

cestvert
Membres-
Compteur de contenus
42 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par cestvert
-
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Bonjour, Quand j'essaye d'installer Java il me dit: 1)Impossible d’accéder au service Windows Installer. Ceci peut se produire si Windows est en mode sans échec (Ce qui n’est pas le cas ), ou si le programme est mal installé. 2)Quand j’essaye d’installer Windows installer il me dit que je n’ai pas l’autorisation de mettre à jours le Windows XP ! Merci pour ton aide mais y-a-t-il une chance de s'en sortir ? A plus, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
bonjour, je ne dois plus espérer ? Merci, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Salut à toi, Lorsque j'active le bouton "restore policy" de VX2finder il m'offre une fenêtre avec le texte suivant "Windows needs to reboot to complete the repair" et je dis Ok. Il re-démarre mais rien à changer. J'ai essayé à deux reprises . En ce qui concerne notre compagnon cscript.exe il est bien dans C:\windows\system32. Je me suis même permis de contrôler que j'avais ce chemin dans le path des variables systèmes. Est-ce que cela pourrait être utile de mettre SeDebug-Restore.exe dans C:\windows\system32 pour le faire fonctionner ??? Merci encore et j'espère encore, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Bonjour, du délai de réponse mais j'avais tout le monde qui me tombait dessus. Il y a des jours comme ça. Et pis, je vais avoir l'air peut-être con mais j'ai un message quand je lance SeDebug-Restaure qui dit: "\'cscript.exe' n'est pas reconnu en tant que commande interne ou externe .... Please reboot your machine Press any key to exit" Et ce message arrive instantanément .... A plus, Stephan -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Merci pour ta promptitude, désolé pour le temps de ma part avais des trucs urgents à faire. Je vais tout ce que tu dis mais juste cela veut dire quoi redémarre ta machine manuellement ? Voici le rapport diaghelp: DiagHelp version v1.2 - http://www.malekal.com excute le 03.10.2007 à 10:02:29.77 Liste des derniers fichies modifies/crees dans windir\system32 et prefetch C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->03.10.2007 10:02:26 C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->03.10.2007 10:02:26 C:\WINDOWS\prefetch\CIDAEMON.EXE-27AE97A4.pf -->03.10.2007 10:02:20 C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->03.10.2007 09:54:31 C:\WINDOWS\prefetch\FIND.EXE-0EC32F1E.pf -->03.10.2007 09:54:20 C:\WINDOWS\prefetch\SORT.EXE-194AE83C.pf -->03.10.2007 09:48:33 C:\WINDOWS\prefetch\REG.EXE-0D2A95F7.pf -->03.10.2007 09:48:12 C:\WINDOWS\prefetch\KPROCCHECK.EXE-165C46A1.pf -->03.10.2007 09:48:11 C:\WINDOWS\prefetch\REALEVENT.EXE-34F30ACA.pf -->03.10.2007 09:42:49 C:\WINDOWS\prefetch\DEFRAG.EXE-273F131E.pf -->03.10.2007 09:37:48 C:\WINDOWS\System32\drivers\update.sys -->23.04.2007 12:32:54 C:\WINDOWS\System32\drivers\Mpfp.sys -->02.03.2007 14:16:52 C:\WINDOWS\System32\drivers\ntfs.sys -->09.02.2007 13:10:35 C:\WINDOWS\System32\drivers\mfeavfk.sys -->22.12.2006 17:02:40 C:\WINDOWS\System32\drivers\mfesmfk.sys -->22.12.2006 17:02:34 C:\WINDOWS\System32\drivers\mferkdk.sys -->22.12.2006 17:02:34 C:\WINDOWS\System32\drivers\mfehidk.sys -->22.12.2006 17:02:34 C:\WINDOWS\System32\wpa.dbl -->03.10.2007 08:40:54 C:\WINDOWS\System32\Config.MPF -->02.10.2007 17:06:36 C:\WINDOWS\System32\MRT.exe -->03.08.2007 06:34:10 C:\WINDOWS\System32\MicrosoftUpdateCatalogWebControl.dll -->31.07.2007 02:25:54 C:\WINDOWS\System32\wuweb.dll -->30.07.2007 19:19:46 C:\WINDOWS\System32\richtx32.oca -->24.07.2007 14:17:22 C:\WINDOWS\System32\mswinsck.oca -->24.07.2007 14:17:21 C:\WINDOWS\System32\PerfStringBackup.INI -->23.07.2007 16:34:20 C:\WINDOWS\System32\perfh00C.dat -->23.07.2007 16:34:20 C:\WINDOWS\System32\perfh009.dat -->23.07.2007 16:34:20 C:\WINDOWS\System32\perfc00C.dat -->23.07.2007 16:34:20 C:\WINDOWS\System32\perfc009.dat -->23.07.2007 16:34:20 C:\WINDOWS\System32\mshtml.dll -->19.07.2007 08:58:09 C:\WINDOWS\System32\wininet.dll -->27.06.2007 15:24:19 C:\WINDOWS\System32\webcheck.dll -->27.06.2007 15:24:15 C:\WINDOWS\System32\urlmon.dll -->27.06.2007 15:24:14 C:\WINDOWS\System32\url.dll -->27.06.2007 15:24:10 C:\WINDOWS\System32\occache.dll -->27.06.2007 15:24:09 C:\WINDOWS\System32\mstime.dll -->27.06.2007 15:24:09 C:\WINDOWS\System32\msrating.dll -->27.06.2007 15:24:07 C:\WINDOWS\System32\mshtmled.dll -->27.06.2007 15:24:06 C:\WINDOWS\System32\msfeedsbs.dll -->27.06.2007 15:23:32 C:\WINDOWS\System32\msfeeds.dll -->27.06.2007 15:23:32 C:\WINDOWS\System32\jsproxy.dll -->27.06.2007 15:23:31 C:\WINDOWS\System32\inetcpl.cpl -->27.06.2007 15:23:31 C:\WINDOWS.log -->03.10.2007 08:39:48 C:\WINDOWS\bootstat.dat -->03.10.2007 08:39:46 C:\WINDOWS\WindowsUpdate.log -->02.10.2007 17:06:42 C:\WINDOWS\SchedLgU.Txt -->02.10.2007 17:06:42 C:\WINDOWS\ntbtlog.txt -->02.10.2007 14:15:01 C:\WINDOWS\vbaddin.ini -->27.09.2007 16:42:11 C:\WINDOWS\setupapi.log -->25.09.2007 10:14:29 C:\WINDOWS\ODBC.INI -->20.09.2007 14:05:15 C:\WINDOWS\setupact.log -->19.09.2007 10:46:18 C:\WINDOWS\tsc.ini -->14.09.2007 08:36:51 C:\WINDOWS\tsc.ptn -->13.09.2007 15:42:16 C:\WINDOWS\vsapi32.dll -->13.09.2007 15:42:15 C:\WINDOWS\tsc.exe -->13.09.2007 15:42:15 C:\WINDOWS\hcextoutput.dll -->13.09.2007 15:42:15 C:\WINDOWS\VPTNFILE.717 -->13.09.2007 15:42:14 MD5 des fichiers sensibles tcpip.sys b2220c618b42a2212a59d91ebd6fc4b4 ndis.sys 558635d3af1c7546d26067d5d9b6959e null.sys 73c1e1f395918bc2c6dd67af7591a3ad svchost.exe 2979b03d5382a602623c0535b16ab9c0 Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\WINDOWS\system 17.07.2002 16:22 4'672 WOWPOST.EXE 1 fichier(s) 4'672 octets 0 Rép(s) 2'619'756'544 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\WINDOWS\system32 20.08.2004 01:09 6'144 csrss.exe 1 fichier(s) 6'144 octets 0 Rép(s) 2'619'752'448 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\WINDOWS\Downloaded Program Files 25.09.2007 10:13 <REP> . 25.09.2007 10:13 <REP> .. 20.12.2004 12:13 274'432 AnagramLib.dll 02.07.2007 15:44 941'688 asquared.ocx 07.12.2004 17:07 32 bdcore.dll 25.05.2006 01:21 118'784 bdupd.dll 18.05.2006 15:01 517 ContactFinderControl.inf 23.06.2003 04:04 65 desktop.ini 22.03.2007 12:08 1'672 dlc.inf 20.03.2007 10:56 124'456 ftm_en-us.xml 20.03.2007 10:56 5'492 ftm_LanguageList.xml 03.04.2007 17:26 95'656 grTransferCtrl.dll 03.04.2007 17:26 546'216 grTransferMgr.dll 20.03.2007 14:16 1'563 hardwaredetection.inf 25.05.2006 01:21 53'248 ipsupd.dll 25.08.2003 19:12 1'096 iuctl.inf 19.09.2003 16:58 819 kdx.inf 16.03.2005 12:34 7'407 lang.ini 13.02.2006 20:03 367 LegitCheckControl.inf 07.12.2004 17:07 32 libfn.dll 11.05.2006 19:40 2'299 LinkedInContactFinderControl.dat 18.05.2006 15:03 923'432 LinkedInContactFinderControl.dll 14.03.2005 14:38 126 live.ini 20.01.2000 16:25 1'162 Microsoft XML Parser for Java.osd 31.07.2007 02:38 386 MicrosoftUpdateCatalogWebControl.inf 26.05.2005 04:19 293 muweb.inf 01.06.2006 02:57 1'331 oscan8.inf 01.06.2006 02:54 471'040 oscan8.ocx 31.05.2006 04:15 10 oscan81.ocx_x 14.03.2005 14:58 7'073 scanoptions.tsi 27.08.2005 13:30 5'065 swflash.inf 03.04.2007 17:26 460'200 TransferMgr.exe 30.07.2007 19:24 293 wuweb.inf 02.11.2005 18:01 1'777 xscan.inf 02.11.2005 18:07 435'712 xscan53.ocx 33 fichier(s) 4'483'741 octets Total des fichiers listés : 33 fichier(s) 4'483'741 octets 2 Rép(s) 2'619'752'448 octets libres Recherche de rootkit! (Merci S!Ri) Recherche d'infections connues Export des clefs sensibles.. Liste des fichiers en exception sur le pare-feu XP SP2 Export de la clef SharedTaskScheduler exports des policies Export des clefs sensibles.. Rechercher adresses sensibles dans le fichier HOSTS... catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-03 10:02:43 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden services: 0 hidden files: 0 KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg) Error loading kernel support driver! Make sure you are running this as Administrator. KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg) Error loading kernel support driver! Make sure you are running this as Administrator. Liste des programmes installes .NET Compact Framework-based Form Stack Sample 3M CaseMix Expert 3M CaseMix Expert - Swiss v2.4 Standalone 3M Connections Plus Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX Adobe Reader 7.0.9 - Français Adobe® Photoshop® Album Edition Découverte 3.0 AdventureWorksDB Apple Software Update ATI Control Panel ATI Display Driver boutons One-Touch C-Dilla Licence Management System Cisco Systems VPN Client 4.0.3 (D) Common Setup Files (3790.0) Conexant 56K ACLink Modem Conexant AC-Link Audio Core SDK (Windows Server 2003) (3790.0) Correctif pour Windows XP (KB914440) Correctif Windows XP - KB834707 Correctif Windows XP - KB867282 Correctif Windows XP - KB873333 Correctif Windows XP - KB873339 Correctif Windows XP - KB884020 Correctif Windows XP - KB885250 Correctif Windows XP - KB885835 Correctif Windows XP - KB885836 Correctif Windows XP - KB885884 Correctif Windows XP - KB886185 Correctif Windows XP - KB887472 Correctif Windows XP - KB887742 Correctif Windows XP - KB888113 Correctif Windows XP - KB888302 Correctif Windows XP - KB890047 Correctif Windows XP - KB890175 Correctif Windows XP - KB890859 Correctif Windows XP - KB890923 Correctif Windows XP - KB891781 Correctif Windows XP - KB893066 Correctif Windows XP - KB893086 CuteFTP 8 Home DameWare Mini Remote Control DameWareClient Debugging Tools for Windows (3790.0) Developer Resources for Windows Mobile 2003 Second Edition Easy CD Creator 5 Basic Emulator Driver for Visual Studio .NET 2003 Environnement d'exécution Java 2, Standard Edition v1.3.1_10 Expresso Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP Free CD to MP3 Converter GDR 1406 for SQL Server Analysis Services 2005 ENU (KB932557) GDR 1406 for SQL Server Database Services 2005 ENU (KB932557) GDR 1406 for SQL Server Tools and Workstation Components 2005 ENU (KB932557) Google Earth Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer HardwareDetection HijackThis 2.0.2 Hotfix for Windows XP (KB890927) Hotfix for Windows XP (KB909394) Hotfix for Windows XP (KB915865) HP Deskjet Preloaded Printer Drivers HP Software Update HpSdpAppCoreApp HTML Help Workshop Innovasys HelpStudio Lite InterVideo WinDVD Introduction to Visual Basic 2005 iPAQ WebReg iTunes J2SE Development Kit 5.0 Update 11 J2SE Runtime Environment 5.0 Update 11 Java 2 Runtime Environment, SE v1.4.1_01 Java 2 Runtime Environment, SE v1.4.2_08 Java 2 SDK Standard Edition v1.3.1_10 Java 2 SDK, SE v1.4.1_01 Java 2 SDK, SE v1.4.2_08 Java SE Runtime Environment 6 Update 1 Lecteur Windows Media 10 LiveReg (Symantec Corporation) LiveUpdate 1.80 (Symantec Corporation) LUCID version romande avril 2002 Macromedia Shockwave Player McAfee SecurityCenter Microsoft .NET Compact Framework 1.0 SP3 Developer Microsoft .NET Compact Framework 2.0 Microsoft .NET Framework 2.0 Microsoft .NET Framework 2.0 Microsoft ActiveSync 4.0 Microsoft Analysis Services Samples (Updated - SP3) Microsoft Data Access Components KB870669 Microsoft Device Emulator version 1.0 - ENU Microsoft Document Explorer 2005 Microsoft Document Explorer 2005 Microsoft FrontPage Client - French Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2000 SR-1 Professional Microsoft Office 2003 Web Components Microsoft Outlook 2002 Microsoft SDK Update February 2003 (5.2.3790.0) Microsoft SQL Server 2000 Microsoft SQL Server 2000 Analysis Services Microsoft SQL Server 2000 Sample Database Scripts Microsoft SQL Server 2005 Microsoft SQL Server 2005 (SQLEXPRESS) Microsoft SQL Server 2005 Analysis Services (SQLEXPRESS) Microsoft SQL Server 2005 Backward compatibility Microsoft SQL Server 2005 Books Online (English) (July 2006) Microsoft SQL Server 2005 Mobile [ENU] Developer Tools Microsoft SQL Server 2005 Reporting Services (SQLEXPRESS) Microsoft SQL Server 2005 Samples Microsoft SQL Server 2005 Tools Microsoft SQL Server Management Studio Express Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual J# 2.0 Redistributable Package Microsoft Visual J# 2.0 Redistributable Package Microsoft Visual Studio 2005 Professional Edition - ENU Microsoft Visual Studio 2005 Professional Edition - ENU Microsoft Visual Studio 2005 SDK April 2006 Microsoft Visual Studio 2005 SDK Power Toys Microsoft Visual Studio 6.0 Enterprise Edition Microsoft Web Publishing Wizard 1.53 Mise à jour de sécurité pour Lecteur Windows Media (KB911564) Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565) Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734) Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782) Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398) Mise à jour de sécurité pour Step by Step Interactive Training (KB898458) Mise à jour de sécurité pour Step by Step Interactive Training (KB923723) Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090) Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969) Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768) Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566) Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143) Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127) Mise à jour de sécurité pour Windows XP (KB883939) Mise à jour de sécurité pour Windows XP (KB890046) Mise à jour de sécurité pour Windows XP (KB893756) Mise à jour de sécurité pour Windows XP (KB896358) Mise à jour de sécurité pour Windows XP (KB896422) Mise à jour de sécurité pour Windows XP (KB896423) Mise à jour de sécurité pour Windows XP (KB896424) Mise à jour de sécurité pour Windows XP (KB896428) Mise à jour de sécurité pour Windows XP (KB896688) Mise à jour de sécurité pour Windows XP (KB899587) Mise à jour de sécurité pour Windows XP (KB899588) Mise à jour de sécurité pour Windows XP (KB899589) Mise à jour de sécurité pour Windows XP (KB899591) Mise à jour de sécurité pour Windows XP (KB900725) Mise à jour de sécurité pour Windows XP (KB901017) Mise à jour de sécurité pour Windows XP (KB901190) Mise à jour de sécurité pour Windows XP (KB901214) Mise à jour de sécurité pour Windows XP (KB902400) Mise à jour de sécurité pour Windows XP (KB903235) Mise à jour de sécurité pour Windows XP (KB904706) Mise à jour de sécurité pour Windows XP (KB905414) Mise à jour de sécurité pour Windows XP (KB905749) Mise à jour de sécurité pour Windows XP (KB905915) Mise à jour de sécurité pour Windows XP (KB908519) Mise à jour de sécurité pour Windows XP (KB908531) Mise à jour de sécurité pour Windows XP (KB911280) Mise à jour de sécurité pour Windows XP (KB911562) Mise à jour de sécurité pour Windows XP (KB911567) Mise à jour de sécurité pour Windows XP (KB911927) Mise à jour de sécurité pour Windows XP (KB912812) Mise à jour de sécurité pour Windows XP (KB912919) Mise à jour de sécurité pour Windows XP (KB913446) Mise à jour de sécurité pour Windows XP (KB913580) Mise à jour de sécurité pour Windows XP (KB914388) Mise à jour de sécurité pour Windows XP (KB914389) Mise à jour de sécurité pour Windows XP (KB916281) Mise à jour de sécurité pour Windows XP (KB917159) Mise à jour de sécurité pour Windows XP (KB917344) Mise à jour de sécurité pour Windows XP (KB917422) Mise à jour de sécurité pour Windows XP (KB917537) Mise à jour de sécurité pour Windows XP (KB917953) Mise à jour de sécurité pour Windows XP (KB918118) Mise à jour de sécurité pour Windows XP (KB918439) Mise à jour de sécurité pour Windows XP (KB918899) Mise à jour de sécurité pour Windows XP (KB919007) Mise à jour de sécurité pour Windows XP (KB920213) Mise à jour de sécurité pour Windows XP (KB920214) Mise à jour de sécurité pour Windows XP (KB920670) Mise à jour de sécurité pour Windows XP (KB920683) Mise à jour de sécurité pour Windows XP (KB920685) Mise à jour de sécurité pour Windows XP (KB921398) Mise à jour de sécurité pour Windows XP (KB921503) Mise à jour de sécurité pour Windows XP (KB921883) Mise à jour de sécurité pour Windows XP (KB922616) Mise à jour de sécurité pour Windows XP (KB922760) Mise à jour de sécurité pour Windows XP (KB922819) Mise à jour de sécurité pour Windows XP (KB923191) Mise à jour de sécurité pour Windows XP (KB923414) Mise à jour de sécurité pour Windows XP (KB923689) Mise à jour de sécurité pour Windows XP (KB923694) Mise à jour de sécurité pour Windows XP (KB923980) Mise à jour de sécurité pour Windows XP (KB924191) Mise à jour de sécurité pour Windows XP (KB924270) Mise à jour de sécurité pour Windows XP (KB924496) Mise à jour de sécurité pour Windows XP (KB924667) Mise à jour de sécurité pour Windows XP (KB925486) Mise à jour de sécurité pour Windows XP (KB925902) Mise à jour de sécurité pour Windows XP (KB926255) Mise à jour de sécurité pour Windows XP (KB926436) Mise à jour de sécurité pour Windows XP (KB927779) Mise à jour de sécurité pour Windows XP (KB927802) Mise à jour de sécurité pour Windows XP (KB928255) Mise à jour de sécurité pour Windows XP (KB928843) Mise à jour de sécurité pour Windows XP (KB929123) Mise à jour de sécurité pour Windows XP (KB930178) Mise à jour de sécurité pour Windows XP (KB931261) Mise à jour de sécurité pour Windows XP (KB931784) Mise à jour de sécurité pour Windows XP (KB932168) Mise à jour de sécurité pour Windows XP (KB935839) Mise à jour de sécurité pour Windows XP (KB935840) Mise à jour de sécurité pour Windows XP (KB936021) Mise à jour de sécurité pour Windows XP (KB938829) Mise à jour de sécurité pour Windows XP (KB939373) Mise à jour pour Windows XP (KB894391) Mise à jour pour Windows XP (KB896727) Mise à jour pour Windows XP (KB898461) Mise à jour pour Windows XP (KB900485) Mise à jour pour Windows XP (KB900930) Mise à jour pour Windows XP (KB904942) Mise à jour pour Windows XP (KB910437) Mise à jour pour Windows XP (KB916595) Mise à jour pour Windows XP (KB920872) Mise à jour pour Windows XP (KB922582) Mise à jour pour Windows XP (KB927891) Mise à jour pour Windows XP (KB929338) Mise à jour pour Windows XP (KB930916) Mise à jour pour Windows XP (KB931836) Mise à jour pour Windows XP (KB936357) Mise à jour pour Windows XP (KB938828) MSDN Library - Visual Studio 6.0a MSDN Library for Visual Studio 2005 MSDN Library for Visual Studio 2005 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) Nokia PC Suite 4.06 Norton Ghost Notebook Utilities Orca Paint Shop Pro 7 PC Suite PDFCreator 0.8.0 Photosmart 140,240,7200,7600,7700,7900 Series PowerQuest PartitionMagic 7.0 PSShortcutsP QuickTime QuickTime Alternative 1.31 RealOne Player Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB925674) Security Update pour Microsoft .NET Framework 2.0 (KB928365) Sheridan ActiveListBar Sheridan ActiveToolBars Sheridan ActiveTreeView Sheridan Calendar Widgets 1.07 Skype™ 3.2 SocketScan Software Sony Ericsson Capability Manager Sony Ericsson File Manager Sony Ericsson Image Editor Sony Ericsson MMS Home Studio Sony Ericsson Mobile Networking Wizard Sony Ericsson Mobile Phone Monitor Sony Ericsson OCS Sony Ericsson Sound Editor Sony Ericsson Sync Station Synaptics Pointing Device Driver TeeChart Pro v4 Activex Control VaudTax2004 VaudTax2005 Virtual Machine Network Services Driver Visionneuse Journal Windows Microsoft Visual Studio.NET Baseline - French WebFldrs XP WebObjects 5.2.4 Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Genuine Advantage Validation Tool Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Installer SDK (Version 2.0) (3790.0) Windows Internet Explorer 7 Windows Media Format Runtime Windows Media Player 10 Hotfix - KB894476 Windows Mobile 5.0 Developer Resource Kit Windows Mobile 5.0 Pocket PC SDK Windows XP Service Pack 2 WinRAR archiver WinZip WinZip Self-Extractor Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\Program Files 20.09.2007 12:14 <REP> . 20.09.2007 12:14 <REP> .. 27.02.2007 18:00 <REP> 3MCME 03.11.2006 11:09 <REP> Adobe 29.01.2007 17:25 <REP> Aide au Codage 12.12.2006 18:00 <REP> Apple Software Update 20.08.2007 11:19 <REP> Arpage 03.02.2004 10:10 <REP> ATI Technologies 03.10.2005 14:32 <REP> AvantGo Connect 05.08.2005 15:25 <REP> CD to MP3 Freeware 27.02.2006 19:13 <REP> CE Remote Tools 10.12.2004 10:23 <REP> Cisco Systems 03.10.2005 14:32 <REP> Common Files 10.02.2004 15:59 <REP> ComPlus Applications 03.02.2004 10:07 <REP> CONEXANT 10.12.2004 10:47 <REP> DameWare Development 28.02.2006 10:40 <REP> Developer Resources for Windows Mobile 2003 Second Edition 03.02.2004 16:48 <REP> Easy Internet signup 24.07.2007 09:26 <REP> eclipse 11.05.2007 09:27 <REP> eclipseV321 02.08.2007 09:36 <REP> Fichiers communs 07.03.2007 12:15 <REP> gestion 18.05.2007 15:14 <REP> GlobalSCAPE 11.05.2007 16:22 <REP> Google 19.09.2007 08:50 <REP> HardwareDetection 26.07.2005 08:49 <REP> Hewlett-Packard 03.02.2004 18:17 <REP> HighMAT CD Writing Wizard 03.01.2006 16:39 <REP> HP 03.02.2004 10:24 <REP> HPQ 09.10.2006 12:20 <REP> HTML Help Workshop 17.07.2006 12:17 <REP> Innovasys 15.08.2007 10:36 <REP> Internet Explorer 03.02.2004 10:17 <REP> InterVideo 12.12.2006 18:05 <REP> iPod 12.12.2006 18:05 <REP> iTunes 09.08.2004 11:49 <REP> Jasc Software Inc 17.04.2007 09:07 <REP> Java 03.02.2004 13:53 <REP> JavaSoft 09.01.2007 12:34 <REP> LUCID 05.05.2006 10:13 <REP> LUCIDFR 07.08.2007 08:53 <REP> McAfee 03.02.2004 12:44 <REP> McAfee VirusScan 7.00 Retail 01.02.2007 09:54 <REP> McAfee.com 24.03.2004 16:19 <REP> Media Player Classic 16.02.2005 21:25 <REP> Messenger 17.01.2006 15:47 <REP> Microsoft ActiveSync 23.10.2006 10:56 <REP> Microsoft Analysis Services 01.11.2006 14:41 <REP> Microsoft Analysis Services Samples 09.05.2007 09:06 <REP> Microsoft CAPICOM 2.1.0.2 27.02.2006 18:08 <REP> Microsoft Device Emulator 03.02.2004 10:42 <REP> microsoft frontpage 26.10.2006 15:45 <REP> Microsoft Office 21.06.2004 11:58 <REP> Microsoft SDK 23.07.2007 16:31 <REP> Microsoft SQL Server 27.02.2006 19:48 <REP> Microsoft SQL Server 2005 Mobile Edition 26.10.2006 15:51 <REP> Microsoft Visual Studio 26.10.2006 15:10 <REP> Microsoft Visual Studio .NET 26.10.2006 15:10 <REP> Microsoft Visual Studio .NET 2003 26.10.2006 15:05 <REP> Microsoft Visual Studio 8 27.02.2006 19:52 <REP> Microsoft.NET 05.10.2004 13:26 <REP> Movie Maker 31.01.2007 17:23 <REP> Mozilla Firefox 27.02.2006 19:32 <REP> MSBuild 03.02.2004 16:48 <REP> MSN Gaming Zone 16.10.2006 09:42 <REP> MSXML 4.0 15.08.2007 10:19 <REP> MSXML 6.0 05.10.2004 13:15 <REP> NetMeeting 16.11.2004 10:57 <REP> Nokia 31.05.2006 15:44 <REP> OfficeUpdate11 21.06.2004 13:53 <REP> Orca 13.06.2007 09:06 <REP> Outlook Express 12.01.2006 22:41 <REP> PDFCreator 03.02.2004 13:02 <REP> PowerQuest 12.12.2006 18:11 <REP> QuickTime 24.03.2004 16:18 <REP> QuickTime Alternative 06.04.2004 17:25 <REP> Real 03.02.2004 10:22 <REP> Roxio 03.02.2004 16:49 <REP> Services en ligne 11.09.2007 00:04 <REP> SiteAdvisor 02.08.2007 09:36 <REP> Skype 20.01.2005 17:29 <REP> Snapshot Viewer 31.05.2006 10:17 <REP> Socket Communications, Inc 15.12.2004 20:45 <REP> Sony Ericsson 03.02.2004 17:59 <REP> Symantec 03.02.2004 10:16 <REP> Synaptics 26.03.2007 15:00 <REP> TeeChart Pro v4 ActiveX Control 03.02.2004 12:55 <REP> TweakUI 07.06.2007 17:14 <REP> Ultrapico 14.07.2006 16:52 <REP> Visual Studio 2005 SDK 28.02.2006 10:40 <REP> VMNetSrv 10.02.2004 15:49 <REP> Web Publish 13.10.2005 10:31 <REP> Windows CE Tools 03.02.2004 18:30 <REP> Windows Journal Viewer 16.02.2006 09:43 <REP> Windows Media Player 05.10.2004 13:14 <REP> Windows NT 08.11.2005 13:35 <REP> WinRAR 06.12.2005 11:05 <REP> WinZip 03.02.2004 16:48 <REP> xerox 01.07.2004 14:25 <REP> Yahoo! 0 fichier(s) 0 octets 99 Rép(s) 2'620'276'736 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\Program Files\fichiers communs 02.08.2007 09:36 <REP> . 02.08.2007 09:36 <REP> .. 03.02.2004 10:23 <REP> Adaptec Shared 21.12.2006 11:14 <REP> Adobe 27.02.2006 19:17 <REP> Business Objects 10.02.2004 15:48 <REP> Designer 10.12.2004 10:10 <REP> Deterministic Networks 03.02.2004 10:12 <REP> InstallShield 15.11.2005 14:47 <REP> Java 31.01.2007 17:20 <REP> McAfee 27.02.2006 19:30 <REP> Merge Modules 24.01.2007 18:08 <REP> Microsoft Shared 03.02.2004 16:48 <REP> MSSoap 16.11.2004 10:58 <REP> Nokia 03.02.2004 16:48 <REP> ODBC 06.04.2004 17:26 <REP> Real 03.02.2004 16:48 <REP> Services 02.08.2007 09:36 <REP> Skype 03.02.2004 16:48 <REP> SpeechEngines 03.02.2004 18:01 <REP> Symantec Shared 21.08.2007 17:29 <REP> System 15.12.2004 20:47 <REP> Teleca Shared 06.04.2004 17:26 <REP> xing shared 0 fichier(s) 0 octets 23 Rép(s) 2'620'280'832 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders 10.10.2005 16:38 <REP> . 10.10.2005 16:38 <REP> .. 09.06.2005 15:00 <REP> 1033 10.10.2005 16:38 <REP> 1036 29.01.2004 07:08 1'277'952 MSONSEXT.DLL 13.02.2001 08:23 58'784 MSOSV.DLL 03.06.1999 09:09 122'937 MSOWS409.DLL 07.03.2001 04:00 127'033 MSOWS40c.DLL 06.08.2000 09:04 401'462 MSVCP60.DLL 29.01.2004 07:08 69'632 PKMAXCTL.DLL 29.01.2004 07:08 868'352 PKMCDO.DLL 29.01.2004 07:08 53'248 PKMCORE.DLL 29.01.2004 07:08 102'400 PKMFORMS.DLL 29.01.2004 07:38 634'880 PKMRES.DLL 29.01.2004 07:08 28'672 PKMSSTLB.DLL 22.01.2001 03:25 40'960 PKMTEMPL.DLL 29.01.2004 07:08 24'576 PKMTRACE.DLL 29.01.2004 07:08 86'016 PKMWS.DLL 29.01.2004 07:08 237'568 PROMDEMO.DLL 18.03.1999 06:37 593'977 RAGENT.DLL 29.01.2004 07:08 184'320 SECMGR.DLL 29.01.2004 07:08 315'392 VAIDDMGR.DLL 29.01.2004 07:08 32'768 VAIMEM.DLL 19 fichier(s) 5'260'929 octets 4 Rép(s) 2'620'280'832 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 0E4D-AF5C Répertoire de C:\Program Files\common files 03.10.2005 14:32 <REP> . 03.10.2005 14:32 <REP> .. 03.10.2005 14:32 <REP> Microsoft Shared 01.10.2004 13:34 <REP> System 0 fichier(s) 0 octets 4 Rép(s) 2'620'276'736 octets libres c:\Documents and Settings\Administrateur\Local Settings\Temp\munA44.exe c:\Documents and Settings\Administrateur\Local Settings\Temp\pft2A~tmp\VSCUTIL.exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\JS56_E17148F55AA39A43847DA21B9F98A28E5D2E5EF9[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\Q322011_WXP_A5B95D9FA4CF10578CBEBAD732C1F9037E953F13[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\q820223_686cce4d764c865441b1e72a3df636f[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\WindowsXP-KB810243-x86-FRA_d8a73b4889a60187b5cbf60384eb2f1[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\WindowsXP-KB821253-x86-FRA_c002e4860a70561e0c5119ba0d486d5[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\WindowsXP-KB823182-x86-FRA_d5e9e96b62ce036e6bda5c402ed2177[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4R6BIVWX\WindowsXP-KB828035-x86-FRA_2b769cb89eec318a4a7eb72412f3096[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\6D01AL8J\hu1002_pro_89FE26A85EB85CA23805DFFBD09CFDB6E787DD58[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\6D01AL8J\q330994_f31ef5b61c5afa39c1e296cfc5223c5[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\6D01AL8J\Q819696_WXP_SP2_x86_FRA_e660a557055a6d209258169745e369e[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\6D01AL8J\WindowsXP-KB817778-x86-FRA_a4d92a49a0476bb55cd44f80d77c215[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\6D01AL8J\WindowsXP-KB826939-x86-FRA-express_e8b15874b8a7ff44eff2e1130498599[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\6D01AL8J\WindowsXP-KB826942-x86-FRA-express_a1edea12f9f3a10e0d26bc58a6f1ae4[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\HMTCDWizard_FRA_e53ce2c18254eb8e89206fb1b868fd4[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\Q811114_WXP_SP2_x86_FRA_31163df37fd7255d4589937917771c1[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\Q832894_374f6c5e712390e5932569a8ab627e5[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\SETUP_8F8C362408FBE4C33693ED8419858AABE9929562[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\WindowsMedia-KB828026-x86-FRA_3f35040dc24b5a84b01d5352af6cf2b[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\WindowsXP-KB820291-x86-FRA_37ccb3354fcb61e216e18b704d55873[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\WindowsXP-KB824141-x86-FRA_01216eedca8ae48d1636cb1ade7962e[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\CVIBCV0J\WindowsXP-KB825119-x86-FRA_a6bf6659ec32a9adf0d781d9005bd2a[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\FRN_Q832483_MDAC_x86_b3f66e58fe2a217736ac8097e3d8019[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\Q327979_WXP_SP2_A36302DFD4E5B1FF60BA2AF0ABB82CD09E34CC13[1].EXE c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\Q814995_WXP_SP2_x86_FRA_a208a164d29522dc1a0be238fe49a38[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\WindowsMedia8-KB817787-x86-FRA_18187544c6d1916907adf699d6d3355[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\WindowsXP-KB810217-x86-FRA_1f41f2c8ca6914bc8e14ab0b0c5f619[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\WindowsXP-KB822603-x86-FRA_61d1de05407bc70700a189ff9f3fece[1].exe c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I1YDSBGH\WindowsXP-KB824105-x86-FRA-express_f9bbad586291ec8e112058dca22056c[1].EXE c:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.0.2.16\iTunesSetupAdmin.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\aspiinst.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe c:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe c:\Documents and Settings\see\Application Data\Microsoft\Installer\{16EA4488-EFFB-4F19-9730-88C528824B29}\_16496df1.exe c:\Documents and Settings\see\Application Data\Microsoft\Installer\{16EA4488-EFFB-4F19-9730-88C528824B29}\_2cd672ae.exe c:\Documents and Settings\see\Application Data\Microsoft\Installer\{16EA4488-EFFB-4F19-9730-88C528824B29}\_69525f90.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\3rly014p01\Cistern.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\drrz1rvq01\Cistern.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\eg-8ttys01\Cistern.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\eqi5bwaw01\donneeTest.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\grrgmtbw01\Cistern.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\guqgx6ml01\donneeTest.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\o9mnxhsy01\Cistern.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\pgnb9tcv01\Cistern.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\qr6zl-ev01\donneeTest.exe c:\Documents and Settings\see\Application Data\Microsoft\VisualStudio\7.1\ProjectAssemblies\wbvhbk5h01\Cistern.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr709_fr_FR.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_d5ixfs1ljxwyrzrf5jqldzcwwxmmis35 c:\Documents and Settings\see.NICECOMPUTING\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_eb5gunxgw1e3pe1mg2hogtxbsyfmioge c:\Documents and Settings\see.NICECOMPUTING\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_hwl1vpqauwy0tmbqzgypnvc4qyylbzlu c:\Documents and Settings\see.NICECOMPUTING\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_vl0dztzyl3mkz4o3cd5aa3idikl3xup1 c:\Documents and Settings\see.NICECOMPUTING\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_vw152twrngauqr5ideguqcbdzpgij4u0 c:\Documents and Settings\see.NICECOMPUTING\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_wfjbdjyva1mbxlmmbbniy5aj0frcoet2 c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{16EA4488-EFFB-4F19-9730-88C528824B29}\_16496df1.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{16EA4488-EFFB-4F19-9730-88C528824B29}\_2cd672ae.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{16EA4488-EFFB-4F19-9730-88C528824B29}\_69525f90.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\ARPPRODUCTICON.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{7D95B533-4BA1-4EED-8096-EFCB6DD6B95F}\ARPPRODUCTICON.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{D6BE7113-21D0-44E2-A576-8FCAB9EF5CB7}\_428b26a6.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{D6BE7113-21D0-44E2-A576-8FCAB9EF5CB7}\_644366bb.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{D6BE7113-21D0-44E2-A576-8FCAB9EF5CB7}\_701f5d03.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{DDF6E319-BCD9-4FE3-9D69-26B2F47BEF7C}\ARPPRODUCTICON.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_124305e.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_12db153c.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_154754de.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_39b32d12.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_440d491c.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_4d064db7.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_74d4dc8.