Rapport hijackthis

Résolu/Fermé
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017 - 4 déc. 2009 à 21:06
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017 - 6 déc. 2009 à 20:11
Bonjour, mon antivirus AVG detecte environ 20 infections qui ne peut pas supprimer, ni reparer.merci

16 réponses

looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
6 déc. 2009 à 20:11
2 rapprt usb

############################## | UsbFix V6.059 |

User : Laurence (Administrateurs) # PC-DE-LAURENCE
Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
Start at: 19:59:49 | 06/12/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

AMD Athlon(tm) 64 X2 Dual Core Processor 4400+
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18828
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local # 290,18 Go (189,59 Go free) [COMPAQ] # NTFS
D:\ -> Disque fixe local # 7,91 Go (1 Go free) [Recovery] # NTFS
E:\ -> Disque CD-ROM # 702,31 Mo (0 Mo free) [2 mars 2008] # UDF
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque amovible
J:\ -> Disque amovible # 1,91 Go (1,8 Go free) # FAT
K:\ -> Disque CD-ROM # 5,45 Mo (0 Mo free) [U3 System] # CDFS

############################## | Processus actifs |

C:\Windows\System32\smss.exe 428
C:\Windows\system32\csrss.exe 496
C:\Windows\system32\wininit.exe 548
C:\Windows\system32\csrss.exe 560
C:\Program Files\AVG\AVG9\avgchsvx.exe 572
C:\Program Files\AVG\AVG9\avgrsx.exe 580
C:\Program Files\AVG\AVG9\avgcsrvx.exe 616
C:\Windows\system32\services.exe 644
C:\Windows\system32\lsass.exe 656
C:\Windows\system32\lsm.exe 672
C:\Windows\system32\winlogon.exe 828
C:\Windows\system32\svchost.exe 1136
C:\Windows\system32\svchost.exe 1200
C:\Windows\System32\svchost.exe 1356
C:\Windows\System32\svchost.exe 1392
C:\Windows\system32\svchost.exe 1428
C:\Windows\system32\svchost.exe 1560
C:\Windows\system32\SLsvc.exe 1584
C:\Windows\system32\svchost.exe 1616
C:\Windows\system32\svchost.exe 1780
C:\Windows\System32\spoolsv.exe 2016
C:\Windows\system32\svchost.exe 192
C:\Windows\system32\taskeng.exe 732
C:\Windows\system32\Dwm.exe 1144
C:\Windows\Explorer.EXE 1420
C:\Windows\system32\taskeng.exe 1688
C:\Program Files\AVG\AVG9\avgwdsvc.exe 2232
C:\Windows\system32\ezNTSvc.exe 2260
C:\Windows\system32\svchost.exe 2392
c:\Program Files\Common Files\LightScribe\LSSrvc.exe 2432
C:\Windows\System32\svchost.exe 2524
C:\Windows\System32\svchost.exe 2600
C:\Windows\system32\svchost.exe 2616
C:\Windows\system32\svchost.exe 2652
C:\Windows\System32\svchost.exe 2712
C:\Program Files\AVG\AVG9\avgnsx.exe 2756
C:\Windows\system32\SearchIndexer.exe 2828
C:\Windows\system32\WUDFHost.exe 3140
C:\Windows\system32\SearchProtocolHost.exe 3744
C:\Windows\system32\SearchFilterHost.exe 3760
C:\Windows\system32\SearchProtocolHost.exe 3792
C:\Windows\system32\runonce.exe 1084
C:\Windows\system32\conime.exe 2136
C:\Windows\system32\wbem\wmiprvse.exe 1940

################## | Fichiers # Dossiers infectieux |

Non supprimé ! K:\autorun.inf

################## | Spyware.OnlineGames |


################## | Registre # Clés infectieuses |

Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoClose"

################## | Registre # Mountpoints2 |

Supprimé ! HKCU\...\Explorer\MountPoints2\{3d3f3c94-750d-11de-ae2a-001bb9760b64}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{8c80427b-dd82-11de-8cb8-001bb9760b64}\Shell\AutoRun\Command

################## | Listing des fichiers présent |

[01/06/2007 23:48|--a------|74] C:\autoexec.bat
[11/04/2009 07:36|-rahs----|333257] C:\bootmgr
[02/06/2007 08:59|-ra-s----|8192] C:\BOOTSECT.BAK
[18/09/2006 22:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[30/11/2009 11:33|-rahs----|0] C:\IO.SYS
[30/11/2009 11:33|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\pagefile.sys
[19/09/2009 08:18|--a------|477] C:\RHDSetup.log
[19/09/2009 19:56|--a------|167] C:\Setup.log
[06/12/2009 20:01|--a------|3892] C:\UsbFix.txt
[04/10/2006 00:02|---hs----|438328] D:\boo.mgr
[02/11/2006 00:53|---hs----|438840] D:\bootmgr
[13/10/2006 15:00|---hs----|1322] D:\Desktop.ini
[02/02/2009 09:50|---hs----|0] D:\DRECOVERY
[16/11/2007 11:50|---hs----|22] D:\HPCD.sys
[16/11/2007 11:18|---hs----|189] D:\MASTER.LOG
[20/07/2009 09:31|---hs----|429] D:\pcdr.ini
[29/01/2007 18:56|---hs----|109060] D:\Protect.ed
[16/11/2007 10:39|---hs----|26] D:\RCBoot.sys
[02/06/2007 11:09|---hs----|44] D:\RESTORE.INI
[07/02/2007 14:56|---hs----|34] D:\SystemRecovery.txt
[26/01/2008 08:14|--a------|721317888] E:\Walt disney_Ratatouille.French (super qualit‚).avi
[07/12/2006 10:45|-ra------|1095224] J:\LaunchU3.exe
[11/12/2006 21:03|-r-------|277] K:\autorun.inf
[07/12/2006 19:45|-r-------|1095224] K:\LaunchU3.exe
[11/12/2006 21:26|-r-------|4557609] K:\LaunchPad.zip

################## | Vaccination |

# C:\autorun.inf -> Dossier créé par UsbFix.
# D:\autorun.inf -> Dossier créé par UsbFix.
# J:\autorun.inf -> Dossier créé par UsbFix.

################## | Cracks / Keygens / Serials |


################## | Upload |

Veuillez envoyer le fichier : C:\Users\Laurence\Desktop\UsbFix_Upload_Me_PC-de-Laurence.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .

################## | ! Fin du rapport # UsbFix V6.059 ! |
1
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
4 déc. 2009 à 21:16
Salut,

Poste le rapport HJT pour voir.
0
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
4 déc. 2009 à 21:30
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:29:44, on 04/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\rundll32.exe
C:\Users\Laurence\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dartybox.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Assistant DartyBox] C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe -m
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\Laurence\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
O23 - Service: Google Desktop Manager 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
4 déc. 2009 à 21:39
...

(si ce n’ est déjà fait) Télécharge CCleaner :
http://www.filehippo.com/download_ccleaner.html
("Download Latest Version", sur la droite) et laisse-toi guider.
A un moment, il te sera demandé de cocher :
"Ajouter la barre d' outils Yahoo". Refuse et …
Laisse-le s’ installer tel que …

-------
Redémarre le PC en mode sans échec ...
https://www.pcastuces.com/pratique/windows/mode_sans_echec/page2.htm
(méthode F8 de préférence)

--------------------------------------------
Tu n' auras pas accès à Internet pendant le "mode sans échec".
Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la
sur le "bureau" pour l' avoir à ta disposition.
--------------------------------------------

Ferme toutes les fenêtres et applications.
Relance HijackThis et clique sur > Do a system scan only puis, coche
la case devant cette ligne qui suit (et uniquement cette ligne), si tjrs présentes :

F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe

Ensuite, clique sur > Fix checked et valide par "Yes". Referme HijackThis.

Lance CCleaner ...
Clique sur > Analyser > Nettoyer, puis sur OK dans la fenêtre qui s' affiche.
(re)Lance le nettoyage et (re)confirme par OK.

Redémarre le PC en mode normal ...

Télécharge, installe et mets à jour Malwarebytes Anti-Malwares
http://forum.telecharger.01net.com/microhebdo/6/tuto-securite/tuto-malwaresbytes-anti-malware-352008/messages-1.html puis, lance un scan COMPLET et poste le rapport.

PS : si MalwareByte's a détecté des infections, clique sur Afficher les résultats,
puis sur Supprimer la sélection.

