Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Bonjour ,

 

sa serai sympas d'analyser ce rapport S'il vous plais ?

 

Logfile of HijackThis v1.99.1

Scan saved at 23:33:58, on 14/10/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe

O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

Posté(e)

salut :P

 

Peux tu donner des précisions quant aux problèmes rencontrés ?

Une petite chose à faire >

 

Démarre Hijackthis et clique sur la case "Do a system scan only", puis coche les lignes suivantes :

R3 - Default URLSearchHook is missing

 

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

-Ferme tous les programmes et clique sur "Fix Checked"

 

Le rapport suivant a été fait en mode sans échec ? Refais en un en mode normal et poste le stp.

A part ca, le rapport ne montre rien de mauvais.

 

@+

Posté(e)
salut :P

 

Peux tu donner des précisions quant aux problèmes rencontrés ?

Une petite chose à faire >

 

Démarre Hijackthis et clique sur la case "Do a system scan only", puis coche les lignes suivantes :

R3 - Default URLSearchHook is missing

 

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

-Ferme tous les programmes et clique sur "Fix Checked"

 

Le rapport suivant a été fait en mode sans échec ? Refais en un en mode normal et poste le stp.

A part ca, le rapport ne montre rien de mauvais.

 

@+

 

 

 

Salut Charles,

 

 

en faite mon portable etait tres tres lent et j'avais mal preparer mon Logfile of HijackThis

car j'avais pas activer les dossiers cachés et desactiver ect.. et aussi oublier le scan antivir !!!

c'est fais ainsi antivir a detecter 10 virus et trojans et j'ai l'impression que sa fonctionne mieux je t'envois quand meme mon dernier Logfile of HijackThis . si tu trouve qu'il est propre et qu'il n'y a plus rien a faire pourrais tu me

conseiller comment le proteger

 

merci et desoler pour l'oubli !!

 

Logfile of HijackThis v1.99.1

Scan saved at 10:41:18, on 17/10/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\atievxx.exe

C:\PROGRA~1\Wanadoo\CnxMon.exe

C:\PROGRA~1\MESSAG~1\StartMessager.exe

C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe

C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\hijackthis\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe

O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

Posté(e)

salut :P

 

si tu trouve qu'il est propre et qu'il n'y a plus rien a faire pourrais tu me

conseiller comment le proteger

...En commencant par ne pas désinstaller le seul programme qui protège ton pc efficacement >> Antivir !!!!

Pourquoi as tu désinstallé l'antivirus? :P

Tu as pû constater son efficacité s'il a trouvé et nettoyé les infections présentes.

Stp réinstalle le d'urgence!! Pour qu'il soit efficace, configure le comme indiqué dans le Tutoriel de tesgaz

 

J'ai l'impression que le rapport hijackthis n'est pas complêt.Poste moi en un après avoir fait ceci >

 

Il faut aussi installer un parefeu car celui de Windows n'est pas efficace!

 

Voila quelques liens pour des pare-feux gratuits

 

Zone Alarm (2 versions )

Lien de téléchargement de la version FREE : http://dl2.zonelabs.com/bin/free/3301_fr/z..._737_000_fr.exe

Lien de téléchargement de la version PRO : http://www.zonelabs.com/store/content/cata...lid=dbtopnav_za

La version pro est payante après une période d'essai.

Tuto de Tesgaz pour la version pro : http://speedweb1.free.fr/frames2.php?page=tuto1

Tuto de Odsen pour la version free : http://benoit.aun.free.fr/securite-facile-php/zonealarm.php

 

Kerio

Lien de téléchargement : http://www.sunbelt-software.com/evaluation/440/kerio.exe

Tuto de Malekal_morte : http://www.malekal.com/kerio_firewall.html

 

Jetico

Lien de téléchargement éditeur : http://www.jetico.com/

Lien de téléchargement sur Zebulon (en fr) : http://telechargement.zebulon.fr/license-1-225.html

Tuto de Odsen (lien site) : http://benoit.aun.free.fr/securite-facile-php/jetico.php

Tuto de Odsen (lien zeb) : http://forum.zebulon.fr/index.php?showtopic=93489

 

Outpost firewall free

Lien de téléchargement éditeur : http://www.agnitum.com/products/outpostfree/download.php

Tuto de Odsen (lien site) : http://securite-facile.ovh.org/outpost.php

 

La liste n'est pas exhaustive, il en existe d'autres gratuits, et d'autres avec plus de fonctions payants. Télécharge l'exécutable d'installation du pare-feu que tu auras choisi. Déconnecte toi, débranche physiquement ta connexion, et lance l'installation de ton pare-feu. Puis reconnecte toi et suis les instructions supplémentaires s'il y en a. Aide toi des tutos.

 

Je te conseille Zone Alarme ou Kério en version gratuite pour commencer, tu pourras en changer par la suite pour un pare-feu plus élaboré quand tu auras le temps de t'y plonger. Un pare-feu bien configuré, est garant de la sécurité du pc et de ta tranquilité .

 

Poste en plus du rapport hijackthis, un rapport comme ceci >

 

Télécharge et lance DiagHelp comme montré dans ce tutoriel> http://www.malekal.com/DiagHelp/DiagHelp.php

Ne lance que l'option 1 et poste le rapport stp.Attention: n'oublie pas d'appuyer sur une touche lorsque cela te sera demandé à la fin du rapport Catchme.

 

Met les protections en place, sinon tu seras toujours embêté!! :P

Posté(e)
salut :P

...En commencant par ne pas désinstaller le seul programme qui protège ton pc efficacement >> Antivir !!!!

Pourquoi as tu désinstallé l'antivirus? :P

Tu as pû constater son efficacité s'il a trouvé et nettoyé les infections présentes.

Stp réinstalle le d'urgence!! Pour qu'il soit efficace, configure le comme indiqué dans le Tutoriel de tesgaz

 

J'ai l'impression que le rapport hijackthis n'est pas complêt.Poste moi en un après avoir fait ceci >

 

Il faut aussi installer un parefeu car celui de Windows n'est pas efficace!

 

Voila quelques liens pour des pare-feux gratuits

 

Zone Alarm (2 versions )

Lien de téléchargement de la version FREE : http://dl2.zonelabs.com/bin/free/3301_fr/z..._737_000_fr.exe

Lien de téléchargement de la version PRO : http://www.zonelabs.com/store/content/cata...lid=dbtopnav_za

La version pro est payante après une période d'essai.

Tuto de Tesgaz pour la version pro : http://speedweb1.free.fr/frames2.php?page=tuto1

Tuto de Odsen pour la version free : http://benoit.aun.free.fr/securite-facile-php/zonealarm.php

 

Kerio

Lien de téléchargement : http://www.sunbelt-software.com/evaluation/440/kerio.exe

Tuto de Malekal_morte : http://www.malekal.com/kerio_firewall.html

 

Jetico

Lien de téléchargement éditeur : http://www.jetico.com/

Lien de téléchargement sur Zebulon (en fr) : http://telechargement.zebulon.fr/license-1-225.html

Tuto de Odsen (lien site) : http://benoit.aun.free.fr/securite-facile-php/jetico.php

Tuto de Odsen (lien zeb) : http://forum.zebulon.fr/index.php?showtopic=93489

 

Outpost firewall free

Lien de téléchargement éditeur : http://www.agnitum.com/products/outpostfree/download.php

Tuto de Odsen (lien site) : http://securite-facile.ovh.org/outpost.php

 

La liste n'est pas exhaustive, il en existe d'autres gratuits, et d'autres avec plus de fonctions payants. Télécharge l'exécutable d'installation du pare-feu que tu auras choisi. Déconnecte toi, débranche physiquement ta connexion, et lance l'installation de ton pare-feu. Puis reconnecte toi et suis les instructions supplémentaires s'il y en a. Aide toi des tutos.

 

Je te conseille Zone Alarme ou Kério en version gratuite pour commencer, tu pourras en changer par la suite pour un pare-feu plus élaboré quand tu auras le temps de t'y plonger. Un pare-feu bien configuré, est garant de la sécurité du pc et de ta tranquilité .

 

Poste en plus du rapport hijackthis, un rapport comme ceci >

 

Télécharge et lance DiagHelp comme montré dans ce tutoriel> http://www.malekal.com/DiagHelp/DiagHelp.php

Ne lance que l'option 1 et poste le rapport stp.Attention: n'oublie pas d'appuyer sur une touche lorsque cela te sera demandé à la fin du rapport Catchme.

 

Met les protections en place, sinon tu seras toujours embêté!! :P

 

 

 

 

 

Salut Charles

 

je te poste le rapport hijackthis suivant :

Posté(e)
salut :P

...En commencant par ne pas désinstaller le seul programme qui protège ton pc efficacement >> Antivir !!!!

Pourquoi as tu désinstallé l'antivirus? :P

Tu as pû constater son efficacité s'il a trouvé et nettoyé les infections présentes.

Stp réinstalle le d'urgence!! Pour qu'il soit efficace, configure le comme indiqué dans le Tutoriel de tesgaz

 

J'ai l'impression que le rapport hijackthis n'est pas complêt.Poste moi en un après avoir fait ceci >

 

Il faut aussi installer un parefeu car celui de Windows n'est pas efficace!

 

Voila quelques liens pour des pare-feux gratuits

 

Zone Alarm (2 versions )

Lien de téléchargement de la version FREE : http://dl2.zonelabs.com/bin/free/3301_fr/z..._737_000_fr.exe

Lien de téléchargement de la version PRO : http://www.zonelabs.com/store/content/cata...lid=dbtopnav_za

La version pro est payante après une période d'essai.

Tuto de Tesgaz pour la version pro : http://speedweb1.free.fr/frames2.php?page=tuto1

Tuto de Odsen pour la version free : http://benoit.aun.free.fr/securite-facile-php/zonealarm.php

 

Kerio

Lien de téléchargement : http://www.sunbelt-software.com/evaluation/440/kerio.exe

Tuto de Malekal_morte : http://www.malekal.com/kerio_firewall.html

 

Jetico

Lien de téléchargement éditeur : http://www.jetico.com/

Lien de téléchargement sur Zebulon (en fr) : http://telechargement.zebulon.fr/license-1-225.html

Tuto de Odsen (lien site) : http://benoit.aun.free.fr/securite-facile-php/jetico.php

Tuto de Odsen (lien zeb) : http://forum.zebulon.fr/index.php?showtopic=93489

 

Outpost firewall free

Lien de téléchargement éditeur : http://www.agnitum.com/products/outpostfree/download.php

Tuto de Odsen (lien site) : http://securite-facile.ovh.org/outpost.php

 

La liste n'est pas exhaustive, il en existe d'autres gratuits, et d'autres avec plus de fonctions payants. Télécharge l'exécutable d'installation du pare-feu que tu auras choisi. Déconnecte toi, débranche physiquement ta connexion, et lance l'installation de ton pare-feu. Puis reconnecte toi et suis les instructions supplémentaires s'il y en a. Aide toi des tutos.

 

Je te conseille Zone Alarme ou Kério en version gratuite pour commencer, tu pourras en changer par la suite pour un pare-feu plus élaboré quand tu auras le temps de t'y plonger. Un pare-feu bien configuré, est garant de la sécurité du pc et de ta tranquilité .

 

Poste en plus du rapport hijackthis, un rapport comme ceci >

 

Télécharge et lance DiagHelp comme montré dans ce tutoriel> http://www.malekal.com/DiagHelp/DiagHelp.php

Ne lance que l'option 1 et poste le rapport stp.Attention: n'oublie pas d'appuyer sur une touche lorsque cela te sera demandé à la fin du rapport Catchme.