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_7e87390c.exe c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Installer\{ED2943EB-230C-44FB-8778-C1C784B49B37}\_f3e99.exe c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_d5ixfs1ljxwyrzrf5jqldzcwwxmmis35 c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_eb5gunxgw1e3pe1mg2hogtxbsyfmioge c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_hwl1vpqauwy0tmbqzgypnvc4qyylbzlu c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_vl0dztzyl3mkz4o3cd5aa3idikl3xup1 c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_vw152twrngauqr5ideguqcbdzpgij4u0 c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Liberty_Associates,_Inc\NorthWindWindows.exe_Url_wfjbdjyva1mbxlmmbbniy5aj0frcoet2 c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Microsoft\VisualStudio\8.0Exp\ProjectAssemblies\yu6h2bc501\NorthWindWindows.exe c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Temporary Internet Files\Y7M87DUS\ATLUHZ1P\Offline\b000039.exe c:\Documents and Settings\Administrateur\Application Data\wsnpoem\audio.dll c:\Documents and Settings\Administrateur\Application Data\wsnpoem\video.dll c:\Documents and Settings\see\Application Data\Microsoft\Émulateur pour Windows CE\VPCKeyboard.dll c:\Documents and Settings\see\Application Data\wsnpoem\audio.dll c:\Documents and Settings\see\Application Data\wsnpoem\video.dll c:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Émulateur pour Windows CE\VPCKeyboard.dll c:\Documents and Settings\see.NICECOMPUTING\Application Data\wsnpoem\audio.dll c:\Documents and Settings\see.NICECOMPUTING\Application Data\wsnpoem\video.dll c:\Documents and Settings\see.NICECOMPUTING\Local Settings\Application Data\Microsoft\VisualStudio\8.0Exp\ProjectAssemblies\hl2g1ykk01\NorthwindDataSet.Designer.vb.dll c:\Documents and Settings\SuperAdmin\Application Data\wsnpoem\audio.dll c:\Documents and Settings\SuperAdmin\Application Data\wsnpoem\video.dll ****** Fin du rapport DiagHelp A plus, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Bonjour, bonsoir, selon Les choses ne se sont pas passées comme cela aurait du. En effet, le logiciel SDFix indique des erreurs du type RegCreateKey Ex : 5 accès refusé. Il me semble qu’il ne peut pas écrire dans le registre bien que je sois administrateur. Mes droits administrateurs sont altérés. Néanmoins, j'ai continué la procédure désirée et vous trouverez le rapport de SDFix et log de hijackthis ! Le rapport SDFix ci-dessous : SDFix: Version 1.107 Run by see on 02.10.2007 at 10:30 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting... Normal Mode: Checking Files: No Trojan Files Found Removing Temp Files... ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\Program Files\\Arpage\\ASAS3\\client\\asasc.exe"="C:\\Program Files\\Arpage\\ASAS3\\client\\asasc.exe:*:Enabled:ASAS - Client COM Interfaces" "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer" "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager" "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager" "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application" "C:\\Apple\\Developer\\Applications\\ProjectBuilder.app\\ProjectBuilder.exe"="C:\\Apple\\Developer\\Applications\\ProjectBuilder.app\\ProjectBuilder.exe:LocalSubNet:Enabled:ProjectBuilder" "C:\\Apple\\jdk1.3.1_10\\bin\\javaw.exe"="C:\\Apple\\jdk1.3.1_10\\bin\\javaw.exe:*:Enabled:javaw.exe" "C:\\Apple\\jdk1.3.1_10\\jre\\bin\\javaw.exe"="C:\\Apple\\jdk1.3.1_10\\jre\\bin\\javaw.exe:*:Enabled:javaw.exe" "C:\\WINDOWS\\system32\\javaw.exe"="C:\\WINDOWS\\system32\\javaw.exe:*:Enabled:javaw" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Arpage\\ASAS3\\client\\asasc.exe"="C:\\Program Files\\Arpage\\ASAS3\\client\\asasc.exe:*:Enabled:ASAS - Client COM Interfaces" "C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft ® HTML Application host" "C:\\Program Files\\Cisco Systems\\VPN Client\\vpnclient.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\vpnclient.exe:*:Enabled:vpnclient.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\ppptool.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\ppptool.exe:*:Enabled:ppptool.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\IPSecLog.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\IPSecLog.exe:*:Enabled:IPSecLog.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\cvpnd.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\cvpnd.exe:*:Enabled:cvpnd.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\ipsecdialer.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\ipsecdialer.exe:*:Enabled:ipsecdialer.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\SetMTU.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\SetMTU.exe:*:Enabled:SetMTU.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\vpngui.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\vpngui.exe:*:Enabled:vpngui.exe" "C:\\Program Files\\Cisco Systems\\VPN Client\\VAInstaller.exe"="C:\\Program Files\\Cisco Systems\\VPN Client\\VAInstaller.exe:*:Enabled:VAInstaller.exe" "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:*:Enabled:ActiveSync Connection Manager" "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:*:Enabled:ActiveSync Application" "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" Remaining Files: --------------- Files with Hidden Attributes: Tue 30 May 2006 7,432 ...HR --- "C:\C_DILLA\B3C88000.BAK" Tue 4 Oct 2005 21,504 A..H. --- "C:\Documents and Settings\see\Application Data\Microsoft\?mulateur pour Windows CE\VPCKeyboard.dll" Thu 19 Aug 2004 78,336 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL1090.tmp" Thu 19 Aug 2004 19,456 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL2260.tmp" Fri 3 Sep 2004 19,456 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL2662.tmp" Fri 3 Sep 2004 254,976 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL2749.tmp" Thu 19 Aug 2004 102,912 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL3121.tmp" Thu 19 Aug 2004 22,016 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL3427.tmp" Thu 19 Aug 2004 80,384 ...H. --- "C:\Documents and Settings\see\Application Data\Microsoft\Word\~WRL3683.tmp" Thu 30 Jun 2005 21,504 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\?mulateur pour Windows CE\VPCKeyboard.dll" Mon 2 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL0372.tmp" Thu 19 Aug 2004 78,336 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL1090.tmp" Thu 19 Aug 2004 19,456 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL2260.tmp" Fri 3 Sep 2004 19,456 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL2662.tmp" Fri 3 Sep 2004 254,976 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL2749.tmp" Thu 19 Aug 2004 102,912 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL3121.tmp" Thu 19 Aug 2004 22,016 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL3427.tmp" Thu 19 Aug 2004 80,384 A..H. --- "C:\Documents and Settings\see.NICECOMPUTING\Application Data\Microsoft\Word\~WRL3683.tmp" Thu 9 Jun 2005 57,092 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\visualstudio\7.1\vs000223.tmp" Wed 14 Aug 2002 65,088 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM" Wed 14 Aug 2002 12,732 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM" Wed 14 Aug 2002 26,424 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM" Wed 14 Aug 2002 28,062 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM" Wed 14 Aug 2002 10,710 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM" Wed 14 Aug 2002 10,083 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM" Wed 14 Aug 2002 10,257 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM" Wed 14 Aug 2002 29,499 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM" Wed 14 Aug 2002 12,660 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM" Wed 14 Aug 2002 11,031 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM" Wed 14 Aug 2002 17,952 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM" Wed 14 Aug 2002 9,424 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM" Wed 14 Aug 2002 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM" Wed 14 Aug 2002 13,673 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM" Wed 14 Aug 2002 14,438 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM" Wed 14 Aug 2002 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM" Wed 14 Aug 2002 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM" Wed 14 Aug 2002 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM" Wed 14 Aug 2002 7,243 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM" Wed 14 Aug 2002 24,767 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM" Wed 14 Aug 2002 7,463 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM" Wed 14 Aug 2002 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM" Wed 14 Aug 2002 10,286 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM" Wed 14 Aug 2002 25,460 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM" Wed 14 Aug 2002 28,866 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM" Wed 14 Aug 2002 14,438 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM" Wed 14 Aug 2002 8,544 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys" Wed 14 Aug 2002 33,149 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys" Wed 28 May 2003 51,150 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS" Wed 14 Aug 2002 35,340 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS" Wed 14 Aug 2002 14,378 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS" Wed 14 Aug 2002 37,984 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS" Wed 14 Aug 2002 44,828 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8U2.SYS" Wed 14 Aug 2002 29,628 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS" Wed 28 May 2003 52,106 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS" Wed 14 Aug 2002 49,242 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS" Wed 14 Aug 2002 50,606 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS" Wed 14 Aug 2002 161,792 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS" Wed 14 Aug 2002 174,080 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys" Wed 14 Aug 2002 21,971 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTCDROM.SYS" Wed 14 Aug 2002 30,955 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTDOSM.SYS" Wed 14 Aug 2002 202,517 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE" Wed 14 Aug 2002 374,038 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE" Wed 14 Aug 2002 22,158 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS" Wed 14 Aug 2002 1,608 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DEVICE.COM" Wed 14 Aug 2002 15,345 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS" Wed 14 Aug 2002 7,840 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS" Wed 14 Aug 2002 56,821 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE" Wed 14 Aug 2002 64,425 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\FLASHPT.SYS" Wed 14 Aug 2002 32,396 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE" Wed 14 Aug 2002 14,160 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS" Wed 14 Aug 2002 10,898 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYB.COM" Wed 14 Aug 2002 53,556 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS" Wed 14 Aug 2002 15,777 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MODE.COM" Wed 14 Aug 2002 37,681 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MOUSE.COM" Wed 14 Aug 2002 354,304 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys" Wed 14 Aug 2002 21,180 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE" Wed 14 Aug 2002 354,263 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe" Wed 14 Aug 2002 8,513 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\NETBIND.COM" Wed 14 Aug 2002 41,302 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OAKCDROM.SYS" Wed 14 Aug 2002 129,240 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE" Wed 14 Aug 2002 28,439 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Paralink.com" Wed 14 Aug 2002 13,770 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE" Wed 14 Aug 2002 130,980 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE" Wed 14 Aug 2002 11,854 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM" Wed 14 Aug 2002 52,715 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM" Wed 14 Aug 2002 62,391 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM" Wed 14 Aug 2002 11,491 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com" Wed 14 Aug 2002 17,791 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com" Wed 14 Aug 2002 17,043 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com" Wed 14 Aug 2002 11,786 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com" Wed 14 Aug 2002 18,300 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com" Wed 14 Aug 2002 48,224 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com" Wed 14 Aug 2002 13,360 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com" Wed 14 Aug 2002 9,190 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com" Wed 14 Aug 2002 12,567 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com" Wed 14 Aug 2002 44,640 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM" Wed 14 Aug 2002 56,896 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com" Wed 14 Aug 2002 44,640 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com" Wed 14 Aug 2002 9,692 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com" Wed 14 Aug 2002 9,537 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM" Wed 14 Aug 2002 32,484 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com" Wed 14 Aug 2002 52,225 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe" Wed 14 Aug 2002 48,491 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe" Wed 14 Aug 2002 50,405 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com" Wed 14 Aug 2002 33,860 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe" Wed 14 Aug 2002 50,175 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe" Wed 14 Aug 2002 50,795 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe" Wed 14 Aug 2002 48,223 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com" Wed 14 Aug 2002 48,641 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe" Wed 14 Aug 2002 49,015 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com" Wed 14 Aug 2002 53,786 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\command.com" Wed 14 Aug 2002 44,240 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM" Wed 14 Aug 2002 42,550 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM" Finished! Ensuite, le log hijackthis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:51:02, on 02.10.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apple\Library\System\machd.exe C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\SYSTEM32\DWRCS.EXE C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE C:\WINDOWS\system32\HPConfig.exe C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe C:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe C:\Program Files\SiteAdvisor\6172\SAService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe C:\WINDOWS\system32\java.exe C:\Apple\Library\System\nmserver.exe E:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\SiteAdvisor\6172\SiteAdv.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe C:\WINDOWS\System32\hphmon05.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe C:\WINDOWS\system32\carpserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\system32\ctfmon.exe C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Program Files\Arpage\ASAS3\client\asasc.exe C:\Apple\Library\System\WindowServer.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\cidaemon.exe C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE E:\transfert\pbOrdi\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=asas:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [siteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [Nokia Connection Monitor] "C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-318002662-2135222273-1471158870-1110\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Pasteboard Server.lnk = C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O4 - Global Startup: Start ASAS Client.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: VPN Client.lnk = ? O4 - Global Startup: Window Server.lnk = C:\Apple\Library\System\WindowServer.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1187623321333 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1190708020199 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1124267662289 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran...ransferCtrl.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\Software\..