Hacktool Rootkit (wincab.sys)
Résolu
Azeal
Messages postés
4
Statut
Membre
-
Seb-ass -
Seb-ass -
Bonsoir à tous, depuis quelques jours mon PC est infecté par un virus "Hacktool Rootkit". J'ai essayé plusieurs logiciel proposé sur les sites et forums mais ils ne detectent pas.
Seul mon AV d'origine (Norton) lance une alerte du virus trouvé dans le fichier "wincab.sys" et cela, seulement lorsque je clique sur un de mes disques durs ...
Je post donc mon log :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:03:23, on 05/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\ntde1ect.com
C:\HiJackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O20 - AppInit_DLLs: 6741f5de
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LPNFEGEKCG - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Admin\LOCALS~1\Temp\LPNFEGEKCG.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Service Norton Protection Center (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TI - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Admin\LOCALS~1\Temp\TI.exe
Seul mon AV d'origine (Norton) lance une alerte du virus trouvé dans le fichier "wincab.sys" et cela, seulement lorsque je clique sur un de mes disques durs ...
Je post donc mon log :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:03:23, on 05/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\ntde1ect.com
C:\HiJackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O20 - AppInit_DLLs: 6741f5de
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LPNFEGEKCG - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Admin\LOCALS~1\Temp\LPNFEGEKCG.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Service Norton Protection Center (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TI - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Admin\LOCALS~1\Temp\TI.exe
A voir également:
- Hacktool Rootkit (wincab.sys)
- Rootkit - Télécharger - Antivirus & Antimalwares
- Rootkit hunter - Télécharger - Antivirus & Antimalwares
- Sophos anti rootkit - Télécharger - Antivirus & Antimalwares
- Avg anti rootkit - Télécharger - Antivirus & Antimalwares
- Panda anti-rootkit - Télécharger - Antivirus & Antimalwares
13 réponses
Bonjour,
1/ * Télécharge SREng (de Smallfrogs) : http://www.kztechs.com/eng/download.html
* Dézippe tout son contenu sur ton bureau (clic droit >Extraire ici).
* Ouvre le dossier SReng2 et double-clique sur SREng.exe.
* Clique sur "smart scan".
* Clique sur le bouton "scan".
* Quand l'analyse est terminée, clique sur le bouton "save reports".
* Sauvegarde alors le rapport sur ton bureau.
* Copie/colle le contenu du rapport SREnglLOG.log dans ta prochaine réponse.
2/ * Télécharge DiagHelp.zip sur ton bureau(Merci Malekal) : http://www.malekal.com/download/DiagHelp.zip
Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
* Ne double-clique pas dessus !! Fais un clic droit sur le fichier et extraire tout.
* Un nouveau dossier chercher va être créé.
* Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
* Une fenêtre va s'ouvrir, choisis l'option 1
* L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.
* Pendant l'analyse après le rapport CATCHME sur l'écran rouge, tu dois appuyer sue entrée pour que l'outil continue ses recherches. Suis les consignes écrites.
* Une fenêtre avec le rapport s'ouvre alors. Copie/colle son contenu. (Il se trouve aussi ici : c:\resultat.txt)
* Double-clique sur ce fichier, Fais CTRL+A puis CTRL+C.
* Dans ta prochaine réponse, colle le rapport en faisant CTRL+V.
FillPCA
1/ * Télécharge SREng (de Smallfrogs) : http://www.kztechs.com/eng/download.html
* Dézippe tout son contenu sur ton bureau (clic droit >Extraire ici).
* Ouvre le dossier SReng2 et double-clique sur SREng.exe.
* Clique sur "smart scan".
* Clique sur le bouton "scan".
* Quand l'analyse est terminée, clique sur le bouton "save reports".
* Sauvegarde alors le rapport sur ton bureau.
* Copie/colle le contenu du rapport SREnglLOG.log dans ta prochaine réponse.
2/ * Télécharge DiagHelp.zip sur ton bureau(Merci Malekal) : http://www.malekal.com/download/DiagHelp.zip
Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
* Ne double-clique pas dessus !! Fais un clic droit sur le fichier et extraire tout.
* Un nouveau dossier chercher va être créé.
* Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
* Une fenêtre va s'ouvrir, choisis l'option 1
* L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.
* Pendant l'analyse après le rapport CATCHME sur l'écran rouge, tu dois appuyer sue entrée pour que l'outil continue ses recherches. Suis les consignes écrites.
* Une fenêtre avec le rapport s'ouvre alors. Copie/colle son contenu. (Il se trouve aussi ici : c:\resultat.txt)
* Double-clique sur ce fichier, Fais CTRL+A puis CTRL+C.
* Dans ta prochaine réponse, colle le rapport en faisant CTRL+V.
FillPCA
Voila, rapport SREng :
[CODE]
2007-09-05,19:46:09
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<avpa><C:\WINDOWS\system32\avpo.exe> []
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<SpybotSD TeaTimer><C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe> [(Verified)Safer Networking Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /installquiet /nodetect> []
<High Definition Audio Property Page Shortcut><CHDAudPropShortcut.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."]
<HP Software Update><C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<hpWirelessAssistant><C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe> [Hewlett-Packard Development Company, L.P.]
<ccApp><"c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<QPService><"C:\Program Files\HP\QuickPlay\QPService.exe"> [CyberLink Corp.]
<eabconfg.cpl><C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start> [Hewlett-Packard ]
<Cpqset><C:\Program Files\HPQ\Default Settings\cpqset.exe> []
<RecGuard><C:\Windows\SMINST\RecGuard.exe> []
<Symantec PIF AlertEng><"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><6741f5de> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
==================================
Startup Folders
[BTTray]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk --> C:\PROGRA~1\WIDCOMM\LOGICI~1\BTTray.exe [Broadcom Corporation.]><N>
[Démarrage rapide de HP Photosmart Premier]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [Hewlett-Packard Development Company, L.P.]><N>
==================================
Services
[Gestion d'applications / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Service d'état ASP.NET / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Bluetooth Service / btwdins][Running/Auto Start]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe><Broadcom Corporation.>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Internet Security Password Validation / ccISPwdSvc][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[COM Host / comHost][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\comHost.exe"><Symantec Corporation>
[Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpqwmiex / hpqwmiex][Running/Auto Start]
<C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe><Hewlett-Packard Development Company, L.P.>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
<"C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[LiveUpdate / LiveUpdate][Stopped/Manual Start]
<"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"><Symantec Corporation>
[LiveUpdate Notice Service / LiveUpdate Notice Service][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"><Symantec Corporation>
[LPNFEGEKCG / LPNFEGEKCG][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\LPNFEGEKCG.exe><Sysinternals - www.sysinternals.com>
[Service Norton AntiVirus Auto-Protect / navapsvc][Running/Auto Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[Service Norton Protection Center / NSCService][Running/Auto Start]
<C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE><Symantec Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Planificateur LiveUpdate automatique / Planificateur LiveUpdate automatique][Running/Auto Start]
<"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"><Symantec Corporation>
[Symantec AVScan / SAVScan][Running/Manual Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe"><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec Core LC / Symantec Core LC][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe"><Symantec Corporation>
[TI / TI][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\TI.exe><Sysinternals - www.sysinternals.com>
==================================
Drivers
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AVG Anti-Rootkit / AVG Anti-Rootkit][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\avgarkt.sys><GRISOFT, s.r.o.>
[Avg Anti-Rootkit Clean Driver / AvgArCln][Running/System Start]
<System32\DRIVERS\AvgArCln.sys><GRISOFT, s.r.o.>
[Enumérateur de bus Bluetooth / BTKRNL][Running/Manual Start]
<system32\DRIVERS\btkrnl.sys><Broadcom Corporation.>
[WIDCOMM USB Bluetooth Driver / BTWUSB][Running/Manual Start]
<System32\Drivers\btwusb.sys><Broadcom Corporation.>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[eabfiltr / eabfiltr][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\EABFiltr.sys><Hewlett-Packard Development Company, L.P.>
[eabusb / eabusb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\eabusb.sys><Hewlett-Packard Development Company, L.P.>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Pilote de bus Microsoft UAA pour High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Intel AHCI Controller / iaStor][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\iaStor.sys><Intel Corporation>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSWEEP2 / MEMSWEEP2][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\B0.tmp><N/A>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NavEx15.Sys><Symantec Corporation>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Boot Tasks Driver / SAVRKBootTasks][Running/System Start]
<\??\C:\WINDOWS\system32\SAVRKBootTasks.sys><Sophos Plc>
[SAVRT / SAVRT][Running/Manual Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Pilote de périphérique SMC IrCC Miniport / SMCIRDA][Stopped/Manual Start]
<system32\DRIVERS\smcirda.sys><SMC>
[SPBBCDrv / SPBBCDrv][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SYMDNS / SYMDNS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20070828.001\symidsco.sys><Symantec Corporation>
[symlcbrd / symlcbrd][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\symlcbrd.sys><Symantec Corporation>
[SYMNDIS / SYMNDIS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tifm21 / tifm21][Running/Manual Start]
<system32\drivers\tifm21.sys><Texas Instruments>
[tmcomm / tmcomm][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\tmcomm.sys><Trend Micro Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel® Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[qaeynkipoilkjhgvd / qaeynkipoilkjhgvd][Stopped/System Start]
<2 - Le fichier spécifié est introuvable.