---
Télécharge Update Checker sur ton bureau :

http://www.filehippo.com/updatechecker/UpdateChecker.exe

Exécute UpdateChecker.exe et patiente pendant qu'il vérifie les versions des logiciels installés.
Une page Internet va afficher les mises à jour disponibles.
Clique sur les flèches vertes pour accéder aux nouvelles mises à jour que tu souhaites installer

-> Attention de ne pas installer les versions bêta !

---
Relance un scan HijackThis et poste le rapport.
0
Malwarebytes' Anti-Malware 1.42
Version de la base de données: 3296
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18828

04/12/2009 23:09:25
mbam-log-2009-12-04 (23-08-54).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 231585
Temps écoulé: 49 minute(s), 57 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Users\Laurence\Downloads\gameztar_installer(2).exe (Trojan.Agent) -> No action taken.
C:\Users\Laurence\Downloads\gameztar_installer(3).exe (Trojan.Agent) -> No action taken.
C:\Users\Laurence\Downloads\gameztar_installer.exe (Trojan.Agent) -> No action taken.
0
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
5 déc. 2009 à 21:31
je sais pas si j'ai fait les bonnes manip, l'ordi s'est eteint tout seul pendant que je copie colle
info.txt logfile of random's system information tool 1.06 2009-12-05 09:07:02

======Uninstall list======

-->MsiExec /X{1C4551A6-4743-4093-91E4-1477CD655043}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
DartyBox-->C:\Program Files\InstallShield Installation Information\{4A975AC1-1E5B-43B7-B42B-6E617B39C936}\setup.exe -runfromtemp -l0x040c -removeonly
EasyBits Magic Desktop-->C:\Windows\system32\ezMDUninstall.exe
Electronic Arts Game Updater-->C:\Windows\IsUninst.exe -f"c:\Program Files\EACom\Update\Uninst.isu"
Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.33\Installer\setup.exe" --uninstall --system-level
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HijackThis 2.0.2-->"C:\Users\Laurence\Downloads\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
HP Photosmart Essential 2.0-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
Java(TM) 6 Update 14-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014F0}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.5.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
muvee autoProducer 6.0-->C:\Program Files\InstallShield Installation Information\{6AF49698-949A-4C89-9B31-041D2CCB5FBD}\setup.exe -runfromtemp -l0x040c -removeonly
Need For Speed - Porsche 2000-->C:\Windows\IsUn040c.exe -f"C:\Program Files\Electronic Arts\Need For Speed - Porsche 2000\uninst.log"
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{1C4551A6-4743-4093-91E4-1477CD655043}
Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
Python 2.4.3-->MsiExec.exe /I{75E71ADD-042C-4F30-BFAC-A9EC42351313}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Roxio Creator Audio-->MsiExec.exe /X{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator Basic v9-->MsiExec.exe /X{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Copy-->MsiExec.exe /X{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data-->MsiExec.exe /X{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator EasyArchive-->MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
Roxio Creator Tools-->MsiExec.exe /X{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler 3-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio MyDVD Basic v9-->MsiExec.exe /X{938B1CD7-7C60-491E-AA90-1F1888168240}
Scooby-Doo(TM), Panique dans la Ville fantôme(TM)-->C:\Program Files\Mindscape\Scooby-Doo(TM), Panique dans la Ville fantôme(TM)\uninstal.exe
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
VLC media player 1.0.0-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

=====HijackThis Backups=====

F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe [2009-12-04]
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll [2009-12-05]

======Security center information======

AV: AVG Anti-Virus Free
AS: AVG Anti-Virus Free (disabled)
AS: Windows Defender

======System event log======

Computer Name: PC-de-Laurence
Event Code: 4374
Message: Windows Servicing a déterminé que ce package KB967723(Security Update) n’est pas applicable à ce système.
Record Number: 30027
Source Name: Microsoft-Windows-Servicing
Time Written: 20090910063244.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Laurence
Event Code: 4374
Message: Windows Servicing a déterminé que ce package KB967723(Security Update) n’est pas applicable à ce système.
Record Number: 30026
Source Name: Microsoft-Windows-Servicing
Time Written: 20090910063244.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Laurence
Event Code: 4374
Message: Windows Servicing a déterminé que ce package KB967723(Security Update) n’est pas applicable à ce système.
Record Number: 30025
Source Name: Microsoft-Windows-Servicing
Time Written: 20090910063244.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Laurence
Event Code: 4374
Message: Windows Servicing a déterminé que ce package KB967723(Security Update) n’est pas applicable à ce système.
Record Number: 30024
Source Name: Microsoft-Windows-Servicing
Time Written: 20090910063244.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Laurence
Event Code: 4374
Message: Windows Servicing a déterminé que ce package KB967723(Security Update) n’est pas applicable à ce système.
Record Number: 30023
Source Name: Microsoft-Windows-Servicing
Time Written: 20090910063244.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

=====Application event log=====

Computer Name: PC-de-Laurence
Event Code: 101
Message:
Record Number: 489
Source Name: Automatic LiveUpdate Scheduler
Time Written: 20090720084355.000000-000
Event Type: Erreur
User: PC-de-Laurence\Laurence

Computer Name: PC-de-Laurence
Event Code: 5007
Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
Record Number: 414
Source Name: WerSvc
Time Written: 20090720082216.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-Laurence
Event Code: 1008
Message: Le service Windows Search tente de supprimer l’ancien catalogue.

Record Number: 409
Source Name: Microsoft-Windows-Search
Time Written: 20090720082132.000000-000
Event Type: Avertissement
User:

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 1036
Message: Échec de InitializePrintProvider pour le fournisseur inetpp.dll. Cela peut se produire à la suite d’une instabilité du système ou d’une insuffisance des ressources système.
Record Number: 378
Source Name: Microsoft-Windows-SpoolerSpoolss
Time Written: 20090720081533.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 5007
Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
Record Number: 371
Source Name: WerSvc
Time Written: 20090720081339.000000-000
Event Type: Erreur
User:

=====Security event log=====

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 4647
Message: Fermeture de session initiée par l’utilisateur :

Sujet :
ID de sécurité : S-1-5-21-1818236925-4069686688-3323932586-500
Nom du compte : Administrator
Domaine du compte : LH-OC6D9NGRLF4Y
ID d’ouverture de session : 0x40a39

Cet événement est généré lorsqu’une fermeture de session est initiée, mais que le nombre de références du jeton n’étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l’utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
Record Number: 308
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20070601231814.979600-000
Event Type: Succès de l'audit
User:

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 4634
Message: Fermeture de session d’un compte.

Sujet :
ID de sécurité : S-1-5-7
Nom du compte : ANONYMOUS LOGON
Domaine du compte : AUTORITE NT
ID du compte : 0x2700b

Type d’ouverture de session : 3

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
Record Number: 307
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20070601231813.170000-000
Event Type: Succès de l'audit
User:

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 4616
Message: L’heure du système a été modifiée.

Sujet :
ID de sécurité : S-1-5-19
Nom du compte : SERVICE LOCAL
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x3e5

Informations sur le processus :
ID du processus : 0x440
Nom : C:\Windows\System32\svchost.exe

Heure précédente : 01:18:13 02/06/2007
Nouvelle heure : 01:18:13 02/06/2007

Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
Record Number: 306
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20070601231813.045200-000
Event Type: Succès de l'audit
User:

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 1100
Message: Le service d’enregistrement des événements a été arrêté.
Record Number: 305
Source Name: Microsoft-Windows-Eventlog
Time Written: 20070601231813.154400-000
Event Type: Succès de l'audit
User:

Computer Name: LH-OC6D9NGRLF4Y
Event Code: 1102
Message: Le journal d’audit a été effacé.
Objet :
ID de sécurité : S-1-5-21-1818236925-4069686688-3323932586-500
Nom de compte : Administrator
Nom de domaine : LH-OC6D9NGRLF4Y
ID de connexion : 0x40a39
Record Number: 304
Source Name: Microsoft-Windows-Eventlog
Time Written: 20070601231724.019765-000
Event Type: Succès de l'audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;c:\Program Files\Common Files\Roxio Shared\DLLShared\;c:\Program Files\Common Files\Roxio Shared\DLLShared\;c:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"RoxioCentral"=c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
"PLATFORM"=HPD
"PCBRAND"=Presario
"OnlineServices"=Services en ligne

-----------------EOF-----------------
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
voici le dernier rapport hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:44:51, on 04/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Users\Laurence\Downloads\HiJackThis.exe
C:\Users\Laurence\Downloads\HiJackThis(2).exe
C:\Windows\system32\rundll32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dartybox.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Assistant DartyBox] C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe -m
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\Laurence\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\RazaWebHook32.dll/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
O23 - Service: Google Desktop Manager 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1ca7530ae8eb2f4) (gupdate1ca7530ae8eb2f4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
5 déc. 2009 à 00:14
...

