Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

ok le rapport n'est pas complêt! stp poste moi un rapport comme ceci plutôt >

 

1) Vas dans le menu Démarrer/Executer et tu tapes : services.msc

 

Cherche le service suivant:ChanService

Double clique dessus:

-dans le champs"Status du service" sélectionne "arrêté"

-dans le champs"Type de démarrage" sélectionne"désactivé" puis "Appliquer" puis"ok"

 

Quitte les services.

2) Télécharge WinPFind3U.exe sur ton bureau.

  • Double clique sur le fichier téléchargé : un dossier nommé WinPFind3U va apparaitre sur ton bureau.
  • Ouvre le dossier et double clique sur le fichier WinPFind3U.exe pour lancer le programme.
  • Sous le groupe Files Created Within sélectionne 30 days
  • Sous le groupe Files Modified Within sélectionne 30 days
  • Sous le groupe String Search sélectionne Non-Microsoft
  • Sous le groupe Additional Scans coche les cases >
    Reg- Security Settings
    Reg- Uninstall List
  • A présent clique sur le bouton Run Scan dans la barre d'outils
  • Lorsque le scan est terminé,le bloc-notes s'ouvre et affiche le rapport.
  • Clique sur le menu "Format" et assure toi que la case "Retour automatique à la ligne" ne soit pas cochée.
  • Copie/Colle le contenu du rapport dans ta prochaine réponse.

Chose importante: nous avons besoin d'analyser un fichier suspect : le même qu'angélique ta demandé de faire analyser en ligne en fait!

 

Rend toi sur cette page > http://www.bleepingcomputer.com/submit-mal....php?channel=26

 

A droite du champs Browse to the file you want to submit: clique sur le bouton Parcourir et recherche le fichier C:\WINDOWS\2pack.exe > clique une fois dessus avec ta souris ( sélectionne le) puis clique sur le bouton Send File sur cette même page afin de faire uploader le fichier .

 

Est ce que ton pc est en réseau ?

 

Merci d'avance et courage :P

Modifié par charles ingals

Posté(e)

Cherche le service suivant:ChanService

Double clique dessus:

-dans le champs"Status du service" sélectionne "arrêté"

-dans le champs"Type de démarrage" sélectionne"désactivé" puis "Appliquer" puis"ok"

 

impossible c'est en grisé.

 

rapport winfind :

 

WinPFind3 logfile created on: 28/07/2007 10:39:45

WinPFind3U by OldTimer - Version 1.0.39 Folder = C:\Documents and Settings\romestan\Bureau\WinPFind3u\

Microsoft Windows XP Service Pack 1 (Version = 5.1.2600)

Internet Explorer (Version = 6.0.2800.1106)

 

247,48 Mb Total Physical Memory | 82,90 Mb Available Physical Memory | 33,50% Memory free

521,67 Mb Paging File | 72,04 Mb Available in Paging File | 13,81% Paging File free

Paging file location(s): C:\pagefile.sys 144 288;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 35,25 Gb Total Space | 30,96 Gb Free Space | 87,81% Space Free

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

 

Computer Name: SN200412170005

Current User Name: romestan

Logged in as Administrator.

Current Boot Mode: Normal

 

 

[Processes - Non-Microsoft Only]

2pack.exe -> %SystemRoot%\2pack.exe -> [Ver = | Size = 585728 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = RHS]

2pack.exe -> %SystemRoot%\2pack.exe -> [Ver = | Size = 585728 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = RHS]

bdagent.exe -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ]

bdmcon.exe -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ]

devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Modified Date = 23/08/2001 17:47:34 | Attr = ]

e_famt9ee.exe -> %System32%\spool\drivers\w32x86\3\E_FAMT9EE.EXE -> SEIKO EPSON CORPORATION [Ver = 3.07 | Size = 110592 bytes | Modified Date = 03/03/2004 05:07:00 | Attr = ]

slserv.exe -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ]

winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.38.0 | Size = 322048 bytes | Modified Date = 23/06/2007 15:15:54 | Attr = ]

xcommsvr.exe -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ]

 

[Win32 Services - Non-Microsoft Only]

(bdss) BitDefender Scan Server [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 19/01/2007 16:12:56 | Attr = ]

(ChanSirv) ChanService [Win32_Own | Auto | Running] -> %SystemRoot%\2pack.exe -> [Ver = | Size = 585728 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = RHS]

(dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.0.503.0 | Size = 205312 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ]

(LIVESRV) BitDefender Desktop Update Service [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 18 | Size = 237568 bytes | Modified Date = 14/07/2007 21:33:04 | Attr = ]

(Seagate Communication) Seagate Communication [Win32_Own | Disabled | Stopped] -> %System32%\dllcache\seagatecom.exe -> File not found

(SLService) SmartLinkService [Win32_Own | Auto | Running] -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ]

(VSSERV) BitDefender Virus Shield [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 147 | Size = 462848 bytes | Modified Date = 14/07/2007 21:32:52 | Attr = ]

(XCOMM) BitDefender Communicator [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ]

 

[Registry - Non-Microsoft Only]

< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->

BDAgent -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ]

BDMCon -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ]

< AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->

*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->

sockspy.dll -> %System32%\sockspy.dll -> [Ver = | Size = 73728 bytes | Modified Date = 26/01/2006 20:19:52 | Attr = ]

< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->

< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->

igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Modified Date = 13/12/2002 07:09:16 | Attr = ]

< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->

< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 36 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> ÿÿÿÿ ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->

127.0.0.1 localhost -> ->

< Internet Explorer Settings > -> ->

HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->

HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->

HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Start Page -> about:blank ->

HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->

HKCU: Local Page -> C:\WINDOWS\System32\blank.htm ->

HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKCU: Start Page -> http://www.google.fr/ ->

HKCU: ProxyEnable -> 0 ->

< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %SystemDrive%\APPS\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 16/04/2001 16:39:02 | Attr = ]

{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ]

< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->

{9112AFD1-4BD4-4285-AFE7-48BFAE17DD2B} -> (Intel® PRO/100 VE Network Connection) ->

{E54B0B60-E0CA-4847-99A6-8BF3DB3AF3F9} -> () ->

{EA06B917-0C19-44AD-88F2-6A85EFDA9002} -> (Carte réseau 1394) ->

< Default Protocols [HKLM] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->

shell -> shell protocol not assigned ->

< Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->

shell -> shell protocol not assigned ->

< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->

ipp -> Reg Data - Key not found -> File not found

msdaipp -> Reg Data - Key not found -> File not found

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->

{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab ->

DirectAnimation Java Classes -> - CodeBase = file://C:\WINDOWS\Java\classes\dajava.cab ->

Microsoft XML Parser for Java -> - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab ->

 

 

[Registry - Additional Scans - Non-Microsoft Only]

< Security Settings > -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> Rpcss; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Utilise la bande passante réseau inactive pour transférer des données. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\system32\qmgr.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Internet Connection Sharing ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;NLA;RasMan;ALG; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11477 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\2pack.exe -> C:\WINDOWS\2pack.exe:*:Enabled:Chan Services For Win32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation de mises à jour Windows critiques. Si le service est désactivé, le système d'exploitation peut être mis à jour manuellement sur le site Web de Windows Update. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\System32\wuauserv.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->

< Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->

{22524CA1-515C-4153-9807-52AE65F73B5F} -> BitDefender Antivirus Plus v10 ->

{350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP ->

{8855FF30-19CE-4CB1-A654-87B38369CCE1} -> Sonic RecordNow DX ->

EPSON Printer and Utilities -> EPSON Logiciel imprimante ->

EPSON Scanner -> EPSON Scan ->

EVEREST Home Edition_is1 -> EVEREST Home Edition v2.20 ->

Free.fr -> Free - Kit de connexion ->

HijackThis -> HijackThis 1.99.1 ->

KB833987 -> Correctif Windows XP - KB833987 ->

KB835409 -> Mise à jour pour Windows XP (KB835409) ->

KB835732 -> Correctif Windows XP - KB835732 ->

KB840987 -> Correctif Windows XP - KB840987 ->

KB842773 -> Correctif Windows XP - KB842773 ->

KB873339 -> Correctif Windows XP - KB873339 ->

KB885835 -> Correctif Windows XP - KB885835 ->

KB885836 -> Correctif Windows XP - KB885836 ->

KB888302 -> Correctif Windows XP - KB888302 ->

KB890046 -> Mise à jour de sécurité pour Windows XP (KB890046) ->

KB890859 -> Correctif Windows XP - KB890859 ->

KB891781 -> Correctif Windows XP - KB891781 ->

KB893756 -> Mise à jour de sécurité pour Windows XP (KB893756) ->

KB893803v2 -> Windows Installer 3.1 (KB893803) ->

KB896358 -> Mise à jour de sécurité pour Windows XP (KB896358) ->

KB896423 -> Mise à jour de sécurité pour Windows XP (KB896423) ->

KB896424 -> Mise à jour de sécurité pour Windows XP (KB896424) ->

KB896428 -> Mise à jour de sécurité pour Windows XP (KB896428) ->

KB898458 -> Mise à jour de sécurité pour Step by Step Interactive Training (KB898458) ->

