2005 22:08 <REP> Real Alternative 02/02/2005 17:44 <REP> Roxio 27/04/2005 18:47 <REP> SAGEM 10/12/2002 11:46 <REP> Services en ligne 10/01/2006 21:51 <REP> Shareaza 17/07/2005 15:39 <REP> Sony Corporation 02/04/2006 19:04 <REP> Spybot - Search & Destroy 17/12/2006 11:27 <REP> SpywareBlaster 10/12/2002 03:15 <REP> Synaptics 06/01/2006 01:13 <REP> ToniArts 22/12/2006 16:22 <REP> Uninstall Information 11/11/2006 13:48 <REP> uTorrent 03/02/2005 15:35 <REP> VideoLAN 22/06/2006 18:05 <REP> VideoraiPodConverter 24/12/2006 12:48 <REP> Wanadoo 02/01/2006 15:55 <REP> Wanadoo Messager 04/12/2006 23:47 <REP> Windows Media Connect 2 04/12/2006 23:55 <REP> Windows Media Player 02/02/2005 19:50 <REP> Windows NT 23/12/2006 16:23 <REP> Winpooch 26/08/2006 20:23 <REP> WinRAR 10/12/2002 11:46 <REP> xerox 10/12/2002 03:08 <REP> Your Application Name 07/09/2006 20:13 <REP> Zeb-Utility 01/01/2006 03:02 <REP> ZTE Corporation 0 fichier(s) 0 octets 95 Rép(s) 13 420 711 936 octets libres C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.0.2.16\iTunesSetupAdmin.exe C:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\Installer\{333BECA0-DED8-4139-A516-8D9E44E22669}\ARPPRODUCTICON.exe C:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\Installer\{333BECA0-DED8-4139-A516-8D9E44E22669}\NewShortcut2_8315396A5EA1419DBEC4978284BDF556.exe C:\Documents and Settings\David BENAYOUN\Application Data\Microsoft\Installer\{333BECA0-DED8-4139-A516-8D9E44E22669}\NewShortcut3_8315396A5EA1419DBEC4978284BDF556.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\dumphive.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\GenericRenosFix.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\Process.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\Reboot.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\restart.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\SmiUpdate.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\SrchSTS.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\swreg.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\swsc.exe C:\Documents and Settings\David BENAYOUN\Bureau\SmitfraudFix\unzip.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ATF-Cleaner.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\avgas-setup-7.5.0.50.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup131.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup132.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup133.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup134.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ccsetup135.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ClamWinPortable.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\ewido-setup_4.0.0.172a.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Setup_Zeb-Utility.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Winpooch-0.5.10.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Winpooch-0.5.9.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Winpooch-0.6.3.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\xcleaner_free.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Antivirus\Antivirus\EClea2_0.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Antivirus\Antivirus\jv16pt_setup1.3.0.195.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\diff.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\FilesInfoCmd.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\Fport.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\grep.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\LFiles.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\LISTDLLS.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\pslist.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\streams.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\DiagHelp\DiagHelp\DiagHelp\swreg.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\notrace\notrace.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\Process.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\Reboot.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\restart.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\SrchSTS.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\swreg.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Antivirus\Smitfraud\SmitfraudFix\swsc.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Complément Excel\xlstat2006\setup.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\eMule0.47c-Installer_2.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Firefox Setup 2.0.