

karlomat
Membres-
Compteur de contenus
29 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par karlomat
-
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Bonjour, Je viens de faire le scan et le nettoyage avec advanced system care free. J'ai redémarré le PC. Sans effets ! L'écoute sur Deezer reste impossible. Le visionnage de vidéo sur you tube est très haché même en réglant le paramétrage vidéo. L'UC est très sollicitée C'est rageant... -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Bonjour, Je viens de lancer la vérif du DD Voici une copie écran du rapport de vérif Bien cordialement, Voici le rapport ! ---------------------------------------------------------------------------- CrystalDiskInfo 6.2.1 © 2008-2014 hiyohiyo Crystal Dew World : http://crystalmark.info/ ---------------------------------------------------------------------------- OS : Windows XP Home Edition SP3 [5.1 Build 2600] (x86) Date : 2014/10/04 18:46:44 -- Controller Map ---------------------------------------------------------- + NVIDIA NForce MCP2 IDE Controller [ATA] + Canal IDE principal (0) - LITE-ON DVDRW SOHW-812S + Canal IDE secondaire (1) - HDS722516VLAT20 -- Disk List --------------------------------------------------------------- (1) HDS722516VLAT20 : 164,6 GB [0/1/0, pd1] ---------------------------------------------------------------------------- (1) HDS722516VLAT20 ---------------------------------------------------------------------------- Model : HDS722516VLAT20 Firmware : V34OA60A Serial Number : VNR4GMC4GAU6VM Disk Size : 164,6 GB (8,4/137,4/164,6/164,6) Buffer Size : 1794 KB Queue Depth : 32 # of Sectors : 321672960 Rotation Rate : Inconnu Interface : Parallel ATA Major Version : ATA/ATAPI-6 Minor Version : ATA/ATAPI-6 T13 1410D version 3a Transfer Mode : UDMA/100 | UDMA/100 Power On Hours : 22531 heures Power On Count : 2944 x Temperature : 35 C (95 F) Health Status : Correct Features : S.M.A.R.T., APM, AAM, 48bit LBA APM Level : 0000h [OFF] AAM Level : 80FEh [OFF] -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 01 100 100 _60 000000000000 Taux Erreur en Lecture 02 100 100 _50 000000000000 Performance général sortie disque 03 107 107 _24 000501180118 Temps moyen mise en rotation 04 100 100 __0 000000000CCD Décompte des cycles de mise en rotation 05 100 100 __5 000000000000 Nombre de secteurs réalloués 07 100 100 _67 000000000000 Taux d'erreurs d'accès des têtes 08 100 100 _20 000000000000 Performance moyenne des opérations d'accès des têtes 09 _97 _97 __0 000000005803 Heures de Fonctionnement 0A 100 100 _60 000000000000 Nombre d'essais de relancement de la rotation 0C 100 100 __0 000000000B80 Nombre total de cycles marche/arrêt du disque dur C0 _97 _97 _50 000000000FC2 Nombre de fois que l'armature magnétique a été rétractée automatiquement suite à une coupure secteur C1 _97 _97 _50 000000000FC2 Nombre de fois que la tête a changé de position C2 157 157 __0 002E00080023 Température interne actuelle. C4 100 100 __0 000000000000 Nombre d'opérations de réallocation (remap) C5 100 100 __0 000000000000 Nombre de secteurs "instables" C6 100 100 __0 000000000000 Nombre total d'erreurs incorrigibles d'un secteur C7 200 200 __0 000000000000 Nombre d'erreurs dans le transfert de données via le câble d'interface -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 045A 3FFF 37C8 0010 0000 0000 003F 0000 0000 0000 .Z?.7........?...... 010: 2020 2020 2020 564E 5234 474D 4334 4741 5536 564D VNR4GMC4GAU6VM 020: 0003 0E04 0034 5633 344F 4136 3041 4844 5337 3232 .....4V34OA60AHDS722 030: 3531 3656 4C41 5432 3020 2020 2020 2020 2020 2020 516VLAT20 040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00 ..../. 050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110 @.......?....?...... 060: FFFF 0FFF 0000 0007 0003 0078 0078 00F0 0078 0000 ...........x.x...x.. 070: 0000 0000 0000 0000 0000 001F 0000 0000 0000 0000 .................... 080: 007C 0019 74EB 7FEA 4023 74E9 3C02 4023 203F 002C .|..t...@#t.<.@# ?., 090: 0000 0000 FFFE 600B 80FE 0000 0000 0000 0000 0000 ......`............. 100: 5700 132C 0000 0000 0000 0000 0000 0000 0000 0000 W..,................ 110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 120: 0000 0000 0000 0000 0000 0000 0000 0000 0009 000B .................... 130: 0000 0000 2982 0CB1 FEA4 0001 43FC 0000 0000 0000 ....).......C....... 140: 0000 07F7 0E04 0E04 0200 0280 3F7F 00C0 0040 41FC ............?....@A. 150: 8000 0000 344F 4136 0000 8014 0000 0000 0000 0000 ....4OA6............ 160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 .................... 250: 0000 0000 0000 0000 0000 ACA5 ............ -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 10 00 01 0B 00 64 64 00 00 00 00 00 00 00 02 05 .....dd......... 010: 00 64 64 00 00 00 00 00 00 00 03 07 00 6B 6B 18 .dd..........kk. 020: 01 18 01 05 00 00 04 12 00 64 64 CD 0C 00 00 00 .........dd..... 030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B ...3.dd......... 040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00 .dd..........dd. 050: 00 00 00 00 00 00 09 12 00 61 61 03 58 00 00 00 .........aa.X... 060: 00 00 0A 13 00 64 64 00 00 00 00 00 00 00 0C 32 .....dd........2 070: 00 64 64 80 0B 00 00 00 00 00 C0 32 00 61 61 C2 .dd........2.aa. 080: 0F 00 00 00 00 00 C1 12 00 61 61 C2 0F 00 00 00 .........aa..... 090: 00 00 C2 02 00 9D 9D 23 00 08 00 2E 00 00 C4 32 .......#.......2 0A0: 00 64 64 00 00 00 00 00 00 00 C5 22 00 64 64 00 .dd........".dd. 0B0: 00 00 00 00 00 00 C6 08 00 64 64 00 00 00 00 00 .........dd..... 0C0: 00 00 C7 0A 00 C8 C8 00 00 00 00 00 00 00 00 00 ................ 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 160: 00 00 00 00 00 00 00 00 00 00 00 00 01 0E 01 1B ................ 170: 03 00 01 00 01 3C 00 00 00 00 00 00 00 00 00 00 .....<.......... 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 ................ -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 10 00 01 3C 00 00 00 00 00 00 00 00 00 00 02 32 ...<...........2 010: 00 00 00 00 00 00 00 00 00 00 03 18 00 00 00 00 ................ 020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 ................ 030: 00 00 05 05 00 00 00 00 00 00 00 00 00 00 07 43 ...............C 040: 00 00 00 00 00 00 00 00 00 00 08 14 00 00 00 00 ................ 050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00 ................ 060: 00 00 0A 3C 00 00 00 00 00 00 00 00 00 00 0C 00 ...<............ 070: 00 00 00 00 00 00 00 00 00 00 C0 32 00 00 00 00 ...........2.... 080: 00 00 00 00 00 00 C1 32 00 00 00 00 00 00 00 00 .......2........ 090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00 ................ 0A0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00 ................ 0B0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00 ................ 0C0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 ................ -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Voici le lien speccy http://speccy.piriform.com/results/o0GcRSmHGzs5ddD2IAJtobS -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Bonjour, Je n'ai pas pu télécharger le logiciel de vérif des DD Kaspersky a bloqué le téléchargement Par contre, j'ai activé speccy et ai enregistré une photo -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Bonjour Je reviens aux affaires après une longue absence ! J'ai téléchargé Process Explorer mais quand je souhaite le lancer j'ai un message d'erreur "Sysinternals Process Exolorer a rencontré un problème ..." Cordialement, -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
je viens de redémarrer comme indiqué. Que dois-je faire ensuite ? Le pb indiqué initialement persiste... Merci -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Bonjour, Lien vers rapport ZHPFix http://cjoint.com/confirm.php?cjoint=3GEnZ3JjrBV Lien vers rapport AdwCleaner http://cjoint.com/confirm.php?cjoint=3GEn1DG8wAf Mon C: est saturé mais le D: l'est autant ! Cela influe-t-il sur mon pb de lenteur ? Récemment installé, MBAM se lance maintenant à chaque démarrage ce qui consomme énormément de ressources comme firefox et Kaspersky... Cordialement, -
Lenteur PC – UC utilisée au maximum
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Bonjour, Ci-joint vers le rapport ZHP http://cjoint.com/data3/3GDvdM4C5i6.htm et voici le résumé système du rapport MSinfo32 Système d'exploitation Microsoft Windows XP Édition familiale Version 5.1.2600 Service Pack 3 Nu 2600 Éditeur Microsoft Corporation Ordinateur LG-YTDTGOXQTUDM Fabricant NVIDIA Modèle AWRDACPI Type PC à base X86 Processeur x86 Family 6 Model 10 Stepping 0 AuthenticAMD ~1829 Mhz Version du BIOS/Date Phoenix Technologies, LTD 6.00 PG, 07/11/2003 Version SMBIOS 2.3 Répertoire Windows C:\WINDOWS Répertoire système C:\WINDOWS\system32 Périphérique de démarrage \Device\HarddiskVolume1 Option régionale France Couche d'abstraction matérielle Version = "5.1.2600.5512 (xpsp.080413-2111)" Utilisateur LG-YTDTGOXQTUDM\Karine & Loïc Fuseaux horaires Paris, Madrid (heure d'été) Mémoire physique totale 1 536,00 Mo Mémoire physique disponible 673,65 Mo Mémoire virtuelle totale 2,00 Go Mémoire virtuelle disponible 1,95 Go Espace pour le fichier d'échange 2,85 Go Fichier d'échange C:\pagefile.sys -
Bonjour, Bonjour, Depuis quelque temps, j'ai des soucis de lenteur sur mon vieux PC (10 ans) sous Windows XP. Dès que je vais sur Internet, l'UC vire vite au 100. Le chargement des PDF est devenu très long ! L'écoute de la musique sur Deezer est hachée donc impossible et idem pour les vidéos sur YouTube dont le visionnage est lui aussi devenu impossible. Je dois me cantonner aux activités bureautiques classiques ou un surf sur Internet sans trop solliciter la bête ! Dois-je changer l'ordinateur ? Comment y remédier ? Voici le rapport MBAM demandé http://forum.zebulon.fr/lenteur-pc-uc-utilisee-au-maximum-t208217.html Merci à vous. Karlomat Malwarebytes Anti-Malware www.malwarebytes.org Date de l'examen: 29/07/2014 Heure de l'examen: 17:15:29 Fichier journal: Administrateur: Oui Version: 2.00.2.1012 Base de données Malveillants: v2014.07.29.04 Base de données Rootkits: v2014.07.17.01 Licence: Essai Protection contre les malveillants: Activé(e) Protection contre les sites Web malveillants: Activé(e) Self-protection: Désactivé(e) Système d'exploitation: Windows XP Service Pack 3 Processeur: x86 Système de fichiers: NTFS Utilisateur: Karine & Loïc Type d'examen: Examen "Menaces" Résultat: Terminé Objets analysés: 265457 Temps écoulé: 37 min, 54 sec Mémoire: Activé(e) Démarrage: Activé(e) Système de fichiers: Activé(e) Archives: Activé(e) Rootkits: Activé(e) Heuristics: Activé(e) PUP: Avertir PUM: Activé(e) Processus: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Clés du Registre: 3 PUP.Optional.Babylon.A, HKU\S-1-5-21-1993962763-507921405-682003330-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Mis en quarantaine, [0d94336d700bfe38691ae27bea1846ba], PUP.Optional.DataMangr.A, HKLM\SOFTWARE\DataMngr, Mis en quarantaine, [0d94ccd42a51d95dce02e6f30df552ae], PUP.Optional.TornTV.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\bicnnkjibmphdeigoodpjlcklcnaobdj, Mis en quarantaine, [326f57495229b5815434598fb34f0000], Valeurs du Registre: 0 (No malicious items detected) Données du Registre: 0 (No malicious items detected) Dossiers: 0 (No malicious items detected) Fichiers: 0 (No malicious items detected) Secteurs physiques: 0 (No malicious items detected) (end)
-
Bonjour, Depuis quelque temps, j'ai des soucis de lenteur sur mon vieux PC (10 ans) sous Windows XP. Dès que je vais sur Internet, l'UC vire vite au 100. Le chargement des PDF est devenu très long ! L'écoute de la musique sur Deezer est hachée donc impossible et idem pour les vidéos sur YouTube dont le visionnage est lui aussi devenu impossible. Je dois me cantonner aux activités bureautiques classiques ou un surf sur Internet sans trop solliciter la bête ! Dois-je changer l'ordinateur ? Comment y remédier ? Merci de vos bons conseils. karlomat