KB898461 -> Mise à jour pour Windows XP (KB898461) ->

KB899587 -> Mise à jour de sécurité pour Windows XP (KB899587) ->

KB899591 -> Mise à jour de sécurité pour Windows XP (KB899591) ->

KB900725 -> Mise à jour de sécurité pour Windows XP (KB900725) ->

KB901017 -> Mise à jour de sécurité pour Windows XP (KB901017) ->

KB901214 -> Mise à jour de sécurité pour Windows XP (KB901214) ->

KB902400 -> Mise à jour de sécurité pour Windows XP (KB902400) ->

KB904706 -> Mise à jour de sécurité pour Windows XP (KB904706) ->

KB905414 -> Mise à jour de sécurité pour Windows XP (KB905414) ->

KB905495 -> Mise à jour de sécurité pour Windows XP (KB905495) ->

KB905749 -> Mise à jour de sécurité pour Windows XP (KB905749) ->

KB908519 -> Mise à jour de sécurité pour Windows XP (KB908519) ->

KB908531 -> Mise à jour pour Windows XP (KB908531) ->

KB910437 -> Mise à jour pour Windows XP (KB910437) ->

KB911280 -> Mise à jour pour Windows XP (KB911280) ->

KB911562 -> Mise à jour de sécurité pour Windows XP (KB911562) ->

KB911564 -> Mise à jour de sécurité pour Lecteur Windows Media (KB911564) ->

KB911567-OE6SP1-20060316.165634 -> Correctif Windows XP - KB911567 ->

KB911927 -> Mise à jour de sécurité pour Windows XP (KB911927) ->

KB912919 -> Mise à jour de sécurité pour Windows XP (KB912919) ->

KB913580 -> Mise à jour de sécurité pour Windows XP (KB913580) ->

KB914388 -> Mise à jour de sécurité pour Windows XP (KB914388) ->

KB914389 -> Mise à jour de sécurité pour Windows XP (KB914389) ->

KB914798 -> Mise à jour de sécurité pour Windows XP (KB914798) ->

KB917344 -> Mise à jour de sécurité pour Windows XP (KB917344) ->

KB917422 -> Mise à jour de sécurité pour Windows XP (KB917422) ->

KB917734_WMP8 -> Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734) ->

KB917953 -> Mise à jour de sécurité pour Windows XP (KB917953) ->

KB918439-IE6SP1-20060530.145346 -> Correctif Windows XP - KB918439 ->

KB918899-IE6SP1-20060725.123917 -> Correctif Windows XP - KB918899 ->

KB919007 -> Mise à jour de sécurité pour Windows XP (KB919007) ->

KB920670 -> Mise à jour de sécurité pour Windows XP (KB920670) ->

KB920683 -> Mise à jour de sécurité pour Windows XP (KB920683) ->

KB920685 -> Mise à jour de sécurité pour Windows XP (KB920685) ->

KB921883 -> Mise à jour de sécurité pour Windows XP (KB921883) ->

KB922616 -> Mise à jour de sécurité pour Windows XP (KB922616) ->

KB922819 -> Mise à jour de sécurité pour Windows XP (KB922819) ->

KB923191 -> Mise à jour de sécurité pour Windows XP (KB923191) ->

KB923414 -> Mise à jour de sécurité pour Windows XP (KB923414) ->

KB924191 -> Mise à jour de sécurité pour Windows XP (KB924191) ->

KB924496 -> Mise à jour de sécurité pour Windows XP (KB924496) ->

KB925486-IE6SP1-20060918.120000 -> Correctif Windows XP - KB925486 ->

mIRC -> mIRC ->

PROSet -> Intel® PRO Ethernet Adapter and Software ->

Q327979 -> Correctif Windows XP (SP2) Q327979 ->

q330512 -> Correctif Windows XP (SP2) q330512 ->

Q330909 -> Correctif Windows XP (SP2) Q330909 ->

Q331060 -> Package du correctif Windows XP [voir Q331060 pour plus de détails] ->

Q331816 -> Correctif Windows XP (SP2) Q331816 ->

Q810020 -> Correctif Windows XP (SP2) Q810020 ->

Q815411 -> Correctif Windows XP (SP2) Q815411 ->

ShockwaveFlash -> Adobe Flash Player 9 ActiveX ->

SigmaTel C-Major -> SigmaTel C-Major Audio ->

Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.4 ->

T r o j a n R e m o v e r_is1 -> Trojan Remover 6.6.1 ->

 

[Files/Folders - Created Within 30 days]

1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Created Date = 16/07/2007 21:54:49 | Attr = ]

APPS -> %SystemDrive%\APPS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = ]

Bases -> %SystemDrive%\Bases -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ]

BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Created Date = 14/07/2007 18:22:08 | Attr = RHS]

cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 14/07/2007 18:21:59 | Attr = RHS]

ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 27/07/2007 21:12:03 | Attr = ]

DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Created Date = 14/07/2007 16:58:00 | Attr = H ]

Downloads -> %SystemDrive%\Downloads -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ]

DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = H ]

hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Created Date = 02/01/1601 23:00:00 | Attr = HS]

hijackthis -> %SystemDrive%\hijackthis -> [Folder | Created Date = 16/07/2007 16:20:33 | Attr = ]

Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Created Date = 17/07/2007 14:33:51 | Attr = ]

PNP -> %SystemDrive%\PNP -> [Folder | Created Date = 14/07/2007 16:58:46 | Attr = H ]

QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 27/07/2007 21:14:55 | Attr = ]

RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 14/07/2007 18:26:49 | Attr = HS]

Sohbet Chat.lnk -> %SystemDrive%\Sohbet Chat.lnk -> [Ver = | Size = 496 bytes | Created Date = 28/07/2007 09:11:41 | Attr = ]

Sohbet-Script -> %SystemDrive%\Sohbet-Script -> [Folder | Created Date = 28/07/2007 09:11:32 | Attr = ]

sohbet.exe -> %SystemDrive%\sohbet.exe -> [Ver = | Size = 1801415 bytes | Created Date = 28/07/2007 09:11:22 | Attr = ]

UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Created Date = 14/07/2007 17:00:32 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 23/07/2007 15:14:30 | Attr = H ]

$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Created Date = 24/07/2007 09:09:56 | Attr = H ]

$NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Created Date = 16/07/2007 21:54:19 | Attr = H ]

$NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Created Date = 23/07/2007 15:15:23 | Attr = H ]

$NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Created Date = 16/07/2007 21:55:00 | Attr = H ]

$NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Created Date = 16/07/2007 21:58:45 | Attr = H ]

$NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Created Date = 24/07/2007 09:10:50 | Attr = H ]

$NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Created Date = 27/07/2007 19:17:16 | Attr = H ]

$NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Created Date = 24/07/2007 09:13:43 | Attr = H ]

$NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Created Date = 27/07/2007 19:18:50 | Attr = H ]

$NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Created Date = 27/07/2007 19:10:47 | Attr = H ]

$NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Created Date = 27/07/2007 19:13:09 | Attr = H ]

$NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Created Date = 27/07/2007 19:05:53 | Attr = H ]

$NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Created Date = 27/07/2007 19:13:29 | Attr = H ]

$NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Created Date = 27/07/2007 19:17:41 | Attr = H ]

$NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Created Date = 24/07/2007 09:08:53 | Attr = H ]

$NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Created Date = 24/07/2007 09:11:28 | Attr = H ]

$NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Created Date = 24/07/2007 09:12:09 | Attr = H ]

$NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Created Date = 27/07/2007 19:09:15 | Attr = H ]

$NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Created Date = 24/07/2007 09:08:17 | Attr = H ]

$NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Created Date = 23/07/2007 15:19:50 | Attr = H ]

$NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Created Date = 24/07/2007 09:14:38 | Attr = H ]

$NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Created Date = 24/07/2007 09:12:26 | Attr = H ]

$NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Created Date = 23/07/2007 15:19:20 | Attr = H ]

$NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Created Date = 27/07/2007 19:18:06 | Attr = H ]

$NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Created Date = 27/07/2007 19:11:50 | Attr = H ]

$NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Created Date = 27/07/2007 19:13:58 | Attr = H ]

$NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Created Date = 23/07/2007 15:22:42 | Attr = H ]

$NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Created Date = 23/07/2007 15:22:05 | Attr = H ]

$NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Created Date = 27/07/2007 19:15:19 | Attr = H ]

$NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Created Date = 27/07/2007 19:09:32 | Attr = H ]

$NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Created Date = 27/07/2007 19:08:53 | Attr = H ]

$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Created Date = 23/07/2007 15:17:02 | Attr = H ]

$NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Created Date = 27/07/2007 19:15:45 | Attr = H ]

$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Created Date = 24/07/2007 09:11:47 | Attr = H ]

$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Created Date = 27/07/2007 19:17:29 | Attr = H ]

$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Created Date = 23/07/2007 15:27:02 | Attr = H ]

$NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Created Date = 27/07/2007 19:09:51 | Attr = H ]

$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Created Date = 24/07/2007 09:13:01 | Attr = H ]

$NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Created Date = 27/07/2007 19:10:26 | Attr = H ]

$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Created Date = 23/07/2007 15:16:12 | Attr = H ]

$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Created Date = 27/07/2007 19:12:50 | Attr = H ]

$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 27/07/2007 19:07:38 | Attr = H ]

$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Created Date = 27/07/2007 19:12:27 | Attr = H ]

$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Created Date = 27/07/2007 19:11:24 | Attr = H ]

$NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Created Date = 23/07/2007 15:21:35 | Attr = H ]

$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Created Date = 27/07/2007 19:12:08 | Attr = H ]

$NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Created Date = 27/07/2007 19:16:08 | Attr = H ]

$NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Created Date = 23/07/2007 15:17:53 | Attr = H ]

$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Created Date = 23/07/2007 15:23:17 | Attr = H ]

$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Created Date = 23/07/2007 15:25:55 | Attr = H ]

$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 23/07/2007 15:14:33 | Attr = H ]

$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Created Date = 27/07/2007 19:17:54 | Attr = H ]

$NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Created Date = 27/07/2007 19:18:37 | Attr = H ]

$NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Created Date = 24/07/2007 09:12:44 | Attr = H ]

$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Created Date = 24/07/2007 09:14:16 | Attr = H ]

$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Created Date = 23/07/2007 15:20:15 | Attr = H ]

$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Created Date = 24/07/2007 09:13:19 | Attr = H ]

$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Created Date = 27/07/2007 19:20:18 | Attr = H ]

$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Created Date = 27/07/2007 19:16:58 | Attr = H ]

$NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Created Date = 24/07/2007 09:10:31 | Attr = H ]

$NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Created Date = 14/07/2007 18:11:50 | Attr = H ]

$NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Created Date = 14/07/2007 18:12:01 | Attr = H ]

$NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Created Date = 14/07/2007 18:12:09 | Attr = H ]

$NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Created Date = 14/07/2007 18:12:15 | Attr = H ]

$NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Created Date = 14/07/2007 18:12:22 | Attr = H ]

$NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Created Date = 14/07/2007 18:12:28 | Attr = H ]

$NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Created Date = 14/07/2007 18:12:34 | Attr = H ]

AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Created Date = 14/07/2007 18:23:10 | Attr = ]

catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ]

CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Created Date = 14/07/2007 22:12:46 | Attr = ]

Drivers -> %SystemRoot%\Drivers -> [Folder | Created Date = 14/07/2007 18:15:46 | Attr = ]

erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 27/07/2007 21:18:34 | Attr = ]

jautoexp.dat -> %SystemRoot%\jautoexp.dat -> [Ver = | Size = 6550 bytes | Created Date = 23/07/2007 15:24:39 | Attr = ]

Minidump -> %SystemRoot%\Minidump -> [Folder | Created Date = 26/07/2007 22:17:32 | Attr = ]

Modio -> %SystemRoot%\Modio -> [Folder | Created Date = 14/07/2007 18:12:58 | Attr = ]

NEC.BMP -> %SystemRoot%\NEC.BMP -> [Ver = | Size = 149262 bytes | Created Date = 14/07/2007 18:15:08 | Attr = ]

nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ]

Profiles -> %SystemRoot%\Profiles -> [Folder | Created Date = 14/07/2007 18:23:11 | Attr = ]

pss -> %SystemRoot%\pss -> [Folder | Created Date = 24/07/2007 10:09:04 | Attr = ]

RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Created Date = 14/07/2007 18:15:32 | Attr = ]

REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Created Date = 14/07/2007 18:29:00 | Attr = ]

RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Created Date = 14/07/2007 18:26:20 | Attr = ]

sl.lng -> %SystemRoot%\sl.lng -> [Ver = | Size = 49354 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

SmCfg.exe -> %SystemRoot%\SmCfg.exe -> [Ver = 2, 80, 1, 0 | Size = 61440 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Created Date = 14/07/2007 18:26:48 | Attr = ]

SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:11:09 | Attr = ]

unvise32qt.exe -> %SystemRoot%\unvise32qt.exe -> MindVision [Ver = 2.8.3 | Size = 86016 bytes | Created Date = 14/07/2007 18:24:04 | Attr = ]

$ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Created Date = 14/07/2007 18:26:44 | Attr = ]

amr_cpl.dll -> %System32%\amr_cpl.dll -> [Ver = 2, 81, 0, 0 | Size = 139264 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Created Date = 14/07/2007 19:20:20 | Attr = ]

bits -> %System32%\bits -> [Folder | Created Date = 24/07/2007 09:10:54 | Attr = ]

ctwdm32.dll -> %System32%\ctwdm32.dll -> Creative Technology Ltd. [Ver = 5.0.0.2001 | Size = 4096 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

devcon32.dll -> %System32%\devcon32.dll -> Creative Technology Ltd. [Ver = 4.06.651 | Size = 256512 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Created Date = 14/07/2007 22:14:02 | Attr = ]

EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ]

EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ]

EPSTP32U.DAT -> %System32%\EPSTP32U.DAT -> [Ver = | Size = 6390 bytes | Created Date = 14/07/2007 22:14:00 | Attr = R ]

eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Created Date = 14/07/2007 22:14:03 | Attr = ]

esccmd.dll -> %System32%\esccmd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 22528 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ]

escimgd.dll -> %System32%\escimgd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 46080 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ]

escwiad.dll -> %System32%\escwiad.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 29696 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ]

E_DCINST.DLL -> %System32%\E_DCINST.DLL -> SEIKO EPSON CORP. [Ver = 1, 0, 0, 1 | Size = 31744 bytes | Created Date = 15/07/2007 08:55:22 | Attr = ]

E_FBCB9EE.DLL -> %System32%\E_FBCB9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 2, 0, 0, 27 | Size = 64000 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ]

E_FBCH9EE.DLL -> %System32%\E_FBCH9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 1, 1, 0, 0 | Size = 34304 bytes | Created Date = 15/07/2007 08:55:16 | Attr = ]