Ferme toutes les fenêtres et applications.
Relance HijackThis et clique sur > Do a system scan only puis, coche
la case devant la ligne qui suit (et uniquement cette ligne), si tjrs présentes :

O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll

Ensuite, clique sur > Fix checked et valide par "Yes". Referme HijackThis.

Rends-toi dans > Démarrer > Panneau de config. > Programmes et fonctionnalités

Supprime, si tu le(s) trouves > Shareaza

Ensuite, va dans > Démarrer > Poste de travail > C:\

et supprime le(s) programme(s)/ fichier(s) en gras, ci-dessous, si tu le(s) trouves.

C:\Program Files\Shareaza <-

Lance CCleaner pour un nettoyage ...

-----
Ensuite, ...

Télécharge RSIT (de random/random) sur le bureau :

http://images.malwareremoval.com/random/RSIT.exe

- Sur le bureau, double clique sur RSIT.exe ;
- Clique sur Continue (Disclaimer) dans la fenêtre ;

Si la dernière version de HijackThis n'est pas détectée sur ton PC, RSIT le téléchargera et te
demandera d'accepter la licence.

Lorsque l’ analyse sera achevée, 2 fichiers texte s’ ouvriront (avec le bloc-notes).

Poste le contenu de log.txt (celui qui apparaît à l’ écran) ainsi que info.txt (que tu verras dans la Barre des tâches).

Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
5 déc. 2009 à 00:26
bonjour

post 4
ces fichiers n'ont pas été supprimés

C:\Users\Laurence\Downloads\gameztar_installer(2).exe (Trojan.Agent) -> No action taken.
C:\Users\Laurence\Downloads\gameztar_installer(3).exe (Trojan.Agent) -> No action taken.
C:\Users\Laurence\Downloads\gameztar_installer.exe (Trojan.Agent) -> No action taken.
0
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
5 déc. 2009 à 09:20
Logfile of random's system information tool 1.06 (written by random/random)
Run by Laurence at 2009-12-05 09:18:16
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 190 GB (64%) free of 297 GB
Total RAM: 3070 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:18:21, on 05/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Laurence\Downloads\RSIT(3).exe
C:\Users\Laurence\Downloads\Laurence.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dartybox.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Assistant DartyBox] C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe -m
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\Laurence\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
O23 - Service: Google Desktop Manager 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1ca7530ae8eb2f4) (gupdate1ca7530ae8eb2f4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
6 déc. 2009 à 01:02
Salut,

Java(TM) 6 Update 14

Désinstalle/supprime cette version de Java !

---
Lance un scan Nod32 : https://www.eset.com/
(il faut utiliser Internet Explorer) …

Coche toutes les cases à chaque fois et, une fois le scan achevé, colle le rapport :

-> C:\Program Files\EsetOnlineScanner\log.txt <- le rapport

PS : désactive AVG le temps du scan.
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
6 déc. 2009 à 01:14
infection par support usb

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d3f3c94-750d-11de-ae2a-001bb9760b64}]
shell\AutoRun\command - J:\Programs\nu2menu\nu2menu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e9c8a088-7504-11de-bec8-806e6f6e6963}]
shell\AutoRun\command - E:\Eautorun.EXE
shell\install\command - E:\INSTALL\mindscape.exe



amicalement
0
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
6 déc. 2009 à 09:55
bonjour, je ne sais pas comment on desactive avg? merci
0
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
6 déc. 2009 à 12:36
Salut,

Regarde ici ...

https://support.avg.com

Si impossible, fais le scan quand même.
0
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
6 déc. 2009 à 18:26
bonsoir, je sais pas si j'ai recuperer le bon rapport voici :
[UNINSTALL]
Product=PCC17

[ALIASES]
%UCOMP%=:DIRECT:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components
%UPROD%=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products