><N/A>
==================================
Browser Add-ons
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Java Plug-in 1.6.0_02]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[@btrez.dll,-4015]
{CCA281CA-C863-46ef-9331-5C8D4460577F} <, N/A>
[Spybot-S&D IE Protection]
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[Java Plug-in 1.6.0_02]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_06]
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll, Sun Microsystems, Inc.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[ActionListener Class]
{2DCCEF96-A260-41CD-91B4-2B30212B5B24} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Adobe Acrobat Control for ActiveX]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\ActiveX\pdf.ocx, Adobe Systems Incorporated>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[Envoyer à &Bluetooth]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm, N/A>
==================================
Running Processes
[PID: 824 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 912 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 956 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1216 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1384 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1408 / SERVICE LOCAL][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1632 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[PID: 1792 / Admin][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\PROGRA~1\SPYBOT~1\SDHelper.dll] [Safer Networking Limited, 1, 5, 0, 8]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 1868 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SPBBC\SPBBCEVT.DLL] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\SYSTEM32\SYMNETI.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASSPMEVT.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCLOGIN.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPXYEVT.DLL] [Symantec Corporation, 104.0.15.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCSETEVT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\NORTON~1\ISSVC.DLL] [Symantec Corporation, 9.1.1.7]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPEVT32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVEVENT.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[PID: 1956 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe] [Symantec Corporation, 104.0.15.2]
[C:\WINDOWS\system32\SYMREDIR.dll] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTML.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPJS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPVBS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFMisc.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFPriv.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFRes.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\SYMURL.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRES.DLL] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFSec.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyIM.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyNNTP.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccCharCv.dll] [Symantec Corporation, 104.0.15.2]
[PID: 1972 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\PollMgr.dll] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[PID: 2032 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\WINDOWS\system32\SymNeti.dll] [Symantec Corporation, 6.0.0.99]
[PID: 180 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\bbRGen.dll] [Symantec Corporation, 2,0,0,73]
[PID: 192 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe] [Symantec Corporation, 1.9.1.762]
[C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcnet.dll] [Symantec Corporation, 1.9.1.762]
[C:\WINDOWS\system32\MSVCR71.DLL] [Microsoft Corporation, 7.10.3052.4]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[PID: 672 / SYSTEM][C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe] [Broadcom Corporation., 4.0.1.2601]
[PID: 708 / SYSTEM][C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.56.1]
[C:\Program Files\Fichiers communs\LightScribe\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\LightScribe\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 748 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[PID: 764 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCJSBL.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\avFPXY.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\isFtMst.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\nscNISpi.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\isFtPxy.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\nisProd.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFtPxy.dll] [Symantec Corporation, 2006.1.0.107]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asNSCPlg.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\Options\asOpts.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[PID: 820 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8320]
[PID: 860 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1476 / SERVICE LOCAL][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1616 / SYSTEM][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 1, 2]
[PID: 3804 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccScan.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 51.3.0.11]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\ecmsvr32.dll] [Symantec Corporation, 71.3.0.25]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVEX32a.DLL] [Symantec Corporation, 20071.3.0.24]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG32.DLL] [Symantec Corporation, 20071.3.0.24]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccDec.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.15.3]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2BZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.15.3]
[PID: 3996 / SERVICE LOCAL][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592 / Admin][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8320]
[C:\WINDOWS\system32\NVRSFR.DLL] [NVIDIA Corporation, 6.14.10.8320]
[PID: 1780 / Admin][C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.20.6]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2112 / Admin][C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe] [Hewlett-Packard Co., 50.0.146.000]
[PID: 2156 / Admin][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[PID: 2164 / Admin][C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 3, 1]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2172 / Admin][C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\OPTIONS\SYMDYNLD.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\ALERTENG.DLL] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\ISLALERT.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\AlertRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NISTRAY.DLL] [Symantec Corporation, 9.1.1.7]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\NORTON~1\NISTrRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\CCIMSCAN.DLL] [Symantec Corporation, 104.0.5.3]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\PROGRA~1\NORTON~1\NORTON~1\DEFALERT.DLL] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPP32.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFilter.dll] [Symantec Corporation, 2006.2.00.153]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asUniPlg.dll] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MAPI32.dll] [Microsoft Corporation, 1.0.2536.0 (XPClient.010817-1148)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVAPW32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asSpmEvt.dll] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\ccFWSetg.dll] [Symantec Corporation, 104.0.13.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVOPTRF.DLL] [Symantec Corporation, 12.0.2.5]
[C:\PROGRA~1\NORTON~1\NORTON~1\STATUSHP.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\Navlcom.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVError.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\HPPEVT32.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\naverror.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\ccAVMail.dll] [Symantec Corporation, 104.0.5.3]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdnt.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdNT.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ccEmlflt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\ObrkAV.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVSTATS.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVEvent.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkIDS.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\SymFWAgt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\NISAlert.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Norton Internet Security\TLevel.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVOpts.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navopts.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSCR.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Symantec\LiveUpdate\ProductRegCom_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\NetDetectController_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\LuComServerPS_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\AlertUi.dll] [Symantec Corporation, 1.2.0.18]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.loc] [Symantec Corporation, 12.8.0.4]
[PID: 2196 / Admin][C:\Program Files\HP\QuickPlay\QPService.exe] [CyberLink Corp., 4.5.0.0000]
[C:\Program Files\HP\QuickPlay\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\helper.dll] [CyberLink Corp., 3.00.3301 ]
[C:\Program Files\HP\QuickPlay\Kernel\common\CLDataSync.dll] [, 1, 0, 0, 1]
[PID: 2216 / Admin][C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 2324 / Admin][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2392 / Admin][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.000.248.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[C:\Program Files\MSN Messenger\msgslang.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corp., 8.0.0812.00]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\MSN Messenger\lmcdata.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\contact.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\dfsr.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\abssm.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\usnsvcps.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 2460 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2568 / Admin][C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] [Safer Networking Limited, 1, 5, 0, 9]
[C:\Program Files\Spybot - Search & Destroy\advcheck.dll] [Safer Networking Limited, 1, 5, 3, 0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2768 / Admin][C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btwhidcs.DLL] [Broadcom Corporation., 4.0.1.2601]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\BtBalloon.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 3040 / Admin][C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btins.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\BtAudioHelper.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 3044 / Admin][C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_421b5006\mscorlib.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqiface\4.0.0.0__a53cf5803f4c3827\hpqiface.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f62fc019\system.windows.forms.dll] [N/A, ]
[c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_64210500\system.drawing.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9a4d49d7\system.dll] [N/A, ]
[c:\windows\assembly\gac\hpqcc2\3.0.0.0__a53cf5803f4c3827\hpqcc2.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqutils\4.0.0.0__a53cf5803f4c3827\hpqutils.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqfmrsc\4.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqtray\4.0.0.0__a53cf5803f4c3827\hpqtray.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqovskn\3.0.0.0__a53cf5803f4c3827\hpqovskn.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqimvlt\3.0.0.0__a53cf5803f4c3827\hpqimvlt.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqimgrc\4.0.0.0__a53cf5803f4c3827\hpqimgrc.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\program files\hp\digital imaging\bin\fr\hpqimzone.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqntrop\4.0.0.0__a53cf5803f4c3827\hpqntrop.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_db99c019\system.xml.dll] [N/A, ]
[c:\windows\assembly\gac\lead\13.0.0.113__9cf889f53ea9b907\lead.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.wrapper\13.0.0.113__9cf889f53ea9b907\lead.wrapper.dll] [LEAD Technologies, Inc., 13.0.0.113]
[C:\Program Files\HP\Digital Imaging\bin\ltkrn13n.dll] [LEAD Technologies, Inc., 13.0.0.098]
[c:\windows\assembly\gac\hpqtray.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqtray.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqfmrsc.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqfmrsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\lead.windows.forms\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.drawing\13.0.0.113__9cf889f53ea9b907\lead.drawing.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\interop.hpqimgr\4.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll] [ , 4.0.0.0]
[C:\Program Files\HP\Digital Imaging\Bin\hpqimgr.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqasset\4.0.0.0__a53cf5803f4c3827\hpqasset.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\hpqmirsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\fr\hpqmirsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqedit\3.0.0.0__a53cf5803f4c3827\hpqedit.dll] [Hewlett-Packard Development Company, L.P., 060.
[CODE]
2007-09-05,19:46:09
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<avpa><C:\WINDOWS\system32\avpo.exe> []
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<SpybotSD TeaTimer><C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe> [(Verified)Safer Networking Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /installquiet /nodetect> []
<High Definition Audio Property Page Shortcut><CHDAudPropShortcut.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."]
<HP Software Update><C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<hpWirelessAssistant><C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe> [Hewlett-Packard Development Company, L.P.]
<ccApp><"c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<QPService><"C:\Program Files\HP\QuickPlay\QPService.exe"> [CyberLink Corp.]