-
Supprimer les messages à la fois sur Webmail et Thunderbird
karlomat a répondu à un(e) sujet de karlomat dans Internet & Réseaux
Non, quand je ne suis pas chez moi le Thunderbird est inactif. Ce que je souhaite simplement, c'est pouvoir supprimer à partir du webmail les messages sans avoir à les resupprimer une 2e fois quand je rentre chez moi et que je me connecte à Thunderbird. Je pense qu'il doit y avoir un paramètrage de ma messagerie (à partir de Thunderbird ou de Webmail ?). Cdt, -
Supprimer les messages à la fois sur Webmail et Thunderbird
karlomat a répondu à un(e) sujet de karlomat dans Internet & Réseaux
up ! up ! -
Supprimer les messages à la fois sur Webmail et Thunderbird
karlomat a répondu à un(e) sujet de karlomat dans Internet & Réseaux
Bonjour, N'y a-t-il pas un paramètrage plus simple de messagerie Thunderbird plutôt que d'installer pop peeper ? Mon souhait est simple : à partir de webmail, supprimer une bonne fois pour toutes les messages. A l'heure actuelle, lorsque je supprime sur webmail, le message tombe quand même sur Thunderbird; du coup, je dois le supprimer une deuxième fois ! Cdt, -
Supprimer les messages à la fois sur Webmail et Thunderbird
karlomat a posté un sujet dans Internet & Réseaux
Bonjour, Comment faire pour supprimer les messages à partir du webamil pour qu'ils soient également supprimés sur Thunderbird ? Quels sont les réglages à faire sur ma messagerie ? J'utilise svt le webmail pour relever mon courrier quand je ne suis pas chez moi et j'aimerais que les messages supprimés (beaucoup de pub !) ne tombent pas à nouveau quand je relève mes messages sur Thunderbird. Merci d'avance. Cdt, -
Merci Notpa, Je vais essayer de désinstaller et réinstaller KAV 2013. Quant à l'autre pb, de quoi s'agit-il ? Il est évoqué le module ntoskrnl.exe (error : kernel_mode_exception_not_handled_m) Cdt, karlomat
-
Bonjour, Mon PC fait tjrs des siennes et les BSoD se succèdent. Apparemment, il y a 2 types de causes : - l'AV kaspersky (j'ai KAV 2013 et je le trouve bien lourd pour mon vieux PC) - le rapport WhoCrashed indique un autre type de pb avec le module ntoskrnl.exe. Qu'est-ce que cela signifie ? J'ai posté le rapport WhoCrashed. Merci de votre aide. karlomat System Information (local) -------------------------------------------------------------------------------- computer name: UNKNOW-9A33YR3L windows version: Windows XP Service Pack 3, 5.1, build: 2600 windows dir: C:\WINDOWS CPU: AuthenticAMD AMD Athlon XP 2500+ AMD586, level: 6 1 logical processors, active mask: 1 RAM: 1610072064 total VM: 2147352576, free: 2065833984 -------------------------------------------------------------------------------- Crash Dump Analysis -------------------------------------------------------------------------------- Crash dump directory: C:\WINDOWS\Minidump Crash dumps are enabled on your computer. On Sat 08/12/2012 18:18:55 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini120912-01.dmp This was probably caused by the following module: klif.sys (klif+0x79AE4) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFF9D62DC90, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\drivers\klif.sys product: Kaspersky™ Anti-Virus ® company: Kaspersky Lab description: Klif Mini-Filter [fre_wnet_x86] Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: klif.sys (Klif Mini-Filter [fre_wnet_x86], Kaspersky Lab). Google query: Kaspersky Lab KERNEL_MODE_EXCEPTION_NOT_HANDLED_M On Sat 08/12/2012 18:18:55 GMT your computer crashed crash dump file: C:\WINDOWS\memory.dmp This was probably caused by the following module: klif.sys (klif+0x79AE4) Bugcheck code: 0x8E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFF9D62DC90, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED file path: C:\WINDOWS\system32\drivers\klif.sys product: Kaspersky™ Anti-Virus ® company: Kaspersky Lab description: Klif Mini-Filter [fre_wnet_x86] Bug check description: This bug check indicates that a kernel-mode application generated an exception that the error handler did not catch. A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: klif.sys (Klif Mini-Filter [fre_wnet_x86], Kaspersky Lab). Google query: Kaspersky Lab KERNEL_MODE_EXCEPTION_NOT_HANDLED On Wed 05/12/2012 16:04:15 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini120512-01.dmp This was probably caused by the following module: klif.sys (klif+0x12ED2) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFF9D9D2B68, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\drivers\klif.sys product: Kaspersky™ Anti-Virus ® company: Kaspersky Lab description: Klif Mini-Filter [fre_wnet_x86] Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: klif.sys (Klif Mini-Filter [fre_wnet_x86], Kaspersky Lab). Google query: Kaspersky Lab KERNEL_MODE_EXCEPTION_NOT_HANDLED_M On Tue 04/12/2012 19:22:09 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini120412-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x20E65) Bugcheck code: 0x1000008E (0xFFFFFFFFC0000005, 0xFFFFFFFF804F7E65, 0xFFFFFFFFB83B4CE0, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sun 25/11/2012 16:34:29 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112512-02.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x8DDDA) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFFF7555C78, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sun 25/11/2012 09:11:55 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112512-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x20E65) Bugcheck code: 0x1000008E (0xFFFFFFFFC0000005, 0xFFFFFFFF804F7E65, 0xFFFFFFFFB58CDCE0, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sat 24/11/2012 08:33:13 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112412-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x8DDDA) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFFAC224C10, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. -------------------------------------------------------------------------------- Conclusion -------------------------------------------------------------------------------- 7 crash dumps have been found and analyzed. A third party driver has been identified to be causing system crashes on your computer. It is strongly suggested that you check for updates for these drivers on their company websites. Click on the links below to search with Google for updates for these drivers: klif.sys (Klif Mini-Filter [fre_wnet_x86], Kaspersky Lab) If no updates for these drivers are available, try searching with Google on the names of these drivers in combination the errors that have been reported for these drivers and include the brand and model name of your computer as well in the query. This often yields interesting results from discussions from users who have been experiencing similar problems. Read the topic general suggestions for troubleshooting system crashes for more information. Note that it's not always possible to state with certainty whether a reported driver is actually responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.
-
Bonjour, je viens de modifier les propriétés système comme recommandé dans le message plus haut. Que dois-je faire maintenant ? Cdt,
-
ok, j'ai mis à jour le driver ATI de ma carte Radeon 9550. j'ai viré les dumps en mémoire pour faire de la place... Quant à Kaspersky (j'ai KAV 2013), je ne sais que faire ? J'ai refait un WhoCrashed en ne conservant que les 3 derniers dumps, voici le résultat : j'ai toujours le même message "kernel mode ..." Merci pour vos avis et conseils. karlomat -------------------------------------------------------------------------------- Welcome to WhoCrashed (HOME EDITION) v 4.01 -------------------------------------------------------------------------------- This program checks for drivers which have been crashing your computer. If your computer has displayed a blue screen of death, suddenly rebooted or shut down then this program will help you find the root cause and possibly a solution. Whenever a computer suddenly reboots without displaying any notice or blue screen of death, the first thing that is often thought about is a hardware failure. In reality, on Windows most crashes are caused by malfunctioning device drivers and kernel modules. In case of a kernel error, many computers do not show a blue screen unless they are configured for this. Instead these systems suddenly reboot without any notice. This program will analyze your crash dumps with the single click of a button. It will tell you what drivers are likely to be responsible for crashing your computer. It will report a conclusion which offers suggestions on how to proceed in any situation while the analysis report will display internet links which will help you further troubleshoot any detected problems. To obtain technical support visit www.resplendence.com/support Click here to check if you have the latest version or if an update is available. Just click the Analyze button for a comprehensible report ... -------------------------------------------------------------------------------- Home Edition Notice -------------------------------------------------------------------------------- This version of WhoCrashed is free for use at home only. If you would like to use this software at work or in a commercial environment you should get the professional edition of WhoCrashed which also allows analysis of crashdumps on remote drives and computers on the network and offers a range of additional features. Click here for more information on the professional edition. Click here to buy the the professional edition of WhoCrashed. -------------------------------------------------------------------------------- System Information (local) -------------------------------------------------------------------------------- computer name: UNKNOW-9A33YR3L windows version: Windows XP Service Pack 3, 5.1, build: 2600 windows dir: C:\WINDOWS CPU: AuthenticAMD AMD Athlon XP 2500+ AMD586, level: 6 1 logical processors, active mask: 1 RAM: 1610072064 total VM: 2147352576, free: 2065838080 -------------------------------------------------------------------------------- Crash Dump Analysis -------------------------------------------------------------------------------- Crash dump directory: C:\WINDOWS\Minidump Crash dumps are enabled on your computer. On Sun 25/11/2012 16:34:29 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112512-02.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x8DDDA) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFFF7555C78, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sun 25/11/2012 09:11:55 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112512-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x20E65) Bugcheck code: 0x1000008E (0xFFFFFFFFC0000005, 0xFFFFFFFF804F7E65, 0xFFFFFFFFB58CDCE0, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sat 24/11/2012 08:33:13 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112412-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x8DDDA) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFFAC224C10, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. -------------------------------------------------------------------------------- Conclusion -------------------------------------------------------------------------------- 3 crash dumps have been found and analyzed. No offending third party drivers have been found. Consider configuring your system to produce a full memory dump for better analysis. Read the topic general suggestions for troubleshooting system crashes for more information. Note that it's not always possible to state with certainty whether a reported driver is actually responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.