[PCC17_FILE]
file=%SYSDRVDIR%\TM_CFW.sys
file=%SYSDRVDIR%\Tmpreflt.sys
file=%SYSDRVDIR%\tmtdi.sys
file=%SYSDRVDIR%\TmXPFlt.sys
file=%SYSDRVDIR%\VSAPINT.sys
file=%SYSDRVDIR%\tmcomm.sys
file=%SYSDRVDIR%\tmactmon.sys
file=%SYSDRVDIR%\tmevtmgr.sys
file=%SYSDRVDIR%\TMLWF.sys
file=%SYSDRVDIR%\TMWFP.sys
file=%SYSTEMDIR%\UfWSC.cpl
file=%APPLDIR%\clnrbin.exe
file=%APPLDIR%\tmlwfins.exe
file=%APPLDIR%\tmwfpins.exe
file=%APPLDIR%\patch.exe
file=%APPLDIR%\Remove.exe
file=%APPLDIR%\SfCtlCom.exe
file=%APPLDIR%\SfFnUp.exe
file=%APPLDIR%\TISPthTl.exe
file=%APPLDIR%\SfFnWSC.exe
file=%APPLDIR%\tisspwiz.exe
file=%APPLDIR%\TISSuprt.exe
file=%APPLDIR%\TMAS_Det.exe
file=%APPLDIR%\TmPfw.exe
file=%APPLDIR%\TmProxy.exe
file=%APPLDIR%\tsc.exe
file=%APPLDIR%\tsc64.exe
file=%APPLDIR%\TSRemove.exe
file=%APPLDIR%\UfIfAvIm.exe
file=%APPLDIR%\UfLogUi.exe
file=%APPLDIR%\UfNavi.exe
file=%APPLDIR%\UfSeAgnt.exe
file=%APPLDIR%\UfUpdUi.exe
file=%APPLDIR%\TVscan32.exe
file=%APPLDIR%\TVscan64.exe
file=%APPLDIR%\Vsapiins.exe
file=%APPLDIR%\atl80.dll
file=%APPLDIR%\BPMNT.dll
file=%APPLDIR%\ciussi32.dll
file=%APPLDIR%\DceLog64.dll
file=%APPLDIR%\GENKEY32.dll
file=%APPLDIR%\GENKEY64.dll
file=%APPLDIR%\HomeNet.dll
file=%APPLDIR%\HCcommon.dll
file=%APPLDIR%\libexpat.dll
file=%APPLDIR%\PcDce.dll
file=%APPLDIR%\PcDceLog.dll
file=%APPLDIR%\PcHisCln.dll
file=%APPLDIR%\PcPaBase.dll
file=%APPLDIR%\mfc80.dll
file=%APPLDIR%\mfc80u.dll
file=%APPLDIR%\mfcm80.dll
file=%APPLDIR%\mfcm80u.dll
file=%APPLDIR%\msvcm80.dll
file=%APPLDIR%\msvcp80.dll
file=%APPLDIR%\msvcr80.dll
file=%APPLDIR%\NetBSrvr.dll
file=%APPLDIR%\patchbld.dll
file=%APPLDIR%\PATCHW32.dll
file=%APPLDIR%\PccScan.dll
file=%APPLDIR%\PccSpy.dll
file=%APPLDIR%\SfEnAs.dll
file=%APPLDIR%\SfEnAv.dll
file=%APPLDIR%\SfEnBehv.dll
file=%APPLDIR%\SfEnCm.dll
file=%APPLDIR%\SfEnCp.dll
file=%APPLDIR%\SfEnCpAs.dll
file=%APPLDIR%\SfEnCpP3.dll
file=%APPLDIR%\SfEnCpPd.dll
file=%APPLDIR%\SfEnCpPh.dll
file=%APPLDIR%\SfEnCpSp.dll
file=%APPLDIR%\SfEnCpUf.dll
file=%APPLDIR%\SfEnCpWm.dll
file=%APPLDIR%\SfEnCpMs.dll
file=%APPLDIR%\SfEnFw.dll
file=%APPLDIR%\SfEnFwLc.dll
file=%APPLDIR%\SfEnFwNl.dll
file=%APPLDIR%\SfEnFwRl.dll
file=%APPLDIR%\SfEnFwSs.dll
file=%APPLDIR%\SfEnMc.dll
file=%APPLDIR%\SfEnMcHn.dll
file=%APPLDIR%\SfEnMcOw.dll
file=%APPLDIR%\SfEnMcTs.dll
file=%APPLDIR%\SfEnMcVa.dll
file=%APPLDIR%\SfEnVSMs.dll
file=%APPLDIR%\SfEnVSRs.dll
file=%APPLDIR%\SfFnAvIm.dll
file=%APPLDIR%\SfFnHttp.dll
file=%APPLDIR%\SfFnProf.dll
file=%APPLDIR%\SfFnSvAg.dll
file=%APPLDIR%\SfFnUtil.dll
file=%APPLDIR%\SfFnWTC.dll
file=%APPLDIR%\SfFniAU.dll
file=%APPLDIR%\SfIfCom.dll
file=%APPLDIR%\SfIfDtCv.dll
file=%APPLDIR%\SfIfDtHd.dll
file=%APPLDIR%\SfIfEvMg.dll
file=%APPLDIR%\SfIfHttp.dll
file=%APPLDIR%\SfPxSt32.dll
file=%APPLDIR%\SfPxSt64.dll
file=%APPLDIR%\SfSvCoMg.dll
file=%APPLDIR%\SfSvEnHd.dll
file=%APPLDIR%\SfSvEvLg.dll
file=%APPLDIR%\SfSvLcMg.dll
file=%APPLDIR%\SfSvQuMg.dll
file=%APPLDIR%\SfSvTkSd.dll
file=%APPLDIR%\SfSvUiSv.dll
file=%APPLDIR%\SfSvUpMg.dll
file=%APPLDIR%\SfSvRcMg.dll
file=%APPLDIR%\ssapi32.dll
file=%APPLDIR%\ssapi64.dll
file=%APPLDIR%\tismsi.dll
file=%APPLDIR%\TisWrapr.dll
file=%APPLDIR%\TMAS_Hlp.dll
file=%APPLDIR%\TmasHlp.dll
file=%APPLDIR%\TMASmsi.dll
file=%APPLDIR%\TMBMCLI.dll
file=%APPLDIR%\TmcfScan.dll
file=%APPLDIR%\TmCfwApi.dll
file=%APPLDIR%\tmdp.dll
file=%APPLDIR%\TmDbg32.dll
file=%APPLDIR%\TmDbg64.dll
file=%APPLDIR%\Tmdshell.dll
file=%APPLDIR%\TmEngDrv.dll
file=%APPLDIR%\TmHash.dll
file=%APPLDIR%\TmpxHash.dll
file=%APPLDIR%\TmMsg.dll
file=%APPLDIR%\TmpeASpm.dll
file=%APPLDIR%\TmpeHosF.dll
file=%APPLDIR%\TmpePDP.dll
file=%APPLDIR%\TmpeUrlF.dll
file=%APPLDIR%\TmpeVS.dll
file=%APPLDIR%\TmPfwApi.dll
file=%APPLDIR%\TmPfwCtl.dll
file=%APPLDIR%\TmPfwHlp.dll
file=%APPLDIR%\TmPfwLog.dll
file=%APPLDIR%\TmPfwRul.dll
file=%APPLDIR%\TmphAim.dll
file=%APPLDIR%\TmphHttp.dll
file=%APPLDIR%\TmphIcq.dll
file=%APPLDIR%\TmphMsn.dll
file=%APPLDIR%\TmphPop3.dll
file=%APPLDIR%\TmphSMTP.dll
file=%APPLDIR%\TmphYmsg.dll
file=%APPLDIR%\tmpp.dll
file=%APPLDIR%\TmProxy.dll
file=%APPLDIR%\TmpxCfg.dll
file=%APPLDIR%\TmpxHelp.dll
file=%APPLDIR%\TmsmHttp.dll
file=%APPLDIR%\TmsmIm.dll
file=%APPLDIR%\TmsmMail.dll
file=%APPLDIR%\Tmtdi.dll
file=%APPLDIR%\TmUpdate.dll
file=%APPLDIR%\Tmufeng.dll
file=%APPLDIR%\Tmwfpapi.dll
file=%APPLDIR%\vstlib32.dll
file=%APPLDIR%\vstlib64.dll
file=%APPLDIR%\UfPack.dll
file=%APPLDIR%\VBProp.dll
file=%APPLDIR%\SfPxSt32.dll
file=%APPLDIR%\SfPx1732.dll
file=%APPLDIR%\SfPxSt64.dll
file=%APPLDIR%\SfPx1764.dll
file=%APPLDIR%\TMAS_AU.exe
file=%APPLDIR%\TSRemove.dll
file=%APPLDIR%\TmUtyPPI.dll
file=%APPLDIR%\TmUtyP64.dll
file=%APPLDIR%\vsapi32.dll
file=%APPLDIR%\vsapi64.dll
file=%APPLDIR%\wtclog.dll
file=%APPLDIR%\TmAtPlay.dll
file=%APPLDIR%\tmfbeng.dll
file=%APPLDIR%\default.prof
file=%APPLDIR%\TMNOTIFY.set
file=%APPLDIR%\hostexp.hsx
file=%APPLDIR%\default.prof
file=%APPLDIR%\*.upz
file=%APPLDIR%\license.rtf
file=%APPLDIR%\tmhelp.chm
file=%APPLDIR%\*.xen
file=%APPLDIR%\*.xml
file=%APPLDIR%\*.xsd
file=%APPLDIR%\*.gif
file=%APPLDIR%\*.htm
file=%APPLDIR%\*.ini
file=%APPLDIR%\*.dat
file=%APPLDIR%\*.manifest
file=%APPLDIR%\*.ptn
file=%APPLDIR%\*.txt
file=%APPLDIR%\*.log
file=%APPLDIR%\*.avi
file=%APPLDIR%\*.bmp
file=%APPLDIR%\*.enc
file=%APPLDIR%\*.pem
file=%APPLDIR%\*.inf
file=%APPLDIR%\*.chm
file=%APPLDIR%\tmblack.*
file=%APPLDIR%\tmwhite.*
file=%APPLDIR%\lpt$vpn.*
file=%APPLDIR%\ssaptn.*
file=%APPLDIR%\ssapiptn.*
file=%APPLDIR%\*.bin
file=%APPLDIR%\*.PDP
file=%APPLDIR%\*.tag
file=%APPLDIR%\*.s
file=%APPLDIR%\*.dll.mui
file=%APPLDIR%\*.exe.mui
file=%ALLUSERSSTARTUPDIR%\tisspwiz.lnk

[PCC17_DIR]
dir=%APPLDIR%\AU_Data
dir=%APPLDIR%\Component
dir=%APPLDIR%\Debug
dir=%APPLDIR%\PFW
dir=%APPLDIR%\Profile
dir=%APPLDIR%\OEM
dir=%APPLDIR%\Quarantine
dir=%APPLDIR%\Report
dir=%APPLDIR%\SpyBackup
dir=%APPLDIR%\Task
dir=%APPLDIR%\Temp
dir=%APPLDIR%\TMAS_OE
dir=%APPLDIR%\TMAS_OL
dir=%APPLDIR%\TmpxTmp
dir=%APPLDIR%\UpdTemp
dir=%APPLDIR%\Log
dir=%APPLDIR%\_rels
dir=%APPLDIR%\docProps
dir=%APPLDIR%\word\_rels
dir=%APPLDIR%\word\theme
dir=%APPLDIR%\word
dir=%APPLDIR%\
dir=%APPLPARENTDIR%\BM
dir=%APPLPARENTDIR%\TrendSecure
dir=%APPLPARENTDIR%\
dir=%ALLUSERSPCCDIR%\
dir=%ALLUSERSTMDIR%\OE
dir=%ALLUSERSTMDIR%\OL