<eabconfg.cpl><C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start> [Hewlett-Packard ]
<Cpqset><C:\Program Files\HPQ\Default Settings\cpqset.exe> []
<RecGuard><C:\Windows\SMINST\RecGuard.exe> []
<Symantec PIF AlertEng><"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><6741f5de> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
==================================
Startup Folders
[BTTray]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk --> C:\PROGRA~1\WIDCOMM\LOGICI~1\BTTray.exe [Broadcom Corporation.]><N>
[Démarrage rapide de HP Photosmart Premier]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [Hewlett-Packard Development Company, L.P.]><N>
==================================
Services
[Gestion d'applications / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Service d'état ASP.NET / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Bluetooth Service / btwdins][Running/Auto Start]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe><Broadcom Corporation.>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Internet Security Password Validation / ccISPwdSvc][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[COM Host / comHost][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\comHost.exe"><Symantec Corporation>
[Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpqwmiex / hpqwmiex][Running/Auto Start]
<C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe><Hewlett-Packard Development Company, L.P.>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
<"C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[LiveUpdate / LiveUpdate][Stopped/Manual Start]
<"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"><Symantec Corporation>
[LiveUpdate Notice Service / LiveUpdate Notice Service][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"><Symantec Corporation>
[LPNFEGEKCG / LPNFEGEKCG][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\LPNFEGEKCG.exe><Sysinternals - www.sysinternals.com>
[Service Norton AntiVirus Auto-Protect / navapsvc][Running/Auto Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[Service Norton Protection Center / NSCService][Running/Auto Start]
<C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE><Symantec Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Planificateur LiveUpdate automatique / Planificateur LiveUpdate automatique][Running/Auto Start]
<"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"><Symantec Corporation>
[Symantec AVScan / SAVScan][Running/Manual Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe"><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec Core LC / Symantec Core LC][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe"><Symantec Corporation>
[TI / TI][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\TI.exe><Sysinternals - www.sysinternals.com>
==================================
Drivers
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AVG Anti-Rootkit / AVG Anti-Rootkit][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\avgarkt.sys><GRISOFT, s.r.o.>
[Avg Anti-Rootkit Clean Driver / AvgArCln][Running/System Start]
<System32\DRIVERS\AvgArCln.sys><GRISOFT, s.r.o.>
[Enumérateur de bus Bluetooth / BTKRNL][Running/Manual Start]
<system32\DRIVERS\btkrnl.sys><Broadcom Corporation.>
[WIDCOMM USB Bluetooth Driver / BTWUSB][Running/Manual Start]
<System32\Drivers\btwusb.sys><Broadcom Corporation.>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[eabfiltr / eabfiltr][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\EABFiltr.sys><Hewlett-Packard Development Company, L.P.>
[eabusb / eabusb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\eabusb.sys><Hewlett-Packard Development Company, L.P.>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Pilote de bus Microsoft UAA pour High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Intel AHCI Controller / iaStor][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\iaStor.sys><Intel Corporation>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSWEEP2 / MEMSWEEP2][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\B0.tmp><N/A>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NavEx15.Sys><Symantec Corporation>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Boot Tasks Driver / SAVRKBootTasks][Running/System Start]
<\??\C:\WINDOWS\system32\SAVRKBootTasks.sys><Sophos Plc>
[SAVRT / SAVRT][Running/Manual Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Pilote de périphérique SMC IrCC Miniport / SMCIRDA][Stopped/Manual Start]
<system32\DRIVERS\smcirda.sys><SMC>
[SPBBCDrv / SPBBCDrv][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SYMDNS / SYMDNS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20070828.001\symidsco.sys><Symantec Corporation>
[symlcbrd / symlcbrd][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\symlcbrd.sys><Symantec Corporation>
[SYMNDIS / SYMNDIS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tifm21 / tifm21][Running/Manual Start]
<system32\drivers\tifm21.sys><Texas Instruments>
[tmcomm / tmcomm][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\tmcomm.sys><Trend Micro Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel® Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[qaeynkipoilkjhgvd / qaeynkipoilkjhgvd][Stopped/System Start]
<2 - Le fichier spécifié est introuvable.
><N/A>
==================================
Browser Add-ons
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Java Plug-in 1.6.0_02]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[@btrez.dll,-4015]
{CCA281CA-C863-46ef-9331-5C8D4460577F} <, N/A>
[Spybot-S&D IE Protection]
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[Java Plug-in 1.6.0_02]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_06]
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll, Sun Microsystems, Inc.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[ActionListener Class]
{2DCCEF96-A260-41CD-91B4-2B30212B5B24} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Adobe Acrobat Control for ActiveX]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\ActiveX\pdf.ocx, Adobe Systems Incorporated>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[Envoyer à &Bluetooth]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm, N/A>
==================================
Running Processes
[PID: 824 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 912 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 956 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1216 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1384 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1408 / SERVICE LOCAL][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1632 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[PID: 1792 / Admin][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\PROGRA~1\SPYBOT~1\SDHelper.dll] [Safer Networking Limited, 1, 5, 0, 8]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 1868 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SPBBC\SPBBCEVT.DLL] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\SYSTEM32\SYMNETI.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASSPMEVT.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCLOGIN.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPXYEVT.DLL] [Symantec Corporation, 104.0.15.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCSETEVT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\NORTON~1\ISSVC.DLL] [Symantec Corporation, 9.1.1.7]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPEVT32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVEVENT.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[PID: 1956 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe] [Symantec Corporation, 104.0.15.2]
[C:\WINDOWS\system32\SYMREDIR.dll] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTML.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPJS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPVBS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFMisc.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFPriv.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFRes.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\SYMURL.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRES.DLL] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFSec.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyIM.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyNNTP.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccCharCv.dll] [Symantec Corporation, 104.0.15.2]
[PID: 1972 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\PollMgr.dll] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[PID: 2032 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\WINDOWS\system32\SymNeti.dll] [Symantec Corporation, 6.0.0.99]
[PID: 180 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\bbRGen.dll] [Symantec Corporation, 2,0,0,73]
[PID: 192 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe] [Symantec Corporation, 1.9.1.762]
[C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcnet.dll] [Symantec Corporation, 1.9.1.762]
[C:\WINDOWS\system32\MSVCR71.DLL] [Microsoft Corporation, 7.10.3052.4]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[PID: 672 / SYSTEM][C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe] [Broadcom Corporation., 4.0.1.2601]
[PID: 708 / SYSTEM][C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.56.1]
[C:\Program Files\Fichiers communs\LightScribe\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\LightScribe\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 748 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[PID: 764 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCJSBL.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\avFPXY.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\isFtMst.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\nscNISpi.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\isFtPxy.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\nisProd.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFtPxy.dll] [Symantec Corporation, 2006.1.0.107]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asNSCPlg.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\Options\asOpts.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[PID: 820 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8320]
[PID: 860 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1476 / SERVICE LOCAL][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1616 / SYSTEM][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 1, 2]
[PID: 3804 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccScan.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 51.3.0.11]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\ecmsvr32.dll] [Symantec Corporation, 71.3.0.25]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVEX32a.DLL] [Symantec Corporation, 20071.3.0.24]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG32.DLL] [Symantec Corporation, 20071.3.0.24]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccDec.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.15.3]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2BZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.15.3]
[PID: 3996 / SERVICE LOCAL][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592 / Admin][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8320]
[C:\WINDOWS\system32\NVRSFR.DLL] [NVIDIA Corporation, 6.14.10.8320]
[PID: 1780 / Admin][C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.20.6]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2112 / Admin][C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe] [Hewlett-Packard Co., 50.0.146.000]
[PID: 2156 / Admin][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[PID: 2164 / Admin][C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 3, 1]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2172 / Admin][C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\OPTIONS\SYMDYNLD.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\ALERTENG.DLL] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\ISLALERT.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\AlertRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NISTRAY.DLL] [Symantec Corporation, 9.1.1.7]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\NORTON~1\NISTrRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\CCIMSCAN.DLL] [Symantec Corporation, 104.0.5.3]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\PROGRA~1\NORTON~1\NORTON~1\DEFALERT.DLL] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPP32.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFilter.dll] [Symantec Corporation, 2006.2.00.153]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asUniPlg.dll] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MAPI32.dll] [Microsoft Corporation, 1.0.2536.0 (XPClient.010817-1148)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVAPW32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asSpmEvt.dll] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\ccFWSetg.dll] [Symantec Corporation, 104.0.13.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVOPTRF.DLL] [Symantec Corporation, 12.0.2.5]
[C:\PROGRA~1\NORTON~1\NORTON~1\STATUSHP.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\Navlcom.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVError.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\HPPEVT32.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\naverror.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\ccAVMail.dll] [Symantec Corporation, 104.0.5.3]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdnt.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdNT.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ccEmlflt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\ObrkAV.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVSTATS.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVEvent.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkIDS.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\SymFWAgt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\NISAlert.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Norton Internet Security\TLevel.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVOpts.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navopts.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSCR.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Symantec\LiveUpdate\ProductRegCom_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\NetDetectController_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\LuComServerPS_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\AlertUi.dll] [Symantec Corporation, 1.2.0.18]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.loc] [Symantec Corporation, 12.8.0.4]
[PID: 2196 / Admin][C:\Program Files\HP\QuickPlay\QPService.exe] [CyberLink Corp., 4.5.0.0000]
[C:\Program Files\HP\QuickPlay\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\helper.dll] [CyberLink Corp., 3.00.3301 ]
[C:\Program Files\HP\QuickPlay\Kernel\common\CLDataSync.dll] [, 1, 0, 0, 1]
[PID: 2216 / Admin][C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 2324 / Admin][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2392 / Admin][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.000.248.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[C:\Program Files\MSN Messenger\msgslang.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corp., 8.0.0812.00]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\MSN Messenger\lmcdata.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\contact.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\dfsr.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\abssm.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\usnsvcps.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 2460 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2568 / Admin][C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] [Safer Networking Limited, 1, 5, 0, 9]
[C:\Program Files\Spybot - Search & Destroy\advcheck.dll] [Safer Networking Limited, 1, 5, 3, 0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2768 / Admin][C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btwhidcs.DLL] [Broadcom Corporation., 4.0.1.2601]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\BtBalloon.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 3040 / Admin][C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btins.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\BtAudioHelper.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 3044 / Admin][C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_421b5006\mscorlib.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqiface\4.0.0.0__a53cf5803f4c3827\hpqiface.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f62fc019\system.windows.forms.dll] [N/A, ]
[c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_64210500\system.drawing.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9a4d49d7\system.dll] [N/A, ]
[c:\windows\assembly\gac\hpqcc2\3.0.0.0__a53cf5803f4c3827\hpqcc2.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqutils\4.0.0.0__a53cf5803f4c3827\hpqutils.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqfmrsc\4.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqtray\4.0.0.0__a53cf5803f4c3827\hpqtray.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqovskn\3.0.0.0__a53cf5803f4c3827\hpqovskn.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqimvlt\3.0.0.0__a53cf5803f4c3827\hpqimvlt.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqimgrc\4.0.0.0__a53cf5803f4c3827\hpqimgrc.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\program files\hp\digital imaging\bin\fr\hpqimzone.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqntrop\4.0.0.0__a53cf5803f4c3827\hpqntrop.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_db99c019\system.xml.dll] [N/A, ]
[c:\windows\assembly\gac\lead\13.0.0.113__9cf889f53ea9b907\lead.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.wrapper\13.0.0.113__9cf889f53ea9b907\lead.wrapper.dll] [LEAD Technologies, Inc., 13.0.0.113]
[C:\Program Files\HP\Digital Imaging\bin\ltkrn13n.dll] [LEAD Technologies, Inc., 13.0.0.098]
[c:\windows\assembly\gac\hpqtray.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqtray.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqfmrsc.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqfmrsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\lead.windows.forms\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.drawing\13.0.0.113__9cf889f53ea9b907\lead.drawing.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\interop.hpqimgr\4.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll] [ , 4.0.0.0]
[C:\Program Files\HP\Digital Imaging\Bin\hpqimgr.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqasset\4.0.0.0__a53cf5803f4c3827\hpqasset.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\hpqmirsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\fr\hpqmirsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqedit\3.0.0.0__a53cf5803f4c3827\hpqedit.dll] [Hewlett-Packard Development Company, L.P., 060.