 

Met les protections en place, sinon tu seras toujours embêté!! :P

 

 

 

 

 

Salut Charles

 

je te poste le rapport hijackthis suivant :

 

Logfile of HijackThis v1.99.1

Scan saved at 10:41:18, on 17/10/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\atievxx.exe

C:\PROGRA~1\Wanadoo\CnxMon.exe

C:\PROGRA~1\MESSAG~1\StartMessager.exe

C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe

C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\hijackthis\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe

O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

 

 

 

 

 

mais pour ce qui est de l'autre rapport !!! sa deconne il me plante le portable !

 

mais j'ai tout de meme le rapport suivant :

 

 

catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-10-18 10:24:43

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden services & system hive ...

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden services: 0

hidden files: 0

 

 

voilà et depuis que j'ai installer zone alarme et antivir sa rame grave !!

 

a bientot !

Posté(e)

salut :P

 

Tu m'a posté le même rapport hijackthis :P

J'aurais aimé en voir un nouveau.

voilà et depuis que j'ai installer zone alarme et antivir sa rame grave !!

pas normal!! de combien de mémoire vive disposes tu ? Dis toi bien que sans l'antivirus, ton pc est très vulnérable.

Les pièges ne manquent pas sur la toile...

Si le rapport fait planter le pc, essaie ceci stp >

 

Télécharge WinPFind3U.exesur ton bureau.

  • Double clique sur le fichier téléchargé : un dossier nommé WinPFind3U va apparaitre sur ton bureau.
  • Ouvre le dossier et double clique sur le fichier WinPFind3U.exe pour lancer le programme.
  • Sous le groupe Files Created Within sélectionne 60 days
  • Sous le groupe Files Modified Within sélectionne 60 days
  • Sous le groupe String Search sélectionne Non-Microsoft
  • Sous le groupe Additional Scans coche les cases >
    Reg- Security Settings
    Reg- Software Policy Settings
    Reg- Uninstall List
    Reg- Additional Folder Scans

  • A présent clique sur le bouton Run Scan dans la barre d'outils
  • Lorsque le scan est terminé,le bloc-notes s'ouvre et affiche le rapport.
  • Clique sur le menu "Format" et assure toi que la case "Retour automatique à la ligne" ne soit pas cochée.
  • Copie/Colle le contenu du rapport dans ta prochaine réponse.

Posté(e)
salut :P

 

Tu m'a posté le même rapport hijackthis :P

J'aurais aimé en voir un nouveau.

 

pas normal!! de combien de mémoire vive disposes tu ? Dis toi bien que sans l'antivirus, ton pc est très vulnérable.

Les pièges ne manquent pas sur la toile...

Si le rapport fait planter le pc, essaie ceci stp >

 

Télécharge WinPFind3U.exesur ton bureau.

  • Double clique sur le fichier téléchargé : un dossier nommé WinPFind3U va apparaitre sur ton bureau.
  • Ouvre le dossier et double clique sur le fichier WinPFind3U.exe pour lancer le programme.
  • Sous le groupe Files Created Within sélectionne 60 days
  • Sous le groupe Files Modified Within sélectionne 60 days
  • Sous le groupe String Search sélectionne Non-Microsoft
  • Sous le groupe Additional Scans coche les cases >
    Reg- Security Settings
    Reg- Software Policy Settings
    Reg- Uninstall List
    Reg- Additional Folder Scans

  • A présent clique sur le bouton Run Scan dans la barre d'outils
  • Lorsque le scan est terminé,le bloc-notes s'ouvre et affiche le rapport.
  • Clique sur le menu "Format" et assure toi que la case "Retour automatique à la ligne" ne soit pas cochée.
  • Copie/Colle le contenu du rapport dans ta prochaine réponse.

 

 

desolé J'ai du mettre le meme rapport par erreur

voici un tout frais !!!

 

Logfile of HijackThis v1.99.1

Scan saved at 12:31:50, on 18/10/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\WINDOWS\system32\atievxx.exe

C:\PROGRA~1\Wanadoo\CnxMon.exe

C:\PROGRA~1\MESSAG~1\StartMessager.exe

C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe

C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program Files\hijackthis\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

C:\Program Files\hijackthis\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe

O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

par contre avec Winpfind3U le scan est interminable??? j'attend encore....

Posté(e)
desolé J'ai du mettre le meme rapport par erreur

voici un tout frais !!!

 

Logfile of HijackThis v1.99.1

Scan saved at 12:31:50, on 18/10/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\WINDOWS\system32\atievxx.exe

C:\PROGRA~1\Wanadoo\CnxMon.exe

C:\PROGRA~1\MESSAG~1\StartMessager.exe

C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe

C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program Files\hijackthis\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

C:\Program Files\hijackthis\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe

O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

par contre avec Winpfind3U le scan est interminable??? j'attend encore....

 

 

 

ca y est enfin c'est arrivé le rapport Winpfind33U

 

WinPFind3 logfile created on: 18/10/2007 13:42:38

WinPFind3U by OldTimer - Version 1.0.42 Folder = C:\Documents and Settings\Loriane\Bureau\WinPFind3u\

Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)

Internet Explorer (Version = 6.0.2900.2180)

 

63,48 Mb Total Physical Memory | 10,19 Mb Available Physical Memory | 16,05% Memory free

244,58 Mb Paging File | 69,36 Mb Available in Paging File | 28,36% Paging File free

Paging file location(s): C:\pagefile.sys 96 192;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 5,58 Gb Total Space | 2,72 Gb Free Space | 48,74% Space Free

D: Drive not present or media not loaded

Drive E: | 249,92 Mb Total Space | 157,25 Mb Free Space | 62,92% Space Free

F: Drive not present or media not loaded

 

Computer Name: SA-8713BE3E1A3A

Current User Name: Loriane

Logged in as Administrator.

Current Boot Mode: Normal

 

 

[Processes - Non-Microsoft Only]

avgnt.exe -> %ProgramFiles%\Avira\AntiVir PersonalEdition Classic\avgnt.exe -> Avira GmbH [Ver = 7.02.00.13 | Size = 249896 bytes | Modified Date = 31/08/2007 12:25:20 | Attr = ]

avguard.exe -> %ProgramFiles%\Avira\AntiVir PersonalEdition Classic\avguard.exe -> Avira GmbH [Ver = 7.00.00.81 | Size = 214056 bytes | Modified Date = 11/09/2007 09:40:34 | Attr = ]

cnxmon.exe -> %ProgramFiles%\Wanadoo\CnxMon.exe -> [Ver = 1, 0, 0, 1 | Size = 24576 bytes | Modified Date = 23/05/2003 08:46:24 | Attr = ]

dragdiag.exe -> %ProgramFiles%\Alcatel\SpeedTouch USB\dragdiag.exe -> THOMSON multimedia [Ver = 200.7.0.0 | Size = 861184 bytes | Modified Date = 06/06/2002 11:15:14 | Attr = ]

sched.exe -> %ProgramFiles%\Avira\AntiVir PersonalEdition Classic\sched.exe -> Avira GmbH [Ver = 7.00.00.62 | Size = 63016 bytes | Modified Date = 28/08/2007 13:16:24 | Attr = ]

startmessager.exe -> %ProgramFiles%\Messager Wanadoo\StartMessager.exe -> France Telecom [Ver = 3, 1, 0, 10 | Size = 32768 bytes | Modified Date = 04/04/2003 16:47:24 | Attr = ]

taskbaricon.exe -> %ProgramFiles%\Wanadoo\TaskbarIcon.exe -> France Télécom R&D [Ver = 5.6 (2) | Size = 53248 bytes | Modified Date = 23/05/2003 08:46:24 | Attr = ]

vsmon.exe -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 75768 bytes | Modified Date = 23/08/2006 23:38:26 | Attr = ]

winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.42.0 | Size = 322560 bytes | Modified Date = 04/09/2007 10:47:26 | Attr = ]

zlclient.exe -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 968696 bytes | Modified Date = 23/08/2006 23:38:28 | Attr = ]

 

[Win32 Services - Non-Microsoft Only]

(AntiVirScheduler) AntiVir PersonalEdition Classic Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\Avira\AntiVir PersonalEdition Classic\sched.exe -> Avira GmbH [Ver = 7.00.00.62 | Size = 63016 bytes | Modified Date = 28/08/2007 13:16:24 | Attr = ]

(AntiVirService) AntiVir PersonalEdition Classic Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Avira\AntiVir PersonalEdition Classic\avguard.exe -> Avira GmbH [Ver = 7.00.00.81 | Size = 214056 bytes | Modified Date = 11/09/2007 09:40:34 | Attr = ]

(dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 225280 bytes | Modified Date = 17/02/2005 19:58:52 | Attr = ]

(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Stopped] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 75768 bytes | Modified Date = 23/08/2006 23:38:26 | Attr = ]

 

[Registry - Non-Microsoft Only]

< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->

avgnt -> %ProgramFiles%\Avira\AntiVir PersonalEdition Classic\avgnt.exe -> Avira GmbH [Ver = 7.02.00.13 | Size = 249896 bytes | Modified Date = 31/08/2007 12:25:20 | Attr = ]

KernelFaultCheck -> -> File not found

MessagerStarter Wanadoo -> %ProgramFiles%\Messager Wanadoo\StartMessager.exe -> France Telecom [Ver = 3, 1, 0, 10 | Size = 32768 bytes | Modified Date = 04/04/2003 16:47:24 | Attr = ]

SpeedTouch USB Diagnostics -> %ProgramFiles%\Alcatel\SpeedTouch USB\dragdiag.exe -> THOMSON multimedia [Ver = 200.7.0.0 | Size = 861184 bytes | Modified Date = 06/06/2002 11:15:14 | Attr = ]

WooCnxMon -> %ProgramFiles%\Wanadoo\CnxMon.exe -> [Ver = 1, 0, 0, 1 | Size = 24576 bytes | Modified Date = 23/05/2003 08:46:24 | Attr = ]

WOOTASKBARICON -> %ProgramFiles%\Wanadoo\TaskbarIcon.exe -> France Télécom R&D [Ver = 5.6 (2) | Size = 53248 bytes | Modified Date = 23/05/2003 08:46:24 | Attr = ]

WOOWATCH -> %ProgramFiles%\Wanadoo\Watch.exe -> France Télécom R&D [Ver = 5.5 (81) | Size = 20480 bytes | Modified Date = 23/05/2003 08:46:24 | Attr = ]

Zone Labs Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 968696 bytes | Modified Date = 23/08/2006 23:38:28 | Attr = ]

< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->

< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->

< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> •

< HOSTS File > (790 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->

127.0.0.1 localhost -> ->

< Internet Explorer Settings > -> ->

HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->

HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->

HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Start Page -> http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home ->

HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->

HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->

HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKCU: Start Page -> http://www.wanadoo.fr ->

HKCU: ProxyEnable -> 0 ->

< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

msn.com [ - ] -> ->

< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->

{FB5F1910-F110-11d2-BB9E-00C04F795683} -> %ProgramFiles%\Messager Wanadoo\Messager Wanadoo.exe [buttonText: Messager Wanadoo] -> France Telecom [Ver = 3, 1, 31, 9 | Size = 1802240 bytes | Modified Date = 07/04/2003 11:10:20 | Attr = ]

< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform ->

SV1 -> ->

< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->

ipp -> Reg Data - Key not found -> File not found

msdaipp -> Reg Data - Key not found -> File not found

 

[Registry - Additional Scans - Non-Microsoft Only]