-
Bonjour, Je viens d'exécuter WhoCrashed dont je fais suivre le rapport plus bas. Merci d'avance. karlomat System Information (local) -------------------------------------------------------------------------------- computer name: UNKNOW-9A33YR3L windows version: Windows XP Service Pack 3, 5.1, build: 2600 windows dir: C:\WINDOWS CPU: AuthenticAMD AMD Athlon™ XP 2500+ AMD586, level: 6 1 logical processors, active mask: 1 RAM: 1610072064 total VM: 2147352576, free: 2065313792 -------------------------------------------------------------------------------- Crash Dump Analysis -------------------------------------------------------------------------------- Crash dump directory: C:\WINDOWS\Minidump Crash dumps are enabled on your computer. On Sun 25/11/2012 09:11:55 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112512-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x20E65) Bugcheck code: 0x1000008E (0xFFFFFFFFC0000005, 0xFFFFFFFF804F7E65, 0xFFFFFFFFB58CDCE0, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sat 24/11/2012 08:33:13 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini112412-01.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x8DDDA) Bugcheck code: 0x1000008E (0xFFFFFFFFC000001D, 0xFFFFFFFF80564DDA, 0xFFFFFFFFAC224C10, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. On Sat 10/11/2012 15:22:26 GMT your computer crashed crash dump file: C:\WINDOWS\Minidump\Mini111012-02.dmp This was probably caused by the following module: ntoskrnl.exe (nt+0x20E65) Bugcheck code: 0x1000008E (0xFFFFFFFFC0000005, 0xFFFFFFFF804F7E65, 0xFFFFFFFFA8642CE0, 0x0) Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M file path: C:\WINDOWS\system32\ntoskrnl.exe product: Système d'exploitation Microsoft® Windows® company: Microsoft Corporation description: Noyau et système NT Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem. The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time. Edit de Notpa : A fin de faciliter la lecture, j'ai supprimé 12 analyses. Elles sont toutes identiques à celles ci-dessus. -------------------------------------------------------------------------------- Conclusion -------------------------------------------------------------------------------- 143 crash dumps have been found and analyzed. Only 15 are included in this report. 4 third party drivers have been identified to be causing system crashes on your computer. It is strongly suggested that you check for updates for these drivers on their company websites. Click on the links below to search with Google for updates for these drivers: ati2dvag.dll (ATI Radeon WindowsNT Display Driver, ATI Technologies Inc.) klif.sys (Klif Mini-Filter [fre_wnet_x86], Kaspersky Lab) klim5.sys (Kaspersky Lab Intermediate Network Driver, Kaspersky Lab ZAO) kl1.sys (Kaspersky Unified Driver, Kaspersky Lab ZAO) If no updates for these drivers are available, try searching with Google on the names of these drivers in combination the errors that have been reported for these drivers and include the brand and model name of your computer as well in the query. This often yields interesting results from discussions from users who have been experiencing similar problems. Read the topic general suggestions for troubleshooting system crashes for more information. Note that it's not always possible to state with certainty whether a reported driver is actually responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.
-
Bonjour, J'ai un vieux pc de 8 ans qui fonctionne sous XP. Le problème est qu'il plante fréquemment (écran bleu avec stop : 0x0000008E / début de vidage de la mémoire physique) et cela depuis de nombreux mois. J'ai fait un MEMTEST car j'ai autrefois rajouté de la RAM : RAS J'ai mis à jour le pilote de la carte garphique. Je suis un peu désemparé car mes connaissances en informatique sont minimes. Je me suis donc décidé (enfin !) à prendre le taureau par les cornes et à consulter un site de spécialistes comme le votre. J'ai fait un rapport blue screen view. Je ne sais pas si cela peut être utile ? Merci pour votre aide. Bien cordialement,
-
comment se débarrasser d'un trojan ?
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
j'ai pas d'autre PC pour tester la connexion mais actuellement ça fonctionne normalement je suis chez free et en faisant le test de connexion sur le site zebulon, je suis en temps normal à 512 kbs et parfois je descends à moins de 300 voire rien !!! ceci dit, le téléphone fonctionne tjrs donc je pense que le modem n'a rien à voir, n'est ce pas ? est-ce logique ces différences de débit ? qui incriminer le FAI ou france télécom ? en tout cas, merci pour ton coup de main ! ps : si j'ai d'autres soucis du même ordre, quelle procédure relativement simple puis-je mettre en route avant d'"ennuyer" les pros de ce forum ? -
comment se débarrasser d'un trojan ?
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
c bizarre, mais la connexion devient nickel par moment et pourri à d'autres ceci dit voici les rapports demandés Logfile of HijackThis v1.99.1 Scan saved at 15:59:38, on 27/08/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\slserv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0C2.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE C:\Documents and Settings\Karine & Loïc\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0C2.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [storageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKCU\..\RunServices: [Remote Procedure Calls] mswinrpc.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Picture Package Menu.lnk = ? O4 - Global Startup: Picture Package VCD Maker.lnk = ? O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8C2BC549-77F6-466C-9F38-C8450A6CF4D1}: NameServer = 212.27.32.176,212.27.32.177 O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe --------------- C:\WINDOWS\System32\wpa.dbl -->27/08/2006 09:01:37 C:\WINDOWS\System32\CONFIG.NT -->14/08/2006 08:38:02 C:\WINDOWS\System32\MRT.exe -->09/08/2006 21:03:04 C:\WINDOWS\System32\aswBoot.exe -->08/08/2006 18:53:28 C:\WINDOWS\System32\AVASTSS.scr -->05/08/2006 08:18:08 C:\WINDOWS\System32\mshtml.dll -->28/07/2006 13:28:08 C:\WINDOWS\System32\inetcomm.dll -->27/07/2006 15:26:19 C:\WINDOWS\System32\urlmon.dll -->25/07/2006 22:41:01 C:\WINDOWS\System32\hlink.dll -->21/07/2006 10:27:28 C:\WINDOWS\System32\PerfStringBackup.INI -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfh00C.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfh009.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfc00C.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfc009.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\netapi32.dll -->14/07/2006 17:41:05 C:\WINDOWS\System32\hhctrl.ocx -->14/07/2006 17:27:53 C:\WINDOWS\System32\shell32.dll -->13/07/2006 15:36:01 C:\WINDOWS\System32\kernel32.dll -->05/07/2006 12:56:38 C:\WINDOWS\System32\rasadhlp.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\dnsapi.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\wininet.dll -->23/06/2006 13:11:45 C:\WINDOWS\System32\shlwapi.dll -->23/06/2006 13:11:45 C:\WINDOWS\System32\shdocvw.dll -->23/06/2006 13:11:45 C:\WINDOWS\System32\pngfilt.dll -->23/06/2006 13:11:44 C:\WINDOWS\System32\mstime.dll -->23/06/2006 13:11:44 C:\WINDOWS\0.log -->27/08/2006 09:01:30 C:\WINDOWS\bootstat.dat -->27/08/2006 09:01:15 C:\WINDOWS\SchedLgU.Txt -->27/08/2006 09:00:20 C:\WINDOWS\WindowsUpdate.log -->27/08/2006 09:00:12 C:\WINDOWS\win.ini -->26/08/2006 18:08:47 C:\WINDOWS\system.ini -->26/08/2006 18:08:47 C:\WINDOWS\ModemLog_NetoDragon 56K Voice Modem.txt -->14/08/2006 10:46:05 C:\WINDOWS\cdplayer.ini -->03/08/2006 22:33:50 C:\WINDOWS\Mozilla Wallpaper.bmp -->24/07/2006 08:50:08 C:\WINDOWS\mozver.dat -->14/07/2006 15:12:59 C:\WINDOWS\MozillaUninstall.exe -->14/07/2006 15:12:59 C:\WINDOWS\GREUninstall.exe -->14/07/2006 15:12:50 C:\WINDOWS\WEKA.INI -->15/04/2006 19:00:01 C:\WINDOWS\StationRipper.INI -->01/03/2006 22:55:21 C:\WINDOWS\wininit.ini -->04/12/2005 19:44:13 C:\WINDOWS\dla.exe |Sonic Solutions |06/09/2004 18:55:40 C:\WINDOWS\GREUninstall.exe |COMPANY |02/02/2005 22:18:56 C:\WINDOWS\IsUn040c.exe |InstallShield Software Corporation |22/09/2004 17:24:20 C:\WINDOWS\MozillaUninstall.exe |COMPANY |02/02/2005 22:19:02 C:\WINDOWS\sllights.exe |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\slrundll.exe |Smart Link |20/08/2004 01:10:02 C:\WINDOWS\smcfg.exe |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\twunk_16.exe |Twain Working Group |24/04/2003 14:00:00 C:\WINDOWS\twunk_32.exe |Twain Working Group |24/04/2003 14:00:00 C:\WINDOWS\UN16040C.EXE |InstallShield Corporation, Inc. |09/09/2004 21:33:02 C:\WINDOWS\UnGins.exe |COMPANY |29/08/2005 18:23:00 C:\WINDOWS\PCDLIB32.DLL |Eastman Kodak |06/09/2004 18:54:26 C:\WINDOWS\twain.dll |Groupe de travail Twain |24/04/2003 14:00:00 C:\WINDOWS\twain_32.dll |Groupe de travail Twain |24/04/2003 14:00:00 C:\WINDOWS\system32\append.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\aswBoot.exe |COMPANY |07/01/2005 20:13:44 C:\WINDOWS\system32\ati2evxx.exe |COMPANY |02/03/2004 14:29:54 C:\WINDOWS\system32\Ati2mdxx.exe |ATI Technologies, Inc. |03/09/2001 18:24:26 C:\WINDOWS\system32\ati2sgag.exe |COMPANY |20/07/2004 11:37:51 C:\WINDOWS\system32\debug.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\dosx.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\dvdplay.exe |COMPANY |23/08/2001 19:47:34 C:\WINDOWS\system32\edlin.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\exe2bin.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\fastopen.