En effet, il y a du avoir mauvaise manip de ma part O_o désolé
Je repost donc ... rapport SREnlog :
[CODE]
2007-09-05,19:46:09
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<avpa><C:\WINDOWS\system32\avpo.exe> []
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<SpybotSD TeaTimer><C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe> [(Verified)Safer Networking Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /installquiet /nodetect> []
<High Definition Audio Property Page Shortcut><CHDAudPropShortcut.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."]
<HP Software Update><C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<hpWirelessAssistant><C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe> [Hewlett-Packard Development Company, L.P.]
<ccApp><"c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<QPService><"C:\Program Files\HP\QuickPlay\QPService.exe"> [CyberLink Corp.]
<eabconfg.cpl><C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start> [Hewlett-Packard ]
<Cpqset><C:\Program Files\HPQ\Default Settings\cpqset.exe> []
<RecGuard><C:\Windows\SMINST\RecGuard.exe> []
<Symantec PIF AlertEng><"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><6741f5de> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
==================================
Startup Folders
[BTTray]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk --> C:\PROGRA~1\WIDCOMM\LOGICI~1\BTTray.exe [Broadcom Corporation.]><N>
[Démarrage rapide de HP Photosmart Premier]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [Hewlett-Packard Development Company, L.P.]><N>
==================================
Services
[Gestion d'applications / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Service d'état ASP.NET / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Bluetooth Service / btwdins][Running/Auto Start]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe><Broadcom Corporation.>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Internet Security Password Validation / ccISPwdSvc][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[COM Host / comHost][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\comHost.exe"><Symantec Corporation>
[Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpqwmiex / hpqwmiex][Running/Auto Start]
<C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe><Hewlett-Packard Development Company, L.P.>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
<"C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[LiveUpdate / LiveUpdate][Stopped/Manual Start]
<"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"><Symantec Corporation>
[LiveUpdate Notice Service / LiveUpdate Notice Service][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"><Symantec Corporation>
[LPNFEGEKCG / LPNFEGEKCG][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\LPNFEGEKCG.exe><Sysinternals - www.sysinternals.com>
[Service Norton AntiVirus Auto-Protect / navapsvc][Running/Auto Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[Service Norton Protection Center / NSCService][Running/Auto Start]
<C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE><Symantec Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Planificateur LiveUpdate automatique / Planificateur LiveUpdate automatique][Running/Auto Start]
<"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"><Symantec Corporation>
[Symantec AVScan / SAVScan][Running/Manual Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe"><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec Core LC / Symantec Core LC][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe"><Symantec Corporation>
[TI / TI][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\TI.exe><Sysinternals - www.sysinternals.com>
==================================
Drivers
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AVG Anti-Rootkit / AVG Anti-Rootkit][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\avgarkt.sys><GRISOFT, s.r.o.>
[Avg Anti-Rootkit Clean Driver / AvgArCln][Running/System Start]
<System32\DRIVERS\AvgArCln.sys><GRISOFT, s.r.o.>
[Enumérateur de bus Bluetooth / BTKRNL][Running/Manual Start]
<system32\DRIVERS\btkrnl.sys><Broadcom Corporation.>
[WIDCOMM USB Bluetooth Driver / BTWUSB][Running/Manual Start]
<System32\Drivers\btwusb.sys><Broadcom Corporation.>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[eabfiltr / eabfiltr][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\EABFiltr.sys><Hewlett-Packard Development Company, L.P.>
[eabusb / eabusb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\eabusb.sys><Hewlett-Packard Development Company, L.P.>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Pilote de bus Microsoft UAA pour High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Intel AHCI Controller / iaStor][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\iaStor.sys><Intel Corporation>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSWEEP2 / MEMSWEEP2][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\B0.tmp><N/A>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NavEx15.Sys><Symantec Corporation>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Boot Tasks Driver / SAVRKBootTasks][Running/System Start]
<\??\C:\WINDOWS\system32\SAVRKBootTasks.sys><Sophos Plc>
[SAVRT / SAVRT][Running/Manual Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Pilote de périphérique SMC IrCC Miniport / SMCIRDA][Stopped/Manual Start]
<system32\DRIVERS\smcirda.sys><SMC>
[SPBBCDrv / SPBBCDrv][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SYMDNS / SYMDNS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20070828.001\symidsco.sys><Symantec Corporation>
[symlcbrd / symlcbrd][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\symlcbrd.sys><Symantec Corporation>
[SYMNDIS / SYMNDIS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tifm21 / tifm21][Running/Manual Start]
<system32\drivers\tifm21.sys><Texas Instruments>
[tmcomm / tmcomm][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\tmcomm.sys><Trend Micro Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel® Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[qaeynkipoilkjhgvd / qaeynkipoilkjhgvd][Stopped/System Start]
<2 - Le fichier spécifié est introuvable.
><N/A>
==================================
Browser Add-ons
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Java Plug-in 1.6.0_02]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[@btrez.dll,-4015]
{CCA281CA-C863-46ef-9331-5C8D4460577F} <, N/A>
[Spybot-S&D IE Protection]
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[Java Plug-in 1.6.0_02]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_06]
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll, Sun Microsystems, Inc.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[ActionListener Class]
{2DCCEF96-A260-41CD-91B4-2B30212B5B24} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Adobe Acrobat Control for ActiveX]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\ActiveX\pdf.ocx, Adobe Systems Incorporated>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[Envoyer à &Bluetooth]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm, N/A>
==================================
Running Processes
[PID: 824 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 912 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 956 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1216 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1384 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1408 / SERVICE LOCAL][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1632 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[PID: 1792 / Admin][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\PROGRA~1\SPYBOT~1\SDHelper.dll] [Safer Networking Limited, 1, 5, 0, 8]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 1868 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SPBBC\SPBBCEVT.DLL] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\SYSTEM32\SYMNETI.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASSPMEVT.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCLOGIN.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPXYEVT.DLL] [Symantec Corporation, 104.0.15.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCSETEVT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\NORTON~1\ISSVC.DLL] [Symantec Corporation, 9.1.1.7]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPEVT32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVEVENT.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[PID: 1956 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe] [Symantec Corporation, 104.0.15.2]
[C:\WINDOWS\system32\SYMREDIR.dll] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTML.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPJS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPVBS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFMisc.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFPriv.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFRes.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\SYMURL.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRES.DLL] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFSec.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyIM.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyNNTP.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccCharCv.dll] [Symantec Corporation, 104.0.15.2]
[PID: 1972 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\PollMgr.dll] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[PID: 2032 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\WINDOWS\system32\SymNeti.dll] [Symantec Corporation, 6.0.0.99]
[PID: 180 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\bbRGen.dll] [Symantec Corporation, 2,0,0,73]
[PID: 192 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe] [Symantec Corporation, 1.9.1.762]
[C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcnet.dll] [Symantec Corporation, 1.9.1.762]
[C:\WINDOWS\system32\MSVCR71.DLL] [Microsoft Corporation, 7.10.3052.4]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[PID: 672 / SYSTEM][C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe] [Broadcom Corporation., 4.0.1.2601]
[PID: 708 / SYSTEM][C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.56.1]
[C:\Program Files\Fichiers communs\LightScribe\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\LightScribe\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 748 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[PID: 764 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCJSBL.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\avFPXY.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\isFtMst.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\nscNISpi.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\isFtPxy.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\nisProd.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFtPxy.dll] [Symantec Corporation, 2006.1.0.107]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asNSCPlg.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\Options\asOpts.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[PID: 820 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8320]
[PID: 860 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1476 / SERVICE LOCAL][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1616 / SYSTEM][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 1, 2]
[PID: 3804 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccScan.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 51.3.0.11]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\ecmsvr32.dll] [Symantec Corporation, 71.3.0.25]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVEX32a.DLL] [Symantec Corporation, 20071.3.0.24]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG32.DLL] [Symantec Corporation, 20071.3.0.24]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccDec.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.15.3]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2BZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.15.3]
[PID: 3996 / SERVICE LOCAL][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592 / Admin][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8320]
[C:\WINDOWS\system32\NVRSFR.DLL] [NVIDIA Corporation, 6.14.10.8320]
[PID: 1780 / Admin][C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.20.6]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2112 / Admin][C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe] [Hewlett-Packard Co., 50.0.146.000]