E_FLM9EE.DLL -> %System32%\E_FLM9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 5, 1, 0, 0 | Size = 79654 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ]

hccutils.dll -> %System32%\hccutils.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

iAlmCoIn_0_v9.dll -> %System32%\iAlmCoIn_0_v9.dll -> Intel Corporation [Ver = 1.00.1000.1 | Size = 61440 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmdd5.dll -> %System32%\ialmdd5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 435266 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmdev5.dll -> %System32%\ialmdev5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 192507 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmdnt5.dll -> %System32%\ialmdnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 114236 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmgdev.dll -> %System32%\ialmgdev.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 188416 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmgicd.dll -> %System32%\ialmgicd.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 1859584 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmrem.dll -> %System32%\ialmrem.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 57344 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmrnt5.dll -> %System32%\ialmrnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 33792 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxcfg.exe -> %System32%\igfxcfg.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 483328 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxcpl.cpl -> %System32%\igfxcpl.cpl -> Intel Corporation [Ver = 3,0,0,1992 | Size = 94208 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdev.dll -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 147456 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdgps.dll -> %System32%\igfxdgps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 45056 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdiag.exe -> %System32%\igfxdiag.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdo.dll -> %System32%\igfxdo.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxeud.dll -> %System32%\igfxeud.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 221184 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxexps.dll -> %System32%\igfxexps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 32768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxext.exe -> %System32%\igfxext.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhara.lhp -> %System32%\igfxhara.lhp -> [Ver = | Size = 55633 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxharb.lhp -> %System32%\igfxharb.lhp -> [Ver = | Size = 55654 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhchs.lhp -> %System32%\igfxhchs.lhp -> [Ver = | Size = 55426 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhcht.lhp -> %System32%\igfxhcht.lhp -> [Ver = | Size = 56139 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhcsy.lhp -> %System32%\igfxhcsy.lhp -> [Ver = | Size = 58343 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhdan.lhp -> %System32%\igfxhdan.lhp -> [Ver = | Size = 56933 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhdeu.lhp -> %System32%\igfxhdeu.lhp -> [Ver = | Size = 58017 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhell.lhp -> %System32%\igfxhell.lhp -> [Ver = | Size = 58791 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxheng.lhp -> %System32%\igfxheng.lhp -> [Ver = | Size = 55186 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhenu.lhp -> %System32%\igfxhenu.lhp -> [Ver = | Size = 55002 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhesp.lhp -> %System32%\igfxhesp.lhp -> [Ver = | Size = 56980 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhfin.lhp -> %System32%\igfxhfin.lhp -> [Ver = | Size = 57762 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhfra.lhp -> %System32%\igfxhfra.lhp -> [Ver = | Size = 56829 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhfrc.lhp -> %System32%\igfxhfrc.lhp -> [Ver = | Size = 56735 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhheb.lhp -> %System32%\igfxhheb.lhp -> [Ver = | Size = 61249 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhhun.lhp -> %System32%\igfxhhun.lhp -> [Ver = | Size = 59369 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhita.lhp -> %System32%\igfxhita.lhp -> [Ver = | Size = 56548 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhjpn.lhp -> %System32%\igfxhjpn.lhp -> [Ver = | Size = 57858 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhk.dll -> %System32%\igfxhk.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 118784 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhkor.lhp -> %System32%\igfxhkor.lhp -> [Ver = | Size = 63399 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhnld.lhp -> %System32%\igfxhnld.lhp -> [Ver = | Size = 57353 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhnor.lhp -> %System32%\igfxhnor.lhp -> [Ver = | Size = 56813 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhplk.lhp -> %System32%\igfxhplk.lhp -> [Ver = | Size = 58108 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhptb.lhp -> %System32%\igfxhptb.lhp -> [Ver = | Size = 56119 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhptg.lhp -> %System32%\igfxhptg.lhp -> [Ver = | Size = 56649 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhrus.lhp -> %System32%\igfxhrus.lhp -> [Ver = | Size = 58767 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhsve.lhp -> %System32%\igfxhsve.lhp -> [Ver = | Size = 56636 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhtha.lhp -> %System32%\igfxhtha.lhp -> [Ver = | Size = 59797 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhtrk.lhp -> %System32%\igfxhtrk.lhp -> [Ver = | Size = 57768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxpph.dll -> %System32%\igfxpph.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 204800 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrara.lrc -> %System32%\igfxrara.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrarb.lrc -> %System32%\igfxrarb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrchs.lrc -> %System32%\igfxrchs.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrcht.lrc -> %System32%\igfxrcht.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrcsy.lrc -> %System32%\igfxrcsy.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrdan.lrc -> %System32%\igfxrdan.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrdeu.lrc -> %System32%\igfxrdeu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrell.lrc -> %System32%\igfxrell.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 163840 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxreng.lrc -> %System32%\igfxreng.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrenu.lrc -> %System32%\igfxrenu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxres.dll -> %System32%\igfxres.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:17:29 | Attr = ]

igfxresp.lrc -> %System32%\igfxresp.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxress.dll -> %System32%\igfxress.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 503808 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrfin.lrc -> %System32%\igfxrfin.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrfra.lrc -> %System32%\igfxrfra.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrfrc.lrc -> %System32%\igfxrfrc.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrheb.lrc -> %System32%\igfxrheb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrhun.lrc -> %System32%\igfxrhun.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrita.lrc -> %System32%\igfxrita.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrjpn.lrc -> %System32%\igfxrjpn.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrkor.lrc -> %System32%\igfxrkor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrnld.lrc -> %System32%\igfxrnld.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrnor.lrc -> %System32%\igfxrnor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrplk.lrc -> %System32%\igfxrplk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrptb.lrc -> %System32%\igfxrptb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrptg.lrc -> %System32%\igfxrptg.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrrus.lrc -> %System32%\igfxrrus.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrsve.lrc -> %System32%\igfxrsve.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrtha.lrc -> %System32%\igfxrtha.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrtrk.lrc -> %System32%\igfxrtrk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxsrvc.dll -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxtray.exe -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

javasup.vxd -> %System32%\javasup.vxd -> [Ver = | Size = 7315 bytes | Created Date = 23/07/2007 15:24:40 | Attr = ]

minirec.exe -> %System32%\minirec.exe -> SmartLink [Ver = 1.0 (8.1.2001) | Size = 163840 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

mpeg2data.ax -> %System32%\mpeg2data.ax -> [Ver = | Size = 57856 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

msdvbnp.ax -> %System32%\msdvbnp.ax -> [Ver = | Size = 52224 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

ntio.sys -> %System32%\ntio.sys -> [Ver = | Size = 34000 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio404.sys -> %System32%\ntio404.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio411.sys -> %System32%\ntio411.sys -> [Ver = | Size = 35648 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio412.sys -> %System32%\ntio412.sys -> [Ver = | Size = 35424 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio804.sys -> %System32%\ntio804.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

PreInstall -> %System32%\PreInstall -> [Folder | Created Date = 23/07/2007 15:19:56 | Attr = ]

psisdecd.dll -> %System32%\psisdecd.dll -> [Ver = | Size = 354816 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

psisrndr.ax -> %System32%\psisrndr.ax -> [Ver = | Size = 30208 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

QuickTime -> %System32%\QuickTime -> [Folder | Created Date = 14/07/2007 18:23:54 | Attr = ]

ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Created Date = 14/07/2007 18:13:07 | Attr = ]

sblfx.dll -> %System32%\sblfx.dll -> Creative Technology Ltd. [Ver = 5.12.01.3210 | Size = 495616 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

sfman32.dll -> %System32%\sfman32.dll -> Creative Technology Ltd. [Ver = 4.06.501 | Size = 51200 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

slcpappl.chm -> %System32%\slcpappl.chm -> [Ver = | Size = 136104 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

slcpappl.cpl -> %System32%\slcpappl.cpl -> SmartLink [Ver = 2, 92, 0, 2 | Size = 339968 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

SLLights.dll -> %System32%\SLLights.dll -> [Ver = 2, 0, 9, 9 | Size = 405504 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

slmh.cab -> %System32%\slmh.cab -> [Ver = | Size = 351388 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

slmh.exe -> %System32%\slmh.exe -> SmartLink [Ver = 2, 92, 0, 3 | Size = 372736 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:12:20 | Attr = ]

spupdsvc.inf -> %System32%\spupdsvc.inf -> [Ver = | Size = 170 bytes | Created Date = 24/07/2007 09:12:03 | Attr = ]

swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ]

swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.0 | Size = 370688 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ]

swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ]

unacev2.dll -> %System32%\unacev2.dll -> [Ver = | Size = 75264 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

UNRAR3.dll -> %System32%\UNRAR3.dll -> [Ver = | Size = 153088 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

vfind.exe -> %System32%\vfind.exe -> [Ver = | Size = 49152 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ]

zonedoff.reg -> %System32%\zonedoff.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:19 | Attr = ]

zonedon.reg -> %System32%\zonedon.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:20 | Attr = ]

ztvunace26.dll -> %System32%\ztvunace26.dll -> [Ver = | Size = 77312 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

ztvunrar36.dll -> %System32%\ztvunrar36.dll -> [Ver = | Size = 162304 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