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\ftpupd.exe |COMPANY |07/01/2005 21:27:27 C:\WINDOWS\system32\java.exe |Sun Microsystems, Inc. |17/12/2005 17:25:01 C:\WINDOWS\system32\javaw.exe |Sun Microsystems, Inc. |17/12/2005 17:25:01 C:\WINDOWS\system32\javaws.exe |Sun Microsystems, Inc. |17/12/2005 17:25:01 C:\WINDOWS\system32\mem.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\mscdexnt.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\nlsfunc.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\nvuaudio.exe |NVIDIA |20/07/2004 10:15:15 C:\WINDOWS\system32\nvuenet.exe |NVIDIA |20/07/2004 10:15:26 C:\WINDOWS\system32\nvugart.exe |NVIDIA |20/07/2004 10:15:26 C:\WINDOWS\system32\nvuide.exe |NVIDIA |20/07/2004 11:28:23 C:\WINDOWS\system32\nvumctl.exe |NVIDIA Corporation |20/07/2004 11:28:15 C:\WINDOWS\system32\NVUninst.exe |NVIDIA Corporation |20/07/2004 11:28:51 C:\WINDOWS\system32\nvusmb.exe |NVIDIA Corporation |20/07/2004 11:28:16 C:\WINDOWS\system32\redir.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\SDK0mCORE.exe |COMPANY |07/01/2005 22:59:32 C:\WINDOWS\system32\setver.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\share.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\slrundll.exe |Smart Link |20/08/2004 01:10:02 C:\WINDOWS\system32\slserv.exe |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\system32\usrmlnka.exe |U.S. Robotics Corporation |23/08/2001 19:47:48 C:\WINDOWS\system32\usrprbda.exe |U.S. Robotics Corporation |23/08/2001 19:47:48 C:\WINDOWS\system32\usrshuta.exe |U.S. Robotics Corporation |23/08/2001 19:47:48 C:\WINDOWS\system32\winms.exe |COMPANY |07/01/2005 23:31:10 C:\WINDOWS\system32\ALut.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\amr_cpl.dll |COMPANY |20/07/2004 11:31:38 C:\WINDOWS\system32\amstream.dll |COMPANY |20/07/2004 11:31:49 C:\WINDOWS\system32\ati2cqag.dll |ATI Technologies Inc. |20/08/2004 01:09:19 C:\WINDOWS\system32\ati2dvaa.dll |ATI Technologies Inc. |20/08/2004 01:09:19 C:\WINDOWS\system32\ati2dvag.dll |ATI Technologies Inc. |02/03/2004 14:31:44 C:\WINDOWS\system32\ati2edxx.dll |ATI Technologies, Inc. |02/03/2004 14:30:02 C:\WINDOWS\system32\ati2evxx.dll |COMPANY |02/03/2004 14:29:58 C:\WINDOWS\system32\ati3d1ag.dll |ATI Technologies Inc. |02/03/2004 14:23:30 C:\WINDOWS\system32\ati3d2ag.dll |ATI Technologies Inc. |02/03/2004 14:25:56 C:\WINDOWS\system32\ati3duag.dll |ATI Technologies Inc. |02/03/2004 14:28:50 C:\WINDOWS\system32\ATIDDC.DLL |ATI Technologies Inc. |02/03/2004 14:29:22 C:\WINDOWS\system32\atiiiexx.dll |ATI Technologies Inc. |20/07/2004 11:37:50 C:\WINDOWS\system32\atioglxx.dll |ATI Technologies Inc. |02/03/2004 14:46:58 C:\WINDOWS\system32\atipdlxx.dll |ATI Technologies, Inc. |02/03/2004 14:30:10 C:\WINDOWS\system32\atitvo32.dll |ATI Technologies Inc. |02/03/2004 14:18:28 C:\WINDOWS\system32\ativcoxx.dll |ATI Technologies, Inc. |08/11/2001 13:01:04 C:\WINDOWS\system32\ativtmxx.dll |ATI Technologies Inc. |20/08/2004 01:09:19 C:\WINDOWS\system32\ativvaxx.dll |ATI Technologies Inc. |02/03/2004 14:20:58 C:\WINDOWS\system32\atmfd.dll |Adobe Systems Incorporated |24/04/2003 14:00:00 C:\WINDOWS\system32\atmlib.dll |Adobe Systems |24/04/2003 14:00:00 C:\WINDOWS\system32\cddbcontrol.dll |Gracenote (formerly CDDB, Inc.) |03/01/2003 01:00:00 C:\WINDOWS\system32\cehelper.dll |Sonic Solutions |03/01/2003 01:00:00 C:\WINDOWS\system32\coinst.dll |COMPANY |20/07/2004 11:31:38 C:\WINDOWS\system32\compatui.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\cpuinf32.dll |COMPANY |06/09/2004 18:54:26 C:\WINDOWS\system32\dgrpsetu.dll |Digi International, Inc. |20/07/2004 11:03:05 C:\WINDOWS\system32\dgsetup.dll |Digi International |24/04/2003 14:00:00 C:\WINDOWS\system32\EBPCHP.DLL |SEIKO EPSON CORPORATION |29/08/2004 11:32:00 C:\WINDOWS\system32\EBPMON24.DLL |SEIKO EPSON CORPORATION |29/08/2004 11:32:00 C:\WINDOWS\system32\ECBTEG.DLL |SEIKO EPSON CORPORATION |29/08/2004 11:32:00 C:\WINDOWS\system32\encdec.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\Epcmlib.dll |SEIKO EPSON CORPORATION |29/08/2004 11:33:25 C:\WINDOWS\system32\EqnClass.Dll |Equinox Systems Inc. |20/07/2004 11:03:04 C:\WINDOWS\system32\E_DCINST.DLL |SEIKO EPSON CORP. |29/08/2004 11:32:00 C:\WINDOWS\system32\hsfcisp2.dll |Conexant Systems, Inc. |20/08/2004 01:09:27 C:\WINDOWS\system32\hticons.dll |Hilgraeve, Inc. |20/07/2004 10:05:07 C:\WINDOWS\system32\hypertrm.dll |Hilgraeve, Inc. |17/11/2004 19:57:39 C:\WINDOWS\system32\iacenc.dll |Intel Corporation |08/07/2005 20:36:32 C:\WINDOWS\system32\iccvid.dll |Radius Inc. |24/04/2003 14:00:00 C:\WINDOWS\system32\idecoi.dll |COMPANY |20/07/2004 10:15:28 C:\WINDOWS\system32\ieencode.dll |COMPANY |20/08/2004 01:09:27 C:\WINDOWS\system32\ir32_32.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\ir41_qc.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\ir41_qcx.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\ir50_32.dll |Intel Corporation |20/08/2004 01:09:30 C:\WINDOWS\system32\ir50_qc.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\ir50_qcx.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\isrdbg32.dll |Intel Corporation |12/03/2005 17:10:03 C:\WINDOWS\system32\jgaw400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\jgdw400.dll |America Online |24/04/2003 14:00:00 C:\WINDOWS\system32\jgmd400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\jgpl400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\jgsd400.dll |America Online |24/04/2003 14:00:00 C:\WINDOWS\system32\jgsh400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\lfavi12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LFCMP12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LFFAX12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\lfgif12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\lfmpg12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LFTIF12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\lockout.dll |COMPANY |24/05/2002 01:00:00 C:\WINDOWS\system32\lockres.dll |COMPANY |24/05/2002 01:00:00 C:\WINDOWS\system32\LTDIS12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTEFX12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTFIL12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTIMG12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTKRN12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTTWN12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\Ltwvc12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\mdmxsdk.dll |Conexant |20/08/2004 01:09:30 C:\WINDOWS\system32\mdwmdmsp.dll |RioPort |23/08/2001 19:47:06 C:\WINDOWS\system32\mohinstall.dll |COMPANY |22/09/2004 17:24:56 C:\WINDOWS\system32\mplaa6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplam6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplapx.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplaw7.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplva6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplvm6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplvpx.dll |Ligos Corporation |06/09/2004 18:54:27 C:\WINDOWS\system32\mplvw7.dll |Ligos Corporation |06/09/2004 18:54:27 C:\WINDOWS\system32\msdmo.dll |COMPANY |20/07/2004 11:31:51 C:\WINDOWS\system32\msencode.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\MSRTEDIT.DLL |COMPANY |22/01/1999 20:46:58 C:\WINDOWS\system32\msvcp61.dll |Sample Corporation |06/04/2004 21:32:46 C:\WINDOWS\system32\mtxparhd.dll |Matrox Graphics Inc. |20/08/2004 01:09:35 C:\WINDOWS\system32\nv4_disp.dll |NVIDIA Corporation |20/08/2004 01:09:36 C:\WINDOWS\system32\nvack.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\nvasio.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\nvopenal.dll |NVIDIA Corporation |20/07/2004 10:15:15 C:\WINDOWS\system32\Oemdspif.dll |ATI Technologies, Inc. |02/03/2004 14:30:06 C:\WINDOWS\system32\OpenAL32.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\paqsp.dll |COMPANY |23/08/2001 19:47:16 C:\WINDOWS\system32\pncrt.dll |Real Networks, Inc |27/12/2005 09:46:58 C:\WINDOWS\system32\pndx5016.dll |RealNetworks, Inc. |27/12/2005 09:47:00 C:\WINDOWS\system32\pndx5032.dll |RealNetworks, Inc. |27/12/2005 09:47:00 C:\WINDOWS\system32\psisdecd.dll |COMPANY |20/07/2004 11:31:53 C:\WINDOWS\system32\px.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\pxdrv.dll |Sonic Solutions |21/02/2003 01:00:00 C:\WINDOWS\system32\pxmas.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\pxwave.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\pxwma.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\qedwipes.dll |COMPANY |20/07/2004 11:31:51 C:\WINDOWS\system32\rmoc3260.dll |RealNetworks, Inc. |27/12/2005 09:47:06 C:\WINDOWS\system32\s3gnb.dll |S3 Graphics, Inc. |20/08/2004 01:09:39 C:\WINDOWS\system32\sbe.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\slbcsp.dll |Schlumberger Technology Corporation |24/04/2003 14:00:00 C:\WINDOWS\system32\slbiop.dll |Schlumberger Technology Corporation |24/04/2003 14:00:00 C:\WINDOWS\system32\slbrccsp.dll |Schlumberger Technology Corporation |24/04/2003 14:00:00 C:\WINDOWS\system32\slcoinst.dll |Smart Link |20/08/2004 01:09:41 C:\WINDOWS\system32\slextspk.dll |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\system32\slgen.dll |Smart Link |20/08/2004 01:09:41 C:\WINDOWS\system32\SONYHCY.DLL |Sony Corporation |11/08/2006 09:49:31 C:\WINDOWS\system32\spnike.dll |S3/Diamond Multimedia |23/08/2001 19:47:18 C:\WINDOWS\system32\sprio600.dll |S3/Diamond Multimedia |23/08/2001 19:47:18 C:\WINDOWS\system32\sprio800.dll |S3/Diamond Multimedia |23/08/2001 19:47:18 C:\WINDOWS\system32\spxcoins.dll |Perle Systems Ltd. |12/03/2005 17:01:46 C:\WINDOWS\system32\tfswapi.dll |Sonic Solutions |06/09/2004 18:55:40 C:\WINDOWS\system32\tsd32.