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Shareaza_2.2.1.0.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Thunderbird Setup 1.5.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\uTorrent-1.6-install.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\webdrive.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\wrar360fr.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Divers\Xtremsplit.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Ipod\iTunesSetup(2).exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Ipod\iTunesSetup.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Ipod\VideoraiPodConverter_Install(2).exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\BitLord_1.01.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\iTunesSetup.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\klcodec275f.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Média\wmp11-windowsxp-x86-fr-fr.exe C:\Documents and Settings\David BENAYOUN\Mes documents\End Note\End Note 6.exe C:\Documents and Settings\David BENAYOUN\Mes documents\End Note\EndNote602Patch.EXE C:\Documents and Settings\David BENAYOUN\Mes documents\My Shared Folder\Firefox Setup 1.5.exe C:\Documents and Settings\David BENAYOUN\Mes documents\My Shared Folder\idman501.exe C:\Documents and Settings\David BENAYOUN\Mes documents\My Shared Folder\kmd(1).exe C:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\instmsia.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\instmsiw.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\OOo_2.0.3_Win32Intel_install_fr.exe C:\Documents and Settings\David BENAYOUN\Mes documents\Open Office\setup.exe Merci à toi par avance. -
Rapport Hijack
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Bonsoir, Alors personne n'est inspiré par mon rapport ? -
Bonjour et longue vie à ce forum qui m'a souvent sorti de quelques soucis informatiques. J'ai récemment changé de FAI et suis actuellement chez Fr** en me connectant par ethernet , usb ou wifi. Toutefois, j'ai remarqué des ralentissements sur mon système et sur la connexion internet. Les analyses easycleaner, adaware, spybot, spyware blaster et ewido ne retrouvent rien. J'ai le couple Avast et Kerio firewall et Winpooch qui surveille le registre. Une analyse antivirus comme mentionné par vos soins en mode sans échec n'a rien donné. Je fais actuellement tourner la machine sur l'antivirus en ligne de Kaspersky. Voici le rapport HiJack dont certaines lignes me sont inconnues (au passage, je sais que je devrais me débarasser de Internet Download Manager mais les problèmes sont plus récents que son installation...). Logfile of HijackThis v1.99.1 Scan saved at 14:12:57, on 23/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\HPConfig.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\WINDOWS\System32\imapi.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Winpooch\Winpooch.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\logonui.exe C:\Program Files\Wanadoo\EspaceWanadoo.exe C:\Program Files\Wanadoo\ComComp.exe C:\PROGRA~1\Wanadoo\Toaster.exe C:\PROGRA~1\Wanadoo\Inactivity.exe C:\PROGRA~1\Wanadoo\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\Wanadoo\Watch.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Winpooch] C:\Program Files\Winpooch\Winpooch.exe O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1141505994945 O17 - HKLM\System\CCS\Services\Tcpip\..\{E493AF57-C7B1-4CCB-BD3C-B837E79F854D}: NameServer = 80.10.246.1 80.10.246.132 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe Merci de me répondre et peut-être de me sauver encore une fois...
-
Mon rapport Smitfraud
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Merci Bruce Lee pour la rapidité de ta réponse... Mais j'ai un problème : dès que je branche le cable USB de mon modem, le ventilo de mon PC se met à tourner et ça fait un bruit incroyable !!! D'où cela peut-il venir ? -
Bonsoir à tous, J'ai fait la procédure préliminaire et RAS, mais Smitfraud me trouve ceci : SmitFraudFix v2.39 Rapport fait à 21:57:17,72, 05/05/2006 Executé à partir de C:\Documents and Settings\David BENAYOUN\Mes documents\Downloads\Documents\Smitfraud\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\David BENAYOUN\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DAVIDB~1\Favoris »»»»»»»»»»»»»»»»»»»»»»»» Bureau »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Ma page d'accueil" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll »»»»»»»»»»»»»»»»»»»»»»»» Fin Qu'en dites vous ? Merci du super travail que vous faites.