< Security Settings > -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\\DisableMonitoring -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> RpcSs; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfère des données entre les clients et les serveurs en tâche de fond. Si le service BITS est désactivé, les fonctionnalités telles que Windows Update ne fonctionneront pas correctement. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\system32\qmgr.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Assure la traduction d'adresses de réseau, l'adressage, les services de résolution de noms et/ou les services de prévention d'intrusion pour un réseau de petite entreprise ou un réseau domestique. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Pare-feu Windows / Partage de connexion Internet ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 262 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 0 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation des mises à jour Windows. Si ce service est désactivé, cet ordinateur ne pourra pas utiliser la fonctionnalité des mises à jour automatiques ou le site Windows Update. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\system32\wuauserv.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->

< Software Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\RTC\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\RTC\{A5B45060-354F-4097-A928-5125436C46F1}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\RTC\{A5B45060-354F-4097-A928-5125436C46F1}\\DisableServerCheck -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\RTC\{A5B45060-354F-4097-A928-5125436C46F1}\\LegacyPresence -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\EnableAdminTSRemote -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\NetCache\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\ExecutableTypes -> ADE;ADP;BAS;BAT;CHM;CMD;COM;CPL;CRT;EXE;HLP;HTA;INF;INS;ISP;LNK;MDB;MDE;MSC;MSI;MSP;MST;OCX;PCD;PIF;REG;SCR;SHS;URL;VB;WSC; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\TransparentEnabled -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\DefaultLevel -> 262144 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\AuthenticodeEnabled -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\PolicyScope -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\FriendlyName -> Mdac11.cab ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemData -> ^«0O•zI‰j

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemSize -> ; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\FriendlyName -> mdac20.cab ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemData -> g°Ô‹4:?Ó¼éÜdgó” ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemSize -> ; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\FriendlyName -> mdac20_a.cab ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemData -> 2xÜþøÈ“ÜŠ°Ý„} ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemSize -> –; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\FriendlyName -> _msadc10.cab ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemData -> ½š*ÛBëØV%Mø/g ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemSize -> å; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\FriendlyName -> msadc11.cab ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemData -> 8k_„ìöiÓk•j"À€ ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemSize -> r; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\Description -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\ItemData -> %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\Terminal Services\ -> ->

< Software Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\policies\ ->

HKEY_CURRENT_USER\Software\Policies\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> ->

< Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->

{350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP ->

{49672EC2-171B-47B4-8CE7-50D7806360D7} -> Windows Live Sign-in Assistant ->

{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7} -> Alcatel SpeedTouch USB Software ->

{F6326B60-1B1D-4ABF-BFCD-7B7404F44411} -> Windows Live Messenger ->

AntiVir PersonalEdition Classic -> Avira AntiVir PersonalEdition Classic ->

EspaceWanadoo.exe -> Wanadoo ->

HijackThis -> HijackThis 1.99.1 ->

Hijackthis Version Française_is1 -> Hijackthis Version Française ->

KB890859 -> Correctif Windows XP - KB890859 ->

KB893803v2 -> Windows Installer 3.1 (KB893803) ->

KB896423 -> Mise à jour de sécurité pour Windows XP (KB896423) ->

KB898461 -> Mise à jour pour Windows XP (KB898461) ->

KB914389 -> Mise à jour de sécurité pour Windows XP (KB914389) ->

KB920683 -> Mise à jour de sécurité pour Windows XP (KB920683) ->

KB923689 -> Mise à jour de sécurité pour Windows XP (KB923689) ->

KB923789 -> Mise à jour de sécurité pour Windows XP (KB923789) ->

KB928843 -> Mise à jour de sécurité pour Windows XP (KB928843) ->

Messager Wanadoo.exe -> Messager Wanadoo ->

MSNINST -> MSN ->

ZoneAlarm -> ZoneAlarm ->

 

[Files/Folders - Created Within 60 days]

hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 66637824 bytes | Created Date = 02/01/1601 23:00:00 | Attr = HS]

Inetpub -> %SystemDrive%\Inetpub -> [Folder | Created Date = 29/09/2007 20:40:00 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 07/10/2007 18:50:28 | Attr = H ]

$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Created Date = 07/10/2007 18:54:41 | Attr = H ]

$NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Created Date = 09/10/2007 21:01:20 | Attr = H ]

$NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Created Date = 09/10/2007 21:24:25 | Attr = H ]

$NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Created Date = 07/10/2007 18:50:29 | Attr = H ]

$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 09/10/2007 21:13:40 | Attr = H ]

$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 09/10/2007 21:18:36 | Attr = H ]

$NtUninstallKB923689$ -> %SystemRoot%\$NtUninstallKB923689$ -> [Folder | Created Date = 09/10/2007 21:22:31 | Attr = H ]

$NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Created Date = 09/10/2007 20:55:19 | Attr = H ]

bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Created Date = 05/10/2007 19:31:40 | Attr = S]

Bulles de savon.bmp -> %SystemRoot%\Bulles de savon.bmp -> [Ver = | Size = 65978 bytes | Created Date = 30/09/2007 09:38:47 | Attr = ]

control.ini -> %SystemRoot%\control.ini -> [Ver = | Size = 0 bytes | Created Date = 05/10/2007 19:13:38 | Attr = ]

desktop.ini -> %SystemRoot%\desktop.ini -> [Ver = | Size = 2 bytes | Created Date = 05/10/2007 18:58:14 | Attr = ]

Granit vert.bmp -> %SystemRoot%\Granit vert.bmp -> [Ver = | Size = 26582 bytes | Created Date = 30/09/2007 09:38:47 | Attr = ]

IIS Temporary Compressed Files -> %SystemRoot%\IIS Temporary Compressed Files -> [Folder | Created Date = 29/09/2007 21:12:08 | Attr = ]

imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Created Date = 30/09/2007 11:20:39 | Attr = ]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Created Date = 17/10/2007 13:28:22 | Attr = ]

Jour de pêche.bmp -> %SystemRoot%\Jour de pêche.bmp -> [Ver = | Size = 17336 bytes | Created Date = 30/09/2007 09:38:47 | Attr = ]

Kit.ini -> %SystemRoot%\Kit.ini -> [Ver = | Size = 67 bytes | Created Date = 08/10/2007 16:44:17 | Attr = ]

LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 18/10/2007 11:06:40 | Attr = ]

Mur de Santa Fe.bmp -> %SystemRoot%\Mur de Santa Fe.bmp -> [Ver = | Size = 65832 bytes | Created Date = 30/09/2007 09:38:48 | Attr = ]

ODBCINST.INI -> %SystemRoot%\ODBCINST.INI -> [Ver = | Size = 4205 bytes | Created Date = 30/09/2007 11:20:18 | Attr = ]

Plume.bmp -> %SystemRoot%\Plume.bmp -> [Ver = | Size = 16730 bytes | Created Date = 30/09/2007 09:38:47 | Attr = ]

REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Created Date = 05/10/2007 19:33:52 | Attr = ]

Rhododendron.bmp -> %SystemRoot%\Rhododendron.bmp -> [Ver = | Size = 17362 bytes | Created Date = 30/09/2007 09:38:48 | Attr = ]

Rivière Sumida.bmp -> %SystemRoot%\Rivière Sumida.bmp -> [Ver = | Size = 26680 bytes | Created Date = 30/09/2007 09:38:48 | Attr = ]

Rosace bleue 16.bmp -> %SystemRoot%\Rosace bleue 16.bmp -> [Ver = | Size = 1272 bytes | Created Date = 30/09/2007 09:38:46 | Attr = ]

SET1C.tmp -> %SystemRoot%\SET1C.tmp -> [Ver = | Size = 1014836 bytes | Created Date = 05/10/2007 20:38:29 | Attr = R ]

SET1F.tmp -> %SystemRoot%\SET1F.tmp -> [Ver = | Size = 1086058 bytes | Created Date = 05/10/2007 20:38:37 | Attr = R ]

SET2B.tmp -> %SystemRoot%\SET2B.tmp -> [Ver = | Size = 14043 bytes | Created Date = 05/10/2007 20:38:51 | Attr = R ]

SET3.tmp -> %SystemRoot%\SET3.tmp -> [Ver = | Size = 1014836 bytes | Created Date = 30/09/2007 11:17:30 | Attr = R ]

SET4.tmp -> %SystemRoot%\SET4.tmp -> [Ver = | Size = 1086058 bytes | Created Date = 30/09/2007 11:17:42 | Attr = R ]

SET8.tmp -> %SystemRoot%\SET8.tmp -> [Ver = | Size = 14043 bytes | Created Date = 30/09/2007 11:18:20 | Attr = R ]

Tasse à café.bmp -> %SystemRoot%\Tasse à café.bmp -> [Ver = | Size = 17062 bytes | Created Date = 30/09/2007 09:38:47 | Attr = ]

vb.ini -> %SystemRoot%\vb.ini -> [Ver = | Size = 36 bytes | Created Date = 05/10/2007 18:52:27 | Attr = ]

vbaddin.ini -> %SystemRoot%\vbaddin.ini -> [Ver = | Size = 37 bytes | Created Date = 05/10/2007 18:52:27 | Attr = ]

Vent de prairie.bmp -> %SystemRoot%\Vent de prairie.bmp -> [Ver = | Size = 65954 bytes | Created Date = 30/09/2007 09:38:48 | Attr = ]

WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest -> [Ver = | Size = 749 bytes | Created Date = 05/10/2007 19:01:21 | Attr = RH ]

winnt.bmp -> %SystemRoot%\winnt.bmp -> [Ver = | Size = 49102 bytes | Created Date = 05/10/2007 18:58:14 | Attr = HS]

winnt256.bmp -> %SystemRoot%\winnt256.bmp -> [Ver = | Size = 49102 bytes | Created Date = 05/10/2007 18:58:14 | Attr = HS]

WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Created Date = 05/10/2007 19:12:44 | Attr = ]

Zapotec.bmp -> %SystemRoot%\Zapotec.bmp -> [Ver = | Size = 9522 bytes | Created Date = 30/09/2007 09:38:48 | Attr = ]

desktop.ini -> %SystemRoot%\tasks\desktop.ini -> [Ver = | Size = 65 bytes | Created Date = 05/10/2007 18:58:00 | Attr = RH ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Created Date = 05/10/2007 19:34:34 | Attr = H ]

$winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 560 bytes | Created Date = 30/09/2007 11:15:08 | Attr = ]

amcompat.tlb -> %System32%\amcompat.tlb -> [Ver = | Size = 16832 bytes | Created Date = 05/10/2007 19:12:52 | Attr = ]

atidrab.dll -> %System32%\atidrab.dll -> ATI Technologies Inc. [Ver = 5.01.2195.5012 (ReleasedBinaries.010718-0005) | Size = 382592 bytes | Created Date = 30/09/2007 11:26:11 | Attr = ]

AUTOEXEC.NT -> %System32%\AUTOEXEC.NT -> [Ver = | Size = 1896 bytes | Created Date = 30/09/2007 11:19:22 | Attr = ]

bopomofo.uce -> %System32%\bopomofo.uce -> [Ver = | Size = 22984 bytes | Created Date = 30/09/2007 09:38:44 | Attr = ]

Cache -> %System32%\Cache -> [Folder | Created Date = 29/09/2007 20:51:31 | Attr = ]

cdplayer.exe.manifest -> %System32%\cdplayer.exe.manifest -> [Ver = | Size = 749 bytes | Created Date = 05/10/2007 19:01:21 | Attr = RH ]

CONFIG.NT -> %System32%\CONFIG.NT -> [Ver = | Size = 3072 bytes | Created Date = 05/10/2007 19:13:38 | Attr = ]