\Telephony: DomainName = nicecomputing O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nicecomputing O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Apple Mach Daemon (Apple_Mach_Daemon) - Unknown owner - C:\Apple\Library\System\machd.exe O23 - Service: Apple Netname Server (Apple_Netname_Server) - Unknown owner - C:/Apple\Library\System\nmserver.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINDOWS\SYSTEM32\DWRCS.EXE O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Unknown owner - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe (file missing) O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe O23 - Service: Apple WebObjects Monitor 5 (WOMONITOR5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\JavaMonitor.woa\WOMonitorService.exe O23 - Service: Apple WebObjects Task Daemon 5 (WOTASKD5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe -- End of file - 14820 bytes Merci encore pour l’aide et à plus je l’espère, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Tchooooo, Après avoir démarré SDFix et appuyer sur y. Il y a plein d’erreur du type RegCreateKey Ex : 5 accès refusé. Il me semble qu’il ne peut pas écrire dans le registre bien que je sois administrateur. Mes droits administrateurs sont altérés. Je vais continuer, mais est-ce bien utile ? En ce qui concerne mon FAI, il est bien localisé en suisse et le lien pointe sur une entreprise que je connais bien …. Salutations et merci pour votre aide, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Merci à vous deux. Je commence les opérations préconisées. A plus, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Ave eclypse ! Puis-je espérer ou des .... Merci de tout façon -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Re-tchooo, Voilà le rapport : WinPFind3 logfile created on: 27.09.2007 14:19:56 WinPFind3U by OldTimer - Version 1.0.42 Folder = E:\transfert\pbOrdi\WinPFind3u\ Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) Internet Explorer (Version = 7.0.5730.11) 958.98 Mb Total Physical Memory | 361.77 Mb Available Physical Memory | 37.72% Memory free 2.81 Gb Paging File | 2.22 Gb Available in Paging File | 79.07% Paging File free Paging file location(s): C:\pagefile.sys 1000 1100;E:\pagefile.sys 1000 2000; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 21.21 Gb Total Space | 2.29 Gb Free Space | 10.78% Space Free D: Drive not present or media not loaded Drive E: | 16.04 Gb Total Space | 5.91 Gb Free Space | 36.87% Space Free F: Drive not present or media not loaded Computer Name: NICEP-SEE Current User Name: see Logged in as Administrator. Current Boot Mode: Normal [Processes - Non-Microsoft Only] apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.50878 | Size = 57344 bytes | Modified Date = 23.06.2005 21:33:00 | Attr = ] asasc.exe -> %ProgramFiles%\Arpage\ASAS3\client\asasc.exe -> Arpage AG [Ver = 3.3.4.0 | Size = 163943 bytes | Modified Date = 10.09.2007 14:14:38 | Attr = ] atiptaxx.exe -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> ATI Technologies, Inc. [Ver = 6.13.10.3022 | Size = 290816 bytes | Modified Date = 14.08.2002 18:29:38 | Attr = ] carpserv.exe -> %System32%\carpserv.exe -> Conexant Systems, Inc. [Ver = 6.02.05 | Size = 4608 bytes | Modified Date = 21.05.2003 15:35:50 | Attr = ] cdantsrv.exe -> %System32%\drivers\CDANTSRV.EXE -> C-Dilla Ltd [Ver = 3.29.000 | Size = 46080 bytes | Modified Date = 01.04.2003 11:21:48 | Attr = ] cvpnd.exe -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> Cisco Systems, Inc. [Ver = 4.0.3 (D) | Size = 1425424 bytes | Modified Date = 26.01.2004 16:01:56 | Attr = ] directcd.exe -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe -> Roxio [Ver = 5.3.5.10 | Size = 684032 bytes | Modified Date = 26.03.2003 12:15:24 | Attr = ] dwrcs.exe -> %System32%\DWRCS.EXE -> DameWare Development [Ver = 3, 70, 1, 0 | Size = 241664 bytes | Modified Date = 30.06.2003 13:00:30 | Attr = ] ghoststarttrayapp.exe -> %ProgramFiles%\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe -> Symantec Corporation [Ver = 2003.775 | Size = 94208 bytes | Modified Date = 19.08.2002 12:58:38 | Attr = ] ghosts~2.exe -> %ProgramFiles%\Symantec\Norton Ghost 2003\GhostStartService.exe -> Symantec Corporation [Ver = 2003.775 | Size = 200704 bytes | Modified Date = 14.08.2002 16:21:16 | Attr = ] hpconfig.exe -> %System32%\HPConfig.exe -> Hewlett-Packard [Ver = 3, 0, 1, 8 | Size = 151552 bytes | Modified Date = 15.08.2002 11:11:00 | Attr = ] hphmon05.exe -> %System32%\hphmon05.exe -> Hewlett-Packard [Ver = 5,0,84 | Size = 483328 bytes | Modified Date = 22.05.2003 20:56:42 | Attr = ] hpwuschd2.exe -> %ProgramFiles%\Hewlett-Packard\HP Software Update\HPWuSchd2.exe -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 16.02.2005 23:11:42 | Attr = ] hwapi.exe -> %CommonProgramFiles%\McAfee\HackerWatch\HWAPI.exe -> McAfee, Inc. [Ver = 8.3.105.0 | Size = 540776 bytes | Modified Date = 13.02.2007 12:09:12 | Attr = ] java.exe -> %System32%\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Modified Date = 14.03.2007 00:31:24 | Attr = ] jucheck.exe -> %ProgramFiles%\Java\jre1.6.0_01\bin\jucheck.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 272024 bytes | Modified Date = 14.03.2007 03:43:42 | Attr = ] jusched.exe -> %ProgramFiles%\Java\jre1.6.0_01\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 83608 bytes | Modified Date = 14.03.2007 03:43:44 | Attr = ] machd.exe -> %SystemDrive%\Apple\Library\System\machd.exe -> [Ver = | Size = 73216 bytes | Modified Date = 16.11.1999 12:41:26 | Attr = ] mcmscsvc.exe -> %ProgramFiles%\McAfee\MSC\mcmscsvc.exe -> McAfee, Inc. [Ver = 7,2,142,0 | Size = 361560 bytes | Modified Date = 05.01.2007 17:22:12 | Attr = ] mcnasvc.exe -> %CommonProgramFiles%\McAfee\MNA\McNASvc.exe -> McAfee, Inc. [Ver = 1,2,108,0 | Size = 2213416 bytes | Modified Date = 09.03.2007 04:36:10 | Attr = ] mcods.exe -> %ProgramFiles%\McAfee\VirusScan\mcods.exe -> McAfee, Inc. [Ver = 11,2,121,0 | Size = 362064 bytes | Modified Date = 16.01.2007 19:03:36 | Attr = ] mcpromgr.exe -> %ProgramFiles%\McAfee\MSC\mcpromgr.exe -> McAfee, Inc. [Ver = 7,2,142,0 | Size = 493144 bytes | Modified Date = 05.01.2007 17:21:40 | Attr = ] mcshield.exe -> %ProgramFiles%\McAfee\VirusScan\Mcshield.exe -> McAfee, Inc. [Ver = VSCORE.13.3.2.101.x86 | Size = 144960 bytes | Modified Date = 22.12.2006 17:02:26 | Attr = ] mpfsrv.exe -> %ProgramFiles%\McAfee\MPF\MpfSrv.exe -> McAfee, Inc. [Ver = 8.2.122.0 | Size = 841256 bytes | Modified Date = 19.06.2007 08:55:24 | Attr = ] nclconf.exe -> %CommonProgramFiles%\Nokia\NCLTools\NclConf.exe -> Nokia Mobile Phones Ltd. [Ver = 4.00.014 | Size = 122880 bytes | Modified Date = 23.03.2001 12:08:42 | Attr = ] nmserver.exe -> %SystemDrive%\Apple\Library\System\nmserver.exe -> [Ver = | Size = 116736 bytes | Modified Date = 16.11.1999 12:42:50 | Attr = ] onetouch.exe -> %ProgramFiles%\HPQ\One-Touch\ONETOUCH.EXE -> Dritek System Inc. [Ver = 1.7.0.0 | Size = 106496 bytes | Modified Date = 13.03.2003 17:11:42 | Attr = ] pbs.exe -> %SystemDrive%\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe -> [Ver = | Size = 222208 bytes | Modified Date = 11.10.2002 18:47:32 | Attr = ] qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.3 | Size = 282624 bytes | Modified Date = 25.10.2006 19:58:18 | Attr = ] realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.1622 | Size = 151597 bytes | Modified Date = 06.04.2004 17:25:46 | Attr = ] redirsvc.exe -> %CommonProgramFiles%\McAfee\RedirSvc\RedirSvc.exe -> McAfee, Inc. [Ver = 1,3,109,0 | Size = 256096 bytes | Modified Date = 08.03.2007 15:42:42 | Attr = ] saservice.exe -> %ProgramFiles%\SiteAdvisor\6172\SAService.exe -> [Ver = | Size = 341280 bytes | Modified Date = 11.09.2007 00:03:48 | Attr = ] siteadv.exe -> %ProgramFiles%\SiteAdvisor\6172\SiteAdv.exe -> McAfee, Inc. [Ver = 2.3.0 | Size = 36904 bytes | Modified Date = 17.01.2007 21:24:46 | Attr = ] syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> Synaptics, Inc. [Ver = 7.5.3 22May03 | Size = 610304 bytes | Modified Date = 23.05.2003 00:06:00 | Attr = ] syntplpr.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> Synaptics, Inc. [Ver = 7.5.3 22May03 | Size = 110592 bytes | Modified Date = 22.05.2003 23:10:00 | Attr = ] windowserver.exe -> %SystemDrive%\Apple\Library\System\WindowServer.exe -> [Ver = | Size = 1748586 bytes | Modified Date = 03.11.1999 11:43:52 | Attr = ] winpfind3u.exe -> E:\transfert\pbOrdi\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.42.0 | Size = 322560 bytes | Modified Date = 04.09.2007 10:47:26 | Attr = ] wotaskdservice.exe -> %SystemDrive%\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe -> [Ver = | Size = 24576 bytes | Modified Date = 28.10.2002 15:51:08 | Attr = ] wzqkpick.exe -> %ProgramFiles%\WinZip\WZQKPICK.EXE -> WinZip Computing, Inc. [Ver = 1.0 (32-bit) | Size = 118784 bytes | Modified Date = 17.12.2004 10:00:00 | Attr = ] [Win32 Services - Non-Microsoft Only] (Apple_Mach_Daemon) Apple Mach Daemon [Win32_Own | Auto | Running] -> %SystemDrive%\Apple\Library\System\machd.exe -> [Ver = | Size = 73216 bytes | Modified Date = 16.11.1999 12:41:26 | Attr = ] (Apple_Netname_Server) Apple Netname Server [Win32_Own | Auto | Running] -> %SystemDrive%\Apple\Library\System\nmserver.exe -> [Ver = | Size = 116736 bytes | Modified Date = 16.11.1999 12:42:50 | Attr = ] (C-DillaSrv) C-DillaSrv [Win32_Own | Auto | Running] -> %System32%\drivers\CDANTSRV.EXE -> C-Dilla Ltd [Ver = 3.29.000 | Size = 46080 bytes | Modified Date = 01.04.2003 11:21:48 | Attr = ] (CVPND) Cisco Systems, Inc. VPN Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> Cisco Systems, Inc. [Ver = 4.0.3 (D) | Size = 1425424 bytes | Modified Date = 26.01.2004 16:01:56 | Attr = ] (dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 225280 bytes | Modified Date = 20.08.2004 01:09:52 | Attr = ] (DWMRCS) DameWare Mini Remote Control [Win32_Own | Auto | Running] -> %System32%\DWRCS.EXE -> DameWare Development [Ver = 3, 70, 1, 0 | Size = 241664 bytes | Modified Date = 30.06.2003 13:00:30 | Attr = ] (Emproxy) McAfee E-mail Proxy [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\McAfee\EmProxy\emproxy.exe -> McAfee, Inc. [Ver = 11,2,206,0 | Size = 341584 bytes | Modified Date = 12.01.2007 17:13:24 | Attr = ] (GhostStartService) GhostStartService [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\Norton Ghost 2003\GhostStartService.exe -> Symantec Corporation [Ver = 2003.775 | Size = 200704 bytes | Modified Date = 14.08.2002 16:21:16 | Attr = ] (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 11.05.2007 16:22:58 | Attr = ] (HPConfig) HP Configuration Interface Service [Win32_Own | Auto | Running] -> %System32%\HPConfig.exe -> Hewlett-Packard [Ver = 3, 0, 1, 8 | Size = 151552 bytes | Modified Date = 15.08.2002 11:11:00 | Attr = ] (HPWirelessMgr) HPWirelessMgr [Win32_Own | Auto | Stopped] -> %ProgramFiles%\HPQ\Notebook Utilities\HPWirelessMgr.exe -> File not found (iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 492608 bytes | Modified Date = 30.10.2006 10:36:32 | Attr = ] (McAfee HackerWatch Service) McAfee HackerWatch Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\McAfee\HackerWatch\HWAPI.exe -> McAfee, Inc. [Ver = 8.3.105.0 | Size = 540776 bytes | Modified Date = 13.02.2007 12:09:12 | Attr = ] (mcmispupdmgr) McAfee Update Manager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee\MSC\mcupdmgr.exe -> McAfee, Inc. [Ver = 7,2,142,0 | Size = 689752 bytes | Modified Date = 05.01.2007 17:22:18 | Attr = ] (mcmscsvc) McAfee Services [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MSC\mcmscsvc.exe -> McAfee, Inc. [Ver = 7,2,142,0 | Size = 361560 bytes | Modified Date = 05.01.2007 17:22:12 | Attr = ] (McNASvc) McAfee Network Agent [Win32_Own | Auto | Running] -> %CommonProgramFiles%\McAfee\MNA\McNASvc.exe -> McAfee, Inc. [Ver = 1,2,108,0 | Size = 2213416 bytes | Modified Date = 09.03.2007 04:36:10 | Attr = ] (McODS) McAfee Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\VirusScan\mcods.exe -> McAfee, Inc. [Ver = 11,2,121,0 | Size = 362064 bytes | Modified Date = 16.01.2007 19:03:36 | Attr = ] (mcpromgr) McAfee Protection Manager [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MSC\mcpromgr.exe -> McAfee, Inc. [Ver = 7,2,142,0 | Size = 493144 bytes | Modified Date = 05.01.2007 17:21:40 | Attr = ] (McRedirector) McAfee Redirector Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\McAfee\RedirSvc\RedirSvc.exe -> McAfee, Inc. [Ver = 1,3,109,0 | Size = 256096 bytes | Modified Date = 08.03.2007 15:42:42 | Attr = ] (McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Running] -> -> File not found (McSysmon) McAfee SystemGuards [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee\VirusScan\mcsysmon.exe -> McAfee, Inc. [Ver = 11,2,131,0 | Size = 643664 bytes | Modified Date = 25.01.2007 19:01:58 | Attr = ] (MpfService) McAfee Personal Firewall Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MPF\MpfSrv.exe -> McAfee, Inc. [Ver = 8.2.122.0 | Size = 841256 bytes | Modified Date = 19.06.2007 08:55:24 | Attr = ] (openexec) openexec [Win32_Own | Disabled | Stopped] -> %System32%\invoker.exe -> [Ver = | Size = 57344 bytes | Modified Date = 30.10.1999 18:16:46 | Attr = ] (SiteAdvisor Service) SiteAdvisor Service [Win32_Own | Auto | Running] -> %ProgramFiles%\SiteAdvisor\6172\SAService.exe -> [Ver = | Size = 341280 bytes | Modified Date = 11.09.2007 00:03:48 | Attr = ] (WOMONITOR5) Apple WebObjects Monitor 5 [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\Apple\Library\WebObjects\JavaApplications\JavaMonitor.woa\WOMonitorService.exe -> [Ver = | Size = 24576 bytes | Modified Date = 28.10.2002 15:51:08 | Attr = ] (WOTASKD5) Apple WebObjects Task Daemon 5 [Win32_Own | Auto | Running] -> %SystemDrive%\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe -> [Ver = | Size = 24576 bytes | Modified Date = 28.10.2002 15:51:08 | Attr = ] [Registry - Non-Microsoft Only] < Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AdaptecDirectCD -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe -> Roxio [Ver = 5.3.5.10 | Size = 684032 bytes | Modified Date = 26.03.2003 12:15:24 | Attr = ] Adobe Photo Downloader -> %ProgramFiles%\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.50878 | Size = 57344 bytes | Modified Date = 23.06.2005 21:33:00 | Attr = ] ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> ATI Technologies, Inc. [Ver = 6.13.10.3022 | Size = 290816 bytes | Modified Date = 14.08.2002 18:29:38 | Attr = ] CARPService -> %System32%\carpserv.exe -> Conexant Systems, Inc. [Ver = 6.02.05 | Size = 4608 bytes | Modified Date = 21.05.2003 15:35:50 | Attr = ] Cpqset -> %ProgramFiles%\HPQ\Default Settings\Cpqset.exe -> [Ver = | Size = 196670 bytes | Modified Date = 05.10.2003 19:28:32 | Attr = ] Display Settings -> %ProgramFiles%\HPQ\Notebook Utilities\hptasks.exe -> Hewlett-Packard [Ver = 1, 14, 0, 3 | Size = 45056 bytes | Modified Date = 15.08.2002 07:26:10 | Attr = ] GhostStartTrayApp -> %ProgramFiles%\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe -> Symantec Corporation [Ver = 2003.775 | Size = 94208 bytes | Modified Date = 19.08.2002 12:58:38 | Attr = ] HP Software Update -> %ProgramFiles%\Hewlett-Packard\HP Software Update\HPWuSchd2.exe -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 16.02.2005 23:11:42 | Attr = ] HPHmon05 -> %System32%\hphmon05.exe -> Hewlett-Packard [Ver = 5,0,84 | Size = 483328 bytes | Modified Date = 22.05.2003 20:56:42 | Attr = ] HPHUPD05 -> %ProgramFiles%\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe -> Hewlett-Packard [Ver = 5,0,84 | Size = 49152 bytes | Modified Date = 22.05.2003 21:03:16 | Attr = ] iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 256576 bytes | Modified Date = 30.10.2006 10:36:36 | Attr = ] KernelFaultCheck -> -> File not found Nokia Connection Monitor -> %CommonProgramFiles%\Nokia\NCLTools\NclConf.exe -> Nokia Mobile Phones Ltd. [Ver = 4.00.014 | Size = 122880 bytes | Modified Date = 23.03.2001 12:08:42 | Attr = ] QT4HPOT -> %ProgramFiles%\HPQ\One-Touch\ONETOUCH.EXE -> Dritek System Inc. [Ver = 1.7.0.0 | Size = 106496 bytes | Modified Date = 13.03.2003 17:11:42 | Attr = ] QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.3 | Size = 282624 bytes | Modified Date = 25.10.2006 19:58:18 | Attr = ] SiteAdvisor -> %ProgramFiles%\SiteAdvisor\6172\SiteAdv.exe -> McAfee, Inc. [Ver = 2.3.0 | Size = 36904 bytes | Modified Date = 17.01.2007 21:24:46 | Attr = ] SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_01\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 83608 bytes | Modified Date = 14.03.2007 03:43:44 | Attr = ] SynTPEnh -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> Synaptics, Inc. [Ver = 7.5.3 22May03 | Size = 610304 bytes | Modified Date = 23.05.2003 00:06:00 | Attr = ] SynTPLpr -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> Synaptics, Inc. [Ver = 7.5.3 22May03 | Size = 110592 bytes | Modified Date = 22.05.2003 23:10:00 | Attr = ] TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.1622 | Size = 151597 bytes | Modified Date = 06.04.2004 17:25:46 | Attr = ] < OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL -> Installed = 1 -> MAPI -> Installed = 1 -> MSFS -> Installed = 1 -> < Common Startup > -> C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage -> %AllUsersStartup%\Lancement rapide d'Adobe Reader.