-
Analyse rapport HijackThis
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Un probléme Tornado, j'essaye d'installer l'Active X en passant par Internet Explorer (que je n'utilise plus depuis que Zebulon m'a expliqué les avantages de Firefox), mais Avast détecte dans cet Active X un Win32: CTX, et bloque donc son installation. -
Analyse rapport HijackThis
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Salut à toi et merci pour ta réponse. Voici un rapport en mode normal: Logfile of HijackThis v1.99.1 Scan saved at 18:49:09, on 17/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\system32\HPConfig.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\WINDOWS\System32\imapi.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Winpooch\Winpooch.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\Program Files\Wanadoo\EspaceWanadoo.exe C:\Program Files\Wanadoo\ComComp.exe C:\PROGRA~1\Wanadoo\Toaster.exe C:\PROGRA~1\Wanadoo\Inactivity.exe C:\PROGRA~1\Wanadoo\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\Wanadoo\Watch.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Winpooch] C:\Program Files\Winpooch\Winpooch.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1141505994945 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1141506349635 O17 - HKLM\System\CCS\Services\Tcpip\..\{E493AF57-C7B1-4CCB-BD3C-B837E79F854D}: NameServer = 80.10.246.130 80.10.246.3 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe Merci encore. -
Bonjour à tous, Voila, depuis quelques temps mon PC me semble être ralenti dès que je vais sur le net. J'ai fait la procédure préliminaire et voici le rapport HiJack en mode sans échec: Logfile of HijackThis v1.99.1 Scan saved at 18:21:46, on 17/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Winpooch] C:\Program Files\Winpooch\Winpooch.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1141505994945 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1141506349635 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe Merci de votre travail formidable qui m'a déjà aidé plus d'une fois.
-
Merci pour tes renseignements et longue vie à ce forum !!!
-
Euh désolé, Je crois en fait que c'est une mise à jour Office Xp Service Pack 3... Que dois-je faire ?
-
Bonjour à tous, Windows Update me propose de télécharger le service pack 3 pour Windows Xp. Quels sont les avantages et les risques surtout !!? Dois-je accepter l'installation. Merci à vous et à votre travail.
-
Bonjour et merci pour ta réponse Jack, J'ai installé Winpooch mais je trouve qu'il ralentit le système alors que tout allait bien avant. La présence de Ewido (qui a dépassé ses 14 jours...) peut-elle expliquer cela? Dois-je désinstaller Ewido ? N'y-a-t-il pas de logiciel type Ewido qui a vraiment l'air très bien, en freeware ? merci.
-
Bonsoir, Voila, Jack Burton m'a conseillé d'installer Winpooch après les 14 jours de version d'essai de Ewido. C'est chose faite mais le logiciel demande des filtres ? Comment bien configurer Winpooch ? Peut-être ce sujet a-t-il déjà été discuté ? Dans ce cas, désolé et merci de m'indiquer où ? Encore merci à ce forum qui a révolutionné mon PC !!!
-
Rapport Hijack This
spiderman2005 a répondu à un(e) sujet de spiderman2005 dans Analyses et éradication malwares
Merci de ta réponse rapide, Effectivement, le scan avec Ewido est normal. Toutefois, que penses-tu de cette ligne ? C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE Pose-t-elle problème ? Et une "connexion manuelle", ça veut dire quoi ? Quels services Wanadoo ne sont pas indispensables ? Désolé, MASTER, de ces questions stupides... Merci à vous tous. -
Bonsoir au forum ZEBULON qui m'a bien aidé à ne pas jeter mon ordinateur par la fenêtre tellement il plantait... A priori, tout va bien mais il persiste une petite lenteur (peut-être due à l'hiver, c'est comme pour les voitures..?) Voici mon rapport Hijack This, dites-moi SVP s'il y a quelquechose de suspect. Longue vie à ce forum qui mérite le prix Nobel de l'informatique (s'il existait...). Logfile of HijackThis v1.99.1 Scan saved at 19:14:50, on 19/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\WINDOWS\system32\HPConfig.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\WINDOWS\System32\imapi.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\HijackThis\HijackThis.exe C:\Program Files\Wanadoo\EspaceWanadoo.exe C:\Program Files\Wanadoo\ComComp.exe C:\PROGRA~1\Wanadoo\Toaster.exe C:\PROGRA~1\Wanadoo\Inactivity.exe C:\PROGRA~1\Wanadoo\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\Wanadoo\Watch.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: CleanUpACLService - Unknown owner - C:\Program Files\CleanUp\CleanUpACLServ.exe (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe Merci à vous tous.
-
J'ai installé Kerio personnel Firewall mais j'ai l'impression que c'est simplement une version d'évaluation qui se désactivera après 30 jours. Dois-je déjà le remplacer ? J'ai Avast pour antivirus, je crois que Zone Alarm est incompatible avec ce dernier, quel autre firewall puis-je utiliser ?