CONFIG.TMP -> %System32%\CONFIG.TMP -> [Ver = | Size = 3072 bytes | Created Date = 30/09/2007 11:19:22 | Attr = ]

c_10006.nls -> %System32%\c_10006.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_10007.nls -> %System32%\c_10007.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:53 | Attr = ]

c_10010.nls -> %System32%\c_10010.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_10017.nls -> %System32%\c_10017.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:53 | Attr = ]

c_10029.nls -> %System32%\c_10029.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_10081.nls -> %System32%\c_10081.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:57 | Attr = ]

c_10082.nls -> %System32%\c_10082.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_20127.nls -> %System32%\c_20127.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:30 | Attr = ]

C_28594.NLS -> %System32%\C_28594.NLS -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:48 | Attr = ]

C_28595.NLS -> %System32%\C_28595.NLS -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:54 | Attr = ]

C_28597.NLS -> %System32%\C_28597.NLS -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_28599.nls -> %System32%\c_28599.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:57 | Attr = ]

c_28603.nls -> %System32%\c_28603.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:59 | Attr = ]

c_737.nls -> %System32%\c_737.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_852.nls -> %System32%\c_852.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_855.nls -> %System32%\c_855.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:48 | Attr = ]

c_857.nls -> %System32%\c_857.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:57 | Attr = ]

c_866.nls -> %System32%\c_866.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:48 | Attr = ]

c_869.nls -> %System32%\c_869.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_875.nls -> %System32%\c_875.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

desktop.ini -> %System32%\desktop.ini -> [Ver = | Size = 2 bytes | Created Date = 05/10/2007 18:58:14 | Attr = ]

dgrpsetu.dll -> %System32%\dgrpsetu.dll -> Digi International, Inc. [Ver = 2.3.7 | Size = 176157 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

dgsetup.dll -> %System32%\dgsetup.dll -> Digi International [Ver = v3.7.3.0 | Size = 86044 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

DRVSTORE -> %System32%\DRVSTORE -> [Folder | Created Date = 07/10/2007 16:35:06 | Attr = ]

emptyregdb.dat -> %System32%\emptyregdb.dat -> [Ver = | Size = 21892 bytes | Created Date = 05/10/2007 18:53:05 | Attr = ]

EqnClass.Dll -> %System32%\EqnClass.Dll -> Equinox Systems Inc. [Ver = 5.0u(58) | Size = 103424 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 90296 bytes | Created Date = 30/09/2007 11:16:10 | Attr = ]

gb2312.uce -> %System32%\gb2312.uce -> [Ver = | Size = 24006 bytes | Created Date = 30/09/2007 09:38:44 | Attr = ]

hticons.dll -> %System32%\hticons.dll -> Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Created Date = 30/09/2007 09:39:01 | Attr = ]

hypertrm.dll -> %System32%\hypertrm.dll -> Hilgraeve, Inc. [Ver = 5.1.2600.2180 | Size = 352256 bytes | Created Date = 30/09/2007 09:38:07 | Attr = ]

ideograf.uce -> %System32%\ideograf.uce -> [Ver = | Size = 60458 bytes | Created Date = 30/09/2007 09:38:45 | Attr = ]

isrdbg32.dll -> %System32%\isrdbg32.dll -> Intel Corporation [Ver = 0.0 | Size = 32768 bytes | Created Date = 05/10/2007 18:57:21 | Attr = ]

kanji_1.uce -> %System32%\kanji_1.uce -> [Ver = | Size = 6948 bytes | Created Date = 30/09/2007 09:38:45 | Attr = ]

kanji_2.uce -> %System32%\kanji_2.uce -> [Ver = | Size = 8484 bytes | Created Date = 30/09/2007 09:38:45 | Attr = ]

korean.uce -> %System32%\korean.uce -> [Ver = | Size = 12876 bytes | Created Date = 30/09/2007 09:38:45 | Attr = ]

libeay32_0.9.6l.dll -> %System32%\libeay32_0.9.6l.dll -> [Ver = | Size = 796584 bytes | Created Date = 17/10/2007 13:31:28 | Attr = ]

Logfiles -> %System32%\Logfiles -> [Folder | Created Date = 29/09/2007 20:39:59 | Attr = ]

logonui.exe.manifest -> %System32%\logonui.exe.manifest -> [Ver = | Size = 488 bytes | Created Date = 05/10/2007 19:02:05 | Attr = RH ]

msdtcprf.h -> %System32%\msdtcprf.h -> [Ver = | Size = 768 bytes | Created Date = 30/09/2007 09:38:38 | Attr = ]

msdtcprf.ini -> %System32%\msdtcprf.ini -> [Ver = | Size = 3914 bytes | Created Date = 30/09/2007 09:38:38 | Attr = ]

ncpa.cpl.manifest -> %System32%\ncpa.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 05/10/2007 19:01:20 | Attr = RH ]

nscompat.tlb -> %System32%\nscompat.tlb -> [Ver = | Size = 23392 bytes | Created Date = 05/10/2007 19:12:52 | Attr = ]

nwc.cpl.manifest -> %System32%\nwc.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 05/10/2007 19:01:20 | Attr = RH ]

PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 827772 bytes | Created Date = 30/09/2007 11:20:24 | Attr = ]

PreInstall -> %System32%\PreInstall -> [Folder | Created Date = 07/10/2007 18:50:41 | Attr = ]

ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Created Date = 29/09/2007 20:30:59 | Attr = ]

rnaph.dll -> %System32%\rnaph.dll -> [Ver = | Size = 0 bytes | Created Date = 06/10/2007 18:35:22 | Attr = ]

sapi.cpl.manifest -> %System32%\sapi.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 05/10/2007 19:01:20 | Attr = RH ]

shiftjis.uce -> %System32%\shiftjis.uce -> [Ver = | Size = 16740 bytes | Created Date = 30/09/2007 09:38:46 | Attr = ]

spxcoins.dll -> %System32%\spxcoins.dll -> Perle Systems Ltd. [Ver = 1.0.0.0007 | Size = 24661 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

stci.dll -> %System32%\stci.dll -> [Ver = | Size = 5607 bytes | Created Date = 06/10/2007 18:39:21 | Attr = ]

subrange.uce -> %System32%\subrange.uce -> [Ver = | Size = 93702 bytes | Created Date = 30/09/2007 09:38:46 | Attr = ]

tslabels.h -> %System32%\tslabels.h -> [Ver = | Size = 3286 bytes | Created Date = 30/09/2007 09:38:40 | Attr = ]

tslabels.ini -> %System32%\tslabels.ini -> [Ver = | Size = 27768 bytes | Created Date = 30/09/2007 09:38:40 | Attr = ]

usrlogon.cmd -> %System32%\usrlogon.cmd -> [Ver = | Size = 1263 bytes | Created Date = 30/09/2007 09:38:41 | Attr = ]

vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 54112 bytes | Created Date = 17/10/2007 13:30:27 | Attr = ]

vsdata.dll -> %System32%\vsdata.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 83960 bytes | Created Date = 17/10/2007 13:28:20 | Attr = ]

vsdatant.sys -> %System32%\vsdatant.sys -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 392824 bytes | Created Date = 17/10/2007 13:30:28 | Attr = ]

vsinit.dll -> %System32%\vsinit.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 157688 bytes | Created Date = 17/10/2007 13:28:20 | Attr = ]

vsmonapi.dll -> %System32%\vsmonapi.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 104440 bytes | Created Date = 17/10/2007 13:30:33 | Attr = ]

vspubapi.dll -> %System32%\vspubapi.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 268280 bytes | Created Date = 17/10/2007 13:30:34 | Attr = ]

vsregexp.dll -> %System32%\vsregexp.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 71672 bytes | Created Date = 17/10/2007 13:31:28 | Attr = ]

vsutil.dll -> %System32%\vsutil.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 440312 bytes | Created Date = 17/10/2007 13:28:19 | Attr = ]

vsutil_loc040c.dll -> %System32%\vsutil_loc040c.dll -> Zone Labs Inc. [Ver = 5.3.017.000 | Size = 42920 bytes | Created Date = 17/10/2007 13:31:57 | Attr = ]

vswmi.dll -> %System32%\vswmi.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 59384 bytes | Created Date = 17/10/2007 13:30:47 | Attr = ]

vsxml.dll -> %System32%\vsxml.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 100344 bytes | Created Date = 17/10/2007 13:30:38 | Attr = ]

WindowsLogon.manifest -> %System32%\WindowsLogon.manifest -> [Ver = | Size = 488 bytes | Created Date = 05/10/2007 19:02:05 | Attr = RH ]

wmimgmt.msc -> %System32%\wmimgmt.msc -> [Ver = | Size = 63488 bytes | Created Date = 30/09/2007 09:38:22 | Attr = ]

WooDial2000.dll -> %System32%\WooDial2000.dll -> France Télécom R&D [Ver = 5.6 (36) | Size = 32768 bytes | Created Date = 06/10/2007 18:46:27 | Attr = ]

wuaucpl.cpl.manifest -> %System32%\wuaucpl.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 05/10/2007 19:01:20 | Attr = RH ]

zlcomm.dll -> %System32%\zlcomm.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 83960 bytes | Created Date = 17/10/2007 13:31:16 | Attr = ]

zlcommdb.dll -> %System32%\zlcommdb.dll -> Zone Labs, LLC [Ver = 6.5.737.000 | Size = 71672 bytes | Created Date = 17/10/2007 13:31:16 | Attr = ]

zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Created Date = 17/10/2007 13:34:43 | Attr = H ]

ZoneLabs -> %System32%\ZoneLabs -> [Folder | Created Date = 17/10/2007 13:30:34 | Attr = ]

big5.nls -> %System32%\dllcache\big5.nls -> [Ver = | Size = 66728 bytes | Created Date = 05/10/2007 19:18:28 | Attr = ]

bopomofo.nls -> %System32%\dllcache\bopomofo.nls -> [Ver = | Size = 82172 bytes | Created Date = 05/10/2007 19:18:29 | Attr = ]

cap7146.sys -> %System32%\dllcache\cap7146.sys -> Philips Semiconductors GmbH [Ver = 1.00 (XPClient.010817-1148) | Size = 54528 bytes | Created Date = 05/10/2007 19:18:57 | Attr = ]

chtskf.dll -> %System32%\dllcache\chtskf.dll -> [Ver = | Size = 173568 bytes | Created Date = 05/10/2007 19:19:11 | Attr = ]

c_10001.nls -> %System32%\dllcache\c_10001.nls -> [Ver = | Size = 162850 bytes | Created Date = 05/10/2007 19:18:32 | Attr = ]

c_10002.nls -> %System32%\dllcache\c_10002.nls -> [Ver = | Size = 195618 bytes | Created Date = 05/10/2007 19:18:32 | Attr = ]

c_10003.nls -> %System32%\dllcache\c_10003.nls -> [Ver = | Size = 177698 bytes | Created Date = 05/10/2007 19:18:33 | Attr = ]

c_10004.nls -> %System32%\dllcache\c_10004.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:33 | Attr = ]

c_10005.nls -> %System32%\dllcache\c_10005.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:33 | Attr = ]

c_10006.nls -> %System32%\dllcache\c_10006.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_10007.nls -> %System32%\dllcache\c_10007.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:53 | Attr = ]

c_10008.nls -> %System32%\dllcache\c_10008.nls -> [Ver = | Size = 173602 bytes | Created Date = 05/10/2007 19:18:34 | Attr = ]

c_10010.nls -> %System32%\dllcache\c_10010.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_10017.nls -> %System32%\dllcache\c_10017.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:53 | Attr = ]