[PID: 2156 / Admin][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[PID: 2164 / Admin][C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 3, 1]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2172 / Admin][C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\OPTIONS\SYMDYNLD.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\ALERTENG.DLL] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\ISLALERT.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\AlertRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NISTRAY.DLL] [Symantec Corporation, 9.1.1.7]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\NORTON~1\NISTrRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\CCIMSCAN.DLL] [Symantec Corporation, 104.0.5.3]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\PROGRA~1\NORTON~1\NORTON~1\DEFALERT.DLL] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPP32.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFilter.dll] [Symantec Corporation, 2006.2.00.153]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asUniPlg.dll] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MAPI32.dll] [Microsoft Corporation, 1.0.2536.0 (XPClient.010817-1148)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVAPW32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asSpmEvt.dll] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\ccFWSetg.dll] [Symantec Corporation, 104.0.13.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVOPTRF.DLL] [Symantec Corporation, 12.0.2.5]
[C:\PROGRA~1\NORTON~1\NORTON~1\STATUSHP.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\Navlcom.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVError.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\HPPEVT32.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\naverror.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\ccAVMail.dll] [Symantec Corporation, 104.0.5.3]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdnt.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdNT.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ccEmlflt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\ObrkAV.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVSTATS.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVEvent.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkIDS.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\SymFWAgt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\NISAlert.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Norton Internet Security\TLevel.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVOpts.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navopts.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSCR.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Symantec\LiveUpdate\ProductRegCom_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\NetDetectController_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\LuComServerPS_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\AlertUi.dll] [Symantec Corporation, 1.2.0.18]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.loc] [Symantec Corporation, 12.8.0.4]
[PID: 2196 / Admin][C:\Program Files\HP\QuickPlay\QPService.exe] [CyberLink Corp., 4.5.0.0000]
[C:\Program Files\HP\QuickPlay\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\helper.dll] [CyberLink Corp., 3.00.3301 ]
[C:\Program Files\HP\QuickPlay\Kernel\common\CLDataSync.dll] [, 1, 0, 0, 1]
[PID: 2216 / Admin][C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 2324 / Admin][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2392 / Admin][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.000.248.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[C:\Program Files\MSN Messenger\msgslang.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corp., 8.0.0812.00]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\MSN Messenger\lmcdata.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\contact.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\dfsr.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\abssm.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\usnsvcps.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 2460 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2568 / Admin][C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] [Safer Networking Limited, 1, 5, 0, 9]
[C:\Program Files\Spybot - Search & Destroy\advcheck.dll] [Safer Networking Limited, 1, 5, 3, 0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2768 / Admin][C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btwhidcs.DLL] [Broadcom Corporation., 4.0.1.2601]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\BtBalloon.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 3040 / Admin][C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btins.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\BtAudioHelper.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 3044 / Admin][C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_421b5006\mscorlib.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqiface\4.0.0.0__a53cf5803f4c3827\hpqiface.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f62fc019\system.windows.forms.dll] [N/A, ]
[c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_64210500\system.drawing.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9a4d49d7\system.dll] [N/A, ]
[c:\windows\assembly\gac\hpqcc2\3.0.0.0__a53cf5803f4c3827\hpqcc2.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqutils\4.0.0.0__a53cf5803f4c3827\hpqutils.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqfmrsc\4.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqtray\4.0.0.0__a53cf5803f4c3827\hpqtray.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqovskn\3.0.0.0__a53cf5803f4c3827\hpqovskn.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqimvlt\3.0.0.0__a53cf5803f4c3827\hpqimvlt.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqimgrc\4.0.0.0__a53cf5803f4c3827\hpqimgrc.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\program files\hp\digital imaging\bin\fr\hpqimzone.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqntrop\4.0.0.0__a53cf5803f4c3827\hpqntrop.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_db99c019\system.xml.dll] [N/A, ]
[c:\windows\assembly\gac\lead\13.0.0.113__9cf889f53ea9b907\lead.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.wrapper\13.0.0.113__9cf889f53ea9b907\lead.wrapper.dll] [LEAD Technologies, Inc., 13.0.0.113]
[C:\Program Files\HP\Digital Imaging\bin\ltkrn13n.dll] [LEAD Technologies, Inc., 13.0.0.098]
[c:\windows\assembly\gac\hpqtray.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqtray.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqfmrsc.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqfmrsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\lead.windows.forms\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.drawing\13.0.0.113__9cf889f53ea9b907\lead.drawing.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\interop.hpqimgr\4.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll] [ , 4.0.0.0]
[C:\Program Files\HP\Digital Imaging\Bin\hpqimgr.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqasset\4.0.0.0__a53cf5803f4c3827\hpqasset.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\hpqmirsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\fr\hpqmirsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac
Je repost donc ... rapport SREnlog :
[CODE]
2007-09-05,19:46:09
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<avpa><C:\WINDOWS\system32\avpo.exe> []
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<SpybotSD TeaTimer><C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe> [(Verified)Safer Networking Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /installquiet /nodetect> []
<High Definition Audio Property Page Shortcut><CHDAudPropShortcut.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."]
<HP Software Update><C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<hpWirelessAssistant><C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe> [Hewlett-Packard Development Company, L.P.]
<ccApp><"c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<QPService><"C:\Program Files\HP\QuickPlay\QPService.exe"> [CyberLink Corp.]
<eabconfg.cpl><C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start> [Hewlett-Packard ]
<Cpqset><C:\Program Files\HPQ\Default Settings\cpqset.exe> []
<RecGuard><C:\Windows\SMINST\RecGuard.exe> []
<Symantec PIF AlertEng><"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><6741f5de> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
==================================
Startup Folders
[BTTray]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk --> C:\PROGRA~1\WIDCOMM\LOGICI~1\BTTray.exe [Broadcom Corporation.]><N>
[Démarrage rapide de HP Photosmart Premier]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [Hewlett-Packard Development Company, L.P.]><N>
==================================
Services
[Gestion d'applications / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Service d'état ASP.NET / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Bluetooth Service / btwdins][Running/Auto Start]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe><Broadcom Corporation.>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Internet Security Password Validation / ccISPwdSvc][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[COM Host / comHost][Stopped/Manual Start]
<"c:\Program Files\Norton Internet Security\comHost.exe"><Symantec Corporation>
[Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpqwmiex / hpqwmiex][Running/Auto Start]
<C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe><Hewlett-Packard Development Company, L.P.>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
<"C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[LiveUpdate / LiveUpdate][Stopped/Manual Start]
<"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"><Symantec Corporation>
[LiveUpdate Notice Service / LiveUpdate Notice Service][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"><Symantec Corporation>
[LPNFEGEKCG / LPNFEGEKCG][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\LPNFEGEKCG.exe><Sysinternals - www.sysinternals.com>
[Service Norton AntiVirus Auto-Protect / navapsvc][Running/Auto Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[Service Norton Protection Center / NSCService][Running/Auto Start]
<C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE><Symantec Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Planificateur LiveUpdate automatique / Planificateur LiveUpdate automatique][Running/Auto Start]
<"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"><Symantec Corporation>
[Symantec AVScan / SAVScan][Running/Manual Start]
<"c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe"><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Running/Auto Start]
<"c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec Core LC / Symantec Core LC][Running/Auto Start]
<"C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe"><Symantec Corporation>
[TI / TI][Stopped/Manual Start]
<C:\DOCUME~1\Admin\LOCALS~1\Temp\TI.exe><Sysinternals - www.sysinternals.com>
==================================
Drivers
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AVG Anti-Rootkit / AVG Anti-Rootkit][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\avgarkt.sys><GRISOFT, s.r.o.>
[Avg Anti-Rootkit Clean Driver / AvgArCln][Running/System Start]
<System32\DRIVERS\AvgArCln.sys><GRISOFT, s.r.o.>
[Enumérateur de bus Bluetooth / BTKRNL][Running/Manual Start]
<system32\DRIVERS\btkrnl.sys><Broadcom Corporation.>
[WIDCOMM USB Bluetooth Driver / BTWUSB][Running/Manual Start]
<System32\Drivers\btwusb.sys><Broadcom Corporation.>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[eabfiltr / eabfiltr][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\EABFiltr.sys><Hewlett-Packard Development Company, L.P.>
[eabusb / eabusb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\eabusb.sys><Hewlett-Packard Development Company, L.P.>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Pilote de bus Microsoft UAA pour High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Intel AHCI Controller / iaStor][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\iaStor.sys><Intel Corporation>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSWEEP2 / MEMSWEEP2][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\B0.tmp><N/A>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NavEx15.Sys><Symantec Corporation>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Boot Tasks Driver / SAVRKBootTasks][Running/System Start]
<\??\C:\WINDOWS\system32\SAVRKBootTasks.sys><Sophos Plc>
[SAVRT / SAVRT][Running/Manual Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Pilote de périphérique SMC IrCC Miniport / SMCIRDA][Stopped/Manual Start]
<system32\DRIVERS\smcirda.sys><SMC>
[SPBBCDrv / SPBBCDrv][Running/System Start]
<\??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SYMDNS / SYMDNS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO][Running/Manual Start]
<\??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20070828.001\symidsco.sys><Symantec Corporation>
[symlcbrd / symlcbrd][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\symlcbrd.sys><Symantec Corporation>
[SYMNDIS / SYMNDIS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tifm21 / tifm21][Running/Manual Start]
<system32\drivers\tifm21.sys><Texas Instruments>
[tmcomm / tmcomm][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\tmcomm.sys><Trend Micro Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel® Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[qaeynkipoilkjhgvd / qaeynkipoilkjhgvd][Stopped/System Start]
<2 - Le fichier spécifié est introuvable.