[PCC17_REGKEY]
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{771A9DA0-731A-11CE-993C-00AA004ADB6C}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.*\shell\Properties\command
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SfCtlCom.EXE
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D22335B0-9C76-44BC-9044-DFC1EDBFA2CD}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\LocalServer32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\ProgID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\TypeLib
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\VersionIndependentProgID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\LocalServer32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\ProgID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\TypeLib
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\VersionIndependentProgID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48F45200-91E6-11CE-8A4F-0080C81A28D4}\InprocServer32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7575A638-D24B-44CC-A6D3-5222AA1F6730}\InprocServer32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7575A638-D24B-44CC-A6D3-5222AA1F6730}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{771A9DA0-731A-11CE-993C-00AA004ADB6C}\InprocServer32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{771A9DA0-731A-11CE-993C-00AA004ADB6C}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DocShortcut\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\A54B126A831D59A4EB01C7BA0AE59FE4
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A54B126A831D59A4EB01C7BA0AE59FE4
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\BF4AB608D543B5A40844015D71D3E588
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\55A21E04405C3224FACA6727BD1FCAED
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\55A21E04405C3224FACA6727BD1FCAED
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\396D4E74204951C42A7D7210600620A7
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\2230B2D9EA44E0642938D4D2A72950EA
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2230B2D9EA44E0642938D4D2A72950EA
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\F9CD68EC81A380B4D91A897B2158088F
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52C9BCA5-491E-4F5B-8565-2D97E28741E4}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52C9BCA5-491E-4F5B-8565-2D97E28741E4}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52C9BCA5-491E-4F5B-8565-2D97E28741E4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69BEC890-8645-48D7-9498-C6DA00536C32}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69BEC890-8645-48D7-9498-C6DA00536C32}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69BEC890-8645-48D7-9498-C6DA00536C32}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69FB91DC-7CC2-4991-846A-A352B19294FA}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69FB91DC-7CC2-4991-846A-A352B19294FA}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69FB91DC-7CC2-4991-846A-A352B19294FA}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7575A638-D24B-44CC-A6D3-5222AA1F6730}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7575A638-D24B-44CC-A6D3-5222AA1F6730}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7575A638-D24B-44CC-A6D3-5222AA1F6730}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9C4631CA-97D5-4AA3-8D46-A3C7F3298BD2}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9C4631CA-97D5-4AA3-8D46-A3C7F3298BD2}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9C4631CA-97D5-4AA3-8D46-A3C7F3298BD2}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A58549E3-A1DC-41A9-9D64-A3F1D4A73DCC}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A58549E3-A1DC-41A9-9D64-A3F1D4A73DCC}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A58549E3-A1DC-41A9-9D64-A3F1D4A73DCC}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B19A95B6-C26C-4ACB-997C-EDBEDB139FBA}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B19A95B6-C26C-4ACB-997C-EDBEDB139FBA}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B19A95B6-C26C-4ACB-997C-EDBEDB139FBA}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BB69D2DF-FEAD-4789-9DDC-323E5B3D6326}\NumMethods
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BB69D2DF-FEAD-4789-9DDC-323E5B3D6326}\ProxyStubClsid32
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BB69D2DF-FEAD-4789-9DDC-323E5B3D6326}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\piffile\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController\CLSID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController\CurVer
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController.1\CLSID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController.1\CurVer
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController.1
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkLocalController\CLSID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkRemoteController\CurVer
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkRemoteController
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkRemoteController.1\CLSID
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkRemoteController.1\CurVer
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SfCtlCom.TmFrwkRemoteController.1
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BF4AB608D543B5A40844015D71D3E588
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\396D4E74204951C42A7D7210600620A7
regkey=%UCOMP%\02CAF7A0CB8A0B34FBBCB58E42B7FE1D
regkey=%UCOMP%\03D546942EA3ECC4B98C51CEF4E49B44
regkey=%UCOMP%\0471BA1D5D5BC194CB06F4A4491AF4D9
regkey=%UCOMP%\05D55C20BB978C24DBB921D5563E0275
regkey=%UCOMP%\0611EDBAEFCE43B4B89C2E48F076E075
regkey=%UCOMP%\07089067CEC9D2F469B295A1EF7E72CA
regkey=%UCOMP%\07B5077AD50182140B99AA566DDAF9BA
regkey=%UCOMP%\07E9D48D2772E0645A588E9A6CF32130
regkey=%UCOMP%\088E60483B8EF1F4FBB90974B8112AB4
regkey=%UCOMP%\08C9821A08D73F945BCC283EE1B7CED3
regkey=%UCOMP%\09FF72E03D50FFE42B8E8005127D1662
regkey=%UCOMP%\0A55ADC0B59BC594299AA7FB39129EC0
regkey=%UCOMP%\0D8A60B099344FD43B1F43D022DD7151
regkey=%UCOMP%\0F9DAF3851742CF4AA42DC5C9EDB99A9
regkey=%UCOMP%\0FC39DEE24C7C1D43B71BB2E969EC9B3
regkey=%UCOMP%\10239061232C61D48ACCF6ACC60BC739
regkey=%UCOMP%\10BAFFF2B0E956747A07A156B06D8472
regkey=%UCOMP%\10EB39EC6719E8D47AA61A2DC6031871
regkey=%UCOMP%\14A581A307656D6498BBC9B64A1F9A79
regkey=%UCOMP%\18F08D80B82AFD545ABEA4456D14E6CF
regkey=%UCOMP%\18EB1F226BC02BC4493588EFDAFB4921
regkey=%UCOMP%\1A1D3E5EBF511734CB776EB3ECB2F0DE
regkey=%UCOMP%\1A9F3DA5ECFD318468435146C1505523
regkey=%UCOMP%\1AA416380742EA94FBCEA2F66B9983FD
regkey=%UCOMP%\1B7CFCC4387C2F4488D27198F3908192
regkey=%UCOMP%\1CC91EB973B91654584DEA710CE8F35E
regkey=%UCOMP%\1FAB4A5F4DB8EF948BB2646A92DFD332
regkey=%UCOMP%\212FFA8FCC3BC0F409902DB857375D73
regkey=%UCOMP%\217EF4460E91145418C0661660A9D82D
regkey=%UCOMP%\229627BD130C7CC40AA4A0DA52BBC5BF
regkey=%UCOMP%\249F79D0473ACE04186E09FFA8B8AEE3
regkey=%UCOMP%\2575A7BE5B01D724F87AFA6AD1166E69
regkey=%UCOMP%\25A35512FF2EF434FAFE9024CBE455FB
regkey=%UCOMP%\26AF0EB9D6607F544A6312480F9F1752
regkey=%UCOMP%\2931D085A924CA9459791C7FF896AD88
regkey=%UCOMP%\2ADB806C537A89243BA52ABE64A0C1D4
regkey=%UCOMP%\2F0DDBAFE81EE4448A287CA8393E028E
regkey=%UCOMP%\30F5BB9CDEFBD6F41B94827E263FC67C
regkey=%UCOMP%\3279D5D6068BDAC4A8421290BCF67189
regkey=%UCOMP%\32E5D88AF5B7B004C94E34E68023E945
regkey=%UCOMP%\34540F0C4DE2C1F4998E303EADCA98AA
regkey=%UCOMP%\34D968EC753E1EA47A2549276AA9D8F5
regkey=%UCOMP%\352410A039311C3469B88CBAE11D5F72
regkey=%UCOMP%\35E3AB89F73E5D14C9889F48AFBC018A
regkey=%UCOMP%\366B144E2CF69BD4092CDF73EED0C42F
regkey=%UCOMP%\36D4BEDF02707B34DBDDC0895EAA22AB
regkey=%UCOMP%\3A533538F78717C499A2958EF876D210
regkey=%UCOMP%\3BC0BD18DDAD41D48BB0784FFB7A27AA
regkey=%UCOMP%\3CAE7141B2081FC4989979DF4819022B
regkey=%UCOMP%\3D314A8B53498D846BF1F55D7666EF26
regkey=%UCOMP%\3E82D31658690D743A6012BE8A1AF0DE
regkey=%UCOMP%\4527063B78F795744A211AE58D1CD229
regkey=%UCOMP%\489A5402EFFC40B4F807E57B05A2BC1C
regkey=%UCOMP%\489E4E0F31099354BBC17563DD4B777B
regkey=%UCOMP%\48E8105318F02E04384D48EF25B14EB4
regkey=%UCOMP%\4A332CA6538801641BC71C93C6F641DB
regkey=%UCOMP%\4A3AFDB1DF8152A499C86A1352C4D21A
regkey=%UCOMP%\4D26CA3B4ADA06348B7E56CF46A8E030
regkey=%UCOMP%\4F2E0F7067595E54EA1DCA1B9D5ABC8A
regkey=%UCOMP%\4F452B13B4B4A6343BEDB3CA3795F12E
regkey=%UCOMP%\5167C2628BC55504BB4912BE4DF63F89
regkey=%UCOMP%\54375327D5D47C048B151BBA9D0FF552
regkey=%UCOMP%\550008564A94C8647AB8C52FEEF27F01
regkey=%UCOMP%\5895370B5B6E8DE469B1629B7639F0AB
regkey=%UCOMP%\58FB643BFAF739F408243093D2A7BE5A
regkey=%UCOMP%\5BE469C2E6241A244B297EAE70E84C28
regkey=%UCOMP%\5EB67BD5B7AAD564FAE688EF633B2CB6
regkey=%UCOMP%\6054E8D9C6A4F5E4ABD02CEE435356D7
regkey=%UCOMP%\60765793C51519E4D9D0EE0E3C6D586A
regkey=%UCOMP%\60C8EC97BE517694C9D8C93C3F0955B0
regkey=%UCOMP%\63A1726190C65694480D94A905759793
regkey=%UCOMP%\65C3361067AC21B40B04989259D40A57
regkey=%UCOMP%\66D1331658C296C49942BB67F28A7A22
regkey=%UCOMP%\684032F066696B94F9DF947B7E4ECF67
regkey=%UCOMP%\69E4CED5DEEC7D74AA2C58DC4A30F918
regkey=%UCOMP%\6A9192C727843864C9FA8D7104E8AD96
regkey=%UCOMP%\6BFA908061826AB428C205AE84A8C509
regkey=%UCOMP%\6CE6740733BE7E6459859BD87905C9EC
regkey=%UCOMP%\6CFE15E5791B42D44908E7070945122E
regkey=%UCOMP%\6E43B0E03A735BC40809A16595D8DAE6
regkey=%UCOMP%\6EA0F0FB69663F040A42D4065A0CABDA
regkey=%UCOMP%\6F0530CEEB51C5F438E7EB43E4E3098A
regkey=%UCOMP%\6F87BEC7594F29948958AEDE4F265384
regkey=%UCOMP%\70FBDA373818E594994B92C0FE857E31
regkey=%UCOMP%\71425D2AA297A3C449E939F5F8702B8E
regkey=%UCOMP%\71EA660585518F146A3ED0118970822C
regkey=%UCOMP%\740D4510C9B1F15488BE57F0476871AC
regkey=%UCOMP%\748527D27FB74714C913EDC325B65F52
regkey=%UCOMP%\763C3E9B269A4A34F8C8E3BD6C3421BE
regkey=%UCOMP%\76B0B9C30A7DEB746BEC0834E6070C15
regkey=%UCOMP%\7729C2B0763BDD94AB1B92CB56DD2930
regkey=%UCOMP%\7AD44494B7B3EC94F8B41A2937B1CAA0
regkey=%UCOMP%\7AF25678276193D4480BDFDF02971EDC
regkey=%UCOMP%\7C3D204C0B4BE754AABA253F129B7CF1
regkey=%UCOMP%\7FFB02A0AB63E7947AEF8C404FF40B3D
regkey=%UCOMP%\81D4EDAF1344F974E9A0CA2B4DECB892
regkey=%UCOMP%\826938A98806F51418A5E8871F87D48D
regkey=%UCOMP%\8381D17DD212D74468A4E45236D263C0
regkey=%UCOMP%\843E05D6FFC4D784BB339B2B3AC61B0F
regkey=%UCOMP%\8611C921587B6EA4D9E68C5C32E5D64E
regkey=%UCOMP%\87BF0593584900741BD063019016E54B
regkey=%UCOMP%\8CAA0A232AA22CB4A82987CE6BF3A466
regkey=%UCOMP%\8F2BFED9A0987384C8D5175DB6EA75E0
regkey=%UCOMP%\914A1ADEE2086D840B477D5510696DD7
regkey=%UCOMP%\91899B5B356B6D847AFDCBD2D3E405D9
regkey=%UCOMP%\91899B5B356B6D847AFDCBD2D3E405D9
regkey=%UCOMP%\91B1427E3A548084E81DC1EC94E8A1CE
regkey=%UCOMP%\967E48927CA48484992D91DA4A5A04ED
regkey=%UCOMP%\9833CC385AAF9C14C9716346C5BCFA02
regkey=%UCOMP%\98DEC4ECC7455A840BDC035C9A2E3724