c_10021.nls -> %System32%\dllcache\c_10021.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:34 | Attr = ]

c_10029.nls -> %System32%\dllcache\c_10029.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_10081.nls -> %System32%\dllcache\c_10081.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:57 | Attr = ]

c_10082.nls -> %System32%\dllcache\c_10082.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_1047.nls -> %System32%\dllcache\c_1047.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:35 | Attr = ]

c_1140.nls -> %System32%\dllcache\c_1140.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:35 | Attr = ]

c_1141.nls -> %System32%\dllcache\c_1141.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:36 | Attr = ]

c_1142.nls -> %System32%\dllcache\c_1142.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:36 | Attr = ]

c_1143.nls -> %System32%\dllcache\c_1143.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:36 | Attr = ]

c_1144.nls -> %System32%\dllcache\c_1144.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:36 | Attr = ]

c_1145.nls -> %System32%\dllcache\c_1145.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:37 | Attr = ]

c_1146.nls -> %System32%\dllcache\c_1146.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:37 | Attr = ]

c_1147.nls -> %System32%\dllcache\c_1147.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:37 | Attr = ]

c_1148.nls -> %System32%\dllcache\c_1148.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:37 | Attr = ]

c_1149.nls -> %System32%\dllcache\c_1149.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:38 | Attr = ]

c_1361.nls -> %System32%\dllcache\c_1361.nls -> [Ver = | Size = 189986 bytes | Created Date = 05/10/2007 19:18:39 | Attr = ]

c_20000.nls -> %System32%\dllcache\c_20000.nls -> [Ver = | Size = 180258 bytes | Created Date = 05/10/2007 19:18:39 | Attr = ]

c_20001.nls -> %System32%\dllcache\c_20001.nls -> [Ver = | Size = 186402 bytes | Created Date = 05/10/2007 19:18:39 | Attr = ]

c_20002.nls -> %System32%\dllcache\c_20002.nls -> [Ver = | Size = 173602 bytes | Created Date = 05/10/2007 19:18:40 | Attr = ]

c_20003.nls -> %System32%\dllcache\c_20003.nls -> [Ver = | Size = 185378 bytes | Created Date = 05/10/2007 19:18:40 | Attr = ]

c_20004.nls -> %System32%\dllcache\c_20004.nls -> [Ver = | Size = 180258 bytes | Created Date = 05/10/2007 19:18:40 | Attr = ]

c_20005.nls -> %System32%\dllcache\c_20005.nls -> [Ver = | Size = 187938 bytes | Created Date = 05/10/2007 19:18:41 | Attr = ]

c_20105.nls -> %System32%\dllcache\c_20105.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:41 | Attr = ]

c_20106.nls -> %System32%\dllcache\c_20106.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:41 | Attr = ]

c_20107.nls -> %System32%\dllcache\c_20107.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:42 | Attr = ]

c_20108.nls -> %System32%\dllcache\c_20108.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:42 | Attr = ]

c_20127.nls -> %System32%\dllcache\c_20127.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:30 | Attr = ]

c_20269.nls -> %System32%\dllcache\c_20269.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:43 | Attr = ]

c_20273.nls -> %System32%\dllcache\c_20273.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:43 | Attr = ]

c_20277.nls -> %System32%\dllcache\c_20277.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:43 | Attr = ]

c_20278.nls -> %System32%\dllcache\c_20278.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:43 | Attr = ]

c_20280.nls -> %System32%\dllcache\c_20280.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:44 | Attr = ]

c_20284.nls -> %System32%\dllcache\c_20284.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:44 | Attr = ]

c_20285.nls -> %System32%\dllcache\c_20285.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:44 | Attr = ]

c_20290.nls -> %System32%\dllcache\c_20290.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:44 | Attr = ]

c_20297.nls -> %System32%\dllcache\c_20297.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:45 | Attr = ]

c_20420.nls -> %System32%\dllcache\c_20420.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:45 | Attr = ]

c_20423.nls -> %System32%\dllcache\c_20423.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:45 | Attr = ]

c_20424.nls -> %System32%\dllcache\c_20424.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:45 | Attr = ]

c_20833.nls -> %System32%\dllcache\c_20833.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:46 | Attr = ]

c_20838.nls -> %System32%\dllcache\c_20838.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:46 | Attr = ]

c_20871.nls -> %System32%\dllcache\c_20871.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:46 | Attr = ]

c_20880.nls -> %System32%\dllcache\c_20880.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:47 | Attr = ]

c_20924.nls -> %System32%\dllcache\c_20924.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:47 | Attr = ]

c_20932.nls -> %System32%\dllcache\c_20932.nls -> [Ver = | Size = 180770 bytes | Created Date = 05/10/2007 19:18:47 | Attr = ]

c_20936.nls -> %System32%\dllcache\c_20936.nls -> [Ver = | Size = 173602 bytes | Created Date = 05/10/2007 19:18:48 | Attr = ]

c_20949.nls -> %System32%\dllcache\c_20949.nls -> [Ver = | Size = 177698 bytes | Created Date = 05/10/2007 19:18:48 | Attr = ]

c_21025.nls -> %System32%\dllcache\c_21025.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:48 | Attr = ]

c_21027.nls -> %System32%\dllcache\c_21027.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:49 | Attr = ]

c_28594.nls -> %System32%\dllcache\c_28594.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:48 | Attr = ]

c_28595.nls -> %System32%\dllcache\c_28595.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:54 | Attr = ]

c_28596.nls -> %System32%\dllcache\c_28596.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:49 | Attr = ]

c_28597.nls -> %System32%\dllcache\c_28597.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_28599.nls -> %System32%\dllcache\c_28599.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:57 | Attr = ]

c_28603.nls -> %System32%\dllcache\c_28603.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:59 | Attr = ]

c_708.nls -> %System32%\dllcache\c_708.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:51 | Attr = ]

c_720.nls -> %System32%\dllcache\c_720.nls -> [Ver = | Size = 66594 bytes | Created Date = 05/10/2007 19:18:52 | Attr = ]

c_737.nls -> %System32%\dllcache\c_737.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_852.nls -> %System32%\dllcache\c_852.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:45 | Attr = ]

c_855.nls -> %System32%\dllcache\c_855.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:48 | Attr = ]

c_857.nls -> %System32%\dllcache\c_857.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:57 | Attr = ]

c_858.nls -> %System32%\dllcache\c_858.nls -> [Ver = | Size = 66594 bytes | Created Date = 05/10/2007 19:18:52 | Attr = ]

c_862.nls -> %System32%\dllcache\c_862.nls -> [Ver = | Size = 66594 bytes | Created Date = 05/10/2007 19:18:53 | Attr = ]

c_864.nls -> %System32%\dllcache\c_864.nls -> [Ver = | Size = 66594 bytes | Created Date = 05/10/2007 19:18:53 | Attr = ]

c_866.nls -> %System32%\dllcache\c_866.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:48 | Attr = ]

c_869.nls -> %System32%\dllcache\c_869.nls -> [Ver = | Size = 66594 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

c_870.nls -> %System32%\dllcache\c_870.nls -> [Ver = | Size = 66082 bytes | Created Date = 05/10/2007 19:18:54 | Attr = ]

c_875.nls -> %System32%\dllcache\c_875.nls -> [Ver = | Size = 66082 bytes | Created Date = 30/09/2007 11:19:50 | Attr = ]

dgrpsetu.dll -> %System32%\dllcache\dgrpsetu.dll -> Digi International, Inc. [Ver = 2.3.7 | Size = 176157 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

dgsetup.dll -> %System32%\dllcache\dgsetup.dll -> Digi International [Ver = v3.7.3.0 | Size = 86044 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

eqnclass.dll -> %System32%\dllcache\eqnclass.dll -> Equinox Systems Inc. [Ver = 5.0u(58) | Size = 103424 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

esucmd.dll -> %System32%\dllcache\esucmd.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 31744 bytes | Created Date = 05/10/2007 19:20:45 | Attr = ]

esuimgd.dll -> %System32%\dllcache\esuimgd.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 57856 bytes | Created Date = 05/10/2007 19:20:45 | Attr = ]

esunid.dll -> %System32%\dllcache\esunid.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 45568 bytes | Created Date = 05/10/2007 19:20:46 | Attr = ]

FP4.CAT -> %System32%\dllcache\FP4.CAT -> [Ver = | Size = 30983 bytes | Created Date = 30/09/2007 11:18:35 | Attr = ]

fpencode.dll -> %System32%\dllcache\fpencode.dll -> [Ver = | Size = 94208 bytes | Created Date = 05/10/2007 19:20:59 | Attr = ]

hanja.lex -> %System32%\dllcache\hanja.lex -> [Ver = | Size = 108827 bytes | Created Date = 05/10/2007 19:21:30 | Attr = ]

HPCRDP.CAT -> %System32%\dllcache\HPCRDP.CAT -> [Ver = | Size = 13497 bytes | Created Date = 30/09/2007 11:18:35 | Attr = ]

hwxjpn.dll -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Created Date = 05/10/2007 19:21:47 | Attr = ]

IASNT4.CAT -> %System32%\dllcache\IASNT4.CAT -> [Ver = | Size = 8599 bytes | Created Date = 30/09/2007 11:18:36 | Attr = ]

imekr.lex -> %System32%\dllcache\imekr.lex -> [Ver = | Size = 134339 bytes | Created Date = 05/10/2007 19:22:26 | Attr = ]

imjpinst.exe -> %System32%\dllcache\imjpinst.exe -> [Ver = | Size = 196665 bytes | Created Date = 05/10/2007 19:22:31 | Attr = ]

IMS.CAT -> %System32%\dllcache\IMS.CAT -> [Ver = | Size = 14043 bytes | Created Date = 30/09/2007 11:18:35 | Attr = ]

imscinst.exe -> %System32%\dllcache\imscinst.exe -> [Ver = | Size = 59392 bytes | Created Date = 05/10/2007 19:22:35 | Attr = ]

isrdbg32.dll -> %System32%\dllcache\isrdbg32.dll -> Intel Corporation [Ver = 0.0 | Size = 32768 bytes | Created Date = 05/10/2007 18:57:21 | Attr = ]

korwbrkr.lex -> %System32%\dllcache\korwbrkr.lex -> [Ver = | Size = 1158818 bytes | Created Date = 05/10/2007 19:23:11 | Attr = ]

ksc.nls -> %System32%\dllcache\ksc.nls -> [Ver = | Size = 47066 bytes | Created Date = 05/10/2007 19:23:13 | Attr = ]

MAPIMIG.CAT -> %System32%\dllcache\MAPIMIG.CAT -> [Ver = | Size = 399670 bytes | Created Date = 30/09/2007 11:18:34 | Attr = ]

mediactr.cat -> %System32%\dllcache\mediactr.cat -> [Ver = | Size = 31965 bytes | Created Date = 30/09/2007 11:18:36 | Attr = ]

msinfo.dll -> %System32%\dllcache\msinfo.dll -> [Ver = 7, 0, 0, 0 | Size = 381952 bytes | Created Date = 05/10/2007 18:57:26 | Attr = ]

MSMSGS.CAT -> %System32%\dllcache\MSMSGS.CAT -> [Ver = | Size = 9581 bytes | Created Date = 30/09/2007 11:18:35 | Attr = ]

msn7.cat -> %System32%\dllcache\msn7.cat -> [Ver = | Size = 19569 bytes | Created Date = 30/09/2007 11:18:36 | Attr = ]

msn9.cat -> %System32%\dllcache\msn9.cat -> [Ver = | Size = 11651 bytes | Created Date = 30/09/2007 11:18:37 | Attr = ]