><N/A>
==================================
Browser Add-ons
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Java Plug-in 1.6.0_02]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[@btrez.dll,-4015]
{CCA281CA-C863-46ef-9331-5C8D4460577F} <, N/A>
[Spybot-S&D IE Protection]
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[Java Plug-in 1.6.0_02]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_06]
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_02]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll, Sun Microsystems, Inc.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SpywareBlock Class]
{0A87E45F-537A-40B4-B812-E2544C21A09F} <C:\Program Files\SpyCatcher\SCActiveBlock.dll, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[ActionListener Class]
{2DCCEF96-A260-41CD-91B4-2B30212B5B24} <C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll, Trend Micro Inc.>
[Spybot-S&D IE Protection]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINDOWS\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, Sun Microsystems, Inc.>
[CNavExtBho Class]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Norton AntiVirus]
{C4069E3A-68F1-403E-B40E-20066696354B} <c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Adobe Acrobat Control for ActiveX]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\ActiveX\pdf.ocx, Adobe Systems Incorporated>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[Envoyer à &Bluetooth]
<C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm, N/A>
==================================
Running Processes
[PID: 824 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 912 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 956 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1216 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1384 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1408 / SERVICE LOCAL][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 1632 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[PID: 1792 / Admin][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\PROGRA~1\SPYBOT~1\SDHelper.dll] [Safer Networking Limited, 1, 5, 0, 8]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 1868 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SPBBC\SPBBCEVT.DLL] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\SYSTEM32\SYMNETI.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASSPMEVT.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCLOGIN.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPXYEVT.DLL] [Symantec Corporation, 104.0.15.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCSETEVT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\NORTON~1\ISSVC.DLL] [Symantec Corporation, 9.1.1.7]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPEVT32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVEVENT.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[PID: 1956 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe] [Symantec Corporation, 104.0.15.2]
[C:\WINDOWS\system32\SYMREDIR.dll] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTML.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPJS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPVBS.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFMisc.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFPriv.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFRes.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\SYMURL.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRES.DLL] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PFSec.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DPHTTP.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyIM.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\PxyNNTP.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccCharCv.dll] [Symantec Corporation, 104.0.15.2]
[PID: 1972 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\PollMgr.dll] [Symantec Corporation, 1.2.0.18]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[PID: 2032 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe] [Symantec Corporation, 6.0.0.99]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\WINDOWS\system32\SymNeti.dll] [Symantec Corporation, 6.0.0.99]
[PID: 180 / SYSTEM][c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe] [Symantec Corporation, 2,0,0,73]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\bbRGen.dll] [Symantec Corporation, 2,0,0,73]
[PID: 192 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe] [Symantec Corporation, 1.9.1.762]
[C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcnet.dll] [Symantec Corporation, 1.9.1.762]
[C:\WINDOWS\system32\MSVCR71.DLL] [Microsoft Corporation, 7.10.3052.4]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[PID: 672 / SYSTEM][C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe] [Broadcom Corporation., 4.0.1.2601]
[PID: 708 / SYSTEM][C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.56.1]
[C:\Program Files\Fichiers communs\LightScribe\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\LightScribe\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 748 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[PID: 764 / SYSTEM][C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCJSBL.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\avFPXY.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\isFtMst.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\nscNISpi.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_WSCR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Norton Internet Security\isFtPxy.dll] [Symantec Corporation, 2006.1.4.4]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Norton Internet Security\nisProd.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFtPxy.dll] [Symantec Corporation, 2006.1.0.107]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asNSCPlg.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\Options\asOpts.dll] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[PID: 820 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8320]
[PID: 860 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1476 / SERVICE LOCAL][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1616 / SYSTEM][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 1, 2]
[PID: 3804 / SYSTEM][c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[c:\Program Files\Fichiers communs\Symantec Shared\ccScan.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 51.3.0.11]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.30.0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\ecmsvr32.dll] [Symantec Corporation, 71.3.0.25]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVEX32a.DLL] [Symantec Corporation, 20071.3.0.24]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG32.DLL] [Symantec Corporation, 20071.3.0.24]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccDec.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.15.3]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2BZIP.dll] [Symantec Corporation, 3.15.3]
[c:\Program Files\Fichiers communs\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.15.3]
[PID: 3996 / SERVICE LOCAL][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592 / Admin][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8320]
[C:\WINDOWS\system32\NVRSFR.DLL] [NVIDIA Corporation, 6.14.10.8320]
[PID: 1780 / Admin][C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.20.6]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2112 / Admin][C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe] [Hewlett-Packard Co., 50.0.146.000]
[PID: 2156 / Admin][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.2.4 10Nov05]
[PID: 2164 / Admin][C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 3, 1]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2172 / Admin][C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\OPTIONS\SYMDYNLD.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\ALERTENG.DLL] [Symantec Corporation, 1.2.0.18]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCTRAY.LOC] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\ISLALERT.DLL] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Fichiers communs\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 6.0.0.99]
[c:\Program Files\Fichiers communs\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.14.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\SECURI~1\NSCUICOR.LOC] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSC_Hlpr.dll] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\AlertRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NISTRAY.DLL] [Symantec Corporation, 9.1.1.7]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 6.0.0.99]
[C:\PROGRA~1\NORTON~1\NISTrRes.dll] [Symantec Corporation, 9.0.3.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\CCIMSCAN.DLL] [Symantec Corporation, 104.0.5.3]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\PROGRA~1\NORTON~1\NORTON~1\DEFALERT.DLL] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPP32.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asFilter.dll] [Symantec Corporation, 2006.2.00.153]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVPS.DLL] [Symantec Corporation, 2006.1.8.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccLogin.dll] [Symantec Corporation, 104.0.14.2]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asUniPlg.dll] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MAPI32.dll] [Microsoft Corporation, 1.0.2536.0 (XPClient.010817-1148)]
[C:\PROGRA~1\NORTON~1\NORTON~1\HPPRES32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVAPW32.DLL] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\AntiSpam\asSpmEvt.dll] [Symantec Corporation, 2006.2.00.153]
[C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.loc] [Symantec Corporation, 12.8.0.4]
[C:\PROGRA~1\NORTON~1\ccFWSetg.dll] [Symantec Corporation, 104.0.13.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\NAVOPTRF.DLL] [Symantec Corporation, 12.0.2.5]
[C:\PROGRA~1\NORTON~1\NORTON~1\STATUSHP.DLL] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\Navlcom.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVError.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\HPPEVT32.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCUIBL.DLL] [Symantec Corporation, 2006.1.8.2]
[C:\PROGRA~1\NORTON~1\NORTON~1\apwutil.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\naverror.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\ccAVMail.dll] [Symantec Corporation, 104.0.5.3]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdnt.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2,0,0,73]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\apwcmdNT.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ccEmlflt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Fichiers communs\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 104.0.15.2]