regkey=%UCOMP%\9B02A4EAE592D8449A0E1E84893C2EC4
regkey=%UCOMP%\9E1020CD36DC2EA49AAC483CAB39B320
regkey=%UCOMP%\9EED2D94496FD9842A2E2B6245E64349
regkey=%UCOMP%\9FBE03350BC4A164C82431D634037F30
regkey=%UCOMP%\9FC985A07507F2E4F8B0A330A6B376E7
regkey=%UCOMP%\A0EA005D14B279A4791CA9B99476E9F2
regkey=%UCOMP%\A10E2B22913B0F84AA7717E4C1252426
regkey=%UCOMP%\A10F6AB63E477BA448B33B5406E09C4E
regkey=%UCOMP%\A1FEAA91E0824494AA1BFF7BE80591E0
regkey=%UCOMP%\A211C637200481E48A8D780E42DF0447
regkey=%UCOMP%\A4FFDD55A76E34A408E9E3ED451F8451
regkey=%UCOMP%\A893987128AEF4749840C0D530F9A89E
regkey=%UCOMP%\A8A3CECEE05D7D744A28B682B9F3A9AC
regkey=%UCOMP%\A8E8059C478705246ACCA42038A3256D
regkey=%UCOMP%\AA838FC20BD19FD4284D037A023F17C6
regkey=%UCOMP%\AF93819E8893324429A088AB0D61B581
regkey=%UCOMP%\B130F86FC69DAE540AEC707527611F6C
regkey=%UCOMP%\B16F424C84527624792630BD48C0238C
regkey=%UCOMP%\B2299FCA05CE34C4995D51919C08F59B
regkey=%UCOMP%\B354B99E0E180EA42876DC60ABAFD860
regkey=%UCOMP%\B48ADC115CEFA6A46B15D0F49BAD8BB4
regkey=%UCOMP%\B5504B969F98BC7429D1955FB55E90EF
regkey=%UCOMP%\B58A20221A7CD6940A60228A4AA49827
regkey=%UCOMP%\B5B2062AC05567144879EA82AFBD020E
regkey=%UCOMP%\B5B4F562F85AD4242948C19B798FD2F9
regkey=%UCOMP%\B729B836136CD73428D5D395A448B9C8
regkey=%UCOMP%\B741F21048740D842B265B593B730F54
regkey=%UCOMP%\BB4E503375942544C84363E84613A9B1
regkey=%UCOMP%\C023DACE6850B664ABE13DFB181DAC84
regkey=%UCOMP%\C0DE19763393D2245B1760563A2E329E
regkey=%UCOMP%\C0F7FF31E1281FA48B073B9B252F5AA7
regkey=%UCOMP%\C23966DA7909B9C4589EC181CDC53ED1
regkey=%UCOMP%\C7A7852E69C851C4BBAD468168B096A0
regkey=%UCOMP%\C9230C636B7196246B68A4C41B4913AE
regkey=%UCOMP%\C92A677198464144485AE3E02538846E
regkey=%UCOMP%\CBEC22935A2FA7348988E1AA73A30852
regkey=%UCOMP%\CC66E4E58158F2749AD6BFC979D52FDB
regkey=%UCOMP%\CCB977C40A6E7874C9CEA11BBFC5F642
regkey=%UCOMP%\CCBD4D5372E689E488AB3D523C5845B5
regkey=%UCOMP%\CCF347FBF1B3FF24CAC18127A5095997
regkey=%UCOMP%\CE61E6BE25F3FE142B86BADF04F80951
regkey=%UCOMP%\D0078F753D3DE9C4287B7B9E5FB094DD
regkey=%UCOMP%\D2683C2211C1B0E4EB218C8BC89155BE
regkey=%UCOMP%\D2BF732EE84EDDD439584C7249FCB870
regkey=%UCOMP%\D401E08DC3FB04244A37ADA3E50E0454
regkey=%UCOMP%\D49E8EE968C600340AEA882571A219F8
regkey=%UCOMP%\D50B608A216229B4389439285C044A2C
regkey=%UCOMP%\D661B3FCDB38A2C4D8034DADDA039A27
regkey=%UCOMP%\D8928221E23D905439FB760A4DF55846
regkey=%UCOMP%\DB6F8CF251FC9DE438B05FB75569610F
regkey=%UCOMP%\DCBCAF3ADC8CAFD4EAD16AFA9FA991AA
regkey=%UCOMP%\DCF85F1847EB01B4FB98DE078E029859
regkey=%UCOMP%\DD1B53F5B20ACEE4E8874793119E0A2A
regkey=%UCOMP%\DD3264A20788ECA4591C510DA9F3102E
regkey=%UCOMP%\E112C8748D768FA4D9BFFDD100EE1E5C
regkey=%UCOMP%\E12254C560876954E9F91040512EE5EB
regkey=%UCOMP%\E13AE3B0E34E6AE4498BBD2D6411D156
regkey=%UCOMP%\E59B1E72EA71B1D47BA5AF8F14343A42
regkey=%UCOMP%\EB61B2165A0CA74459A6C870247EF1B7
regkey=%UCOMP%\ED6245EADE6FACE40B46B7F217969B46
regkey=%UCOMP%\EE4F472B10BF05B4785AE4B4025266BB
regkey=%UCOMP%\F0799FDC47553234088BF285DC928FBC
regkey=%UCOMP%\F0FD87093F552184BBEE85933BFC8B24
regkey=%UCOMP%\F10BBE93CA8287A4790F072A892263E7
regkey=%UCOMP%\F3D170D6565EBBA4F8D52C1FBE2FC784
regkey=%UCOMP%\F3EA7BD9B27A6CF41BD71C41413EE33F
regkey=%UCOMP%\F556789A55C49154685E8A100C59DC9E
regkey=%UCOMP%\F588400B672ACA446B63013C5DF6B5B1
regkey=%UCOMP%\F8C58B404DF0E1C4A9DFD89068B2848E
regkey=%UCOMP%\F9A16410F09E9C147BCBDAD3AD4248F8
regkey=%UCOMP%\F9B7089BABF70754BA02C0F696722FB6
regkey=%UCOMP%\FA58BD177FD288B4894B30229283C65D
regkey=%UCOMP%\FC7A7ACAD2E919F4AB551403E91FCF93
regkey=%UCOMP%\FCEDC8E022B63E443B47424CB3BF942D
regkey=%UCOMP%\FD677B5BB5744584A83229CC5BE850DE
regkey=%UCOMP%\FE7961328DEE86A439FEEAD6131EB4A3
regkey=%UPROD%\A54B126A831D59A4EB01C7BA0AE59FE4
regkey=%UPROD%\2230B2D9EA44E0642938D4D2A72950EA
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{40E12A55-C504-4223-AFAC-7672DBF1ACDE}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A621B45A-D138-4A95-BE10-7CABA05EF94E}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{23D6060D-8746-4c8e-B62E-4B63931AF4DD}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FA573BC8-9E4C-4B4B-8696-3C6836967249}
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D2B0322-44AE-460e-9283-4D2D7A9205AE}
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SFCTLCOM
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TMPREFLT
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TMTDI
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TMXPFLT
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSAPINT
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\TM_CFWMP
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SfCtlCom
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmcfw
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tmntsrv
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TmPfw
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmpreflt
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmproxy
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmtdi
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmxpflt
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmwfp
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tmlwf
regkey=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsapint
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SFCTLCOM
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TMPREFLT
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TMTDI
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TMXPFLT
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSAPINT
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\TM_CFWMP
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SfCtlCom
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmcfw
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmmbd
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tmntsrv
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TmPfw
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmpreflt
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmproxy
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmtdi
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmxpflt
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmwfp
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmlwf
regkey=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsapint
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\NSC\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillin\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMAS\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TrendSecure\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\ActNavi\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\TMAutoplayScan\
regkey=HKEY_CLASSES_ROOT\AppID\SfCtlCom.EXE
regkey=HKEY_CLASSES_ROOT\AppID\{D22335B0-9C76-44BC-9044-DFC1EDBFA2CD}
regkey=HKEY_CLASSES_ROOT\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\LocalServer32
regkey=HKEY_CLASSES_ROOT\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\ProgID
regkey=HKEY_CLASSES_ROOT\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\TypeLib
regkey=HKEY_CLASSES_ROOT\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}\VersionIndependentProgID
regkey=HKEY_CLASSES_ROOT\CLSID\{1A65BAB7-30B1-4FB7-BC13-D00C28FCF605}
regkey=HKEY_CLASSES_ROOT\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\LocalServer32
regkey=HKEY_CLASSES_ROOT\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\ProgID
regkey=HKEY_CLASSES_ROOT\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\TypeLib
regkey=HKEY_CLASSES_ROOT\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}\VersionIndependentProgID
regkey=HKEY_CLASSES_ROOT\CLSID\{42CB8A9C-AF22-4CA2-B616-B4E8920BBFDC}
regkey=HKEY_CLASSES_ROOT\CLSID\{48F45200-91E6-11CE-8A4F-0080C81A28D4}\InprocServer32
regkey=HKEY_CLASSES_ROOT\CLSID\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regkey=HKEY_CLASSES_ROOT\CLSID\{7575A638-D24B-44CC-A6D3-5222AA1F6730}\InprocServer32
regkey=HKEY_CLASSES_ROOT\CLSID\{7575A638-D24B-44CC-A6D3-5222AA1F6730}
regkey=HKEY_CLASSES_ROOT\CLSID\{771A9DA0-731A-11CE-993C-00AA004ADB6C}\InprocServer32
regkey=HKEY_CLASSES_ROOT\CLSID\{771A9DA0-731A-11CE-993C-00AA004ADB6C}
regkey=HKEY_CLASSES_ROOT\CLSID\{BB7E88E2-443A-456A-9D7D-F25B9F5F7A95}\InprocServer32
regkey=HKEY_CLASSES_ROOT\CLSID\{BB7E88E2-443A-456A-9D7D-F25B9F5F7A95}
regkey=HKEY_CLASSES_ROOT\Installer\Features\A54B126A831D59A4EB01C7BA0AE59FE4
regkey=HKEY_CLASSES_ROOT\Installer\Products\A54B126A831D59A4EB01C7BA0AE59FE4
regkey=HKEY_CLASSES_ROOT\Installer\UpgradeCodes\BF4AB608D543B5A40844015D71D3E588
regkey=HKEY_CLASSES_ROOT\Installer\Features\55A21E04405C3224FACA6727BD1FCAED
regkey=HKEY_CLASSES_ROOT\Installer\Products\55A21E04405C3224FACA6727BD1FCAED
regkey=HKEY_CLASSES_ROOT\Installer\UpgradeCodes\396D4E74204951C42A7D7210600620A7
regkey=HKEY_CLASSES_ROOT\Installer\Features\2230B2D9EA44E0642938D4D2A72950EA
regkey=HKEY_CLASSES_ROOT\Installer\Products\2230B2D9EA44E0642938D4D2A72950EA
regkey=HKEY_CLASSES_ROOT\Installer\UpgradeCodes\F9CD68EC81A380B4D91A897B2158088F
regkey=HKEY_CLASSES_ROOT\Interface\{52C9BCA5-491E-4F5B-8565-2D97E28741E4}
regkey=HKEY_CLASSES_ROOT\Interface\{69BEC890-8645-48D7-9498-C6DA00536C32}
regkey=HKEY_CLASSES_ROOT\Interface\{69FB91DC-7CC2-4991-846A-A352B19294FA}
regkey=HKEY_CLASSES_ROOT\Interface\{7575A638-D24B-44CC-A6D3-5222AA1F6730}
regkey=HKEY_CLASSES_ROOT\Interface\{9C4631CA-97D5-4AA3-8D46-A3C7F3298BD2}
regkey=HKEY_CLASSES_ROOT\Interface\{A58549E3-A1DC-41A9-9D64-A3F1D4A73DCC}
regkey=HKEY_CLASSES_ROOT\Interface\{B19A95B6-C26C-4ACB-997C-EDBEDB139FBA}
regkey=HKEY_CLASSES_ROOT\Interface\{BB69D2DF-FEAD-4789-9DDC-323E5B3D6326}
regkey=HKEY_CLASSES_ROOT\TMAS_OLA.OLAgent
regkey=HKEY_CLASSES_ROOT\TMAS_OLA.OLAgent.1
regkey=HKEY_CLASSES_ROOT\SfCtlCom.TmFrwkLocalController\
regkey=HKEY_CLASSES_ROOT\SfCtlCom.TmFrwkLocalController.1\
regkey=HKEY_CLASSES_ROOT\SfCtlCom.TmFrwkRemoteController\
regkey=HKEY_CLASSES_ROOT\SfCtlCom.TmFrwkRemoteController.1\
regkey=HKEY_CLASSES_ROOT\TM.AutoplayScan\
regkey=HKEY_CURRENT_USER\Software\Microsoft\office\Outlook\addins\TMAS_OLA.OLAgent
regkey=HKEY_CURRENT_USER\Software\Microsoft\OEMonCtl
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{54B89198-879A-4086-B082-854D3EBFDCC3}\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{54B89298-879A-4086-B082-854D3EBFDCC3}\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EFA2E970-BA63-4607-AB47-76CA6B83BD1B}\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5A20523-62BB-4D8C-A180-B7E05953ACDC}\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FB57D4-41B3-410F-92FB-F6726D4D6EB3}\
regkey=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB04F6E5-7638-4486-9295-1BA1859B0619}\
regkey=HKEY_CURRENT_USER\Software\TrendMicro\TrendSecure\
regkey=HKEY_CURRENT_USER\Software\TrendMicro