MSTSWEB.CAT -> %System32%\dllcache\MSTSWEB.CAT -> [Ver = | Size = 7245 bytes | Created Date = 30/09/2007 11:18:36 | Attr = ]

MW770.CAT -> %System32%\dllcache\MW770.CAT -> [Ver = | Size = 37509 bytes | Created Date = 30/09/2007 11:18:35 | Attr = ]

netfx.cat -> %System32%\dllcache\netfx.cat -> [Ver = | Size = 141702 bytes | Created Date = 30/09/2007 11:18:37 | Attr = ]

nls302en.lex -> %System32%\dllcache\nls302en.lex -> [Ver = | Size = 4399505 bytes | Created Date = 05/10/2007 18:59:21 | Attr = ]

NT5.CAT -> %System32%\dllcache\NT5.CAT -> [Ver = | Size = 1897552 bytes | Created Date = 30/09/2007 11:18:31 | Attr = ]

NT5IIS.CAT -> %System32%\dllcache\NT5IIS.CAT -> [Ver = | Size = 809394 bytes | Created Date = 30/09/2007 11:18:34 | Attr = ]

NT5INF.CAT -> %System32%\dllcache\NT5INF.CAT -> [Ver = | Size = 623110 bytes | Created Date = 30/09/2007 11:18:31 | Attr = ]

NTPRINT.CAT -> %System32%\dllcache\NTPRINT.CAT -> [Ver = | Size = 1086058 bytes | Created Date = 30/09/2007 11:18:33 | Attr = ]

OEMBIOS.CAT -> %System32%\dllcache\OEMBIOS.CAT -> [Ver = | Size = 7382 bytes | Created Date = 30/09/2007 11:18:36 | Attr = ]

pinball.exe -> %System32%\dllcache\pinball.exe -> Cinematronics [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 284160 bytes | Created Date = 30/09/2007 09:38:09 | Attr = ]

pintlcsa.dll -> %System32%\dllcache\pintlcsa.dll -> [Ver = | Size = 175104 bytes | Created Date = 05/10/2007 19:26:07 | Attr = ]

prc.nls -> %System32%\dllcache\prc.nls -> [Ver = | Size = 83748 bytes | Created Date = 05/10/2007 19:26:11 | Attr = ]

prcp.nls -> %System32%\dllcache\prcp.nls -> [Ver = | Size = 83748 bytes | Created Date = 05/10/2007 19:26:12 | Attr = ]

rw330ext.dll -> %System32%\dllcache\rw330ext.dll -> RICOH Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 26624 bytes | Created Date = 05/10/2007 19:26:54 | Attr = ]

rwia001.dll -> %System32%\dllcache\rwia001.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 81408 bytes | Created Date = 05/10/2007 19:26:54 | Attr = ]

rwia330.dll -> %System32%\dllcache\rwia330.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 81408 bytes | Created Date = 05/10/2007 19:26:55 | Attr = ]

SP2.CAT -> %System32%\dllcache\SP2.CAT -> [Ver = | Size = 1014836 bytes | Created Date = 30/09/2007 11:18:33 | Attr = ]

spxcoins.dll -> %System32%\dllcache\spxcoins.dll -> Perle Systems Ltd. [Ver = 1.0.0.0007 | Size = 24661 bytes | Created Date = 30/09/2007 11:19:26 | Attr = ]

srframe.mmf -> %System32%\dllcache\srframe.mmf -> [Ver = | Size = 984 bytes | Created Date = 05/10/2007 18:58:05 | Attr = ]

tabletpc.cat -> %System32%\dllcache\tabletpc.cat -> [Ver = | Size = 103124 bytes | Created Date = 30/09/2007 11:18:36 | Attr = ]

wmerrenu.cat -> %System32%\dllcache\wmerrenu.cat -> [Ver = | Size = 7334 bytes | Created Date = 30/09/2007 11:18:35 | Attr = ]

xjis.nls -> %System32%\dllcache\xjis.nls -> [Ver = | Size = 28288 bytes | Created Date = 05/10/2007 19:30:32 | Attr = ]

ac97intc.sys -> %System32%\drivers\ac97intc.sys -> Intel Corporation [Ver = 5.10.3523 built by: WinDDK | Size = 96256 bytes | Created Date = 30/09/2007 11:26:32 | Attr = ]

alcacr.sys -> %System32%\drivers\alcacr.sys -> THOMSON multimedia [Ver = 200.7.0.0 | Size = 4000 bytes | Created Date = 06/10/2007 18:39:20 | Attr = ]

alcan5wn.sys -> %System32%\drivers\alcan5wn.sys -> THOMSON multimedia [Ver = 200.7.0.0 | Size = 53168 bytes | Created Date = 06/10/2007 18:39:19 | Attr = ]

alcaudsl.sys -> %System32%\drivers\alcaudsl.sys -> THOMSON multimedia [Ver = 200.7.0.0 | Size = 743136 bytes | Created Date = 06/10/2007 18:39:20 | Attr = ]

alcawh.sys -> %System32%\drivers\alcawh.sys -> THOMSON multimedia [Ver = 200.7.0.0 | Size = 5312 bytes | Created Date = 06/10/2007 18:39:20 | Attr = ]

atimpab.sys -> %System32%\drivers\atimpab.sys -> ATI Technologies Inc. [Ver = 5.00.2195.5007 (ReleasedBinaries.010718-0005) | Size = 289920 bytes | Created Date = 30/09/2007 11:26:12 | Attr = ]

avg7rsw.sys -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Created Date = 05/10/2007 20:01:46 | Attr = ]

avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Created Date = 05/10/2007 20:01:58 | Attr = ]

avgntdd.sys -> %System32%\drivers\avgntdd.sys -> Avira GmbH [Ver = 6.39.00.02 | Size = 40768 bytes | Created Date = 17/10/2007 12:51:17 | Attr = ]

avgntmgr.sys -> %System32%\drivers\avgntmgr.sys -> Avira GmbH [Ver = 6.37.01.01 | Size = 21312 bytes | Created Date = 17/10/2007 12:51:18 | Attr = ]

avipbb.sys -> %System32%\drivers\avipbb.sys -> AVIRA GmbH [Ver = 1.00.02.11 | Size = 62016 bytes | Created Date = 17/10/2007 12:51:09 | Attr = ]

KProcCheck.sys -> %System32%\drivers\KProcCheck.sys -> [Ver = | Size = 4096 bytes | Created Date = 17/10/2007 15:03:23 | Attr = ]

ltmdmnt.sys -> %System32%\drivers\ltmdmnt.sys -> LT [Ver = 8.28 | Size = 607452 bytes | Created Date = 30/09/2007 11:25:57 | Attr = ]

ssmdrv.sys -> %System32%\drivers\ssmdrv.sys -> Avira GmbH [Ver = 7.0.1.1 | Size = 28352 bytes | Created Date = 17/10/2007 12:51:16 | Attr = ]

hosts.msn -> %System32%\drivers\etc\hosts.msn -> [Ver = | Size = 790 bytes | Created Date = 07/10/2007 16:49:46 | Attr = ]

avg7 -> %AllUsersAppData%\avg7 -> [Folder | Created Date = 05/10/2007 20:01:41 | Attr = ]

Avira -> %AllUsersAppData%\Avira -> [Folder | Created Date = 14/10/2007 22:11:34 | Attr = ]

desktop.ini -> %AllUsersAppData%\desktop.ini -> [Ver = | Size = 62 bytes | Created Date = 05/10/2007 20:39:09 | Attr = HS]

Microsoft -> %AllUsersAppData%\Microsoft -> [Folder | Created Date = 05/10/2007 20:35:48 | Attr = S]

AVG7 -> %UserAppData%\AVG7 -> [Folder | Created Date = 05/10/2007 21:24:43 | Attr = ]

desktop.ini -> %UserAppData%\desktop.ini -> [Ver = | Size = 62 bytes | Created Date = 05/10/2007 21:21:57 | Attr = HS]

Help -> %UserAppData%\Help -> [Folder | Created Date = 07/10/2007 14:29:35 | Attr = ]

Identities -> %UserAppData%\Identities -> [Folder | Created Date = 05/10/2007 21:22:58 | Attr = ]

Macromedia -> %UserAppData%\Macromedia -> [Folder | Created Date = 07/10/2007 15:12:14 | Attr = ]

Microsoft -> %UserAppData%\Microsoft -> [Folder | Created Date = 05/10/2007 21:21:55 | Attr = S]

GDIPFONTCACHEV1.DAT -> %LocalAppData%\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 12328 bytes | Created Date = 06/10/2007 19:47:03 | Attr = ]

Help -> %LocalAppData%\Help -> [Folder | Created Date = 07/10/2007 14:29:35 | Attr = ]

IconCache.db -> %LocalAppData%\IconCache.db -> [Ver = | Size = 2107040 bytes | Created Date = 05/10/2007 21:34:07 | Attr = H ]

Identities -> %LocalAppData%\Identities -> [Folder | Created Date = 07/10/2007 12:50:59 | Attr = ]

Microsoft -> %LocalAppData%\Microsoft -> [Folder | Created Date = 05/10/2007 21:21:55 | Attr = ]

desktop.ini -> %AllUsersDocuments%\desktop.ini -> [Ver = | Size = 62 bytes | Created Date = 05/10/2007 20:39:09 | Attr = HS]

Ma musique -> %AllUsersDocuments%\Ma musique -> [Folder | Created Date = 05/10/2007 18:51:30 | Attr = R ]

Mes images -> %AllUsersDocuments%\Mes images -> [Folder | Created Date = 05/10/2007 18:56:33 | Attr = R ]

Mes vidéos -> %AllUsersDocuments%\Mes vidéos -> [Folder | Created Date = 05/10/2007 18:50:11 | Attr = R ]

antivir_workstation_win7u_en_h.exe -> %UserDocuments%\antivir_workstation_win7u_en_h.exe -> [Ver = | Size = 17788920 bytes | Created Date = 14/10/2007 21:50:50 | Attr = ]

desktop.ini -> %UserDocuments%\desktop.ini -> [Ver = | Size = 79 bytes | Created Date = 05/10/2007 21:22:33 | Attr = HS]

DiagHelp.zip -> %UserDocuments%\DiagHelp.zip -> [Ver = | Size = 623220 bytes | Created Date = 17/10/2007 14:38:09 | Attr = ]

hijackthis.zip -> %UserDocuments%\hijackthis.zip -> [Ver = | Size = 212849 bytes | Created Date = 14/10/2007 21:51:55 | Attr = ]

HijackThisFR.exe -> %UserDocuments%\HijackThisFR.exe -> Pc-Help-Bordeaux [Ver = | Size = 506140 bytes | Created Date = 14/10/2007 21:51:56 | Attr = ]

lauriane.moinard -> %UserDocuments%\lauriane.moinard -> [Folder | Created Date = 07/10/2007 01:50:03 | Attr = ]

Ma musique -> %UserDocuments%\Ma musique -> [Folder | Created Date = 05/10/2007 21:22:33 | Attr = R ]

maria.moinard -> %UserDocuments%\maria.moinard -> [Folder | Created Date = 07/10/2007 14:32:00 | Attr = ]

Mes dossiers de partage.lnk -> %UserDocuments%\Mes dossiers de partage.lnk -> [Ver = | Size = 585 bytes | Created Date = 07/10/2007 17:17:11 | Attr = ]

Mes fichiers reçus -> %UserDocuments%\Mes fichiers reçus -> [Folder | Created Date = 07/10/2007 16:43:46 | Attr = ]