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Modified Date = 23.09.2005 23:05:26 | Attr = ] %AllUsersStartup%\Pasteboard Server.lnk -> %SystemDrive%\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe -> [Ver = | Size = 222208 bytes | Modified Date = 11.10.2002 18:47:32 | Attr = ] %AllUsersStartup%\Start ASAS Client.lnk -> %ProgramFiles%\Arpage\ASAS3\client\asasc.exe -> Arpage AG [Ver = 3.3.4.0 | Size = 163943 bytes | Modified Date = 10.09.2007 14:14:38 | Attr = ] %AllUsersStartup%\VPN Client.lnk -> %SystemRoot%\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico -> [Ver = | Size = 6144 bytes | Modified Date = 10.12.2004 10:24:48 | Attr = R ] %AllUsersStartup%\Window Server.lnk -> %SystemDrive%\Apple\Library\System\WindowServer.exe -> [Ver = | Size = 1748586 bytes | Modified Date = 03.11.1999 11:43:52 | Attr = ] %AllUsersStartup%\WinZip Quick Pick.lnk -> %ProgramFiles%\WinZip\WZQKPICK.EXE -> WinZip Computing, Inc. [Ver = 1.0 (32-bit) | Size = 118784 bytes | Modified Date = 17.12.2004 10:00:00 | Attr = ] < User Startup > -> E:\see\Menu Démarrer\Programmes\Démarrage -> %UserStartup%\asasc.lnk -> %ProgramFiles%\Arpage\ASAS3\client\asasc.exe -> Arpage AG [Ver = 3.3.4.0 | Size = 163943 bytes | Modified Date = 10.09.2007 14:14:38 | Attr = ] < SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\RUN\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{17492023-C23A-453E-A040-C7C580BBF700} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\UNINSTALL\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WINDOWSUPDATE\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp\ -> -> < CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < HOSTS File > (792 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 127.0.0.1 localhost -> -> < Internet Explorer Settings > -> -> HKLM: Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKLM: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKLM: Local Page -> %SystemRoot%\system32\blank.htm -> HKLM: Search Bar -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKLM: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKCU: Local Page -> C:\WINDOWS\system32\blank.htm -> HKCU: Search Bar -> http://red.clientapps.yahoo.com/customize/.../search/ie.html -> HKCU: Search Page -> http://red.clientapps.yahoo.com/customize/...//www.yahoo.com -> HKCU: Start Page -> about:blank -> HKCU: ProxyEnable -> 0 -> < BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 59032 bytes | Modified Date = 18.12.2006 05:16:42 | Attr = ] {089FD14D-132B-48FC-8861-0048AE113215} [HKLM] -> %ProgramFiles%\SiteAdvisor\6172\SiteAdv.dll [Reg Data - Value does not exist] -> [Ver = | Size = 910624 bytes | Modified Date = 13.08.2007 20:05:04 | Attr = ] {22BF413B-C6D2-4d91-82A9-A0F997BA588C} [HKLM] -> %ProgramFiles%\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [skype add-on (mastermind)] -> Skype Technologies S.A. [Ver = 2, 2, 0, 98 | Size = 1062184 bytes | Modified Date = 02.07.2007 17:10:58 | Attr = ] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [sSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 14.03.2007 03:43:40 | Attr = ] {7DB2D5A0-7241-4E79-B68D-6309F01C5231} [HKLM] -> %ProgramFiles%\McAfee\virusscan\scriptcl.dll [scriptproxy] -> McAfee, Inc. [Ver = VSCORE.13.3.2.101.x86 | Size = 67136 bytes | Modified Date = 22.12.2006 17:02:40 | Attr = ] {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\googletoolbar1.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 11.05.2007 16:22:58 | Attr = R ] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 2, 0, 301, 7164 | Size = 325048 bytes | Modified Date = 06.07.2007 10:01:16 | Attr = ] < Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found < Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {0BF43445-2F28-4351-9252-17FE6E806AA0} [HKLM] -> %ProgramFiles%\SiteAdvisor\6172\SiteAdv.dll [McAfee SiteAdvisor] -> [Ver = | Size = 910624 bytes | Modified Date = 13.08.2007 20:05:04 | Attr = ] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 11.05.2007 16:22:58 | Attr = R ] < Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 11.05.2007 16:22:58 | Attr = R ] < Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 14.03.2007 03:43:42 | Attr = ] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 14.03.2007 03:43:40 | Attr = ] {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -> Reg Data - Value does not exist [buttonText: Create Mobile Favorite] -> File not found {77BF5300-1474-4EC7-9980-D32B190E9B07} -> Reg Data - Value does not exist [buttonText: Skype] -> File not found {85d1f590-48f4-11d9-9669-0800200c9a66} [HKLM] -> Reg Data - Key not found [MenuText: Uninstall BitDefender Online Scanner v8] -> File not found {e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found < User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> sv1 -> -> < DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {175DD31B-F68D-47F5-969F-DAA405BF22F5} -> (Carte réseau 1394) -> {21D40329-A754-49CD-87A6-D56A46312D1C} -> () -> {8FEF849F-2829-494B-B497-5A89C0379D81} -> (Carte réseau 1394) -> {F5CD2440-7466-4A23-8128-AA83635699DA} -> (Carte réseau 1394) -> {F87A7DD4-A470-4733-93EC-DEC1493A36E7} -> (Windows Mobile-based Device) -> < Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp -> Reg Data - Key not found -> File not found mctp -> %ProgramFiles%\Microsoft ActiveSync\aatp.dll -> File not found msdaipp -> Reg Data - Key not found -> File not found siteadvisor -> %ProgramFiles%\SiteAdvisor\6172\SiteAdv.dll -> [Ver = | Size = 910624 bytes | Modified Date = 13.08.2007 20:05:04 | Attr = ] skype4com -> %CommonProgramFiles%\Skype\Skype4COM.dll -> Skype Technologies [Ver = 1, 0, 27, 1 | Size = 1828440 bytes | Modified Date = 02.07.2007 17:10:58 | Attr = R ] < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {17492023-C23A-453E-A040-C7C580BBF700} -> Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=48835 -> {493ACF15-5CD9-4474-82A6-91670C3DD66E} -> LinkedIn ContactFinderControl - CodeBase = http://www.linkedin.com/cab/LinkedInContactFinderControl.cab -> {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} -> MUCatalogWebControl Class - CodeBase = http://catalog.update.microsoft.com/v7/sit...b?1187623321333 -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> BDSCANONLINE Control - CodeBase = http://www.zebulon.fr/scan8/oscan8.cab -> {6414512B-B978-451D-A0D8-FCFDF33E833C} -> WUWebControl Class - CodeBase = http://www.update.microsoft.com/windowsupd...b?1190708020199 -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdat...b?1124267662289 -> {74D05D43-3236-11D4-BDCD-00C04F9A3B61} -> HouseCall Control - CodeBase = http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab -> {82774781-8F4E-11D1-AB1C-0000F8773BF0} -> DLC Class - CodeBase = https://transfers.ds.microsoft.com/FTM/Tran...ransferCtrl.cab -> {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -> HardwareDetection Control - CodeBase = http://config.zebulon.fr/plugins/hardwaredetection.cab -> {8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -> {9F1C11AA-197B-4942-BA54-47A8489BB47F} -> - CodeBase = http://v4.windowsupdate.microsoft.com/CAB/...8020.0817013889 -> {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} -> a-squared Scanner - CodeBase = http://ax.emsisoft.com/asquared.cab -> {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} -> Java Plug-in 1.4.1_01 - CodeBase = http://java.sun.com/products/plugin/autodl...indows-i586.cab -> {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_11 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -> {D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab -> Microsoft XML Parser for Java -> - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab -> [Registry - Additional Scans - Non-Microsoft Only] < Security Settings > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> Rpcss; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfère des fichiers en tâche de fond en utilisant la bande passante du réseau lors de ses périodes d'inactivité. Si le service est arrêté, des fonctionnalités telles que Windows Update et MSN Explorer ne pourront plus télécharger automatiquement des programmes et d'autres informations. Si ce service est désactivé, tous les services qui en dépendent explicitement peuvent présenter des problèmes de transfert de fichiers s'ils ne disposent pas d'un mécanisme sûr de remplacement pour transférer les fichier -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\System32\qmgr.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Pare-feu Windows / Partage de connexion Internet -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Assure la traduction d'adresses de réseau, l'adressage, les services de résolution de noms et/ou les services de prévention d'intrusion pour un réseau de petite entreprise ou un réseau domestique. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 5154 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ -> -> Key not found -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{0C54C6BA-AC8B-44B8-A17F-CC2A05A68EE4} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{E36774A2-4255-49DD-A225-875A95A6DD06} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{8FEF849F-2829-494B-B497-5A89C0379D81} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{AC3761FD-EF4A-41B6-8FDC-36C1300D424C} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{F5CD2440-7466-4A23-8128-AA83635699DA} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation des mises à jour Windows. Si ce service est désactivé, cet ordinateur ne pourra pas utiliser la fonctionnalité des mises à jour automatiques ou le site Windows Update. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\system32\wuauserv.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> < Software Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Netlogon\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ErrorReporting\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ErrorReporting\OLAP Server\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ErrorReporting\OLAP Server\\DWAllowHeadless -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\EnableAdminTSRemote -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\NetCache\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\ExecutableTypes -> ADE;ADP;BAS;BAT;CHM;CMD;COM;CPL;CRT;EXE;HLP;HTA;INF;INS;ISP;LNK;MDB;MDE;MSC;MSI;MSP;MST;OCX;PCD;PIF;REG;SCR;SHS;URL;VB;WSC; -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\TransparentEnabled -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\DefaultLevel -> 262144 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\AuthenticodeEnabled -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\PolicyScope -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\Description -> Stop the download of this file -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\FriendlyName -> Mdac11.cab -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\SaferFlags -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\HashAlg -> 32771 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemData -> ^«0O•zI‰j HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\LastModified -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemSize -> ; -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\Description -> Stop the download of this file -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\FriendlyName -> mdac20.cab -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\SaferFlags -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\HashAlg -> 32771 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemData -> g°Ô‹4:?Ó¼éÜdgó” -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\LastModified -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemSize -> ; -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\Description -> Stop the download of this file -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\FriendlyName -> mdac20_a.cab -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\SaferFlags -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\HashAlg -> 32771 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemData -> 2xÜþøÈ“ÜŠ°Ý„} -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\LastModified -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemSize -> –; -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\Description -> Stop the download of this file -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\FriendlyName -> _msadc10.cab -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\SaferFlags -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\HashAlg -> 32771 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemData -> ½š*ÛBëØV%Mø/g -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\LastModified -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemSize -> å; -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\Description -> Stop the download of this file -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\FriendlyName -> msadc11.cab -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\SaferFlags -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\HashAlg -> 32771 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemData -> 8k_„ìöiÓk•j"À€ -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\LastModified -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemSize -> r; -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\Description -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\SaferFlags -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\ItemData -> %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\LastModified -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Windows Update\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\Terminal Services\ -> -> < Software Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\policies\ -> HKEY_CURRENT_USER\Software\Policies\ -> -> HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> -> < Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> {0001040C-78E1-11D2-B60F-006097C998E7} -> Microsoft Office 2000 SR-1 Professional -> {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} -> PDFCreator 0.8.0 -> {01546E14-7DE6-4F4B-962A-64DEDA5325C0} -> Sony Ericsson OCS -> {0A869A65-8C94-4F7C-A5C7-972D3C8CED9E} -> MSXML 6.0 Parser (KB933579) -> {0BEDBD4E-2D34-47B5-9973-57E62B29307C} -> ATI Control Panel -> {0DAA9912-3FE2-4B84-B926-8D7F71A8A99A} -> Microsoft SQL Server 2005 Reporting Services (SQLEXPRESS) -> {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} -> Security Update for CAPICOM (KB931906) -> {0F211D27-C463-43A9-9B8A-12CA8D6D90DE} -> Paint Shop Pro 7 -> {1389C6A4-4965-4AEC-9175-08B54A10FA48} -> Microsoft SQL Server 2005 Mobile [ENU] Developer Tools -> {142E4006-B557-498F-B5E1-D6B309D92166} -> Debugging Tools for Windows (3790.0) -> {14CCB6D9-7D38-4555-AF95-457C44E65473} -> Microsoft Analysis Services Samples (Updated - SP3) -> {14E1009D-0C87-4191-BC8B-ADE524B6EDA8} -> Microsoft SQL Server 2005 Books Online (English) (July 2006) -> {15EE79F4-4ED1-4267-9B0F-351009325D7D} -> HP Software Update -> {1666FA7C-CB5F-11D6-A78C-00B0D079AF64} -> Java 2 Runtime Environment, SE v1.4.1_01 -> {1666FA7F-CB5F-11D6-A78C-00B0D079AF64} -> Java 2 SDK, SE v1.4.1_01 -> {16EA4488-EFFB-4F19-9730-88C528824B29} -> .NET Compact Framework-based Form Stack Sample -> {1CBE3804-20DF-48DA-B048-895C206E80A5} -> Microsoft SQL Server VSS Writer -> {1E5007FA-DA5E-4EDD-BDE5-14D128D66887} -> PowerQuest PartitionMagic 7.0 -> {20608BFA-6068-48FE-A410-400F2A124C27} -> Microsoft SQL Server Management