[PCC17_REGVALUE]
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\\MajorUpgradeScen
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x00000004\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x00000010\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x14000000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x21000800\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x21080000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22000010\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22000040\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22000080\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22000080\OEM\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22000080\OEM\NonAUPtn\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22004000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22001000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x22010000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x24080000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x24200000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x24800000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x28088000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Engine\0x28100000\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\155\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\156\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\157\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\158\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\158\PFW
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\159\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\160\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\161\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\162\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\163\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\164\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\165\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\171\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\209\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\210\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\211\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\212\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\212\PFW\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\213\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\214\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\215\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\216\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\217\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\218\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\219\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Function\220\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Patch\223\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Patch\224\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Patch\225\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\Patch\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Component\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLDIR%Profile\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\%APPLPARENTDIR%\
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{771A9DA0-731A-11CE-993C-00AA004ADB6C}
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468e-B848-2B2E8E697B74} 2\\%SystemRoot%\System32\UfWSC.cpl
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShareDLLs\\%SYSTEMDIR%\UfWSC.cpl
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UfSeAgnt.exe
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tisspwiz.exe
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\GenericVolumeArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayCDAudioOnArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayDVDMovieOnArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayMusicFilesOnArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayVideoFilesOnArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Ravemp2300Arrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Rio600Arrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Rio800Arrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\RioOneArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\RNDeviceArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\ShowPicturesOnArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\VideoCameraArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\AutorunINFLegacyArrival\\TMAutoplayScan
regvalue=:DIRECT:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\MixedContentOnArrival\\TMAutoplayScan
0
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
6 déc. 2009 à 18:57
...