Mes images -> %UserDocuments%\Mes images -> [Folder | Created Date = 05/10/2007 21:22:33 | Attr = R ]

winpfind3u.exe -> %UserDocuments%\winpfind3u.exe -> [Ver = | Size = 356045 bytes | Created Date = 18/10/2007 11:29:48 | Attr = ]

zlsSetup_65_737_000_fr.exe -> %UserDocuments%\zlsSetup_65_737_000_fr.exe -> [Ver = | Size = 14364584 bytes | Created Date = 17/10/2007 14:38:15 | Attr = ]

Espace Wanadoo.lnk -> %AllUsersDesktop%\Espace Wanadoo.lnk -> [Ver = | Size = 1514 bytes | Created Date = 06/10/2007 18:46:03 | Attr = ]

Installation MSN.lnk -> %AllUsersDesktop%\Installation MSN.lnk -> [Ver = | Size = 1941 bytes | Created Date = 07/10/2007 13:18:53 | Attr = ]

Windows Live Messenger.lnk -> %AllUsersDesktop%\Windows Live Messenger.lnk -> [Ver = | Size = 1650 bytes | Created Date = 07/10/2007 16:33:09 | Attr = ]

DiagHelp -> %UserDesktop%\DiagHelp -> [Folder | Created Date = 17/10/2007 14:41:12 | Attr = ]

Hijackthis Version Française.lnk -> %UserDesktop%\Hijackthis Version Française.lnk -> [Ver = | Size = 921 bytes | Created Date = 17/10/2007 09:34:01 | Attr = ]

WinPFind3u -> %UserDesktop%\WinPFind3u -> [Folder | Created Date = 18/10/2007 11:35:25 | Attr = ]

desktop.ini -> %AllUsersStartup%\desktop.ini -> [Ver = | Size = 84 bytes | Created Date = 05/10/2007 20:39:09 | Attr = HS]

desktop.ini -> %UserStartup%\desktop.ini -> [Ver = | Size = 84 bytes | Created Date = 05/10/2007 21:21:56 | Attr = HS]

InstallShield -> %CommonProgramFiles%\InstallShield -> [Folder | Created Date = 06/10/2007 18:37:53 | Attr = ]

 

[Files/Folders - Modified Within 60 days]

$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 05/10/2007 21:58:16 | Attr = RH ]

boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 212 bytes | Modified Date = 05/10/2007 19:47:40 | Attr = HS]

Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 14/10/2007 23:30:34 | Attr = ]

hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 66637824 bytes | Modified Date = 18/10/2007 11:46:04 | Attr = HS]

Inetpub -> %SystemDrive%\Inetpub -> [Folder | Modified Date = 29/09/2007 22:12:36 | Attr = ]

Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Modified Date = 30/09/2007 01:58:04 | Attr = ]

Program Files -> %ProgramFiles% -> [Folder | Modified Date = 17/10/2007 14:30:36 | Attr = R ]

RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 17/10/2007 09:19:52 | Attr = HS]

System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 05/10/2007 20:34:44 | Attr = HS]

WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 18/10/2007 12:06:42 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 09/10/2007 21:44:48 | Attr = H ]

$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 07/10/2007 19:55:04 | Attr = H ]

$NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Modified Date = 09/10/2007 22:01:54 | Attr = H ]

$NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Modified Date = 09/10/2007 22:24:26 | Attr = H ]

$NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Modified Date = 07/10/2007 19:50:30 | Attr = H ]

$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 09/10/2007 22:13:48 | Attr = H ]

$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 09/10/2007 22:18:40 | Attr = H ]

$NtUninstallKB923689$ -> %SystemRoot%\$NtUninstallKB923689$ -> [Folder | Modified Date = 09/10/2007 22:22:36 | Attr = H ]

$NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Modified Date = 09/10/2007 21:55:30 | Attr = H ]

AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 30/09/2007 12:14:14 | Attr = ]

bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 18/10/2007 11:46:06 | Attr = S]

control.ini -> %SystemRoot%\control.ini -> [Ver = | Size = 0 bytes | Modified Date = 05/10/2007 20:13:40 | Attr = ]

CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 18/10/2007 11:46:14 | Attr = HS]

Cursors -> %SystemRoot%\Cursors -> [Folder | Modified Date = 30/09/2007 10:39:16 | Attr = ]

Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 30/09/2007 12:16:32 | Attr = ]

Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 05/10/2007 20:02:08 | Attr = S]

ehome -> %SystemRoot%\ehome -> [Folder | Modified Date = 30/09/2007 12:14:12 | Attr = ]

Fichiers d'installation de Windows Update -> %SystemRoot%\Fichiers d'installation de Windows Update -> [Folder | Modified Date = 30/09/2007 12:05:56 | Attr = ]

Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 30/09/2007 12:20:00 | Attr = R S]

Help -> %SystemRoot%\Help -> [Folder | Modified Date = 07/10/2007 12:52:10 | Attr = ]

Historique -> %SystemRoot%\Historique -> [Folder | Modified Date = 30/09/2007 12:06:02 | Attr = ]

IIS Temporary Compressed Files -> %SystemRoot%\IIS Temporary Compressed Files -> [Folder | Modified Date = 29/09/2007 22:12:10 | Attr = ]

ime -> %SystemRoot%\ime -> [Folder | Modified Date = 30/09/2007 12:14:12 | Attr = ]

imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 09/10/2007 22:24:48 | Attr = ]

inf -> %SystemRoot%\inf -> [Folder | Modified Date = 18/10/2007 12:18:32 | Attr = H ]

Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 07/10/2007 17:42:48 | Attr = HS]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 18/10/2007 12:13:42 | Attr = ]

Kit.ini -> %SystemRoot%\Kit.ini -> [Ver = | Size = 67 bytes | Modified Date = 08/10/2007 17:44:46 | Attr = ]

LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 18/10/2007 12:06:46 | Attr = ]

Media -> %SystemRoot%\Media -> [Folder | Modified Date = 30/09/2007 12:14:10 | Attr = ]

Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 18/10/2007 11:46:06 | Attr = ]

msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 30/09/2007 12:12:56 | Attr = ]

ODBCINST.INI -> %SystemRoot%\ODBCINST.INI -> [Ver = | Size = 4205 bytes | Modified Date = 05/10/2007 20:11:52 | Attr = ]

Offline Web Pages -> %SystemRoot%\Offline Web Pages -> [Folder | Modified Date = 05/10/2007 20:02:08 | Attr = R ]

PCHEALTH -> %SystemRoot%\PCHEALTH -> [Folder | Modified Date = 30/09/2007 01:11:00 | Attr = ]

PeerNet -> %SystemRoot%\PeerNet -> [Folder | Modified Date = 30/09/2007 12:13:46 | Attr = ]

Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 07/10/2007 12:25:40 | Attr = ]

pss -> %SystemRoot%\pss -> [Folder | Modified Date = 30/09/2007 12:06:14 | Attr = ]

Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 05/10/2007 20:10:32 | Attr = ]

REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Modified Date = 05/10/2007 20:33:54 | Attr = ]

repair -> %SystemRoot%\repair -> [Folder | Modified Date = 05/10/2007 20:15:18 | Attr = ]

security -> %SystemRoot%\security -> [Folder | Modified Date = 05/10/2007 21:07:48 | Attr = ]

setup.pss -> %SystemRoot%\setup.pss -> [Folder | Modified Date = 30/09/2007 09:58:14 | Attr = ]

SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 07/10/2007 12:53:30 | Attr = ]

srchasst -> %SystemRoot%\srchasst -> [Folder | Modified Date = 05/10/2007 19:59:24 | Attr = ]

system -> %SystemRoot%\system -> [Folder | Modified Date = 14/10/2007 23:11:48 | Attr = ]

system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 231 bytes | Modified Date = 05/10/2007 21:39:56 | Attr = ]

system32 -> %System32% -> [Folder | Modified Date = 17/10/2007 14:34:44 | Attr = ]

Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 05/10/2007 20:34:36 | Attr = S]

Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 18/10/2007 11:47:48 | Attr = ]

twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 30/09/2007 12:09:36 | Attr = ]

U2VhYnJh -> %SystemRoot%\U2VhYnJh -> [Folder | Modified Date = 30/09/2007 12:06:40 | Attr = HS]

vb.ini -> %SystemRoot%\vb.ini -> [Ver = | Size = 36 bytes | Modified Date = 05/10/2007 19:52:28 | Attr = ]

vbaddin.ini -> %SystemRoot%\vbaddin.ini -> [Ver = | Size = 37 bytes | Modified Date = 05/10/2007 19:52:28 | Attr = ]

Web -> %SystemRoot%\Web -> [Folder | Modified Date = 05/10/2007 20:02:26 | Attr = R ]

win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 477 bytes | Modified Date = 05/10/2007 20:13:36 | Attr = ]

WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest -> [Ver = | Size = 749 bytes | Modified Date = 05/10/2007 20:01:22 | Attr = RH ]

WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 07/10/2007 17:32:28 | Attr = ]

WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 05/10/2007 20:13:02 | Attr = ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 18/10/2007 11:46:52 | Attr = H ]

$winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 560 bytes | Modified Date = 05/10/2007 20:32:02 | Attr = ]

1033 -> %System32%\1033 -> [Folder | Modified Date = 30/09/2007 12:08:12 | Attr = ]

1036 -> %System32%\1036 -> [Folder | Modified Date = 30/09/2007 12:09:42 | Attr = ]

amcompat.tlb -> %System32%\amcompat.tlb -> [Ver = | Size = 16832 bytes | Modified Date = 05/10/2007 20:12:54 | Attr = ]

appmgmt -> %System32%\appmgmt -> [Folder | Modified Date = 06/10/2007 22:18:40 | Attr = ]

bits -> %System32%\bits -> [Folder | Modified Date = 30/09/2007 12:06:20 | Attr = ]

Cache -> %System32%\Cache -> [Folder | Modified Date = 29/09/2007 21:51:32 | Attr = ]

CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 05/10/2007 21:40:02 | Attr = ]

CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 18/10/2007 12:06:28 | Attr = ]

cdplayer.exe.manifest -> %System32%\cdplayer.exe.manifest -> [Ver = | Size = 749 bytes | Modified Date = 05/10/2007 20:01:22 | Attr = RH ]

Com -> %System32%\Com -> [Folder | Modified Date = 05/10/2007 19:53:10 | Attr = ]

config -> %System32%\config -> [Folder | Modified Date = 05/10/2007 20:33:08 | Attr = ]

CONFIG.NT -> %System32%\CONFIG.NT -> [Ver = | Size = 3072 bytes | Modified Date = 05/10/2007 20:13:40 | Attr = ]

dllcache -> %System32%\dllcache -> [Folder | Modified Date = 09/10/2007 22:24:30 | Attr = RHS]

drivers -> %System32%\drivers -> [Folder | Modified Date = 17/10/2007 16:03:24 | Attr = ]

DRVSTORE -> %System32%\DRVSTORE -> [Folder | Modified Date = 07/10/2007 17:35:10 | Attr = ]

emptyregdb.dat -> %System32%\emptyregdb.dat -> [Ver = | Size = 21892 bytes | Modified Date = 05/10/2007 19:53:06 | Attr = ]

FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 90296 bytes | Modified Date = 14/10/2007 22:30:42 | Attr = ]

ias -> %System32%\ias -> [Folder | Modified Date = 05/10/2007 20:08:22 | Attr = ]

icsxml -> %System32%\icsxml -> [Folder | Modified Date = 30/09/2007 12:09:08 | Attr = ]

inetsrv -> %System32%\inetsrv -> [Folder | Modified Date = 30/09/2007 12:06:34 | Attr = ]