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\TWAIN32d.dll |COMPANY |14/09/1998 21:43:16 C:\WINDOWS\system32\umloader.dll |Sonic Solutions |13/02/2003 01:01:00 C:\WINDOWS\system32\usrcntra.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrcoina.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrdpa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrdtea.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrfaxa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrlbva.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrrtosa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrsdpia.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrsvpia.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrv42a.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrv80a.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrvoica.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrvpa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\VXBLOCK.dll |Sonic Solutions |18/08/2003 02:00:00 C:\WINDOWS\system32\vxdmdcdlg.dll |Sonic Solutions |13/03/2003 16:10:24 C:\WINDOWS\system32\vxpsapi.dll |COMPANY |14/08/2001 11:47:08 C:\WINDOWS\system32\win87em.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\WooDial2000.dll |France Télécom R&D |29/09/2004 21:12:18 C:\WINDOWS\system32\xmlparse.dll |COMPANY |07/01/2005 22:03:09 C:\WINDOWS\system32\xmltok.dll |COMPANY |07/01/2005 22:03:09 Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\WINDOWS\system32 20/08/2004 01:09 6 144 csrss.exe 1 fichier(s) 6 144 octets 0 Rép(s) 10 545 905 664 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\WINDOWS\Downloaded Program Files 27/08/2006 09:17 <REP> . 27/08/2006 09:17 <REP> .. 12/03/2005 17:10 65 desktop.ini 23/02/2005 18:57 <REP> rave 18/04/2003 21:11 6 638 ravllio.vxd 04/09/2003 16:00 200 704 ravonline.dll 04/09/2003 16:02 583 ravonline.inf 04/09/2003 15:33 167 936 ravscan.dll 04/09/2003 15:34 290 816 ravupdt.dll 05/03/2003 21:27 381 ravupdt.ini 29/05/2002 23:12 9 488 sporder.dll 23/02/2005 18:57 11 358 update.log 30/06/2003 23:41 1 689 WMV9VCM.inf 10 fichier(s) 689 658 octets Répertoire de C:\WINDOWS\Downloaded Program Files\rave 23/02/2005 18:57 <REP> . 23/02/2005 18:57 <REP> .. 17/08/2003 19:24 298 414 avirexe.vdm 17/06/2003 19:31 119 120 avirscr.vdm 06/05/2003 18:51 98 350 base.vdm 21/02/2005 19:25 395 678 daily.vdm 21/02/2005 19:25 176 162 daily.vdt 25/02/2003 17:54 19 135 filters.vdm 24/06/2003 10:34 49 628 kernel.vdk 30/10/2002 18:35 265 keyring.vdk 25/02/2003 17:54 1 956 mapi_vdm.vdm 30/10/2002 18:35 265 modules.vdk 21/02/2005 17:14 1 466 329 rav8def.vdm 06/12/2004 21:18 22 482 rufs.vdm 04/06/2003 18:24 64 967 rufsplg.vdm 06/05/2003 14:01 112 783 unarch.vdm 24/06/2003 10:34 45 209 unmail.vdm 07/05/2004 13:50 158 229 unpack.vdm 16 fichier(s) 3 028 972 octets Total des fichiers listés : 26 fichier(s) 3 718 630 octets 5 Rép(s) 10 545 905 664 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\Program Files 27/08/2006 09:16 <REP> . 27/08/2006 09:16 <REP> .. 13/03/2005 13:02 <REP> 7-Zip 03/09/2005 15:41 <REP> Adobe 21/05/2006 12:13 <REP> Ahead 09/01/2005 23:04 <REP> Alwil Software 06/09/2004 18:53 <REP> ArcSoft 20/07/2004 11:38 <REP> ATI Technologies 14/08/2006 14:26 <REP> Championship Manager 3 29/08/2004 11:33 <REP> Common Files 20/07/2004 10:05 <REP> ComPlus Applications 29/08/2004 12:25 <REP> CyberLink 02/04/2005 10:39 <REP> DeskAd Service 29/08/2004 11:33 <REP> EPSON 27/08/2006 09:16 <REP> ewido anti-spyware 4.0 11/08/2006 09:48 <REP> Fichiers communs 15/03/2006 17:16 <REP> Google 15/08/2006 13:42 <REP> Internet Explorer 17/12/2005 17:25 <REP> Java 12/03/2005 13:28 <REP> Kerio 28/02/2005 22:14 <REP> Lavalys 13/06/2005 21:58 <REP> Lavasoft 08/07/2006 09:43 <REP> LimeWire 15/02/2005 15:32 <REP> Messenger 30/08/2004 18:55 <REP> microsoft frontpage 08/07/2005 20:31 <REP> Microsoft Games 06/10/2004 16:46 <REP> Microsoft Office 06/10/2004 16:46 <REP> Microsoft Visual Studio 06/10/2004 16:46 <REP> Microsoft Works 06/10/2004 16:47 <REP> Microsoft.NET 13/03/2005 19:18 <REP> Movie Maker 17/01/2005 22:08 <REP> mozilla.org 28/03/2005 20:00 <REP> MSN 20/07/2004 10:05 <REP> MSN Gaming Zone 03/07/2006 14:08 <REP> NBPROF 13/03/2005 19:18 <REP> NetMeeting 27/04/2006 09:25 <REP> Outlook Express 11/08/2006 09:51 <REP> PIXELA 01/03/2006 22:52 <REP> Ratajik Software 20/07/2006 15:55 <REP> Real 27/02/2005 21:33 <REP> RegCleaner 20/07/2006 15:54 774 144 RngInterstitial.dll 20/07/2004 10:06 <REP> Services en ligne 04/12/2005 19:44 <REP> Sonic 11/08/2006 09:49 <REP> Sony Corporation 12/12/2005 13:04 <REP> Spybot - Search & Destroy 03/07/2006 20:18 <REP> Téléchargement PHOTOWAYS 16/02/2006 14:22 <REP> Windows Media Player 13/03/2005 19:18 <REP> Windows NT 20/07/2004 10:07 <REP> xerox 27/08/2006 09:17 <REP> Yahoo! 20/07/2006 15:43 <REP> Zylom Games 1 fichier(s) 774 144 octets 51 Rép(s) 10 545 905 664 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\Program Files\fichiers communs 11/08/2006 09:48 <REP> . 11/08/2006 09:48 <REP> .. 03/09/2005 15:31 <REP> Adobe 06/10/2004 16:46 <REP> DESIGNER 15/03/2006 17:16 <REP> InstallShield 15/02/2005 17:21 <REP> Java 06/10/2004 16:47 <REP> Microsoft Shared 02/02/2005 22:18 <REP> mozilla.org 20/07/2004 10:06 <REP> MSSoap 11/08/2006 09:48 <REP> muvee Technologies 20/07/2004 11:03 <REP> ODBC 20/07/2006 15:54 <REP> Real 20/07/2004 10:06 <REP> Services 05/03/2005 12:22 <REP> Softwin 06/09/2004 18:55 <REP> Sonic 20/07/2004 11:03 <REP> SpeechEngines 27/04/2006 09:25 <REP> System 27/12/2005 09:47 <REP> xing shared 0 fichier(s) 0 octets 18 Rép(s) 10 545 905 664 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\ 31/10/2005 17:56 700 416 StubInstaller.exe 1 fichier(s) 700 416 octets 0 Rép(s) 10 545 905 664 octets libres c:\Documents and Settings\Karine & Loïc\.limewire\.NetworkShare\LimeWireWin4.12.4.exe c:\Documents and Settings\Karine & Loïc\Application Data\Microsoft\Installer\{532EFE70-19BC-4F0F-8F50-D5F15C243133}\NewShortcut1_8315396A5EA1419DBEC4978284BDF556.exe c:\Documents and Settings\Karine & Loïc\Application Data\Microsoft\Installer\{8DD86BF7-28B3-4CE9-88AE-E6EC790CAECA}\NewShortcut1_8315396A5EA1419DBEC4978284BDF556.exe c:\Documents and Settings\Karine & Loïc\Bureau\balistic.exe c:\Documents and Settings\Karine & Loïc\Bureau\HijackThis.exe c:\Documents and Settings\Karine & Loïc\Bureau\Tetris.exe c:\Documents and Settings\Karine & Loïc\Bureau\chercher\chercher\FilesInfoCmd.exe c:\Documents and Settings\Karine & Loïc\Bureau\chercher\chercher\LFiles.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\GLB1A2B.EXE c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\~nsu.tmp\Au_.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Karine\Dossiers Karine\Merry_Xmas.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Karine\Dossiers Karine\cours de 5°\5° Lazar SEQU I\setup.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\cm304e.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\CMScout.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\condom.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\Strip.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Divers\setup.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\avast-_avast_4.6.603_francais_anglais_11113.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\everesthome151.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\kerio-personal-firewall_kerio_personal_firewall_4.1.2_francais_11071.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\stinger.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\X files\Masturbation.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\X files\Pêcheur.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Mes images\Léa et les copains de Mathilde\LimeWireWin.exe c:\Documents and Settings\All Users\Application Data\Microsoft\USMT\iconlib.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\MyZylomExtension\MyZylomExtension.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\ZylomDeluxeInstaller\ZylomDeluxeInstaller.dll c:\Documents and Settings\Karine & Loïc\Application Data\Identities\{000HQ7FF-AD7A-3FG1-FP6A-215DM52C4VUV}\xmlparse.dll Vérifications de quelques clefs Recherche de clefs EGDACCESS HKLM\SOFTWARE\Microsoft\Windows\explorer\SharedTaskScheduler ---------------------- GMER 1.0.10.10122 - http://www.gmer.net Rootkit 2006-08-27 16:15:11 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.10 ---- SSDT \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ZwOpenProcess SSDT \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ZwTerminateProcess ---- Devices - GMER 1.0.10 ---- Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_DEVICE_CONTROL [AA080175] tfsnifs.sys Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_DEVICE_CONTROL [AA080175] tfsnifs.sys Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_DEVICE_CONTROL [AA080175] tfsnifs.sys Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_DEVICE_CONTROL [AA080175] tfsnifs.sys Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_DEVICE_CONTROL [AA080175] tfsnifs.sys Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL [AA0802ED] tfsnifs.sys ---- Files - GMER 1.0.10 ---- File C:\System Volume Information\MountPointManagerRemoteDatabase File C:\System Volume Information\tracking.log File C:\System Volume Information\_restore{332D1542-888D-41CD-9774-9E6295B18D9A} File D:\System Volume Information\MountPointManagerRemoteDatabase File D:\System Volume Information\tracking.log File D:\System Volume Information\_restore{332D1542-888D-41CD-9774-9E6295B18D9A} ---- EOF - GMER 1.0.10 ---- -
comment se débarrasser d'un trojan ?