[c:\Program Files\Norton Internet Security\ObrkData.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\ObrkAV.dll] [Symantec Corporation, 9.1.1.7]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVSTATS.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVEvent.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\ObrkIDS.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\SymFWAgt.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\N32Exclu.dll] [Symantec Corporation, 12.8.0.4]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[c:\Program Files\Norton Internet Security\NISAlert.dll] [Symantec Corporation, 9.1.1.7]
[c:\Program Files\Norton Internet Security\NISRes.dll] [Symantec Corporation, 9.0.3.4]
[c:\Program Files\Norton Internet Security\TLevel.dll] [Symantec Corporation, 104.0.13.2]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVOpts.dll] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\navopts.loc] [Symantec Corporation, 12.8.0.4]
[c:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSCR.dll] [Symantec Corporation, 12.8.0.4]
[C:\Program Files\Symantec\LiveUpdate\ProductRegCom_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\NetDetectController_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\Program Files\Symantec\LiveUpdate\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec\LiveUpdate\LuComServerPS_3_0.DLL] [Symantec Corporation, 3.0.0.171]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\PIF\{B8E1D~1\AlertUi.dll] [Symantec Corporation, 1.2.0.18]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.dll] [Symantec Corporation, 12.8.0.4]
[c:\PROGRA~1\NORTON~1\NORTON~1\NAVTasks.loc] [Symantec Corporation, 12.8.0.4]
[PID: 2196 / Admin][C:\Program Files\HP\QuickPlay\QPService.exe] [CyberLink Corp., 4.5.0.0000]
[C:\Program Files\HP\QuickPlay\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HP\QuickPlay\helper.dll] [CyberLink Corp., 3.00.3301 ]
[C:\Program Files\HP\QuickPlay\Kernel\common\CLDataSync.dll] [, 1, 0, 0, 1]
[PID: 2216 / Admin][C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 2324 / Admin][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2392 / Admin][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.000.248.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[C:\Program Files\MSN Messenger\msgslang.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corp., 8.0.0812.00]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\MSN Messenger\lmcdata.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\contact.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\dfsr.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\abssm.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\Program Files\MSN Messenger\usnsvcps.dll] [Microsoft Corporation, 8.0.0812.00]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[PID: 2460 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2568 / Admin][C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] [Safer Networking Limited, 1, 5, 0, 9]
[C:\Program Files\Spybot - Search & Destroy\advcheck.dll] [Safer Networking Limited, 1, 5, 3, 0]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 2768 / Admin][C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btwhidcs.DLL] [Broadcom Corporation., 4.0.1.2601]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\BtBalloon.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll] [N/A, ]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] [Hewlett-Packard , 5, 20, 6, 2]
[C:\WINDOWS\system32\avpo0.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
[PID: 3040 / Admin][C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btins.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\BtAudioHelper.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\btrez.dll] [Broadcom Corporation., 4.0.1.2601]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 3044 / Admin][C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_421b5006\mscorlib.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407]
[C:\PROGRA~1\FICHIE~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] [Symantec Corporation, 2006.2.00.153]
[c:\Program Files\Fichiers communs\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.14.2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqiface\4.0.0.0__a53cf5803f4c3827\hpqiface.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f62fc019\system.windows.forms.dll] [N/A, ]
[c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_64210500\system.drawing.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2407]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9a4d49d7\system.dll] [N/A, ]
[c:\windows\assembly\gac\hpqcc2\3.0.0.0__a53cf5803f4c3827\hpqcc2.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqutils\4.0.0.0__a53cf5803f4c3827\hpqutils.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqfmrsc\4.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqtray\4.0.0.0__a53cf5803f4c3827\hpqtray.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqovskn\3.0.0.0__a53cf5803f4c3827\hpqovskn.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\windows\assembly\gac\hpqimvlt\3.0.0.0__a53cf5803f4c3827\hpqimvlt.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\hpqimgrc\4.0.0.0__a53cf5803f4c3827\hpqimgrc.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\program files\hp\digital imaging\bin\fr\hpqimzone.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqntrop\4.0.0.0__a53cf5803f4c3827\hpqntrop.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] [Hewlett-Packard Development Company, L.P., 60.0.155.000]
[c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_db99c019\system.xml.dll] [N/A, ]
[c:\windows\assembly\gac\lead\13.0.0.113__9cf889f53ea9b907\lead.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.wrapper\13.0.0.113__9cf889f53ea9b907\lead.wrapper.dll] [LEAD Technologies, Inc., 13.0.0.113]
[C:\Program Files\HP\Digital Imaging\bin\ltkrn13n.dll] [LEAD Technologies, Inc., 13.0.0.098]
[c:\windows\assembly\gac\hpqtray.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqtray.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\hpqfmrsc.resources\4.0.0.0_fr_a53cf5803f4c3827\hpqfmrsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac\lead.windows.forms\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\lead.drawing\13.0.0.113__9cf889f53ea9b907\lead.drawing.dll] [LEAD Technologies, Inc., 13.0.0.113]
[c:\windows\assembly\gac\interop.hpqimgr\4.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll] [ , 4.0.0.0]
[C:\Program Files\HP\Digital Imaging\Bin\hpqimgr.dll] [Hewlett-Packard Development Company, L.P., 060.000.087.000]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71FRA.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\windows\assembly\gac\hpqasset\4.0.0.0__a53cf5803f4c3827\hpqasset.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\hpqmirsc.dll] [Hewlett-Packard Development Company, L.P., 060.000.155.000]
[c:\program files\hp\digital imaging\bin\fr\hpqmirsc.resources.dll] [ , 60.0.83.0]
[c:\windows\assembly\gac
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bon apparement mes posts sont trop long pour le forum :p
On va donc proceder a un rapport par post ^^
DiagHelp version v1.2 - http://www.malekal.com
excute le 05/09/2007 à 20:00:25,67
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->05/09/2007 20:00:22
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->05/09/2007 20:00:19
C:\WINDOWS\prefetch\WMIPRVSE.EXE-28F301A9.pf -->05/09/2007 20:00:08
C:\WINDOWS\prefetch\WUAUCLT.EXE-399A8E72.pf -->05/09/2007 20:00:06
C:\WINDOWS\prefetch\NTDE1ECT.COM-35094B9D.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\MSMSGS.EXE-2B6052DE.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\HPQTOA~1.EXE-39311BAA.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\EXPLORER.EXE-082F38A9.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\NTOSBOOT-B00DFAAD.pf -->05/09/2007 20:00:02
C:\WINDOWS\System32\drivers\SYMEVENT.INF -->02/09/2007 22:36:01
C:\WINDOWS\System32\drivers\SYMEVENT.CAT -->02/09/2007 22:36:01
C:\WINDOWS\System32\drivers\SYMEVENT.SYS -->02/09/2007 22:36:00
C:\WINDOWS\System32\drivers\103C_HP_NTBK_HP Pavilion dv8000 (EW920EA#ABF)_YN_0Pavi_QCND6122J30_E398803052_46_I30A6_SHP_V56.24_BF.09_T060313_WXH2_L40C_M1023_J80_7Intel_8T2300_91.66_#060227_N80861092_(EW920EA#ABF)_XMOBILE_CN10_Z_2F.09_G10DE01D8.MRK -->02/09/2007 21:53:25
C:\WINDOWS\System32\drivers\update.sys -->23/04/2007 12:32:54
C:\WINDOWS\System32\drivers\ntfs.sys -->09/02/2007 13:10:35
C:\WINDOWS\System32\drivers\avgarkt.sys -->31/01/2007 15:33:46
C:\WINDOWS\System32\avpo0.dll -->05/09/2007 19:59:14
C:\WINDOWS\System32\nvapps.xml -->05/09/2007 19:59:12
C:\WINDOWS\System32\PerfStringBackup.INI -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfh00C.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfh009.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfc00C.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfc009.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\Thumbs.db -->05/09/2007 17:01:06
C:\WINDOWS\System32\jupdate-1.6.0_02-b06.log -->03/09/2007 21:47:25
C:\WINDOWS\System32\wpa.dbl -->03/09/2007 21:44:35
C:\WINDOWS\System32\TZLog.log -->02/09/2007 23:51:34
C:\WINDOWS\System32\FNTCACHE.DAT -->02/09/2007 23:31:05
C:\WINDOWS\System32\S32EVNT1.DLL -->02/09/2007 22:36:00
C:\WINDOWS\System32\$winnt$.inf -->02/09/2007 21:52:06
C:\WINDOWS\System32\avpo.exe -->28/08/2007 20:50:12
C:\WINDOWS\System32\SAVRKBootTasks.sys -->14/08/2007 09:12:18
C:\WINDOWS\System32\MRT.exe -->02/08/2007 21:34:12
C:\WINDOWS\System32\wuaucpl.cpl.mui -->30/07/2007 19:20:06
C:\WINDOWS\System32\wuapi.dll.mui -->30/07/2007 19:19:52
C:\WINDOWS\System32\wuaueng.dll -->30/07/2007 19:19:42
C:\WINDOWS\System32\wuapi.dll -->30/07/2007 19:19:36
C:\WINDOWS\System32\wucltui.dll -->30/07/2007 19:19:32
C:\WINDOWS\System32\wuweb.dll -->30/07/2007 19:19:28
C:\WINDOWS\System32\wuaucpl.cpl -->30/07/2007 19:19:28
C:\WINDOWS\System32\cdm.dll -->30/07/2007 19:19:20
C:\WINDOWS\WindowsUpdate.log -->05/09/2007 19:59:54
C:\WINDOWS\0.log -->05/09/2007 19:59:09
C:\WINDOWS\bootstat.dat -->05/09/2007 19:59:01
C:\WINDOWS\SchedLgU.Txt -->05/09/2007 19:58:03
C:\WINDOWS\ntbtlog.txt -->05/09/2007 17:32:19
C:\WINDOWS\wiaservc.log -->04/09/2007 23:19:25
C:\WINDOWS\wiadebug.log -->04/09/2007 23:19:25
C:\WINDOWS\tsoc.log -->04/09/2007 19:27:50
C:\WINDOWS\setupapi.log -->04/09/2007 19:27:50
C:\WINDOWS\ocmsn.log -->04/09/2007 19:27:50
C:\WINDOWS\ocgen.log -->04/09/2007 19:27:50
C:\WINDOWS\ntdtcsetup.log -->04/09/2007 19:27:50
C:\WINDOWS\msgsocm.log -->04/09/2007 19:27:50
C:\WINDOWS\KB937143-IE7.log -->04/09/2007 19:27:50
C:\WINDOWS\imsins.log -->04/09/2007 19:27:50
MD5 des fichiers sensibles
tcpip.sys 1dbf125862891817f374f407626967f4
ndis.sys 558635d3af1c7546d26067d5d9b6959e
null.sys 73c1e1f395918bc2c6dd67af7591a3ad
svchost.exe 1bd6c2f707a275cb7c16fd99fe0f31ca
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\WINDOWS\system32
05/08/2004 10:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 62 534 307 840 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\WINDOWS\Downloaded Program Files
03/09/2007 14:22 <REP> .
03/09/2007 14:22 <REP> ..