2gmgsmt.sf2 -> %System32%\drivers\2gmgsmt.sf2 -> [Ver = | Size = 2104298 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

a302.sys -> %System32%\drivers\a302.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a303.sys -> %System32%\drivers\a303.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 27703 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a304.sys -> %System32%\drivers\a304.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 45111 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a305.sys -> %System32%\drivers\a305.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a306.sys -> %System32%\drivers\a306.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 16439 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a307.sys -> %System32%\drivers\a307.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20535 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a308.sys -> %System32%\drivers\a308.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a309.sys -> %System32%\drivers\a309.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 25655 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a310.sys -> %System32%\drivers\a310.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 32823 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a311.sys -> %System32%\drivers\a311.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 31799 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a312.sys -> %System32%\drivers\a312.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a313.sys -> %System32%\drivers\a313.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 35895 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a314.sys -> %System32%\drivers\a314.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 17463 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ctlfacem.sys -> %System32%\drivers\ctlfacem.sys -> Creative Technology Ltd. [Ver = 5.12.01.2108 built by: WinDDK | Size = 6912 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

ctljystk.sys -> %System32%\drivers\ctljystk.sys -> Creative Technology Ltd. [Ver = 5.1.2501.0 built by: WinDDK | Size = 3712 bytes | Created Date = 14/07/2007 18:08:52 | Attr = ]

emu10k1m.sys -> %System32%\drivers\emu10k1m.sys -> Creative Technology Ltd. [Ver = 5.12.01.3300 built by: WinDDK | Size = 283904 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

fbxusb.sys -> %System32%\drivers\fbxusb.sys -> FreeBox SA [Ver = 1.2.0.0 | Size = 18848 bytes | Created Date = 14/07/2007 19:31:27 | Attr = R ]

ialmkchw.sys -> %System32%\drivers\ialmkchw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 78144 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmnt5.sys -> %System32%\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 87579 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmsbw.sys -> %System32%\drivers\ialmsbw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 108480 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

KProcCheck.sys -> %System32%\drivers\KProcCheck.sys -> [Ver = | Size = 4096 bytes | Created Date = 26/07/2007 22:17:01 | Attr = ]

sfmanm.sys -> %System32%\drivers\sfmanm.sys -> Creative Technology Ltd. [Ver = 4.10.3300 | Size = 36480 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

ssmdrv.sys -> %System32%\drivers\ssmdrv.sys -> Avira GmbH [Ver = 7.0.1.1 | Size = 28352 bytes | Created Date = 14/07/2007 18:50:45 | Attr = ]

vch.sys -> %System32%\drivers\vch.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20021 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

wa301a.sys -> %System32%\drivers\wa301a.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

wa301b.sys -> %System32%\drivers\wa301b.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

winddx.sys -> %System32%\drivers\winddx.sys -> Smart Link Ltd. [Ver = 2.80.02 | Size = 42328 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

 

[Files/Folders - Modified Within 30 days]

1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Modified Date = 16/07/2007 22:56:28 | Attr = ]

APPS -> %SystemDrive%\APPS -> [Folder | Modified Date = 14/07/2007 19:24:22 | Attr = ]

Bases -> %SystemDrive%\Bases -> [Folder | Modified Date = 17/07/2007 15:36:36 | Attr = ]

BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Modified Date = 14/07/2007 19:17:44 | Attr = RHS]

BOOT.INI -> %SystemDrive%\BOOT.INI -> [Ver = | Size = 274 bytes | Modified Date = 14/07/2007 19:44:24 | Attr = RHS]

cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 14/07/2007 19:22:10 | Attr = RHS]

ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 27/07/2007 22:29:28 | Attr = ]

DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Modified Date = 14/07/2007 17:58:00 | Attr = H ]

Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 14/07/2007 19:43:22 | Attr = ]

Downloads -> %SystemDrive%\Downloads -> [Folder | Modified Date = 26/07/2007 15:49:52 | Attr = ]

DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Modified Date = 14/07/2007 19:44:30 | Attr = H ]

hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Modified Date = 28/07/2007 10:10:56 | Attr = HS]

hijackthis -> %SystemDrive%\hijackthis -> [Folder | Modified Date = 16/07/2007 18:17:02 | Attr = ]

Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Modified Date = 18/07/2007 09:48:56 | Attr = ]

PNP -> %SystemDrive%\PNP -> [Folder | Modified Date = 14/07/2007 17:58:46 | Attr = H ]

Program Files -> %ProgramFiles% -> [Folder | Modified Date = 27/07/2007 22:40:42 | Attr = R ]

QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 27/07/2007 22:14:56 | Attr = ]

RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 14/07/2007 20:12:42 | Attr = HS]

Sohbet Chat.lnk -> %SystemDrive%\Sohbet Chat.lnk -> [Ver = | Size = 496 bytes | Modified Date = 28/07/2007 10:32:38 | Attr = ]

Sohbet-Script -> %SystemDrive%\Sohbet-Script -> [Folder | Modified Date = 28/07/2007 10:36:10 | Attr = ]

sohbet.exe -> %SystemDrive%\sohbet.exe -> [Ver = | Size = 1801415 bytes | Modified Date = 28/07/2007 10:32:32 | Attr = ]

System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 23/07/2007 22:02:54 | Attr = HS]

UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Modified Date = 14/07/2007 18:00:32 | Attr = ]

WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 27/07/2007 23:04:40 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 27/07/2007 20:15:44 | Attr = H ]

$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 24/07/2007 10:10:04 | Attr = H ]

$NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Modified Date = 16/07/2007 22:54:20 | Attr = H ]

$NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Modified Date = 23/07/2007 16:15:26 | Attr = H ]

$NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Modified Date = 27/07/2007 20:18:26 | Attr = H ]

$NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Modified Date = 16/07/2007 22:58:52 | Attr = H ]

$NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Modified Date = 24/07/2007 10:10:54 | Attr = H ]

$NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Modified Date = 27/07/2007 20:17:18 | Attr = H ]

$NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Modified Date = 24/07/2007 10:13:46 | Attr = H ]

$NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Modified Date = 27/07/2007 20:18:52 | Attr = H ]

$NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Modified Date = 27/07/2007 20:10:50 | Attr = H ]

$NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Modified Date = 27/07/2007 20:13:12 | Attr = H ]

$NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Modified Date = 27/07/2007 20:05:56 | Attr = H ]

$NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Modified Date = 27/07/2007 20:13:30 | Attr = H ]

$NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Modified Date = 27/07/2007 20:17:44 | Attr = H ]

$NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Modified Date = 24/07/2007 10:08:56 | Attr = H ]

$NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Modified Date = 24/07/2007 10:11:30 | Attr = H ]

$NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Modified Date = 24/07/2007 10:12:12 | Attr = H ]

$NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Modified Date = 27/07/2007 20:09:18 | Attr = H ]

$NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Modified Date = 24/07/2007 10:08:20 | Attr = H ]

$NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Modified Date = 23/07/2007 16:19:52 | Attr = H ]

$NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Modified Date = 24/07/2007 10:14:42 | Attr = H ]

$NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Modified Date = 24/07/2007 10:12:30 | Attr = H ]

$NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Modified Date = 23/07/2007 16:19:22 | Attr = H ]

$NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Modified Date = 27/07/2007 20:18:08 | Attr = H ]

$NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Modified Date = 27/07/2007 20:11:52 | Attr = H ]

$NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Modified Date = 27/07/2007 20:14:02 | Attr = H ]

$NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Modified Date = 23/07/2007 16:22:44 | Attr = H ]

$NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Modified Date = 23/07/2007 16:22:08 | Attr = H ]

$NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Modified Date = 27/07/2007 20:15:22 | Attr = H ]

$NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Modified Date = 27/07/2007 20:09:34 | Attr = H ]

$NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Modified Date = 27/07/2007 20:08:56 | Attr = H ]

$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Modified Date = 23/07/2007 16:17:04 | Attr = H ]

$NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Modified Date = 27/07/2007 20:15:48 | Attr = H ]

$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Modified Date = 24/07/2007 10:11:50 | Attr = H ]

$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Modified Date = 27/07/2007 20:17:32 | Attr = H ]

$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Modified Date = 23/07/2007 16:27:04 | Attr = H ]

$NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Modified Date = 27/07/2007 20:09:56 | Attr = H ]

$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Modified Date = 24/07/2007 10:13:04 | Attr = H ]

$NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Modified Date = 27/07/2007 20:10:28 | Attr = H ]

$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Modified Date = 23/07/2007 16:16:16 | Attr = H ]

$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Modified Date = 27/07/2007 20:12:52 | Attr = H ]