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
j'ai parlé trop tôt tout à l'heure et j'ai à nouveau des difficultés de connexion internet . mêmes symptomes qu'avant, je suis obligé d'insister plusieurs fois avant d'avoir une connexion et j'ai des deconnexions régulières. dur d'envoyer ce post ! ce matin, pourtant quand j'ai envoyé mon post c'était nickel !! et en +, je viens de virer tous les softs qui ont servis précedemment -
comment se débarrasser d'un trojan ?
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
Merci bcp pour ton aide cela semble marcher mieux ! dernières questions : vais-je continuer à reçevoir des spams ? comment m'en débarasser sinon ? enfin, j'ai une suite mozilla en anglais car je n'ai pas su le mettre en français (navigateur + mail) dont la copie semble dépassée : comment faire la m.a.j. en français de cette suite sans perdre de données (notamment pour les mails) ? -
comment se débarrasser d'un trojan ?
karlomat a répondu à un(e) sujet de karlomat dans Analyses et éradication malwares
voila, les 2 rapports kasperky scan on line + celui de chercher.zip KASPERSKY ON-LINE SCANNER REPORT Saturday, August 26, 2006 10:52:58 PM Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version : 5.0.83.0 Dernière mise à jour de la base antivirus Kaspersky : 26/08/2006 Enregistrements dans la base antivirus Kaspersky : 218559 Paramètres d'analyse Analyser avec la base antivirus suivante étendue Analyser les archives vrai Analyser les bases de messagerie vrai Cible de l'analyse Zones critiques C:\WINDOWS C:\DOCUME~1\KARINE~1\LOCALS~1\Temp\ Statistiques de l'analyse Total d'objets analysés 17233 Nombre de virus trouvés 0 Nombre d'objets infectés 0 / 0 Nombre d'objets suspects 0 Durée de l'analyse 00:10:00 Nom de l'objet infecté Nom du virus Dernière action C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré C:\WINDOWS\Temp\Perflib_Perfdata_56c.dat L'objet est verrouillé ignoré C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré Analyse terminée. C:\WINDOWS\System32\wpa.dbl -->26/08/2006 18:10:15 C:\WINDOWS\System32\CONFIG.NT -->14/08/2006 08:38:02 C:\WINDOWS\System32\MRT.exe -->09/08/2006 21:03:04 C:\WINDOWS\System32\aswBoot.exe -->08/08/2006 18:53:28 C:\WINDOWS\System32\AVASTSS.scr -->05/08/2006 08:18:08 C:\WINDOWS\System32\mshtml.dll -->28/07/2006 13:28:08 C:\WINDOWS\System32\inetcomm.dll -->27/07/2006 15:26:19 C:\WINDOWS\System32\urlmon.dll -->25/07/2006 22:41:01 C:\WINDOWS\System32\hlink.dll -->21/07/2006 10:27:28 C:\WINDOWS\System32\PerfStringBackup.INI -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfh00C.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfh009.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfc00C.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\perfc009.dat -->16/07/2006 08:46:54 C:\WINDOWS\System32\netapi32.dll -->14/07/2006 17:41:05 C:\WINDOWS\System32\hhctrl.ocx -->14/07/2006 17:27:53 C:\WINDOWS\System32\shell32.dll -->13/07/2006 15:36:01 C:\WINDOWS\System32\kernel32.dll -->05/07/2006 12:56:38 C:\WINDOWS\System32\rasadhlp.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\dnsapi.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\wininet.dll -->23/06/2006 13:11:45 C:\WINDOWS\System32\shlwapi.dll -->23/06/2006 13:11:45 C:\WINDOWS\System32\shdocvw.dll -->23/06/2006 13:11:45 C:\WINDOWS\System32\pngfilt.dll -->23/06/2006 13:11:44 C:\WINDOWS\System32\mstime.dll -->23/06/2006 13:11:44 C:\WINDOWS\0.log -->26/08/2006 18:10:09 C:\WINDOWS\bootstat.dat -->26/08/2006 18:09:52 C:\WINDOWS\SchedLgU.Txt -->26/08/2006 18:08:57 C:\WINDOWS\win.ini -->26/08/2006 18:08:47 C:\WINDOWS\system.ini -->26/08/2006 18:08:47 C:\WINDOWS\WindowsUpdate.log -->26/08/2006 18:07:09 C:\WINDOWS\setupapi.log -->25/08/2006 18:59:03 C:\WINDOWS\wmsetup.log -->25/08/2006 17:19:43 C:\WINDOWS\wiaservc.log -->17/08/2006 22:20:47 C:\WINDOWS\wiadebug.log -->17/08/2006 22:20:47 C:\WINDOWS\setupact.log -->17/08/2006 09:52:46 C:\WINDOWS\tsoc.log -->15/08/2006 13:43:24 C:\WINDOWS\ocmsn.log -->15/08/2006 13:43:24 C:\WINDOWS\ocgen.log -->15/08/2006 13:43:24 C:\WINDOWS\ntdtcsetup.log -->15/08/2006 13:43:24 C:\WINDOWS\dla.exe |Sonic Solutions |06/09/2004 18:55:40 C:\WINDOWS\GREUninstall.exe |COMPANY |02/02/2005 22:18:56 C:\WINDOWS\IsUn040c.exe |InstallShield Software Corporation |22/09/2004 17:24:20 C:\WINDOWS\MozillaUninstall.exe |COMPANY |02/02/2005 22:19:02 C:\WINDOWS\sllights.exe |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\slrundll.exe |Smart Link |20/08/2004 01:10:02 C:\WINDOWS\smcfg.exe |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\twunk_16.exe |Twain Working Group |24/04/2003 14:00:00 C:\WINDOWS\twunk_32.exe |Twain Working Group |24/04/2003 14:00:00 C:\WINDOWS\UN16040C.EXE |InstallShield Corporation, Inc. |09/09/2004 21:33:02 C:\WINDOWS\UnGins.exe |COMPANY |29/08/2005 18:23:00 C:\WINDOWS\PCDLIB32.DLL |Eastman Kodak |06/09/2004 18:54:26 C:\WINDOWS\twain.dll |Groupe de travail Twain |24/04/2003 14:00:00 C:\WINDOWS\twain_32.dll |Groupe de travail Twain |24/04/2003 14:00:00 C:\WINDOWS\system32\append.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\aswBoot.exe |COMPANY |07/01/2005 20:13:44 C:\WINDOWS\system32\ati2evxx.exe |COMPANY |02/03/2004 14:29:54 C:\WINDOWS\system32\Ati2mdxx.exe |ATI Technologies, Inc. |03/09/2001 18:24:26 C:\WINDOWS\system32\ati2sgag.exe |COMPANY |20/07/2004 11:37:51 C:\WINDOWS\system32\debug.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\dosx.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\dvdplay.exe |COMPANY |23/08/2001 19:47:34 C:\WINDOWS\system32\edlin.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\exe2bin.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\fastopen.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\ftpupd.exe |COMPANY |07/01/2005 21:27:27 C:\WINDOWS\system32\java.exe |Sun Microsystems, Inc. |17/12/2005 17:25:01 C:\WINDOWS\system32\javaw.exe |Sun Microsystems, Inc. |17/12/2005 17:25:01 C:\WINDOWS\system32\javaws.exe |Sun Microsystems, Inc. |17/12/2005 17:25:01 C:\WINDOWS\system32\mem.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\mscdexnt.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\nlsfunc.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\nvuaudio.exe |NVIDIA |20/07/2004 10:15:15 C:\WINDOWS\system32\nvuenet.exe |NVIDIA |20/07/2004 10:15:26 C:\WINDOWS\system32\nvugart.exe |NVIDIA |20/07/2004 10:15:26 C:\WINDOWS\system32\nvuide.exe |NVIDIA |20/07/2004 11:28:23 C:\WINDOWS\system32\nvumctl.exe |NVIDIA Corporation |20/07/2004 11:28:15 C:\WINDOWS\system32\NVUninst.exe |NVIDIA Corporation |20/07/2004 11:28:51 C:\WINDOWS\system32\nvusmb.exe |NVIDIA Corporation |20/07/2004 11:28:16 C:\WINDOWS\system32\redir.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\SDK0mCORE.exe |COMPANY |07/01/2005 22:59:32 C:\WINDOWS\system32\setver.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\share.exe |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\slrundll.exe |Smart Link |20/08/2004 01:10:02 C:\WINDOWS\system32\slserv.exe |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\system32\usrmlnka.exe |U.S. Robotics Corporation |23/08/2001 19:47:48 C:\WINDOWS\system32\usrprbda.exe |U.S. Robotics Corporation |23/08/2001 19:47:48 C:\WINDOWS\system32\usrshuta.exe |U.S. Robotics Corporation |23/08/2001 19:47:48 C:\WINDOWS\system32\winms.exe |COMPANY |07/01/2005 23:31:10 C:\WINDOWS\system32\ALut.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\amr_cpl.dll |COMPANY |20/07/2004 11:31:38 C:\WINDOWS\system32\amstream.dll |COMPANY |20/07/2004 11:31:49 C:\WINDOWS\system32\ati2cqag.dll |ATI Technologies Inc. |20/08/2004 01:09:19 C:\WINDOWS\system32\ati2dvaa.dll |ATI Technologies Inc. |20/08/2004 01:09:19 C:\WINDOWS\system32\ati2dvag.dll |ATI Technologies Inc. |02/03/2004 14:31:44 C:\WINDOWS\system32\ati2edxx.dll |ATI Technologies, Inc. |02/03/2004 14:30:02 C:\WINDOWS\system32\ati2evxx.dll |COMPANY |02/03/2004 14:29:58 C:\WINDOWS\system32\ati3d1ag.dll |ATI Technologies Inc. |02/03/2004 14:23:30 C:\WINDOWS\system32\ati3d2ag.dll |ATI Technologies Inc. |02/03/2004 14:25:56 C:\WINDOWS\system32\ati3duag.dll |ATI Technologies Inc. |02/03/2004 14:28:50 C:\WINDOWS\system32\ATIDDC.DLL |ATI Technologies Inc. |02/03/2004 14:29:22 C:\WINDOWS\system32\atiiiexx.dll |ATI Technologies Inc. |20/07/2004 11:37:50 C:\WINDOWS\system32\atioglxx.dll |ATI Technologies Inc. |02/03/2004 14:46:58 C:\WINDOWS\system32\atipdlxx.dll |ATI Technologies, Inc. |02/03/2004 14:30:10 C:\WINDOWS\system32\atitvo32.dll |ATI Technologies Inc. |02/03/2004 14:18:28 C:\WINDOWS\system32\ativcoxx.dll |ATI Technologies, Inc. |08/11/2001 13:01:04 C:\WINDOWS\system32\ativtmxx.dll |ATI Technologies Inc. |20/08/2004 01:09:19 C:\WINDOWS\system32\ativvaxx.dll |ATI Technologies Inc. |02/03/2004 14:20:58 C:\WINDOWS\system32\atmfd.dll |Adobe Systems Incorporated |24/04/2003 14:00:00 C:\WINDOWS\system32\atmlib.dll |Adobe Systems |24/04/2003 14:00:00 C:\WINDOWS\system32\cddbcontrol.dll |Gracenote (formerly CDDB, Inc.) |03/01/2003 01:00:00 C:\WINDOWS\system32\cehelper.dll |Sonic Solutions |03/01/2003 01:00:00 C:\WINDOWS\system32\coinst.dll |COMPANY |20/07/2004 11:31:38 C:\WINDOWS\system32\compatui.