Non, c' est pas le bon rapport.

---
Télécharge et installe UsbFix (par Chiquitine29) :

http://pagesperso-orange.fr/nostools/usbfix.html

(!) Branche tes sources de données externes au PC (clé USB, disque dur externe, etc ...) susceptibles d'avoir été infectées et ce, sans les ouvrir.

Sur le bureau, double clique sur le raccourci UsbFix.

Au menu principal, choisis l'option F pour français et valide par [Entrée].

Au second menu, choisis l'option 1 (recherche) et valide par [Entrée].

Laisse l' outil travailler ... jusqu' à l' apparition du rapport.

Poste le rapport UsbFix.txt.

Note : Le rapport UsbFix.txt est aussi conservé a la racine du disque (C:\UsbFix.txt)

(Ctrl+A pour tout selectionner, Ctrl+C pour copier et Ctrl+V pour coller)

• Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus
(AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité
(Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
looo ooo Messages postés 147 Date d'inscription mercredi 25 février 2009 Statut Membre Dernière intervention 19 mai 2017
6 déc. 2009 à 19:26
rapport usb :

############################## | UsbFix V6.059 |

User : Laurence (Administrateurs) # PC-DE-LAURENCE
Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
Start at: 19:22:55 | 06/12/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

AMD Athlon(tm) 64 X2 Dual Core Processor 4400+
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18828
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local # 290,18 Go (189,79 Go free) [COMPAQ] # NTFS
D:\ -> Disque fixe local # 7,91 Go (1 Go free) [Recovery] # NTFS
E:\ -> Disque CD-ROM # 702,31 Mo (0 Mo free) [2 mars 2008] # UDF
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque amovible
J:\ -> Disque amovible # 1,91 Go (1,8 Go free) # FAT
K:\ -> Disque CD-ROM # 5,45 Mo (0 Mo free) [U3 System] # CDFS

############################## | Processus actifs |

C:\Windows\System32\smss.exe 492
C:\Windows\system32\csrss.exe 560
C:\Windows\system32\wininit.exe 612
C:\Windows\system32\csrss.exe 624
C:\Program Files\AVG\AVG9\avgchsvx.exe 636
C:\Program Files\AVG\AVG9\avgrsx.exe 644
C:\Program Files\AVG\AVG9\avgcsrvx.exe 680
C:\Windows\system32\services.exe 708
C:\Windows\system32\lsass.exe 724
C:\Windows\system32\lsm.exe 736
C:\Windows\system32\svchost.exe 972
C:\Windows\system32\winlogon.exe 1004
C:\Windows\system32\svchost.exe 1168
C:\Windows\System32\svchost.exe 1356
C:\Windows\System32\svchost.exe 1388
C:\Windows\system32\svchost.exe 1408
C:\Windows\system32\svchost.exe 1548
C:\Windows\system32\SLsvc.exe 1584
C:\Windows\system32\svchost.exe 1628
C:\Windows\system32\svchost.exe 1808
C:\Windows\System32\spoolsv.exe 324
C:\Windows\system32\svchost.exe 360
C:\Windows\system32\taskeng.exe 528
C:\Windows\system32\Dwm.exe 788
C:\Windows\system32\taskeng.exe 808
C:\Windows\Explorer.EXE 1516
C:\Program Files\AVG\AVG9\avgwdsvc.exe 2196
C:\Windows\system32\ezNTSvc.exe 2228
C:\Windows\system32\svchost.exe 2368
c:\Program Files\Common Files\LightScribe\LSSrvc.exe 2412
C:\Windows\System32\svchost.exe 2492
C:\Windows\System32\svchost.exe 2532
C:\Windows\system32\svchost.exe 2548
C:\Windows\system32\svchost.exe 2580
C:\Windows\System32\svchost.exe 2620
C:\Windows\system32\SearchIndexer.exe 2664
C:\Program Files\AVG\AVG9\avgnsx.exe 2868
C:\Windows\system32\WUDFHost.exe 3224
C:\hp\support\hpsysdrv.exe 2204
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe 1512
C:\WINDOWS\RtHDVCpl.exe 2448
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe 2528
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 2736
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe 2780
C:\WINDOWS\System32\rundll32.exe 3124
C:\Program Files\Java\jre6\bin\jusched.exe 3152
C:\Program Files\AVG\AVG9\avgtray.exe 3132
C:\Program Files\Common Files\Real\Update_OB\realsched.exe 3272
C:\Program Files\Windows Sidebar\sidebar.exe 3296
C:\WINDOWS\ehome\ehtray.exe 3252
C:\Program Files\DartyBox_v3\Sagem\AssistantDB\AssistantDB_Sagem.exe 1916
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 1688
C:\WINDOWS\System32\rundll32.exe 1372
C:\Windows\ehome\ehmsas.exe 3316
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe 4076
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 2516
C:\Windows\system32\conime.exe 4364
C:\Windows\system32\rundll32.exe 1508
C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE 2172
C:\Program Files\Mozilla Firefox\firefox.exe 5264
C:\Windows\system32\SearchProtocolHost.exe 5952
C:\Windows\system32\SearchFilterHost.exe 6132
C:\Windows\System32\mobsync.exe 1084
C:\Windows\system32\wbem\wmiprvse.exe 5772

################## | Fichiers # Dossiers infectieux |

K:\autorun.inf

################## | Spyware.OnlineGames |


################## | Registre # Clés infectieuses |

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

################## | Registre # Mountpoints2 |

HKCU\..\..\Explorer\MountPoints2\{3d3f3c94-750d-11de-ae2a-001bb9760b64}
shell\AutoRun\command =J:\Programs\nu2menu\nu2menu.exe

HKCU\..\..\Explorer\MountPoints2\{8c80427b-dd82-11de-8cb8-001bb9760b64}
shell\AutoRun\command =K:\LaunchU3.exe -a

################## | Cracks / Keygens / Serials |


################## | ! Fin du rapport # UsbFix V6.059 ! |
0
kduc Messages postés 1462 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 1 novembre 2011 133
6 déc. 2009 à 19:36
...

(!) Branche tes sources de données externes au PC (clé USB, disque dur externe, etc ...) susceptibles d avoir été infectées et ce, sans les ouvrir.

Clique droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur".

Au menu principal, choisis l'option F pour français et valide par [entrée].

Au 2ème menu, choisis l'option 2 (Suppression) et valide par [entrée].

• Ton bureau va disparaitre et le PC redémarrer.

• Au redémarrage, UsbFix scannera le PC ... Laisse l' outil travailler !

Ensuite, poste le rapport UsbFix.txt qui s' affiche avec le bureau.

PS : le rapport UsbFix.txt est conservé à la racine du disque (C:\UsbFix.txt)
0