$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 27/07/2007 20:07:42 | Attr = H ]

$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Modified Date = 27/07/2007 20:12:30 | Attr = H ]

$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Modified Date = 27/07/2007 20:11:28 | Attr = H ]

$NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Modified Date = 23/07/2007 16:21:38 | Attr = H ]

$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Modified Date = 27/07/2007 20:12:10 | Attr = H ]

$NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Modified Date = 27/07/2007 20:16:10 | Attr = H ]

$NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Modified Date = 23/07/2007 16:18:04 | Attr = H ]

$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Modified Date = 23/07/2007 16:23:20 | Attr = H ]

$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Modified Date = 23/07/2007 16:25:58 | Attr = H ]

$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 23/07/2007 16:14:36 | Attr = H ]

$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Modified Date = 27/07/2007 20:17:56 | Attr = H ]

$NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Modified Date = 27/07/2007 20:18:40 | Attr = H ]

$NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Modified Date = 24/07/2007 10:12:46 | Attr = H ]

$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Modified Date = 24/07/2007 10:14:18 | Attr = H ]

$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Modified Date = 23/07/2007 16:20:18 | Attr = H ]

$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Modified Date = 24/07/2007 10:13:22 | Attr = H ]

$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Modified Date = 27/07/2007 20:20:20 | Attr = H ]

$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Modified Date = 27/07/2007 20:17:02 | Attr = H ]

$NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Modified Date = 24/07/2007 10:10:34 | Attr = H ]

$NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Modified Date = 14/07/2007 19:11:52 | Attr = H ]

$NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Modified Date = 14/07/2007 19:12:02 | Attr = H ]

$NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Modified Date = 14/07/2007 19:12:10 | Attr = H ]

$NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Modified Date = 14/07/2007 19:12:16 | Attr = H ]

$NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Modified Date = 14/07/2007 19:12:24 | Attr = H ]

$NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Modified Date = 14/07/2007 19:12:30 | Attr = H ]

$NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Modified Date = 14/07/2007 19:12:36 | Attr = H ]

AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Modified Date = 14/07/2007 19:23:18 | Attr = ]

bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 28/07/2007 10:11:00 | Attr = S]

catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Modified Date = 20/07/2007 00:47:24 | Attr = ]

CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Modified Date = 14/07/2007 23:12:48 | Attr = ]

Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 27/07/2007 20:19:04 | Attr = ]

Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 23/07/2007 16:25:26 | Attr = S]

Drivers -> %SystemRoot%\Drivers -> [Folder | Modified Date = 14/07/2007 19:15:48 | Attr = ]

erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 27/07/2007 22:18:36 | Attr = ]

Help -> %SystemRoot%\Help -> [Folder | Modified Date = 17/07/2007 09:12:30 | Attr = ]

imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 27/07/2007 20:19:00 | Attr = ]

inf -> %SystemRoot%\inf -> [Folder | Modified Date = 27/07/2007 23:06:16 | Attr = H ]

Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 14/07/2007 20:19:52 | Attr = HS]

Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 27/07/2007 22:58:22 | Attr = ]

Modio -> %SystemRoot%\Modio -> [Folder | Modified Date = 14/07/2007 19:13:00 | Attr = ]

msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 27/07/2007 20:25:08 | Attr = ]

Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 26/07/2007 18:47:54 | Attr = ]

Profiles -> %SystemRoot%\Profiles -> [Folder | Modified Date = 14/07/2007 19:23:12 | Attr = ]

pss -> %SystemRoot%\pss -> [Folder | Modified Date = 24/07/2007 11:09:06 | Attr = ]

RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Modified Date = 14/07/2007 19:15:34 | Attr = ]

Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 14/07/2007 19:42:14 | Attr = ]

REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Modified Date = 14/07/2007 19:29:02 | Attr = ]

RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Modified Date = 14/07/2007 19:26:26 | Attr = ]

security -> %SystemRoot%\security -> [Folder | Modified Date = 24/07/2007 10:17:26 | Attr = ]

setupapi.log.0.old -> %SystemRoot%\setupapi.log.0.old -> [Ver = | Size = 1595275 bytes | Modified Date = 16/07/2007 22:55:14 | Attr = ]

smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Modified Date = 14/07/2007 19:26:50 | Attr = ]

SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:30 | Attr = ]

system -> %SystemRoot%\system -> [Folder | Modified Date = 14/07/2007 19:26:26 | Attr = ]

system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 231 bytes | Modified Date = 14/07/2007 19:29:10 | Attr = ]

system32 -> %System32% -> [Folder | Modified Date = 28/07/2007 10:12:00 | Attr = ]

Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 28/07/2007 10:26:30 | Attr = ]

twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 14/07/2007 23:13:24 | Attr = ]

Web -> %SystemRoot%\Web -> [Folder | Modified Date = 17/07/2007 14:41:56 | Attr = R ]

win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 620 bytes | Modified Date = 27/07/2007 22:56:14 | Attr = ]

WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 23/07/2007 16:20:26 | Attr = ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 26/07/2007 17:49:30 | Attr = H ]

$ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Modified Date = 14/07/2007 19:26:46 | Attr = ]

$winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 497 bytes | Modified Date = 14/07/2007 19:43:10 | Attr = ]

bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Modified Date = 28/07/2007 10:26:50 | Attr = ]

bits -> %System32%\bits -> [Folder | Modified Date = 24/07/2007 10:10:56 | Attr = ]

CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 27/07/2007 20:18:28 | Attr = ]

CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 27/07/2007 23:07:36 | Attr = ]

Com -> %System32%\Com -> [Folder | Modified Date = 27/07/2007 20:14:10 | Attr = ]

config -> %System32%\config -> [Folder | Modified Date = 27/07/2007 22:18:42 | Attr = ]

dllcache -> %System32%\dllcache -> [Folder | Modified Date = 27/07/2007 20:20:22 | Attr = RHS]

drivers -> %System32%\drivers -> [Folder | Modified Date = 27/07/2007 22:38:34 | Attr = ]

EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Modified Date = 14/07/2007 23:14:06 | Attr = ]

EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ]

EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Modified Date = 14/07/2007 23:14:02 | Attr = ]

eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ]

FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 90296 bytes | Modified Date = 24/07/2007 10:56:36 | Attr = ]

Macromed -> %System32%\Macromed -> [Folder | Modified Date = 14/07/2007 19:24:36 | Attr = ]

perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 39992 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ]

perfc00C.dat -> %System32%\perfc00C.dat -> [Ver = | Size = 48616 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ]

perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 311604 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ]

perfh00C.dat -> %System32%\perfh00C.dat -> [Ver = | Size = 367658 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ]

PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 775034 bytes | Modified Date = 14/07/2007 19:43:40 | Attr = ]

PreInstall -> %System32%\PreInstall -> [Folder | Modified Date = 23/07/2007 16:19:58 | Attr = ]

QuickTime -> %System32%\QuickTime -> [Folder | Modified Date = 14/07/2007 19:24:06 | Attr = ]

ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 14/07/2007 19:13:08 | Attr = ]

Restore -> %System32%\Restore -> [Folder | Modified Date = 23/07/2007 22:02:54 | Attr = ]

SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:22 | Attr = ]

spupdsvc.inf -> %System32%\spupdsvc.inf -> [Ver = | Size = 170 bytes | Modified Date = 24/07/2007 10:12:04 | Attr = ]

swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ]

wmpscheme.xml -> %System32%\wmpscheme.xml -> [Ver = | Size = 25065 bytes | Modified Date = 14/07/2007 19:43:30 | Attr = ]

wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1170 bytes | Modified Date = 26/07/2007 10:42:02 | Attr = ]

etc -> %System32%\drivers\etc -> [Folder | Modified Date = 27/07/2007 22:20:40 | Attr = ]

 

[File String Scan - Non-Microsoft Only]

PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ]

UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ]

winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ]

PTech , -> %System32%\drivers\mtlstrm.sys -> [Ver = 3.00.01 | Size = 1805544 bytes | Modified Date = 18/04/2002 09:58:02 | Attr = ]

 

< End of report >

 

 

 

Chose importante: nous avons besoin d'analyser un fichier suspect : le même qu'angélique ta demandé de faire analyser en ligne en fait!

je le fait et je reposte

 

Est ce que ton pc est en réseau ?

non

Posté(e)

ça y est j'ai envoyé le fichier 2pack.exe avec bleeping, mais en tapant le chemin car je ne le trouvais pas sous c:\windows.