Logfiles -> %System32%\Logfiles -> [Folder | Modified Date = 29/09/2007 21:40:00 | Attr = ]

logonui.exe.manifest -> %System32%\logonui.exe.manifest -> [Ver = | Size = 488 bytes | Modified Date = 05/10/2007 20:02:06 | Attr = RH ]

MsDtc -> %System32%\MsDtc -> [Folder | Modified Date = 05/10/2007 19:51:58 | Attr = ]

ncpa.cpl.manifest -> %System32%\ncpa.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 05/10/2007 20:01:22 | Attr = RH ]

npp -> %System32%\npp -> [Folder | Modified Date = 30/09/2007 12:13:14 | Attr = ]

nscompat.tlb -> %System32%\nscompat.tlb -> [Ver = | Size = 23392 bytes | Modified Date = 05/10/2007 20:12:54 | Attr = ]

nwc.cpl.manifest -> %System32%\nwc.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 05/10/2007 20:01:22 | Attr = RH ]

oobe -> %System32%\oobe -> [Folder | Modified Date = 05/10/2007 19:58:22 | Attr = ]

perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 45966 bytes | Modified Date = 07/10/2007 11:50:16 | Attr = ]

perfc00C.dat -> %System32%\perfc00C.dat -> [Ver = | Size = 55720 bytes | Modified Date = 07/10/2007 11:50:16 | Attr = ]

perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 331064 bytes | Modified Date = 07/10/2007 11:50:16 | Attr = ]

perfh00C.dat -> %System32%\perfh00C.dat -> [Ver = | Size = 388620 bytes | Modified Date = 07/10/2007 11:50:18 | Attr = ]

PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 827772 bytes | Modified Date = 07/10/2007 11:50:10 | Attr = ]

PreInstall -> %System32%\PreInstall -> [Folder | Modified Date = 07/10/2007 19:50:42 | Attr = ]

ras -> %System32%\ras -> [Folder | Modified Date = 30/09/2007 12:09:20 | Attr = ]

ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 30/09/2007 09:50:00 | Attr = ]

Restore -> %System32%\Restore -> [Folder | Modified Date = 05/10/2007 20:34:44 | Attr = ]

rnaph.dll -> %System32%\rnaph.dll -> [Ver = | Size = 0 bytes | Modified Date = 06/10/2007 19:35:24 | Attr = ]

sapi.cpl.manifest -> %System32%\sapi.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 05/10/2007 20:01:22 | Attr = RH ]

Setup -> %System32%\Setup -> [Folder | Modified Date = 30/09/2007 12:14:48 | Attr = ]

usmt -> %System32%\usmt -> [Folder | Modified Date = 30/09/2007 12:14:32 | Attr = ]

vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 54112 bytes | Modified Date = 18/10/2007 12:01:32 | Attr = ]

wbem -> %System32%\wbem -> [Folder | Modified Date = 05/10/2007 19:50:58 | Attr = ]

WindowsLogon.manifest -> %System32%\WindowsLogon.manifest -> [Ver = | Size = 488 bytes | Modified Date = 05/10/2007 20:02:06 | Attr = RH ]

wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 17/10/2007 08:56:32 | Attr = ]

wuaucpl.cpl.manifest -> %System32%\wuaucpl.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 05/10/2007 20:01:22 | Attr = RH ]

zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Modified Date = 17/10/2007 14:50:58 | Attr = H ]

ZoneLabs -> %System32%\ZoneLabs -> [Folder | Modified Date = 17/10/2007 14:32:12 | Attr = ]

avg7rsw.sys -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Modified Date = 05/10/2007 21:01:48 | Attr = ]

avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Modified Date = 05/10/2007 21:02:00 | Attr = ]

avipbb.sys -> %System32%\drivers\avipbb.sys -> AVIRA GmbH [Ver = 1.00.02.11 | Size = 62016 bytes | Modified Date = 07/09/2007 12:05:20 | Attr = ]

etc -> %System32%\drivers\etc -> [Folder | Modified Date = 07/10/2007 17:49:48 | Attr = ]

KProcCheck.sys -> %System32%\drivers\KProcCheck.sys -> [Ver = | Size = 4096 bytes | Modified Date = 02/09/2007 20:37:44 | Attr = ]

avg7 -> %AllUsersAppData%\avg7 -> [Folder | Modified Date = 14/10/2007 23:10:50 | Attr = ]

Avira -> %AllUsersAppData%\Avira -> [Folder | Modified Date = 17/10/2007 13:50:54 | Attr = ]

desktop.ini -> %AllUsersAppData%\desktop.ini -> [Ver = | Size = 62 bytes | Modified Date = 05/10/2007 21:39:10 | Attr = HS]

Microsoft -> %AllUsersAppData%\Microsoft -> [Folder | Modified Date = 07/10/2007 17:32:26 | Attr = S]

AVG7 -> %UserAppData%\AVG7 -> [Folder | Modified Date = 14/10/2007 22:37:54 | Attr = ]

desktop.ini -> %UserAppData%\desktop.ini -> [Ver = | Size = 62 bytes | Modified Date = 05/10/2007 21:39:10 | Attr = HS]

Help -> %UserAppData%\Help -> [Folder | Modified Date = 07/10/2007 15:29:36 | Attr = ]

Identities -> %UserAppData%\Identities -> [Folder | Modified Date = 05/10/2007 22:23:00 | Attr = ]

Macromedia -> %UserAppData%\Macromedia -> [Folder | Modified Date = 07/10/2007 16:12:16 | Attr = ]

Microsoft -> %UserAppData%\Microsoft -> [Folder | Modified Date = 17/10/2007 10:46:28 | Attr = S]

GDIPFONTCACHEV1.DAT -> %LocalAppData%\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 12328 bytes | Modified Date = 06/10/2007 20:47:18 | Attr = ]

Help -> %LocalAppData%\Help -> [Folder | Modified Date = 07/10/2007 15:29:36 | Attr = ]

IconCache.db -> %LocalAppData%\IconCache.db -> [Ver = | Size = 2107040 bytes | Modified Date = 17/10/2007 15:01:24 | Attr = H ]

Identities -> %LocalAppData%\Identities -> [Folder | Modified Date = 07/10/2007 13:51:02 | Attr = ]

Microsoft -> %LocalAppData%\Microsoft -> [Folder | Modified Date = 17/10/2007 14:54:54 | Attr = ]

desktop.ini -> %AllUsersDocuments%\desktop.ini -> [Ver = | Size = 62 bytes | Modified Date = 05/10/2007 21:39:10 | Attr = HS]

Ma musique -> %AllUsersDocuments%\Ma musique -> [Folder | Modified Date = 05/10/2007 20:13:06 | Attr = R ]

Mes images -> %AllUsersDocuments%\Mes images -> [Folder | Modified Date = 05/10/2007 19:58:16 | Attr = R ]

Mes vidéos -> %AllUsersDocuments%\Mes vidéos -> [Folder | Modified Date = 05/10/2007 19:50:14 | Attr = R ]

antivir_workstation_win7u_en_h.exe -> %UserDocuments%\antivir_workstation_win7u_en_h.exe -> [Ver = | Size = 17788920 bytes | Modified Date = 11/10/2007 15:36:10 | Attr = ]

desktop.ini -> %UserDocuments%\desktop.ini -> [Ver = | Size = 79 bytes | Modified Date = 05/10/2007 22:23:38 | Attr = HS]

DiagHelp.zip -> %UserDocuments%\DiagHelp.zip -> [Ver = | Size = 623220 bytes | Modified Date = 17/10/2007 13:59:26 | Attr = ]

hijackthis.zip -> %UserDocuments%\hijackthis.zip -> [Ver = | Size = 212849 bytes | Modified Date = 11/10/2007 15:36:58 | Attr = ]

HijackThisFR.exe -> %UserDocuments%\HijackThisFR.exe -> Pc-Help-Bordeaux [Ver = | Size = 506140 bytes | Modified Date = 11/10/2007 15:29:04 | Attr = ]

lauriane.moinard -> %UserDocuments%\lauriane.moinard -> [Folder | Modified Date = 07/10/2007 02:50:04 | Attr = ]

Ma musique -> %UserDocuments%\Ma musique -> [Folder | Modified Date = 05/10/2007 22:23:38 | Attr = R ]

maria.moinard -> %UserDocuments%\maria.moinard -> [Folder | Modified Date = 07/10/2007 15:32:02 | Attr = ]

Mes dossiers de partage.lnk -> %UserDocuments%\Mes dossiers de partage.lnk -> [Ver = | Size = 585 bytes | Modified Date = 07/10/2007 19:19:48 | Attr = ]

Mes fichiers reçus -> %UserDocuments%\Mes fichiers reçus -> [Folder | Modified Date = 07/10/2007 17:43:48 | Attr = ]

Mes images -> %UserDocuments%\Mes images -> [Folder | Modified Date = 05/10/2007 22:23:38 | Attr = R ]

winpfind3u.exe -> %UserDocuments%\winpfind3u.exe -> [Ver = | Size = 356045 bytes | Modified Date = 18/10/2007 12:24:44 | Attr = ]

zlsSetup_65_737_000_fr.exe -> %UserDocuments%\zlsSetup_65_737_000_fr.exe -> [Ver = | Size = 14364584 bytes | Modified Date = 17/10/2007 13:57:50 | Attr = ]

Espace Wanadoo.lnk -> %AllUsersDesktop%\Espace Wanadoo.lnk -> [Ver = | Size = 1514 bytes | Modified Date = 07/10/2007 22:13:18 | Attr = ]

Installation MSN.lnk -> %AllUsersDesktop%\Installation MSN.lnk -> [Ver = | Size = 1941 bytes | Modified Date = 07/10/2007 14:18:56 | Attr = ]

Windows Live Messenger.lnk -> %AllUsersDesktop%\Windows Live Messenger.lnk -> [Ver = | Size = 1650 bytes | Modified Date = 07/10/2007 17:33:12 | Attr = ]

DiagHelp -> %UserDesktop%\DiagHelp -> [Folder | Modified Date = 18/10/2007 11:42:30 | Attr = ]

Hijackthis Version Française.lnk -> %UserDesktop%\Hijackthis Version Française.lnk -> [Ver = | Size = 921 bytes | Modified Date = 17/10/2007 10:34:02 | Attr = ]

WinPFind3u -> %UserDesktop%\WinPFind3u -> [Folder | Modified Date = 18/10/2007 12:35:28 | Attr = ]

desktop.ini -> %AllUsersStartup%\desktop.ini -> [Ver = | Size = 84 bytes | Modified Date = 05/10/2007 20:14:04 | Attr = HS]

desktop.ini -> %UserStartup%\desktop.ini -> [Ver = | Size = 84 bytes | Modified Date = 05/10/2007 20:14:04 | Attr = HS]

InstallShield -> %CommonProgramFiles%\InstallShield -> [Folder | Modified Date = 06/10/2007 19:38:24 | Attr = ]

Microsoft Shared -> %CommonProgramFiles%\Microsoft Shared -> [Folder | Modified Date = 07/10/2007 17:41:52 | Attr = ]

 

[File String Scan - Non-Microsoft Only]

PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 17/02/2005 19:58:46 | Attr = ]

winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 17/02/2005 20:03:42 | Attr = ]

WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 17/02/2005 19:56:36 | Attr = ]

UPX0 , -> %System32%\dllcache\NT5IIS.CAT -> [Ver = | Size = 809394 bytes | Modified Date = 17/02/2005 20:02:36 | Attr = ]

 

< End of report >

 

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...