Studio Express -> {2318C2B1-4965-11d4-9B18-009027A5CD4F} -> Google Toolbar for Internet Explorer -> {2373A92B-1C1C-4E71-B494-5CA97F96AA19} -> Microsoft SQL Server 2005 (SQLEXPRESS) -> {23959E96-A80F-4172-A655-210E9BB7BFBE} -> MSDN Library for Visual Studio 2005 -> {26235B9B-6EEF-4E13-A2D5-7FDE4A2DA9FE} -> 3M Connections Plus -> {2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1} -> HpSdpAppCoreApp -> {2A9369BF-1EC6-43EB-993E-89D169DB85CA} -> Sony Ericsson Image Editor -> {2ABD5914-4F3F-4A34-A313-A7182901733E} -> HardwareDetection -> {2DC0FF1E-F6E3-4D12-BA61-2AA758DB51F4} -> Windows Installer SDK (Version 2.0) (3790.0) -> {3248F0A8-6813-11D6-A77B-00B0D0150110} -> J2SE Runtime Environment 5.0 Update 11 -> {3248F0A8-6813-11D6-A77B-00B0D0160010} -> Java SE Runtime Environment 6 Update 1 -> {32A3A4F4-B792-11D6-A78A-00B0D0150110} -> J2SE Development Kit 5.0 Update 11 -> {350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP -> {35A3A4F4-B792-11D6-A78A-00B0D0142080} -> Java 2 SDK, SE v1.4.2_08 -> {37477865-A3F1-4772-AD43-AAFC6BCFF99F} -> MSXML 4.0 SP2 (KB927978) -> {39FE919A-05B2-4AFC-8E12-F49DF0432CED} -> DameWareClient -> {3D49A2B7-04B3-451A-A1EF-3B0D3C297DD5} -> Sony Ericsson Mobile Phone Monitor -> {3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6} -> Cisco Systems VPN Client 4.0.3 (D) -> {407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B} -> Google Earth -> {42D06ADD-A13D-4F59-8A67-ECA943464429} -> Sony Ericsson Sync Station -> {437AB8E0-FB69-4222-B280-A64F3DE22591} -> Microsoft Visual Studio 2005 Professional Edition - ENU -> {43DCF766-6838-4F9A-8C91-D92DA586DFA7} -> Visionneuse Journal Windows Microsoft -> {44120EB1-EC80-41B1-A46F-6B8BD60F49E3} -> PC Suite -> {446DBFFA-4088-48E3-8932-74316BA4CAE4} -> iTunes -> {44D4AF75-6870-41F5-9181-662EA05507E1} -> Microsoft Document Explorer 2005 -> {45B6180B-DCAB-4093-8EE8-6164457517F0} -> Photosmart 140,240,7200,7600,7700,7900 Series -> {4BDFD2CE-6329-42E4-9801-9B3D1F10D79B} -> Adobe® Photoshop® Album Edition Découverte 3.0 -> {50D8FFDD-90CD-4859-841F-AA1961C7767A} -> QuickTime -> {53F5C3EE-05ED-4830-994B-50B2F0D50FCE} -> Microsoft SQL Server Setup Support Files (English) -> {57986526-077F-4604-BED7-4E44A5372732} -> Sony Ericsson File Manager -> {5C82DAE5-6EB0-4374-9254-BE3319BA4E82} -> Skype™ 3.2 -> {609F7AC8-C510-11D4-A788-009027ABA5D0} -> Easy CD Creator 5 Basic -> {625386A4-B6B6-4911-A6E8-23189C3F2D15} -> Microsoft .NET Compact Framework 2.0 -> {63569CE9-FA00-469C-AF5C-E5D4D93ACF91} -> Windows Genuine Advantage v1.3.0254.0 -> {638C1D72-FFAD-4EC3-B1AD-ABA96BB15B0B} -> Introduction to Visual Basic 2005 -> {63A68338-16A3-4763-8478-A45F91A61E7A} -> Orca -> {654EF90B-6DAD-4734-B6F0-F56AF7F2B1A0} -> Microsoft Visual Studio 2005 SDK April 2006 -> {68249B6E-B714-11D7-88E8-0050DA21757E} -> Environnement d'exécution Java 2, Standard Edition v1.3.1_10 -> {68A35043-C55A-4237-88C9-37EE1C63ED71} -> Microsoft Visual J# 2.0 Redistributable Package -> {6975E810-C92F-45F0-0BFD-187B312F10E8} -> Norton Ghost -> {69880C00-08DD-4385-B752-9C62656F6D1E} -> Microsoft SQL Server 2005 Backward compatibility -> {6C531060-84FB-4F96-8F33-29DF020632EB} -> Microsoft .NET Compact Framework 1.0 SP3 Developer -> {6E5256B1-43FC-4ED7-91A7-4248F8C398CB} -> Windows Mobile 5.0 Developer Resource Kit -> {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} -> Microsoft .NET Framework 2.0 -> {7148F0A8-6813-11D6-A77B-00B0D0142080} -> Java 2 Runtime Environment, SE v1.4.2_08 -> {78B75C6D-E53C-424C-BF83-4B63BD4A6682} -> Microsoft Device Emulator version 1.0 - ENU -> {7BBD57D6-09B1-4CC3-9664-A0D53EE25247} -> PSShortcutsP -> {7D95B533-4BA1-4EED-8096-EFCB6DD6B95F} -> AdventureWorksDB -> {7FC0D670-057F-4D50-A7B8-2CA291360708} -> Common Setup Files (3790.0) -> {830B105A-40FA-4D9B-992A-44E4D1BE0D2F} -> SocketScan Software -> {8FB7C528-035E-4B6F-AB6A-9AF3121E73B9} -> DameWare Mini Remote Control -> {90032DD0-ABEE-4424-AC1E-B076BDD4E350} -> Microsoft SQL Server 2005 Tools -> {90A40409-6000-11D3-8CFE-0150048383C9} -> Microsoft Office 2003 Web Components -> {911A040C-6000-11D3-8CFE-0050048383C9} -> Microsoft Outlook 2002 -> {949DBB22-2FB7-4de1-804C-23D495A988D8} -> CuteFTP 8 Home -> {96539822-B716-11D7-88E8-0050DA21757E} -> Java 2 SDK Standard Edition v1.3.1_10 -> {982DB00A-9C4E-436B-8707-18E113BAA44C} -> Microsoft SQL Server 2005 Analysis Services (SQLEXPRESS) -> {98E8A2EF-4EAE-43B8-A172-74842B764777} -> InterVideo WinDVD -> {99ECD770-082D-4771-BFE8-1B79D3CA6ED9} -> 3M CaseMix Expert -> {9F749993-8E29-48A8-BEE7-8398BEBD1B59} -> Sony Ericsson MMS Home Studio -> {A1795AC0-9B6A-40D9-8E07-A82662268D9F} -> Virtual Machine Network Services Driver -> {A50C25D7-62E9-4511-AD70-8E2DA5E79B7D} -> Apple Software Update -> {A8F2DCDE-AE4E-4AC9-BECD-496FB80FBF6A} -> Notebook Utilities -> {A9CF9052-F4A0-475D-A00F-A8388C62DD63} -> MSXML 4.0 SP2 (KB925672) -> {ABB6AC00-F1D8-4EBF-8128-830D090B76C0} -> Microsoft SQL Server 2000 Sample Database Scripts -> {AC76BA86-7AD7-1036-7B44-A70900000002} -> Adobe Reader 7.0.9 - Français -> {AE314E8E-2514-4F04-8496-F90F65B382DF} -> Core SDK (Windows Server 2003) (3790.0) -> {AF623729-4A2A-4CE9-BDD7-A66B28E316B0} -> Microsoft Visual Studio 2005 SDK Power Toys -> {B208806F-A231-4FA0-AB3F-5C1B8979223E} -> Microsoft ActiveSync 4.0 -> {B7A70AF7-C412-4972-A5F8-B241A437ACFD} -> Innovasys HelpStudio Lite -> {BC98294D-DCC5-4BCF-A734-D0C1618DC2D2} -> Windows Mobile 5.0 Pocket PC SDK -> {C04E32E0-0416-434D-AFB9-6969D703A9EF} -> MSXML 4.0 SP2 (KB936181) -> {C06F36B6-6D08-452A-BF41-29C5AAB7BE2E} -> Sony Ericsson Capability Manager -> {C1446F2B-8B97-45AC-89A7-C40BE59284B8} -> Emulator Driver for Visual Studio .NET 2003 -> {C2C9528A-289B-11D5-A54A-0090278A1BB8} -> Microsoft FrontPage Client - French -> {CC140072-0A89-4C7B-BFD1-14A193AA76AE} -> Sony Ericsson Sound Editor -> {CC697D78-8983-4427-9398-F7607F7F2790} -> Visual Studio.NET Baseline - French -> {D37C6152-89DF-4D29-83CF-666200D5F398} -> iPAQ WebReg -> {D6BE7113-21D0-44E2-A576-8FCAB9EF5CB7} -> Expresso -> {DBEA1034-5882-4A88-8033-81C4EF0CFA29} -> Google Toolbar for Internet Explorer -> {DCA2E540-DB44-11D3-8456-00A0C9F1380D} -> WebObjects 5.2.4 -> {DDF6E319-BCD9-4FE3-9D69-26B2F47BEF7C} -> Microsoft SQL Server 2005 Samples -> {ED2943EB-230C-44FB-8778-C1C784B49B37} -> Developer Resources for Windows Mobile 2003 Second Edition -> {EDFBD8E7-CDC1-4FA7-A477-9E8E57AF4F9E} -> Nokia PC Suite 4.06 -> {F1614CF8-6B0D-4812-89C4-ED04F04E60D4} -> Sony Ericsson Mobile Networking Wizard -> {F419D20A-7719-4639-8E30-C073A040D878} -> HP Deskjet Preloaded Printer Drivers -> {F9B3DD02-B0B3-42E9-8650-030DFF0D133D} -> Microsoft SQL Server Native Client -> {FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F} -> Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP -> Adobe Acrobat 5.0 -> Adobe Acrobat 5.0 -> ATI Display Driver -> ATI Display Driver -> CNXT_MODEM_PCI_VEN_10B9&DEV_5457&SUBSYS_0850103C -> Conexant 56K ACLink Modem -> Conexant PCI Audio -> Conexant AC-Link Audio -> Free CD to MP3 Converter -> Free CD to MP3 Converter -> HijackThis -> HijackThis 2.0.2 -> HTML Help Workshop -> HTML Help Workshop -> IDNMitigationAPIs -> Microsoft Internationalized Domain Names Mitigation APIs -> ie7 -> Windows Internet Explorer 7 -> InstallShield_{99ECD770-082D-4771-BFE8-1B79D3CA6ED9} -> 3M CaseMix Expert - Swiss v2.4 Standalone -> KB834707 -> Correctif Windows XP - KB834707 -> KB867282 -> Correctif Windows XP - KB867282 -> KB870669 -> Microsoft Data Access Components KB870669 -> KB873333 -> Correctif Windows XP - KB873333 -> KB873339 -> Correctif Windows XP - KB873339 -> KB883939 -> Mise à jour de sécurité pour Windows XP (KB883939) -> KB884020 -> Correctif Windows XP - KB884020 -> KB885250 -> Correctif Windows XP - KB885250 -> KB885835 -> Correctif Windows XP - KB885835 -> KB885836 -> Correctif Windows XP - KB885836 -> KB885884 -> Correctif Windows XP - KB885884 -> KB886185 -> Correctif Windows XP - KB886185 -> KB887472 -> Correctif Windows XP - KB887472 -> KB887742 -> Correctif Windows XP - KB887742 -> KB888113 -> Correctif Windows XP - KB888113 -> KB888302 -> Correctif Windows XP - KB888302 -> KB890046 -> Mise à jour de sécurité pour Windows XP (KB890046) -> KB890047 -> Correctif Windows XP - KB890047 -> KB890175 -> Correctif Windows XP - KB890175 -> KB890859 -> Correctif Windows XP - KB890859 -> KB890923 -> Correctif Windows XP - KB890923 -> KB890927 -> Hotfix for Windows XP (KB890927) -> KB891781 -> Correctif Windows XP - KB891781 -> KB893066 -> Correctif Windows XP - KB893066 -> KB893086 -> Correctif Windows XP - KB893086 -> KB893756 -> Mise à jour de sécurité pour Windows XP (KB893756) -> KB893803 -> Windows Installer 3.1 (KB893803) -> KB893803v2 -> Windows Installer 3.1 (KB893803) -> KB894391 -> Mise à jour pour Windows XP (KB894391) -> KB894476 -> Windows Media Player 10 Hotfix - KB894476 -> KB896358 -> Mise à jour de sécurité pour Windows XP (KB896358) -> KB896422 -> Mise à jour de sécurité pour Windows XP (KB896422) -> KB896423 -> Mise à jour de sécurité pour Windows XP (KB896423) -> KB896424 -> Mise à jour de sécurité pour Windows XP (KB896424) -> KB896428 -> Mise à jour de sécurité pour Windows XP (KB896428) -> KB896688 -> Mise à jour de sécurité pour Windows XP (KB896688) -> KB896727 -> Mise à jour pour Windows XP (KB896727) -> KB898458 -> Mise à jour de sécurité pour Step by Step Interactive Training (KB898458) -> KB898461 -> Mise à jour pour Windows XP (KB898461) -> KB899587 -> Mise à jour de sécurité pour Windows XP (KB899587) -> KB899588 -> Mise à jour de sécurité pour Windows XP (KB899588) -> KB899589 -> Mise à jour de sécurité pour Windows XP (KB899589) -> KB899591 -> Mise à jour de sécurité pour Windows XP (KB899591) -> KB900485 -> Mise à jour pour Windows XP (KB900485) -> KB900725 -> Mise à jour de sécurité pour Windows XP (KB900725) -> KB900930 -> Mise à jour pour Windows XP (KB900930) -> KB901017 -> Mise à jour de sécurité pour Windows XP (KB901017) -> KB901190 -> Mise à jour de sécurité pour Windows XP (KB901190) -> KB901214 -> Mise à jour de sécurité pour Windows XP (KB901214) -> KB902400 -> Mise à jour de sécurité pour Windows XP (KB902400) -> KB903235 -> Mise à jour de sécurité pour Windows XP (KB903235) -> KB904706 -> Mise à jour de sécurité pour Windows XP (KB904706) -> KB904942 -> Mise à jour pour Windows XP (KB904942) -> KB905414 -> Mise à jour de sécurité pour Windows XP (KB905414) -> KB905749 -> Mise à jour de sécurité pour Windows XP (KB905749) -> KB905915 -> Mise à jour de sécurité pour Windows XP (KB905915) -> KB908519 -> Mise à jour de sécurité pour Windows XP (KB908519) -> KB908531 -> Mise à jour de sécurité pour Windows XP (KB908531) -> KB909394 -> Hotfix for Windows XP (KB909394) -> KB910437 -> Mise à jour pour Windows XP (KB910437) -> KB911280 -> Mise à jour de sécurité pour Windows XP (KB911280) -> KB911562 -> Mise à jour de sécurité pour Windows XP (KB911562) -> KB911564 -> Mise à jour de sécurité pour Lecteur Windows Media (KB911564) -> KB911565 -> Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565) -> KB911567 -> Mise à jour de sécurité pour Windows XP (KB911567) -> KB911927 -> Mise à jour de sécurité pour Windows XP (KB911927) -> KB912812 -> Mise à jour de sécurité pour Windows XP (KB912812) -> KB912919 -> Mise à jour de sécurité pour Windows XP (KB912919) -> KB913446 -> Mise à jour de sécurité pour Windows XP (KB913446) -> KB913580 -> Mise à jour de sécurité pour Windows XP (KB913580) -> KB914388 -> Mise à jour de sécurité pour Windows XP (KB914388) -> KB914389 -> Mise à jour de sécurité pour Windows XP (KB914389) -> KB914440 -> Correctif pour Windows XP (KB914440) -> KB915865 -> Hotfix for Windows XP (KB915865) -> KB916281 -> Mise à jour de sécurité pour Windows XP (KB916281) -> KB916595 -> Mise à jour pour Windows XP (KB916595) -> KB917159 -> Mise à jour de sécurité pour Windows XP (KB917159) -> KB917344 -> Mise à jour de sécurité pour Windows XP (KB917344) -> KB917422 -> Mise à jour de sécurité pour Windows XP (KB917422) -> KB917537 -> Mise à jour de sécurité pour Windows XP (KB917537) -> KB917734_WMP10 -> Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734) -> KB917953 -> Mise à jour de sécurité pour Windows XP (KB917953) -> KB918118 -> Mise à jour de sécurité pour Windows XP (KB918118) -> KB918439 -> Mise à jour de sécurité pour Windows XP (KB918439) -> KB918899 -> Mise à jour de sécurité pour Windows XP (KB918899) -> KB919007 -> Mise à jour de sécurité pour Windows XP (KB919007) -> KB920213 -> Mise à jour de sécurité pour Windows XP (KB920213) -> KB920214 -> Mise à jour de sécurité pour Windows XP (KB920214) -> KB920670 -> Mise à jour de sécurité pour Windows XP (KB920670) -> KB920683 -> Mise à jour de sécurité pour Windows XP (KB920683) -> KB920685 -> Mise à jour de sécurité pour Windows XP (KB920685) -> KB920872 -> Mise à jour pour Windows XP (KB920872) -> KB921398 -> Mise à jour de sécurité pour Windows XP (KB921398) -> KB921503 -> Mise à jour de sécurité pour Windows XP (KB921503) -> KB921883 -> Mise à jour de sécurité pour Windows XP (KB921883) -> KB922582 -> Mise à jour pour Windows XP (KB922582) -> KB922616 -> Mise à jour de sécurité pour Windows XP (KB922616) -> KB922760 -> Mise à jour de sécurité pour Windows XP (KB922760) -> KB922819 -> Mise à jour de sécurité pour Windows XP (KB922819) -> KB923191 -> Mise à jour de sécurité pour Windows XP (KB923191) -> KB923414 -> Mise à jour de sécurité pour Windows XP (KB923414) -> KB923689 -> Mise à jour de sécurité pour Windows XP (KB923689) -> KB923694 -> Mise à jour de sécurité pour Windows XP (KB923694) -> KB923723 -> Mise à jour de sécurité pour Step by Step Interactive Training (KB923723) -> KB923980 -> Mise à jour de sécurité pour Windows XP (KB923980) -> KB924191 -> Mise à jour de sécurité pour Windows XP (KB924191) -> KB924270 -> Mise à jour de sécurité pour Windows XP (KB924270) -> KB924496 -> Mise à jour de sécurité pour Windows XP (KB924496) -> KB924667 -> Mise à jour de sécurité pour Windows XP (KB924667) -> KB925398_WMP64 -> Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398) -> KB925486 -> Mise à jour de sécurité pour Windows XP (KB925486) -> KB925674.T2_29ToU275_29 -> Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB925674) -> KB925902 -> Mise à jour de sécurité pour Windows XP (KB925902) -> KB926255 -> Mise à jour de sécurité pour Windows XP (KB926255) -> KB926436 -> Mise à jour de sécurité pour Windows XP (KB926436) -> KB927779 -> Mise à jour de sécurité pour Windows XP (KB927779) -> KB927802 -> Mise à jour de sécurité pour Windows XP (KB927802) -> KB927891 -> Mise à jour pour Windows XP (KB927891) -> KB928090-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090) -> KB928255 -> Mise à jour de sécurité pour Windows XP (KB928255) -> KB928365.T1_1ToU569_1 -> Security Update pour Microsoft .NET Framework 2.0 (KB928365) -> KB928843 -> Mise à jour de sécurité pour Windows XP (KB928843) -> KB929123 -> Mise à jour de sécurité pour Windows XP (KB929123) -> KB929338 -> Mise à jour pour Windows XP (KB929338) -> KB929969 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969) -> KB930178 -> Mise à jour de sécurité pour Windows XP (KB930178) -> KB930916 -> Mise à jour pour Windows XP (KB930916) -> KB931261 -> Mise à jour de sécurité pour Windows XP (KB931261) -> KB931768-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768) -> KB931784 -> Mise à jour de sécurité pour Windows XP (KB931784) -> KB931836 -> Mise à jour pour Windows XP (KB931836) -> KB931906 -> Security Update for CAPICOM (KB931906) -> KB932168 -> Mise à jour de sécurité pour Windows XP (KB932168) -> KB932557_OLAP9 -> GDR 1406 for SQL Server Analysis Services 2005 ENU (KB932557) -> KB932557_SQL9 -> GDR 1406 for SQL Server Database Services 2005 ENU (KB932557) -> KB932557_SQLTools9 -> GDR 1406 for SQL Server Tools and Workstation Components 2005 ENU (KB932557) -> KB933566-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566) -> KB935839 -> Mise à jour de sécurité pour Windows XP (KB935839) -> KB935840 -> Mise à jour de sécurité pour Windows XP (KB935840) -> KB936021 -> Mise à jour de sécurité pour Windows XP (KB936021) -> KB936357 -> Mise à jour pour Windows XP (KB936357) -> KB936782_WMP10 -> Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782) -> KB937143-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143) -> KB938127-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127) -> KB938828 -> Mise à jour pour Windows XP (KB938828) -> KB938829 -> Mise à jour de sécurité pour