 

J'attends tes instructions. Merci :P

Posté(e) (modifié)

salut :P

 

Merci pour l'envoi du fichier :P c'est très important pour nous.

 

Tu as aussi envoyé le fichier sohbet.exe dis tu ? la manipulation n'a pas fonctionné pour celui là : si tu veux bien réessayer (juste celui là) :P

 

Voilà la suite des hostilités >

 

Va jusqu'au bout et si tu rencontres un problème, n'hésite pas à me le dire :P

 

Tu as deux possiblités pour consulter les instructions qui suivent:

 

-Soit tu copie/colles le contenu de la procédure dans un fichier texte(que tu met sur le bureau) pour pouvoir le consulter en mode sans échec(tu n'auras pas accès à internet!).

 

-Tu peux également enregistrer la page web complète, sur laquelle se trouve la procédure,

en le faisant à partir de ton navigateur :

 

-Aller en haut de page et cliquer sur le menu"Fichier" : une liste apparait=>

-Choisis "Enregistrer sous" et choisis "Bureau".

-Ensuite cliquer sur le bouton "Enregistrer" à droite du champs "nom du fichier".

 

Pour lire la procédure en mode sans échec, tu n'auras qu'à double cliquer sur le fichier Infection par trojan et ver ? (avec l'icone de ton navigateur) situé sur le bureau.(tu noteras qu'un nouveau dossier va se créer sur le bureau en plus du fichier : c'est normal!) De cette manière, tu conserveras toutes les mises en formes et les couleurs de la procédure, et cela permettra de t'y retrouver.

--------------------------------------------------------------------------------------------------------------------------

 

1) Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

***Si le lien ne fonctionne pas, essaie celui-ci : http://download.bleepingcomputer.com/andymanchesta/SDFix.exe ***

 

Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.

Ne lance pas le programme pour l'instant!

 

2) Démarre WinPFind3U en double cliquant sur WinPFind3U.exe et copie/colle le texte ci dessous (ne copie pas le mot CITATION) dans le Panneau Paste fix here , puis clique sur le bouton Run Fix.

[Processes - Non-Microsoft Only]

YY -> 2pack.exe -> %SystemRoot%\2pack.exe

YY -> 2pack.exe -> %SystemRoot%\2pack.exe

[Win32 Services - Non-Microsoft Only]

YY -> (ChanSirv) ChanService [Win32_Own | Auto | Running] -> %SystemRoot%\2pack.exe

[Registry - Additional Scans - Non-Microsoft Only]

< Security Settings > ->

YY -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\2pack.exe -> C:\WINDOWS\2pack.exe:*:Enabled:Chan Services For Win32

[Files/Folders - Created Within 30 days]

NY -> Sohbet Chat.lnk -> %SystemDrive%\Sohbet Chat.lnk

NY -> Sohbet-Script -> %SystemDrive%\Sohbet-Script

NY -> sohbet.exe -> %SystemDrive%\sohbet.exe

[Files/Folders - Modified Within 30 days]

NY -> Sohbet Chat.lnk -> %SystemDrive%\Sohbet Chat.lnk

NY -> Sohbet-Script -> %SystemDrive%\Sohbet-Script

NY -> sohbet.exe -> %SystemDrive%\sohbet.exe

[Reboot]

Le Fix va se faire rapidement,puis il te sera demandé de redémarrer ton pc : accepte en cliquant sur Yes

 

3) Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.

Déroule la liste des instructions ci-dessous :

  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

4) Poste stp les rapports suivants >

 

- le rapport de SDFix

- le rapport qui se trouve dans le dossier WinPFind3u( c'est un rapport qui a pour nom la date du jour\mois\année\heure).

-un nouveau rapport hijackthis.

 

Est ce que tu utilises mIRC ?

 

courage :P

Modifié par charles ingals
Posté(e)

hello, voici les rapports :

 

report.txt :

 

 

SDFix: Version 1.94

 

Run by romestan on 29/07/2007 at 01:36

 

Microsoft Windows XP [version 5.1.2600]

 

Running From: C:\SDFix

 

Safe Mode:

Checking Services:

 

Name:

Seagate Communication

 

ImagePath:

"C:\WINDOWS\System32\dllcache\seagatecom.exe"

 

Seagate Communication - Deleted

 

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

 

Rebooting...

 

 

Normal Mode:

Checking Files:

 

Trojan Files Found:

 

C:\WINDOWS\system32\i - Deleted

C:\WINDOWS\system32\o - Deleted

 

 

 

Removing Temp Files...

 

ADS Check:

 

C:\WINDOWS

No streams found.

 

C:\WINDOWS\system32

No streams found.

 

C:\WINDOWS\system32\svchost.exe

No streams found.

 

C:\WINDOWS\system32\ntoskrnl.exe

No streams found.

 

 

 

Final Check:

 

Remaining Services:

------------------

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

 

Remaining Files:

---------------

 

Backups Folder: - C:\SDFix\backups\backups.zip

 

Files with Hidden Attributes:

 

C:\Documents and Settings\romestan\Bureau\WinPFind3u\MovedFiles\WINDOWS\2pack.exe

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0004.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0284.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0292.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL1758.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3125.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3375.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3690.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Peyrolles\~WRL0796.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\tsouin tsouin\~WRL3039.tmp

C:\WINDOWS\system32\config\DEFAULT.tmp.LOG

C:\WINDOWS\system32\config\SAM.tmp.LOG

C:\WINDOWS\system32\config\SECURITY.tmp.LOG

C:\WINDOWS\system32\config\SOFTWARE.tmp.LOG

C:\WINDOWS\system32\config\SYSTEM.tmp.LOG

 

Finished

 

win :

[Processes - Non-Microsoft Only]

Unable to kill process 2pack.exe .

C:\WINDOWS\2pack.exe moved successfully.

Unable to kill process 2pack.exe .

File C:\WINDOWS\2pack.exe not found.

[Win32 Services - Non-Microsoft Only]

Service ChanSirv stopped successfully.

Service ChanSirv deleted successfully.

File C:\WINDOWS\2pack.exe not found.

[Registry - Additional Scans - Non-Microsoft Only]

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\2pack.exe deleted successfully.

File C:\WINDOWS\2pack.exe:*:Enabled:Chan Services For Win32 not found.

[Files/Folders - Created Within 30 days]

C:\Sohbet Chat.lnk moved successfully.

C:\Sohbet-Script\sounds moved successfully.

C:\Sohbet-Script\logs moved successfully.

C:\Sohbet-Script\download moved successfully.

C:\Sohbet-Script\DLL moved successfully.

C:\Sohbet-Script\Code\text moved successfully.

C:\Sohbet-Script\Code\ses moved successfully.

C:\Sohbet-Script\Code\resim moved successfully.

C:\Sohbet-Script\Code\korumalar moved successfully.

C:\Sohbet-Script\Code\ini moved successfully.

C:\Sohbet-Script\Code\icon moved successfully.

C:\Sohbet-Script\Code\html moved successfully.

C:\Sohbet-Script\Code\addon moved successfully.

C:\Sohbet-Script\Code moved successfully.

C:\Sohbet-Script\channels moved successfully.

C:\Sohbet-Script moved successfully.

C:\sohbet.exe moved successfully.

[Files/Folders - Modified Within 30 days]

File C:\Sohbet Chat.lnk not found!

File C:\Sohbet-Script not found!

File C:\sohbet.exe not found!

< End of log >

Created on 07/29/2007 01:29:51

 

et hijackthis :

 

Logfile of HijackThis v1.99.1

Scan saved at 02:03:55, on 29/07/2007

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\Softwin\BitDefender10\bdmcon.exe

C:\Program Files\Softwin\BitDefender10\bdagent.exe

C:\WINDOWS\System32\devldr32.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe

C:\Program Files\Softwin\BitDefender10\vsserv.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\romestan\Bureau\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg

O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)

O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)

O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)

O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

 

 

non je n'utilise pas mIRC, je sais meme pas ce que c'est. comment c'est arrivé dans ma pacoule ??

Est-ce que mon cauchemar est terminé ??

Posté(e) (modifié)

salut :P

 

C'est beaucoup mieux!

 

Est ce que tu as pû expédier le fichier demandé ? > sohbet.exe

 

Si tu n'a pas pû le faire, expédie stp la copie que tu trouveras dans le dossier sur ton bureau > WinPFind3u\MovedFiles\WINDOWS\sohbet.exe (envoie aussi Sohbet-Script )

envoie les à la même adresse stp.