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\cpuinf32.dll |COMPANY |06/09/2004 18:54:26 C:\WINDOWS\system32\dgrpsetu.dll |Digi International, Inc. |20/07/2004 11:03:05 C:\WINDOWS\system32\dgsetup.dll |Digi International |24/04/2003 14:00:00 C:\WINDOWS\system32\EBPCHP.DLL |SEIKO EPSON CORPORATION |29/08/2004 11:32:00 C:\WINDOWS\system32\EBPMON24.DLL |SEIKO EPSON CORPORATION |29/08/2004 11:32:00 C:\WINDOWS\system32\ECBTEG.DLL |SEIKO EPSON CORPORATION |29/08/2004 11:32:00 C:\WINDOWS\system32\encdec.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\Epcmlib.dll |SEIKO EPSON CORPORATION |29/08/2004 11:33:25 C:\WINDOWS\system32\EqnClass.Dll |Equinox Systems Inc. |20/07/2004 11:03:04 C:\WINDOWS\system32\E_DCINST.DLL |SEIKO EPSON CORP. |29/08/2004 11:32:00 C:\WINDOWS\system32\hsfcisp2.dll |Conexant Systems, Inc. |20/08/2004 01:09:27 C:\WINDOWS\system32\hticons.dll |Hilgraeve, Inc. |20/07/2004 10:05:07 C:\WINDOWS\system32\hypertrm.dll |Hilgraeve, Inc. |17/11/2004 19:57:39 C:\WINDOWS\system32\iacenc.dll |Intel Corporation |08/07/2005 20:36:32 C:\WINDOWS\system32\iccvid.dll |Radius Inc. |24/04/2003 14:00:00 C:\WINDOWS\system32\idecoi.dll |COMPANY |20/07/2004 10:15:28 C:\WINDOWS\system32\ieencode.dll |COMPANY |20/08/2004 01:09:27 C:\WINDOWS\system32\ir32_32.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\ir41_qc.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\ir41_qcx.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\ir50_32.dll |Intel Corporation |20/08/2004 01:09:30 C:\WINDOWS\system32\ir50_qc.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\ir50_qcx.dll |Intel Corporation. |20/08/2004 01:09:30 C:\WINDOWS\system32\isrdbg32.dll |Intel Corporation |12/03/2005 17:10:03 C:\WINDOWS\system32\jgaw400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\jgdw400.dll |America Online |24/04/2003 14:00:00 C:\WINDOWS\system32\jgmd400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\jgpl400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\jgsd400.dll |America Online |24/04/2003 14:00:00 C:\WINDOWS\system32\jgsh400.dll |Johnson-Grace Company |24/04/2003 14:00:00 C:\WINDOWS\system32\lfavi12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LFCMP12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LFFAX12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\lfgif12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\lfmpg12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LFTIF12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\lockout.dll |COMPANY |24/05/2002 01:00:00 C:\WINDOWS\system32\lockres.dll |COMPANY |24/05/2002 01:00:00 C:\WINDOWS\system32\LTDIS12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTEFX12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTFIL12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTIMG12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTKRN12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\LTTWN12n.DLL |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\Ltwvc12n.dll |LEAD Technologies, Inc. |11/08/2006 09:49:13 C:\WINDOWS\system32\mdmxsdk.dll |Conexant |20/08/2004 01:09:30 C:\WINDOWS\system32\mdwmdmsp.dll |RioPort |23/08/2001 19:47:06 C:\WINDOWS\system32\mohinstall.dll |COMPANY |22/09/2004 17:24:56 C:\WINDOWS\system32\mplaa6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplam6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplapx.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplaw7.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplva6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplvm6.dll |Ligos Corporation |06/09/2004 18:54:26 C:\WINDOWS\system32\mplvpx.dll |Ligos Corporation |06/09/2004 18:54:27 C:\WINDOWS\system32\mplvw7.dll |Ligos Corporation |06/09/2004 18:54:27 C:\WINDOWS\system32\msdmo.dll |COMPANY |20/07/2004 11:31:51 C:\WINDOWS\system32\msencode.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\MSRTEDIT.DLL |COMPANY |22/01/1999 20:46:58 C:\WINDOWS\system32\msvcp61.dll |Sample Corporation |06/04/2004 21:32:46 C:\WINDOWS\system32\mtxparhd.dll |Matrox Graphics Inc. |20/08/2004 01:09:35 C:\WINDOWS\system32\nv4_disp.dll |NVIDIA Corporation |20/08/2004 01:09:36 C:\WINDOWS\system32\nvack.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\nvasio.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\nvopenal.dll |NVIDIA Corporation |20/07/2004 10:15:15 C:\WINDOWS\system32\Oemdspif.dll |ATI Technologies, Inc. |02/03/2004 14:30:06 C:\WINDOWS\system32\OpenAL32.dll |NVIDIA Corporation |20/07/2004 10:15:14 C:\WINDOWS\system32\paqsp.dll |COMPANY |23/08/2001 19:47:16 C:\WINDOWS\system32\pncrt.dll |Real Networks, Inc |27/12/2005 09:46:58 C:\WINDOWS\system32\pndx5016.dll |RealNetworks, Inc. |27/12/2005 09:47:00 C:\WINDOWS\system32\pndx5032.dll |RealNetworks, Inc. |27/12/2005 09:47:00 C:\WINDOWS\system32\psisdecd.dll |COMPANY |20/07/2004 11:31:53 C:\WINDOWS\system32\px.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\pxdrv.dll |Sonic Solutions |21/02/2003 01:00:00 C:\WINDOWS\system32\pxmas.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\pxwave.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\pxwma.dll |Sonic Solutions |06/02/2003 01:01:00 C:\WINDOWS\system32\qedwipes.dll |COMPANY |20/07/2004 11:31:51 C:\WINDOWS\system32\rmoc3260.dll |RealNetworks, Inc. |27/12/2005 09:47:06 C:\WINDOWS\system32\s3gnb.dll |S3 Graphics, Inc. |20/08/2004 01:09:39 C:\WINDOWS\system32\sbe.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\slbcsp.dll |Schlumberger Technology Corporation |24/04/2003 14:00:00 C:\WINDOWS\system32\slbiop.dll |Schlumberger Technology Corporation |24/04/2003 14:00:00 C:\WINDOWS\system32\slbrccsp.dll |Schlumberger Technology Corporation |24/04/2003 14:00:00 C:\WINDOWS\system32\slcoinst.dll |Smart Link |20/08/2004 01:09:41 C:\WINDOWS\system32\slextspk.dll |COMPANY |20/07/2004 11:31:39 C:\WINDOWS\system32\slgen.dll |Smart Link |20/08/2004 01:09:41 C:\WINDOWS\system32\SONYHCY.DLL |Sony Corporation |11/08/2006 09:49:31 C:\WINDOWS\system32\spnike.dll |S3/Diamond Multimedia |23/08/2001 19:47:18 C:\WINDOWS\system32\sprio600.dll |S3/Diamond Multimedia |23/08/2001 19:47:18 C:\WINDOWS\system32\sprio800.dll |S3/Diamond Multimedia |23/08/2001 19:47:18 C:\WINDOWS\system32\spxcoins.dll |Perle Systems Ltd. |12/03/2005 17:01:46 C:\WINDOWS\system32\tfswapi.dll |Sonic Solutions |06/09/2004 18:55:40 C:\WINDOWS\system32\tsd32.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\TWAIN32d.dll |COMPANY |14/09/1998 21:43:16 C:\WINDOWS\system32\umloader.dll |Sonic Solutions |13/02/2003 01:01:00 C:\WINDOWS\system32\usrcntra.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrcoina.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrdpa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrdtea.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrfaxa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrlbva.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrrtosa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrsdpia.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrsvpia.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrv42a.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrv80a.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrvoica.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\usrvpa.dll |U.S. Robotics Corporation |23/08/2001 19:47:20 C:\WINDOWS\system32\VXBLOCK.dll |Sonic Solutions |18/08/2003 02:00:00 C:\WINDOWS\system32\vxdmdcdlg.dll |Sonic Solutions |13/03/2003 16:10:24 C:\WINDOWS\system32\vxpsapi.dll |COMPANY |14/08/2001 11:47:08 C:\WINDOWS\system32\win87em.dll |COMPANY |24/04/2003 14:00:00 C:\WINDOWS\system32\WooDial2000.dll |France Télécom R&D |29/09/2004 21:12:18 C:\WINDOWS\system32\xmlparse.dll |COMPANY |07/01/2005 22:03:09 C:\WINDOWS\system32\xmltok.dll |COMPANY |07/01/2005 22:03:09 Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\WINDOWS\system32 20/08/2004 01:09 6 144 csrss.exe 1 fichier(s) 6 144 octets 0 Rép(s) 8 499 957 760 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\WINDOWS\Downloaded Program Files 25/08/2006 18:59 <REP> . 25/08/2006 18:59 <REP> .. 12/03/2005 17:10 65 desktop.ini 08/08/2006 11:45 576 kavwebscan.inf 23/02/2005 18:57 <REP> rave 18/04/2003 21:11 6 638 ravllio.vxd 04/09/2003 16:00 200 704 ravonline.dll 04/09/2003 16:02 583 ravonline.inf 04/09/2003 15:33 167 936 ravscan.dll 04/09/2003 15:34 290 816 ravupdt.dll 05/03/2003 21:27 381 ravupdt.ini 29/05/2002 23:12 9 488 sporder.dll 23/02/2005 18:57 11 358 update.log 30/06/2003 23:41 1 689 WMV9VCM.inf 11 fichier(s) 690 234 octets Répertoire de C:\WINDOWS\Downloaded Program Files\rave 23/02/2005 18:57 <REP> . 23/02/2005 18:57 <REP> .. 17/08/2003 19:24 298 414 avirexe.vdm 17/06/2003 19:31 119 120 avirscr.vdm 06/05/2003 18:51 98 350 base.vdm 21/02/2005 19:25 395 678 daily.vdm 21/02/2005 19:25 176 162 daily.vdt 25/02/2003 17:54 19 135 filters.vdm 24/06/2003 10:34 49 628 kernel.vdk 30/10/2002 18:35 265 keyring.vdk 25/02/2003 17:54 1 956 mapi_vdm.vdm 30/10/2002 18:35 265 modules.vdk 21/02/2005 17:14 1 466 329 rav8def.vdm 06/12/2004 21:18 22 482 rufs.vdm 04/06/2003 18:24 64 967 rufsplg.vdm 06/05/2003 14:01 112 783 unarch.vdm 24/06/2003 10:34 45 209 unmail.vdm 07/05/2004 13:50 158 229 unpack.vdm 16 fichier(s) 3 028 972 octets Total des fichiers listés : 27 fichier(s) 3 719 206 octets 5 Rép(s) 8 499 957 760 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\Program Files 26/08/2006 16:52 <REP> . 26/08/2006 16:52 <REP> .. 13/03/2005 13:02 <REP> 7-Zip 03/09/2005 15:41 <REP> Adobe 21/05/2006 12:13 <REP> Ahead 09/01/2005 23:04 <REP> Alwil Software 06/09/2004 18:53 <REP> ArcSoft 20/07/2004 11:38 <REP> ATI Technologies 14/08/2006 14:26 <REP> Championship Manager 3 29/08/2004 11:33 <REP> Common Files 20/07/2004 10:05 <REP> ComPlus Applications 29/08/2004 12:25 <REP> CyberLink 02/04/2005 10:39 <REP> DeskAd Service 29/08/2004 11:33 <REP> EPSON 26/08/2006 10:56 <REP> ewido anti-spyware 4.0 11/08/2006 09:48 <REP> Fichiers communs 15/03/2006 17:16 <REP> Google 15/08/2006 13:42 <REP> Internet Explorer 17/12/2005 17:25 <REP> Java 12/03/2005 13:28 <REP> Kerio 28/02/2005 22:14 <REP> Lavalys 13/06/2005 21:58 <REP> Lavasoft 08/07/2006 09:43 <REP> LimeWire 15/02/2005 15:32 <REP> Messenger 30/08/2004 18:55 <REP> microsoft frontpage 08/07/2005 20:31 <REP> Microsoft Games 06/10/2004 16:46 <REP> Microsoft Office 06/10/2004 16:46 <REP> Microsoft Visual Studio 06/10/2004 16:46 <REP> Microsoft Works 06/10/2004 16:47 <REP> Microsoft.NET 13/03/2005 19:18 <REP> Movie Maker 17/01/2005 22:08 <REP> mozilla.org 28/03/2005 20:00 <REP> MSN 20/07/2004 10:05 <REP> MSN Gaming Zone 03/07/2006 14:08 <REP> NBPROF 13/03/2005 19:18 <REP> NetMeeting 27/04/2006 09:25 <REP> Outlook Express 11/08/2006 09:51 <REP> PIXELA 01/03/2006 22:52 <REP> Ratajik Software 20/07/2006 15:55 <REP> Real 27/02/2005 21:33 <REP> RegCleaner 20/07/2006 15:54 774 144 RngInterstitial.dll 20/07/2004 10:06 <REP> Services en ligne 04/12/2005 19:44 <REP> Sonic 11/08/2006 09:49 <REP> Sony Corporation 12/12/2005 13:04 <REP> Spybot - Search & Destroy 03/07/2006 20:18 <REP> Téléchargement PHOTOWAYS 16/02/2006 14:22 <REP> Windows Media Player 13/03/2005 19:18 <REP> Windows NT 20/07/2004 10:07 <REP> xerox 20/07/2006 15:43 <REP> Zylom Games 1 fichier(s) 774 144 octets 50 Rép(s) 8 499 957 760 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\Program Files\fichiers communs 11/08/2006 09:48 <REP> . 11/08/2006 09:48 <REP> .. 03/09/2005 15:31 <REP> Adobe 06/10/2004 16:46 <REP> DESIGNER 15/03/2006 17:16 <REP> InstallShield 15/02/2005 17:21 <REP> Java 06/10/2004 16:47 <REP> Microsoft Shared 02/02/2005 22:18 <REP> mozilla.org 20/07/2004 10:06 <REP> MSSoap 11/08/2006 09:48 <REP> muvee Technologies 20/07/2004 11:03 <REP> ODBC 20/07/2006 15:54 <REP> Real 20/07/2004 10:06 <REP> Services 05/03/2005 12:22 <REP> Softwin 06/09/2004 18:55 <REP> Sonic 20/07/2004 11:03 <REP> SpeechEngines 27/04/2006 09:25 <REP> System 27/12/2005 09:47 <REP> xing shared 0 fichier(s) 0 octets 18 Rép(s) 8 499 957 760 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 6816-A890 Répertoire de C:\ 31/10/2005 17:56 700 416 StubInstaller.exe 1 fichier(s) 700 416 octets 0 Rép(s) 8 499 957 760 octets libres c:\Documents and Settings\Karine & Loïc\.limewire\.NetworkShare\LimeWireWin4.12.4.exe c:\Documents and Settings\Karine & Loïc\Application Data\Microsoft\Installer\{532EFE70-19BC-4F0F-8F50-D5F15C243133}\NewShortcut1_8315396A5EA1419DBEC4978284BDF556.exe c:\Documents and Settings\Karine & Loïc\Application Data\Microsoft\Installer\{8DD86BF7-28B3-4CE9-88AE-E6EC790CAECA}\NewShortcut1_8315396A5EA1419DBEC4978284BDF556.exe c:\Documents and Settings\Karine & Loïc\Bureau\balistic.exe c:\Documents and Settings\Karine & Loïc\Bureau\ewido-setup_4.0.0.172a.exe c:\Documents and Settings\Karine & Loïc\Bureau\HijackThis.exe c:\Documents and Settings\Karine & Loïc\Bureau\Tetris.exe c:\Documents and Settings\Karine & Loïc\Bureau\chercher\chercher\FilesInfoCmd.exe c:\Documents and Settings\Karine & Loïc\Bureau\chercher\chercher\LFiles.exe c:\Documents and Settings\Karine & Loïc\Bureau\clean\clean\pskill.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\AutoRun.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\BootVis.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\eauninstall.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\msnsearch.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\setup_wm.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\.zylominstallertemp1153330601\ZylomGameInstallerTemp.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\.zylominstallertemp1153386696\ZylomGameInstallerTemp.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\.zylominstallertemp1153402998\ZylomGameInstallerTemp.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temp\Répertoire temporaire 2 pour hijackthis.zip\HijackThis.exe c:\Documents and Settings\Karine & Loïc\Local Settings\Temporary Internet Files\Content.IE5\0ZYBQ5IP\kav6.0.0.303fr[1].exe c:\Documents and Settings\Karine & Loïc\Mes documents\Karine\Dossiers Karine\Merry_Xmas.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Karine\Dossiers Karine\cours de 5°\5° Lazar SEQU I\setup.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\cm304e.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\CMScout.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\condom.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Cool files\Strip.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Divers\setup.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\avast-_avast_4.6.603_francais_anglais_11113.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\everesthome151.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\kerio-personal-firewall_kerio_personal_firewall_4.1.2_francais_11071.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\Maintenance informatique\installation softs\stinger.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\X files\Masturbation.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Loïc\X files\Pêcheur.exe c:\Documents and Settings\Karine & Loïc\Mes documents\Mes images\Léa et les copains de Mathilde\LimeWireWin.exe c:\Documents and Settings\All Users\Application Data\Microsoft\USMT\iconlib.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\MyZylomExtension\MyZylomExtension.dll c:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\ZylomDeluxeInstaller\ZylomDeluxeInstaller.dll c:\Documents and Settings\Karine & Loïc\Application Data\Identities\{000HQ7FF-AD7A-3FG1-FP6A-215DM52C4VUV}\xmlparse.dll Vérifications de quelques clefs Recherche de clefs EGDACCESS HKLM\SOFTWARE\Microsoft\Windows\explorer\SharedTaskScheduler