Windows XP (KB938829) -> KB939373 -> Mise à jour de sécurité pour Windows XP (KB939373) -> LiveReg -> LiveReg (Symantec Corporation) -> LiveUpdate -> LiveUpdate 1.80 (Symantec Corporation) -> LMS -> C-Dilla Licence Management System -> Macromedia Shockwave Player -> Macromedia Shockwave Player -> Microsoft .NET Framework 2.0 -> Microsoft .NET Framework 2.0 -> Microsoft Developer Network - Visual Studio 6.0a -> MSDN Library - Visual Studio 6.0a -> Microsoft Document Explorer 2005 -> Microsoft Document Explorer 2005 -> Microsoft SDK Update -> Microsoft SDK Update February 2003 (5.2.3790.0) -> Microsoft SQL Server 2000 -> Microsoft SQL Server 2000 -> Microsoft SQL Server 2000 Analysis Services -> Microsoft SQL Server 2000 Analysis Services -> Microsoft SQL Server 2005 -> Microsoft SQL Server 2005 -> Microsoft Visual J# 2.0 Redistributable Package -> Microsoft Visual J# 2.0 Redistributable Package -> Microsoft Visual Studio 2005 Professional Edition - ENU -> Microsoft Visual Studio 2005 Professional Edition - ENU -> MSC -> McAfee SecurityCenter -> MSDN Library for Visual Studio 2005 -> MSDN Library for Visual Studio 2005 -> NLSDownlevelMapping -> Microsoft National Language Support Downlevel APIs -> QT4HPOT -> boutons One-Touch -> QuicktimeAlt_is1 -> QuickTime Alternative 1.31 -> RealPlayer 6.0 -> RealOne Player -> Sheridan ActiveListBar -> Sheridan ActiveListBar -> Sheridan ActiveToolBars -> Sheridan ActiveToolBars -> Sheridan ActiveTreeView -> Sheridan ActiveTreeView -> Sheridan Calendar Widgets -> Sheridan Calendar Widgets 1.07 -> ShockwaveFlash -> Adobe Flash Player 9 ActiveX -> ST6UNST #3 -> LUCID version romande avril 2002 -> SynTPDeinstKey -> Synaptics Pointing Device Driver -> TeeChart Pro v4 Activex Control -> TeeChart Pro v4 Activex Control -> VaudTax2004 -> VaudTax2004 -> VaudTax2005 -> VaudTax2005 -> Visual Studio 6.0 Enterprise Edition -> Microsoft Visual Studio 6.0 Enterprise Edition -> WebPost -> Microsoft Web Publishing Wizard 1.53 -> WGA -> Windows Genuine Advantage Validation Tool -> WgaNotify -> Windows Genuine Advantage Notifications (KB905474) -> Windows Media Format Runtime -> Windows Media Format Runtime -> Windows Media Player -> Lecteur Windows Media 10 -> Windows XP Service Pack -> Windows XP Service Pack 2 -> WinRAR archiver -> WinRAR archiver -> WinZip -> WinZip -> WinZip Self-Extractor -> WinZip Self-Extractor -> [Files/Folders - Created Within 60 days] !KillBox -> %SystemDrive%\!KillBox -> [Folder | Created Date = 20.09.2007 16:07:35 | Attr = ] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 15.08.2007 09:09:34 | Attr = HS] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1005637632 bytes | Created Date = 02.01.1601 23:00:00 | Attr = HS] $NtUninstallKB921503$ -> %SystemRoot%\$NtUninstallKB921503$ -> [Folder | Created Date = 15.08.2007 09:21:20 | Attr = H ] $NtUninstallKB936021$ -> %SystemRoot%\$NtUninstallKB936021$ -> [Folder | Created Date = 15.08.2007 09:22:25 | Attr = H ] $NtUninstallKB936782_WMP10$ -> %SystemRoot%\$NtUninstallKB936782_WMP10$ -> [Folder | Created Date = 15.08.2007 09:07:49 | Attr = H ] $NtUninstallKB938828$ -> %SystemRoot%\$NtUninstallKB938828$ -> [Folder | Created Date = 15.08.2007 09:21:52 | Attr = H ] $NtUninstallKB938829$ -> %SystemRoot%\$NtUninstallKB938829$ -> [Folder | Created Date = 15.08.2007 09:20:33 | Attr = H ] AU_Backup -> %SystemRoot%\AU_Backup -> [Folder | Created Date = 13.09.2007 14:42:16 | Attr = ] AU_Log -> %SystemRoot%\AU_Log -> [Folder | Created Date = 13.09.2007 14:41:02 | Attr = ] AU_Temp -> %SystemRoot%\AU_Temp -> [Folder | Created Date = 13.09.2007 14:41:05 | Attr = ] BDOSCAN8 -> %SystemRoot%\BDOSCAN8 -> [Folder | Created Date = 18.09.2007 08:09:59 | Attr = ] BPMNT.dll -> %SystemRoot%\BPMNT.dll -> Trend Micro Inc. [Ver = 8.000-1001 | Size = 86094 bytes | Created Date = 13.09.2007 14:42:14 | Attr = ] ERUNT -> %SystemRoot%\ERUNT -> [Folder | Created Date = 12.09.2007 12:50:14 | Attr = ] GetServer.ini -> %SystemRoot%\GetServer.ini -> [Ver = | Size = 170 bytes | Created Date = 13.09.2007 14:41:06 | Attr = ] hcextoutput.dll -> %SystemRoot%\hcextoutput.dll -> [Ver = | Size = 71749 bytes | Created Date = 13.09.2007 14:42:15 | Attr = ] LPT$VPN.717 -> %SystemRoot%\LPT$VPN.717 -> [Ver = | Size = 36765101 bytes | Created Date = 13.09.2007 14:42:41 | Attr = ] PATCH.EXE -> %SystemRoot%\PATCH.EXE -> Trend Micro Inc. [Ver = 1,81,0,1011 | Size = 286720 bytes | Created Date = 13.09.2007 14:40:55 | Attr = ] report -> %SystemRoot%\report -> [Folder | Created Date = 13.09.2007 14:42:57 | Attr = ] TMUPDATE.DLL -> %SystemRoot%\TMUPDATE.DLL -> Trend Micro Inc. [Ver = 1,81,0,1011 | Size = 507904 bytes | Created Date = 13.09.2007 14:40:56 | Attr = ] tsc.exe -> %SystemRoot%\tsc.exe -> Trend Micro Inc. [Ver = 5.3.0.1103 | Size = 267845 bytes | Created Date = 13.09.2007 14:42:15 | Attr = ] tsc.ini -> %SystemRoot%\tsc.ini -> [Ver = | Size = 823 bytes | Created Date = 13.09.2007 14:42:15 | Attr = ] tsc.ptn -> %SystemRoot%\tsc.ptn -> [Ver = | Size = 1871245 bytes | Created Date = 13.09.2007 14:42:15 | Attr = ] UNZIP.DLL -> %SystemRoot%\UNZIP.DLL -> Trend Micro Inc. [Ver = 1.32.0.1000 | Size = 69689 bytes | Created Date = 13.09.2007 14:40:55 | Attr = ] VPTNFILE.717 -> %SystemRoot%\VPTNFILE.717 -> [Ver = | Size = 36765101 bytes | Created Date = 13.09.2007 14:42:02 | Attr = ] vsapi32.dll -> %SystemRoot%\vsapi32.dll -> Trend Micro Inc. [Ver = 8.500-1002 | Size = 1163344 bytes | Created Date = 13.09.2007 14:42:14 | Attr = ] addr_file.html -> %AllUsersAppData%\addr_file.html -> [Ver = | Size = 305 bytes | Created Date = 16.09.2007 13:47:28 | Attr = ] Avira -> %AllUsersAppData%\Avira -> [Folder | Created Date = 14.09.2007 13:33:59 | Attr = ] Skype -> %AllUsersAppData%\Skype -> [Folder | Created Date = 02.08.2007 08:36:15 | Attr = ] Skype -> %UserAppData%\Skype -> [Folder | Created Date = 02.08.2007 08:37:51 | Attr = ] wsnpoem -> %UserAppData%\wsnpoem -> [Folder | Created Date = 20.08.2007 08:07:27 | Attr = HS] asas -> %UserDocuments%\asas -> [Folder | Created Date = 20.08.2007 09:11:54 | Attr = ] Skype.lnk -> %AllUsersDesktop%\Skype.lnk -> [Ver = | Size = 1870 bytes | Created Date = 02.08.2007 08:36:44 | Attr = ] 070728résumé.doc -> %UserDesktop%70728résumé.doc -> [Ver = | Size = 26624 bytes | Created Date = 30.07.2007 08:03:28 | Attr = ] SDfix -> %UserDesktop%\SDfix -> [Folder | Created Date = 12.09.2007 12:41:56 | Attr = ] Lancement rapide d'Adobe Reader.lnk -> %AllUsersStartup%\Lancement rapide d'Adobe Reader.lnk -> [Ver = | Size = 1757 bytes | Created Date = 10.09.2007 15:32:23 | Attr = ] Microsoft Office.lnk -> %AllUsersStartup%\Microsoft Office.lnk -> [Ver = | Size = 1740 bytes | Created Date = 10.09.2007 15:32:23 | Attr = ] Pasteboard Server.lnk -> %AllUsersStartup%\Pasteboard Server.lnk -> [Ver = | Size = 1794 bytes | Created Date = 10.09.2007 15:32:23 | Attr = ] Service Manager.lnk -> %AllUsersStartup%\Service Manager.lnk -> [Ver = | Size = 1852 bytes | Created Date = 10.09.2007 15:32:23 | Attr = ] Start ASAS Client.lnk -> %AllUsersStartup%\Start ASAS Client.lnk -> [Ver = | Size = 772 bytes | Created Date = 10.09.2007 15:32:23 | Attr = ] VPN Client.lnk -> %AllUsersStartup%\VPN Client.lnk -> [Ver = | Size = 2447 bytes | Created Date = 10.09.2007 15:32:23 | Attr = ] Window Server.lnk -> %AllUsersStartup%\Window Server.lnk -> [Ver = | Size = 1530 bytes | Created Date = 10.09.2007 15:32:22 | Attr = ] WinZip Quick Pick.lnk -> %AllUsersStartup%\WinZip Quick Pick.lnk -> [Ver = | Size = 1518 bytes | Created Date = 10.09.2007 15:32:22 | Attr = ] asasc.lnk -> %UserStartup%\asasc.lnk -> [Ver = | Size = 730 bytes | Created Date = 10.09.2007 15:32:22 | Attr = ] Skype -> %CommonProgramFiles%\Skype -> [Folder | Created Date = 02.08.2007 08:36:31 | Attr = ] [Files/Folders - Modified Within 60 days] !KillBox -> %SystemDrive%\!KillBox -> [Folder | Modified Date = 20.09.2007 17:07:36 | Attr = ] boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 212 bytes | Modified Date = 10.09.2007 16:30:52 | Attr = RHS] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 15.08.2007 10:36:46 | Attr = HS] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 20.08.2007 14:27:42 | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1005637632 bytes | Modified Date = 27.09.2007 08:48:00 | Attr = HS] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 20.09.2007 12:14:46 | Attr = R ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 25.09.2007 12:37:46 | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 15.08.2007 09:55:38 | Attr = H ] $NtUninstallKB921503$ -> %SystemRoot%\$NtUninstallKB921503$ -> [Folder | Modified Date = 15.08.2007 10:21:22 | Attr = H ] $NtUninstallKB936021$ -> %SystemRoot%\$NtUninstallKB936021$ -> [Folder | Modified Date = 15.08.2007 10:22:28 | Attr = H ] $NtUninstallKB936782_WMP10$ -> %SystemRoot%\$NtUninstallKB936782_WMP10$ -> [Folder | Modified Date = 15.08.2007 10:07:52 | Attr = H ] $NtUninstallKB938828$ -> %SystemRoot%\$NtUninstallKB938828$ -> [Folder | Modified Date = 15.08.2007 10:21:56 | Attr = H ] $NtUninstallKB938829$ -> %SystemRoot%\$NtUninstallKB938829$ -> [Folder | Modified Date = 15.08.2007 10:20:36 | Attr = H ] AU_Backup -> %SystemRoot%\AU_Backup -> [Folder | Modified Date = 13.09.2007 15:42:18 | Attr = ] AU_Log -> %SystemRoot%\AU_Log -> [Folder | Modified Date = 13.09.2007 15:41:04 | Attr = ] AU_Temp -> %SystemRoot%\AU_Temp -> [Folder | Modified Date = 13.09.2007 15:42:18 | Attr = ] BDOSCAN8 -> %SystemRoot%\BDOSCAN8 -> [Folder | Modified Date = 18.09.2007 15:21:56 | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 27.09.2007 08:48:02 | Attr = S] BPMNT.dll -> %SystemRoot%\BPMNT.dll -> Trend Micro Inc. [Ver = 8.000-1001 | Size = 86094 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] cdplayer.ini -> %SystemRoot%\cdplayer.ini -> [Ver = | Size = 11181 bytes | Modified Date = 09.08.2007 10:07:08 | Attr = ] CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 25.09.2007 09:51:46 | Attr = HS] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 13.09.2007 15:42:58 | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 25.09.2007 10:13:58 | Attr = S] ERUNT -> %SystemRoot%\ERUNT -> [Folder | Modified Date = 12.09.2007 14:36:50 | Attr = ] GetServer.ini -> %SystemRoot%\GetServer.ini -> [Ver = | Size = 170 bytes | Modified Date = 13.09.2007 15:41:08 | Attr = ] hcextoutput.dll -> %SystemRoot%\hcextoutput.dll -> [Ver = | Size = 71749 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 25.09.2007 10:14:34 | Attr = ] ie7updates -> %SystemRoot%\ie7updates -> [Folder | Modified Date = 15.08.2007 10:12:56 | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 2170 bytes | Modified Date = 20.08.2007 10:22:14 | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 25.09.2007 10:14:34 | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 15.08.2007 10:20:04 | Attr = HS] lnat.ini -> %SystemRoot%\lnat.ini -> [Ver = | Size = 3839 bytes | Modified Date = 17.08.2007 10:04:58 | Attr = ] LPT$VPN.717 -> %SystemRoot%\LPT$VPN.717 -> [Ver = | Size = 36765101 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 4025 bytes | Modified Date = 20.09.2007 14:05:16 | Attr = ] PATCH.EXE -> %SystemRoot%\PATCH.EXE -> Trend Micro Inc. [Ver = 1,81,0,1011 | Size = 286720 bytes | Modified Date = 13.09.2007 15:40:56 | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 27.09.2007 14:16:16 | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 10.09.2007 16:32:24 | Attr = ] report -> %SystemRoot%\report -> [Folder | Modified Date = 14.09.2007 08:35:54 | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 10.09.2007 16:30:52 | Attr = ] system32 -> %System32% -> [Folder | Modified Date = 25.09.2007 12:44:40 | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 25.09.2007 09:51:46 | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 27.09.2007 09:18:14 | Attr = ] TMUPDATE.DLL -> %SystemRoot%\TMUPDATE.DLL -> Trend Micro Inc. [Ver = 1,81,0,1011 | Size = 507904 bytes | Modified Date = 13.09.2007 15:40:58 | Attr = ] tsc.exe -> %SystemRoot%\tsc.exe -> Trend Micro Inc. [Ver = 5.3.0.1103 | Size = 267845 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] tsc.ini -> %SystemRoot%\tsc.ini -> [Ver = | Size = 823 bytes | Modified Date = 14.09.2007 08:36:52 | Attr = ] tsc.ptn -> %SystemRoot%\tsc.ptn -> [Ver = | Size = 1871245 bytes | Modified Date = 13.09.2007 15:42:18 | Attr = ] UNZIP.DLL -> %SystemRoot%\UNZIP.DLL -> Trend Micro Inc. [Ver = 1.32.0.1000 | Size = 69689 bytes | Modified Date = 13.09.2007 15:40:56 | Attr = ] vbaddin.ini -> %SystemRoot%\vbaddin.ini -> [Ver = | Size = 117 bytes | Modified Date = 24.09.2007 12:06:14 | Attr = ] VPTNFILE.717 -> %SystemRoot%\VPTNFILE.717 -> [Ver = | Size = 36765101 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] vsapi32.dll -> %SystemRoot%\vsapi32.dll -> Trend Micro Inc. [Ver = 8.500-1002 | Size = 1163344 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 847 bytes | Modified Date = 10.09.2007 16:30:52 | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 15.08.2007 10:10:02 | Attr = ] AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 18.09.2007 21:00:02 | Attr = ] McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [Ver = | Size = 346 bytes | Modified Date = 15.09.2007 01:00:02 | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 27.09.2007 08:48:04 | Attr = H ] User_Feed_Synchronization-{916610BA-B459-4548-A69C-70EA9E8A0BFA}.job -> %SystemRoot%\tasks\User_Feed_Synchronization-{916610BA-B459-4548-A69C-70EA9E8A0BFA}.job -> [Ver = | Size = 418 bytes | Modified Date = 27.09.2007 12:44:10 | Attr = H ] CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 25.09.2007 09:49:26 | Attr = ] CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 25.09.2007 10:13:56 | Attr = ] Config.MPF -> %System32%\Config.MPF -> [Ver = | Size = 9020 bytes | Modified Date = 26.09.2007 17:49:40 | Attr = ] dllcache -> %System32%\dllcache -> [Folder | Modified Date = 25.09.2007 10:14:36 | Attr = RHS] drivers -> %System32%\drivers -> [Folder | Modified Date = 14.09.2007 14:34:10 | Attr = ] inetsrv -> %System32%\inetsrv -> [Folder | Modified Date = 27.09.2007 08:50:14 | Attr = ] wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 27.09.2007 08:51:04 | Attr = ] etc -> %System32%\drivers\etc -> [Folder | Modified Date = 25.09.2007 09:48:58 | Attr = ] addr_file.html -> %AllUsersAppData%\addr_file.html -> [Ver = | Size = 305 bytes | Modified Date = 16.09.2007 14:47:30 | Attr = ] Avira -> %AllUsersAppData%\Avira -> [Folder | Modified Date = 14.09.2007 14:34:00 | Attr = ] SiteAdvisor -> %AllUsersAppData%\SiteAdvisor -> [Folder | Modified Date = 27.09.2007 08:51:46 | Attr = ] Skype -> %AllUsersAppData%\Skype -> [Folder | Modified Date = 02.08.2007 09:36:42 | Attr = ] Skype -> %UserAppData%\Skype -> [Folder | Modified Date = 10.09.2007 15:28:42 | Attr = ] wsnpoem -> %UserAppData%\wsnpoem -> [Folder | Modified Date = 10.09.2007 16:18:26 | Attr = HS] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %LocalAppData%\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 10240 bytes | Modified Date = 13.08.2007 12:01:08 | Attr = ] Microsoft -> %LocalAppData%\Microsoft -> [Folder | Modified Date = 20.08.2007 17:22:10 | Attr = ] asas -> %UserDocuments%\asas -> [Folder | Modified Date = 20.08.2007 10:12:06 | Attr = ] Default.rdp -> %UserDocuments%\Default.rdp -> [Ver = | Size = 1136 bytes | Modified Date = 26.09.2007 17:49:24 | Attr = H ] Ma musique -> %UserDocuments%\Ma musique -> [Folder | Modified Date = 13.08.2007 12:01:24 | Attr = R ] Skype.lnk -> %AllUsersDesktop%\Skype.lnk -> [Ver = | Size = 1870 bytes | Modified Date = 02.08.2007 09:36:46 | Attr = ] 070728résumé.doc -> %UserDesktop%70728résumé.doc -> [Ver = | Size = 26624 bytes | Modified Date = 30.07.2007 09:03:30 | Attr = ] SDfix -> %UserDesktop%\SDfix -> [Folder | Modified Date = 12.09.2007 13:45:18 | Attr = ] Vacances.lnk -> %UserDesktop%\Vacances.lnk -> [Ver = | Size = 751 bytes | Modified Date = 24.08.2007 09:17:18 | Attr = ] VPN Client.lnk -> %AllUsersStartup%\VPN Client.lnk -> [Ver = | Size = 2447 bytes | Modified Date = 27.09.2007 08:52:00 | Attr = ] Skype -> %CommonProgramFiles%\Skype -> [Folder | Modified Date = 02.08.2007 09:36:32 | Attr = ] System -> %CommonProgramFiles%\System -> [Folder | Modified Date = 21.08.2007 17:29:02 | Attr = ] [File String Scan - Non-Microsoft Only] UPX! , -> %SystemDrive%\VIRTPART.DAT -> [Ver = | Size = 27262976 bytes | Modified Date = 07.02.2007 16:19:18 | Attr = ] UPX! , UPX0 , -> %SystemRoot%\tsc.exe -> Trend Micro Inc. [Ver = 5.3.0.1103 | Size = 267845 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] UPX! , aspack , -> %SystemRoot%\vsapi32.dll -> Trend Micro Inc. [Ver = 8.500-1002 | Size = 1163344 bytes | Modified Date = 13.09.2007 15:42:16 | Attr = ] Thawte Consulting , -> %System32%\CSGina.dll -> [Ver = | Size = 139280 bytes | Modified Date = 26.01.2004 16:01:56 | Attr = ] PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 24.04.2003 04:00:00 | Attr = ] PEC2 , -> %System32%\MFC42.PDB -> [Ver = | Size = 8024064 bytes | Modified Date = 27.10.1999 01:00:00 | Attr = ] PEC2 , -> %System32%\MFC42D.PDB -> [Ver = | Size = 3944448 bytes | Modified Date = 27.10.1999 01:00:00 | Attr = ] PEC2 , -> %System32%\MFCD42D.PDB -> [Ver = | Size = 2052096 bytes | Modified Date = 27.10.1999 01:00:00 | Attr = ] PEC2 , -> %System32%\MFCN42D.PDB -> [Ver = | Size = 1454080 bytes | Modified Date = 27.10.1999 01:00:00 | Attr = ] PEC2 , -> %System32%\MFCO42D.PDB -> [Ver = | Size = 4395008 bytes | Modified Date = 27.10.1999 01:00:00 | Attr = ] winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 24.04.2003 04:00:00 | Attr = ] WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 24.04.2003 09:00:00 | Attr = ] PTech , -> %System32%\dllcache\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 04.08.2004 07:41:38 | Attr = ] PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 04.08.2004 07:41:38 | Attr = ] < End of report > Bonne lecture de l'antre de mon pc ... Merci encore -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Tchoooo, As-tu une solution ..... ? A plus, je l'espère -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Re-Tchooo, Le résultat est "Aucune infection caractéristique trouvée !" ?????? Je souhaite encore te remercier de ton aide. A plus, -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Tchooooo, Merci de ton aide. Le logiciel Look2me-Destroyer n’a rien trouvé. Dois-je le faire fonctionner en mode sans échec ? Le rapport est : Look2Me-Destroyer V1.0.12 Scanning for infected files..... Scan started at 25.09.2007 09:38:02 Attempting to delete infected files... Making registry repairs. Restoring Windows certificates. Replaced hosts file with default windows hosts file Pour le logiciel Zeb Restaure ne possède pas la restriction qui concerne les droits administrateurs… Je me permets d’expliquer le problème, j’ai des droits administrateurs mais je remarque que je ne les ai pas tous. Par exemple, changer l’heure, installer certain programme … Alors, j’ai pris ce que je pensais qui ne fonctionnai pas et ce que je connaissais pas ! J’ai pris les restaurations suivantes : - Clés RUN : réactive le lancement de programmes par clés RunXX - Policies : remet en place des éléments désactivés par "Policies" - Bureau : réactive le bureau - Réparation IE : répare Internet Exploreur (pages de recherche) - Sites de confiance et sensibles : efface le contenu de ces zones (à utiliser si vous êtes infecté par des malwares) - Préfixes et Protocoles Internet : restore les clés des protocoles Internet (ZoneMap etc.) - Réinitialiser Fichier Hosts : réinitialise le fichier Hosts - Window update - restauration du système L’application à la fin indique que tout a été restauré. Il est à noter que l’onglet « Restauration du système » n’est pas revenu. ET, le problème des droits administrateurs persiste. A plus je l’espère -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Bonjour, bonsoir, selon Malheureusement pas de changement en ce qui concerne droits administrateurs ... A plus et merci encore -
Le second log HijackThis pour une petite analyse
cestvert a posté un sujet dans Analyses et éradication malwares
Je poste un nouveau log HijackThis suite à un «nettoyage » partiel. En effet, j’ai déjà posté une demande le jeudi 20 septembre 2007 à 12h39 intitulé «Un log HijackThis, une analyse SVP ». Eclypse m’a répondu, je l’en remercie. Mais n’ai pas pu effectuer tout à fait ces prescriptions, car, en autre le fichier ntos.exe n’existait plus. Ayant répondu à la suite, en mettant mon nouveau log HijackThis. Mais n’ayant pas eu de réponse. C’est pourquoi, je me permets par la présente de le reposer. Et espère que je vais pouvoir résoudre ce problème. Remercie par avance toute personne pouvant m’aider. Merci. Le log HijackThis : Le log : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:27:58, on 20.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apple\Library\System\machd.exe C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\SYSTEM32\DWRCS.EXE C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\System32\inetsrv\inetinfo.exe C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe C:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe C:\Program Files\SiteAdvisor\6172\SAService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe C:\Apple\Library\System\nmserver.exe C:\WINDOWS\system32\java.exe E:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\SiteAdvisor\6172\SiteAdv.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe C:\WINDOWS\System32\hphmon05.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe C:\WINDOWS\system32\carpserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe C:\Apple\Library\System\WindowServer.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\explorer.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe E:\transfert\pbOrdi\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=asas:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [siteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [Nokia Connection Monitor] "C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-3653917127-210295829-688940020-1004 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-3653917127-210295829-688940020-1004 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Pasteboard Server.lnk = C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O4 - Global Startup: Start ASAS Client.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: VPN Client.lnk = ? O4 - Global Startup: Window Server.lnk = C:\Apple\Library\System\WindowServer.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O15 - Trusted Zone: http://www.emsisoft.net O15 - Trusted Zone: http://www.secuser.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1187623321333 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1096631198787 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1124267662289 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran...ransferCtrl.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\Software\..\Telephony: DomainName = nicecomputing O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nicecomputing O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Apple Mach Daemon (Apple_Mach_Daemon) - Unknown owner - C:\Apple\Library\System\machd.exe O23 - Service: Apple Netname Server (Apple_Netname_Server) - Unknown owner - C:/Apple\Library\System\nmserver.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINDOWS\SYSTEM32\DWRCS.EXE O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Unknown owner - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe (file missing) O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe O23 - Service: Apple WebObjects Monitor 5 (WOMONITOR5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\JavaMonitor.woa\WOMonitorService.exe O23 - Service: Apple WebObjects Task Daemon 5 (WOTASKD5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe -- End of file - 15886 bytes -
Un log HijackThis, une analyse SVP
cestvert a répondu à un(e) sujet de cestvert dans Analyses et éradication malwares
Tout d’abord merci pour ta réponse ! Ensuite quand j’ai souhaité effacer le fichier ntos.exe à l’aide Pocketkillbox il n’existait plus !!! (Je l’ai peut-être effacé précédemment …) Toutefois, j’ai continué la procédure proposée, ai-je bien fait ?, c’est-à-dire j’ai cliqué sur Fixme.reg. Mais pas pu effacer les éléments suivants : Fichier : C:\WINNT\system32\ntos.exe Dossier : C:\WINNT\system32\wsnpoem Car ils n’existaient pas. Le log : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:27:58, on 20.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apple\Library\System\machd.exe C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\SYSTEM32\DWRCS.EXE C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\System32\inetsrv\inetinfo.exe C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe C:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe C:\Program Files\SiteAdvisor\6172\SAService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe C:\Apple\Library\System\nmserver.exe C:\WINDOWS\system32\java.exe E:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\SiteAdvisor\6172\SiteAdv.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe C:\WINDOWS\System32\hphmon05.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe C:\WINDOWS\system32\carpserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe C:\Apple\Library\System\WindowServer.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\explorer.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe E:\transfert\pbOrdi\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=asas:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [siteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [Nokia Connection Monitor] "C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-3653917127-210295829-688940020-1004 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-3653917127-210295829-688940020-1004 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Pasteboard Server.lnk = C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O4 - Global Startup: Start ASAS Client.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: VPN Client.lnk = ? O4 - Global Startup: Window Server.lnk = C:\Apple\Library\System\WindowServer.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O15 - Trusted Zone: http://www.emsisoft.net O15 - Trusted Zone: http://www.secuser.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1187623321333 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1096631198787 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1124267662289 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran...ransferCtrl.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\Software\..\Telephony: DomainName = nicecomputing O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nicecomputing O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Apple Mach Daemon (Apple_Mach_Daemon) - Unknown owner - C:\Apple\Library\System\machd.exe O23 - Service: Apple Netname Server (Apple_Netname_Server) - Unknown owner - C:/Apple\Library\System\nmserver.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINDOWS\SYSTEM32\DWRCS.EXE O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Unknown owner - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe (file missing) O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe O23 - Service: Apple WebObjects Monitor 5 (WOMONITOR5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\JavaMonitor.woa\WOMonitorService.exe O23 - Service: Apple WebObjects Task Daemon 5 (WOTASKD5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe -- End of file - 15886 bytes Merci encore de m'aider -
Bonjour à tous, Mon ordinateur ne va plus du tout. En effet, les comptes administrateurs sont altérés notamment ne peux plus changer l’heure ou installer certain application. J’ai désinfecté avec Avira en mode sans échec il semble que tous a été effacé ou mis en quarantaine. Par la suite en mode normale j’ai exécuter HijackThis qui donne le log suivant : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:24:06, on 20.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apple\Library\System\machd.exe C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\SYSTEM32\DWRCS.EXE C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\System32\inetsrv\inetinfo.exe C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe C:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe C:\WINDOWS\system32\invoker.exe C:\Apple\OpenBase\bin\openexec.exe C:\Apple\Library\Frameworks\Foundation.framework\Resources\pgroup.exe C:\Apple\OpenBase\bin\openinfo.exe C:\Program Files\SiteAdvisor\6172\SAService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe C:\Apple\Library\System\nmserver.exe C:\WINDOWS\system32\java.exe E:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\SiteAdvisor\6172\SiteAdv.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe C:\WINDOWS\System32\hphmon05.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe C:\WINDOWS\system32\carpserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe C:\Apple\Library\System\WindowServer.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\explorer.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe E:\transfert\pbOrdi\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=asas:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file) O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [siteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [Nokia Connection Monitor] "C:\Program Files\Fichiers communs\Nokia\NCLTools\NCLConf.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-318002662-2135222273-1471158870-1110\..\Run: [userinit] C:\Documents and Settings\see.NICECOMPUTING\Application Data\ntos.exe (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?') O4 - HKUS\S-1-5-21-3653917127-210295829-688940020-1004\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-318002662-2135222273-1471158870-1110 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-3653917127-210295829-688940020-1004 Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - S-1-5-21-3653917127-210295829-688940020-1004 User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe (User '?') O4 - Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - User Startup: asasc.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Pasteboard Server.lnk = C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O4 - Global Startup: Start ASAS Client.lnk = C:\Program Files\Arpage\ASAS3\client\asasc.exe O4 - Global Startup: VPN Client.lnk = ? O4 - Global Startup: Window Server.lnk = C:\Apple\Library\System\WindowServer.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O15 - Trusted Zone: http://www.emsisoft.net O15 - Trusted Zone: http://www.secuser.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1187623321333 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1096631198787 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1124267662289 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran...ransferCtrl.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\Software\..\Telephony: DomainName = nicecomputing O17 - HKLM\System\CCS\Services\Tcpip\..\{0C54C6BA-AC8B-44B8-A17F-CC2A05A68EE4}: NameServer = 193.193.144.12,193.193.158.10 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\System\CS1\Services\Tcpip\..\{0C54C6BA-AC8B-44B8-A17F-CC2A05A68EE4}: NameServer = 193.193.144.12,193.193.158.10 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\System\CS2\Services\Tcpip\..\{0C54C6BA-AC8B-44B8-A17F-CC2A05A68EE4}: NameServer = 193.193.144.12,193.193.158.10 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nicecomputing O17 - HKLM\System\CS3\Services\Tcpip\..\{0C54C6BA-AC8B-44B8-A17F-CC2A05A68EE4}: NameServer = 193.193.144.12,193.193.158.10 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Apple Mach Daemon (Apple_Mach_Daemon) - Unknown owner - C:\Apple\Library\System\machd.exe O23 - Service: Apple Netname Server (Apple_Netname_Server) - Unknown owner - C:/Apple\Library\System\nmserver.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINDOWS\SYSTEM32\DWRCS.EXE O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Unknown owner - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe (file missing) O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~2\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: openexec - Unknown owner - C:\WINDOWS\system32\invoker.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe O23 - Service: Apple WebObjects Monitor 5 (WOMONITOR5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\JavaMonitor.woa\WOMonitorService.exe O23 - Service: Apple WebObjects Task Daemon 5 (WOTASKD5) - Unknown owner - C:\Apple\Library\WebObjects\JavaApplications\wotaskd.woa\WOTaskDService.exe -- End of file - 16830 bytes Je m’en sors pas du tout tout. Si vous pouviez m’aider ce serait génial …. Merci par avance !