 

J'aimerai stp que tu fasses ce scan rapide des ports de ton pc pour voir si celui ci est bien protégé par BitDefender >

 

http://www.zebulon.fr/outils/scanports/test-securite.php

 

Si un port est détecté comme ouvert, poste le rapport.

 

Si tu n'utilise pas mIRC, passe par Ajouter/Supprimer des Programmes et désinstalle le.

 

Poste stp un dernier rapport DiagHelp pour vérification.

 

@+

Modifié par charles ingals
Posté(e)

hello,

 

 

Est ce que tu as pû expédier le fichier demandé ? > sohbet.exe

Si tu n'a pas pû le faire, expédie stp la copie que tu trouveras dans le dossier sur ton bureau > WinPFind3u\MovedFiles\WINDOWS\sohbet.exe (envoie aussi Sohbet-Script )

envoie les à la même adresse stp.

 

 

C'est fait mais sohbet-script non c'est un répertoire, pas de fichier à ce nom.

 

 

J'aimerai stp que tu fasses ce scan rapide des ports de ton pc pour voir si celui ci est bien protégé par BitDefender >

voila le rapport :

 

Attention ! Il existe un ou plusieurs ports ouverts ainsi que un ou plusieurs ports détectés comme fermés !

Un ou plusieurs ports ont répondu aux test, cela signifie qu'ils sont ouvert. Un port ouvert permet aux pirates potentiels d'accéder facilement à votre machine. De plus, un ou plusieurs ports fermés ont également été détecté. Bien qu'il soit protégé, un port fermé reste visible, un pirate potentiel peut donc tenter d'attaquer votre machine. Il est vivement conseillé de masquer (ou à défaut fermer) ces ports ou de modifier la configuration de votre firewall.

 

Ports TCP ouverts 135 N/A Utilisé pour les applications client/server basées sur des systèmes d'exploitation Microsoft Trojans possibles : W32.Blaster.Worm, W32/Lovsan.worm

 

139 netbios-ssn Utilisé pour le partage de fichiers dans un réseau local Trojans possibles : Chode, God Message worm, Msinit, Netlog, Network, Qaz, Sadmind, SMB Relay

 

 

Ports TCP fermés 21 ftp Utilisé pour le transfert de fichier entre ordinateurs Trojans possibles : Back Construction, Blade Runner, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, Fore, FreddyK, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Net Administrator, Ramen, RTB 666, Senna Spy FTP server, The Flu, Traitor 21, WebEx, WinCrash

 

22 ssh Le shell SSH permet de se connecter à un serveur de façon sécurisée Trojans possibles : Adore sshd, Shaft

 

23 telnet Utilisé pour obtenir un shell distant Trojans possibles : ADM worm, Fire HacKer, My Very Own trojan, RTB 666, Telnet Pro, Tiny Telnet Server - TTS, Truva Atl

 

25 smtp Utilisé pour le transfert de courrier électronique entre deux hôtes. Si vous n'utilisez pas de serveur de messagerie, il est conseillé de fermer ce port. Trojans possibles : Ajan, Antigen, Barok, BSE, Email Password Sender - EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, Hybris, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Stukach, Tapiras, Terminator, WinPC, WinSpy

 

79 finger Permet de connaître diverses informations relatives à votre profil Trojans possibles : CDK, Firehotcker

 

80 http Utilisé pour les services Web. Si vous n'utilisez pas de serveur web, il est conseillé de fermer ce port Trojans possibles : 711 trojan (Seven Eleven), AckCmd, Back End, Back Orifice 2000 Plug-Ins, Cafeini, CGI Backdoor, Code Red, Executor, God Message, God Message 4 Creator, Hooker, IISworm, MTX, NCX, Nimda, Noob, Ramen, Reverse WWW Tunnel Backdoor, RingZero, RTB 666, Seeker, WAN Remote, Web Server CT, WebDownloader

 

110 pop3 Utilisé par les serveurs de messagerie Internet. Si vous n'utilisez pas de serveur de messagerie, il est conseillé de fermer ce port. Trojans possibles : ProMail trojan

 

113 auth Utilisé par certains serveurs de messagerie ou de newsgroups (MiRC - Virc...). Des problèmes de performances peuvent survenir si ce port est masqué Trojans possibles : Invisible Identd Deamon, Kazimas

 

119 nntp Utilisé par les serveurs de news pour la distribution d'articles Usenet Trojans possibles : Happy99

 

143 imap Utilisé par les serveurs de messagerie Internet pour l'envoi de messages électroniques. Si vous n'utilisez pas de serveur IMAP, il est conseillé de fermer ce port. Trojans possibles : N/A

 

389 ldap LDAP (Lightweight Directory Access Protocol) : utilisé pour accéder automatiquement à des services d'annuaires en ligne Trojans possibles : N/A

 

443 https Utilisé pour sécuriser les communications HTTP. Si vous n'utilisez pas de serveur web, il est conseillé de fermer ce port. Ce port est également utilisé par AOL Instant Messenger Trojans possibles : N/A

 

445 microsoft-ds Utilisé pour le partage des protocoles SMB. Son exploitation peut permettre d'obtenir vos mots de passe Trojans possibles : Lioten, Randon, WORM_DELODER.A, W32/Deloder.A, W32.HLLW.Deloder

 

1002 N/A Port non standard Trojans possibles : N/A

 

1024 N/A Port réservé Trojans possibles : Jade, Latinus, NetSpy, Remote Administration Tool - RAT [no 2]

 

1025 N/A Port non standard Trojans possibles : Fraggle Rock, md5 Backdoor, NetSpy, Remote Storm

 

1026 N/A Port non standard Trojans possibles : N/A

 

1027 N/A Port non standard Trojans possibles : ICKiller

 

1028 N/A Port non standard Trojans possibles : N/A

 

1029 N/A Port non standard Trojans possibles : InCommand Access, ICQ Nuke 98

 

1030 N/A Port non standard Trojans possibles : N/A

 

1720 h323hostcall Port non standard. Peut être utilisé par NetMeeting Trojans possibles : N/A

 

5000 N/A Utilisé pour communiquer avec tous les périphériques UpnP reliés à votre réseau Trojans possibles : Back Door Setup, BioNet Lite, Blazer5, Bubbel, ICKiller, Ra1d, Sockets des Troie

 

 

Ports TCP masqués Aucun port détecté

 

 

 

Poste stp un dernier rapport DiagHelp pour vérification.

voilà le rapport, mais incomplet il me reboote tjs qd je valide.

 

J'ai tjs un message de mémoire virtuelle minimale insuffisante, qu'est-ce qu'il faut faire ? cela ne vient pas encore d'un virus ??

Zonk m'avait conseillé Secunia, mais comment ça marche ? qd je fait scan now, rien ne se passe ??

Merci à +

Posté(e)

salut :P

 

Merci d'avoir expédié les fichiers crissou, c'est tout bon :P

 

Le rapport de scan montre que ton firewall ne fait pas son boulot correctement !

On va fermer ces ports pour des raisons de sécurité.

Si ton pc n'est pas en réseau, fais ceci >

 

Télécharge Windows Worms Doors Cleaner depuis cette page > http://www.firewallleaktester.com/wwdc.htm

Met le fichier sur ton bureau et double clique dessus. (l'icône d'un bouclier).

Clique sur les cases qui correspondent aux ports 135 et 139 (Close 135 et Close 137:139) > tu verras une croix rouge devant.

Une fois ceci fait, quitte le programme et redémarre ton pc puis refais le test en ligne : dis moi si un port ouvert est encore détecté.

Poste stp un dernier rapport DiagHelp pour vérification.

voilà le rapport, mais incomplet il me reboote tjs qd je valide.

Je ne le vois pas ? stp après avoir fais l'opération ci dessus (fermer les ports), vas dans le dossier C:\ et élimine le fichier resultat.txt . Relance DaigHelp et poste le rapport stp : il est normal que le pc reboote lors de l'utilisation de DiagHelp!

 

Est ce que tu aas désinstallé mIRC ?

J'ai tjs un message de mémoire virtuelle minimale insuffisante, qu'est-ce qu'il faut faire ?

Est ce que tu avais ce problème en arrivant sur le forum ? as tu fait des modifications au niveau du fichier d'échange ?

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...