17/08/2004 11:16 65 desktop.ini
25/07/2002 19:13 24 576 dwusplay.dll
25/07/2002 19:13 196 608 dwusplay.exe
14/10/2006 00:16 723 hcImpl.inf
23/05/2007 18:26 385 536 Housecall_ActiveX.dll
27/07/2004 17:48 323 584 isusweb.dll
02/11/2005 18:01 1 777 xscan.inf
02/11/2005 18:07 435 712 xscan53.ocx
8 fichier(s) 1 368 581 octets
Total des fichiers listés :
8 fichier(s) 1 368 581 octets
2 Rép(s) 62 534 307 840 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL France"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-05 20:00:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
152 - SPBBCSvc.exe
172 - symlcsvc.exe
436 - wuauclt.exe
548 - spoolsv.exe
652 - btwdins.exe
732 - NAVAPSVC.EXE
736 - NSCSRVCE.EXE
772 - nvsvc32.exe
836 - AluSchedulerSvc
868 - rundll32.exe
884 - csrss.exe
912 - winlogon.exe
956 - services.exe
972 - lsass.exe
1128 - svchost.exe
1196 - svchost.exe
1236 - svchost.exe
1360 - svchost.exe
1384 - svchost.exe
1408 - wdfmgr.exe
1536 - hpqwmiex.exe
1608 - CCSETMGR.EXE
1676 - hpwuSchd2.exe
1712 - notepad.exe
1748 - SynTPEnh.exe
1764 - HP Wireless Ass
1772 - explorer.exe
1848 - CCEVTMGR.EXE
1940 - CCPROXY.EXE
2024 - SNDSrvc.exe
2056 - CCAPP.EXE
2112 - QPService.exe
2124 - eabservr.exe
2172 - iexplore.exe
2340 - ctfmon.exe
2416 - msnmsgr.exe
2420 - wmiprvse.exe
2424 - TeaTimer.exe
2444 - LUCOMS~1.EXE
2552 - BTTray.exe
2736 - cmd.exe
2848 - BTStackServer.e
2852 - SAVScan.exe
3180 - hpqimzone.exe
3532 - msmsgs.exe
3652 - HPQTOA~1.EXE
4032 - alg.exe
Total number of processes = 48
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806E2000 - \WINDOWS\system32\hal.dll
F7B12000 - \WINDOWS\system32\KDCOM.DLL
F7A22000 - \WINDOWS\system32\BOOTVID.dll
F74E2000 - ACPI.sys
F7B14000 - \WINDOWS\system32\DRIVERS\WMILIB.SYS
F74D1000 - pci.sys
F7612000 - isapnp.sys
F7622000 - ohci1394.sys
F7632000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
F7B16000 - avgarkt.sys
F7A26000 - compbatt.sys
F7A2A000 - \WINDOWS\system32\DRIVERS\BATTC.SYS
F7BDA000 - pciide.sys
F7892000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F7B18000 - intelide.sys
F7B1A000 - viaide.sys
F7B1C000 - aliide.sys
F74B3000 - pcmcia.sys
F7642000 - MountMgr.sys
F7494000 - ftdisk.sys
F7A2E000 - ACPIEC.sys
F7BDB000 - \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F789A000 - PartMgr.sys
F7652000 - VolSnap.sys
F747C000 - atapi.sys
F73A6000 - iaStor.sys
F7662000 - disk.sys
F7672000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F7386000 - fltMgr.sys
F78A2000 - PxHelp20.sys
F736F000 - KSecDD.sys
F72E2000 - Ntfs.sys
F72B5000 - NDIS.sys
F72A4000 - serial.sys
F7289000 - Mup.sys
F7782000 - \SystemRoot\system32\DRIVERS\intelppm.sys
F724D000 - \SystemRoot\system32\DRIVERS\wmiacpi.sys
BA04F000 - \SystemRoot\system32\DRIVERS\nv4_mini.sys
BA03B000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
BA016000 - \SystemRoot\system32\DRIVERS\HDAudBus.sys
B9EB9000 - \SystemRoot\system32\DRIVERS\w39n51.sys
F791A000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
B9E96000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F7922000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F7792000 - \SystemRoot\system32\DRIVERS\nic1394.sys
B9E6E000 - \SystemRoot\system32\drivers\tifm21.sys
B9E5D000 - \SystemRoot\system32\DRIVERS\sdbus.sys
B9E36000 - \SystemRoot\system32\DRIVERS\e100b325.sys
BAFC8000 - \SystemRoot\system32\DRIVERS\CmBatt.sys
F77A2000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F792A000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
B9E07000 - \SystemRoot\system32\DRIVERS\SynTP.sys
F7B56000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F798A000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F7882000 - \SystemRoot\system32\DRIVERS\imapi.sys
F76F2000 - \SystemRoot\system32\DRIVERS\cdrom.sys
B941D000 - \SystemRoot\system32\DRIVERS\redbook.sys
B7E65000 - \SystemRoot\system32\DRIVERS\ks.sys
B4528000 - \SystemRoot\system32\DRIVERS\btkrnl.sys
F7D37000 - \SystemRoot\system32\DRIVERS\audstub.sys
B630E000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F7AEE000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
B2F86000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
B62FE000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
B62EE000 - \SystemRoot\system32\DRIVERS\raspptp.sys
B80B9000 - \SystemRoot\system32\DRIVERS\TDI.SYS
B2F75000 - \SystemRoot\system32\DRIVERS\psched.sys
B62DE000 - \SystemRoot\system32\DRIVERS\msgpc.sys
B80B1000 - \SystemRoot\system32\DRIVERS\ptilink.sys
B80A9000 - \SystemRoot\system32\DRIVERS\raspti.sys
B62BE000 - \SystemRoot\system32\DRIVERS\termdd.sys
F7BB2000 - \SystemRoot\system32\DRIVERS\swenum.sys
B2F1C000 - \SystemRoot\system32\DRIVERS\update.sys
F7B02000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
B1A9C000 - \SystemRoot\System32\Drivers\NDProxy.SYS
AEC51000 - \SystemRoot\system32\drivers\CHDAud.sys
AEC2D000 - \SystemRoot\system32\drivers\portcls.sys
B1A8C000 - \SystemRoot\system32\drivers\drmk.sys
AEBFB000 - \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
AEAFE000 - \SystemRoot\system32\DRIVERS\HSF_DPV.sys
AEA4E000 - \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
B1F8F000 - \SystemRoot\System32\Drivers\Modem.SYS
ABD2A000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F7B76000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
AB88A000 - \SystemRoot\System32\Drivers\Null.SYS
F7B78000 - \SystemRoot\System32\Drivers\Beep.SYS
AB889000 - \SystemRoot\System32\DRIVERS\AvgArCln.sys
B63A5000 - \SystemRoot\System32\drivers\vga.sys
F7B7A000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7B7C000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
B639D000 - \SystemRoot\System32\Drivers\Msfs.SYS
B6395000 - \SystemRoot\System32\Drivers\Npfs.SYS
AC039000 - \SystemRoot\system32\DRIVERS\rasacd.sys
AB168000 - \SystemRoot\system32\DRIVERS\ipsec.sys
AB110000 - \SystemRoot\system32\DRIVERS\tcpip.sys
AB0EF000 - \SystemRoot\system32\DRIVERS\ipnat.sys
AB0B4000 - \SystemRoot\System32\Drivers\SYMTDI.SYS
ABD0A000 - \SystemRoot\system32\DRIVERS\wanarp.sys
AB091000 - \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
ABCFA000 - \SystemRoot\system32\DRIVERS\arp1394.sys
ABCEA000 - \SystemRoot\System32\Drivers\SYMREDRV.SYS
B638D000 - \SystemRoot\System32\Drivers\SYMDNS.SYS
ABCDA000 - \SystemRoot\System32\Drivers\SYMNDIS.SYS
AB068000 - \SystemRoot\System32\Drivers\SYMFW.SYS
ABCCA000 - \SystemRoot\System32\Drivers\SYMIDS.SYS
AB037000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20070828.001\symidsco.sys
AB00F000 - \SystemRoot\system32\DRIVERS\netbt.sys
AAFED000 - \SystemRoot\System32\drivers\afd.sys
ABCBA000 - \SystemRoot\system32\DRIVERS\netbios.sys
B637D000 - \??\C:\WINDOWS\system32\SAVRKBootTasks.sys
AAF8B000 - \??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys
AAF77000 - \??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS
AAF4C000 - \SystemRoot\system32\DRIVERS\rdbss.sys
AAEDD000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
AB562000 - \SystemRoot\System32\Drivers\Fips.SYS
AAE7A000 - \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys
AAE5B000 - \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
F7B7E000 - \??\C:\WINDOWS\system32\drivers\EABFiltr.sys
AAE38000 - \SystemRoot\System32\Drivers\Fastfat.SYS
B583C000 - \SystemRoot\system32\DRIVERS\USBSTOR.SYS
AB22A000 - \SystemRoot\system32\DRIVERS\hidusb.sys
AB522000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
AB1D3000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
AB512000 - \SystemRoot\System32\Drivers\Cdfs.SYS
AB4F2000 - \SystemRoot\System32\Drivers\btwusb.sys
AB222000 - \SystemRoot\system32\DRIVERS\mouhid.sys
AAD62000 - \SystemRoot\System32\Drivers\dump_iaStor.sys
BF800000 - \SystemRoot\System32\win32k.sys
AB766000 - \SystemRoot\System32\drivers\Dxapi.sys
AB1AB000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F7CDD000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\nv4_disp.dll
B2C78000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
A7258000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
A71DE000 - \SystemRoot\system32\DRIVERS\srv.sys
A72D1000 - \SystemRoot\system32\DRIVERS\mdmxsdk.sys
A7101000 - \SystemRoot\system32\drivers\wdmaud.sys
B16AA000 - \SystemRoot\system32\drivers\sysaudio.sys
B80A1000 - \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
A6EE1000 - \??\C:\WINDOWS\system32\drivers\tmcomm.sys
A6C31000 - \??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS
A6B37000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NavEx15.Sys
A6B24000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG.Sys
A69F3000 - \SystemRoot\System32\Drivers\HTTP.sys
AB882000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 147
Liste des programmes installes
Adobe Flash Player ActiveX
Adobe Reader 6.0.1 - Français
Amélioration de nos services
Amélioration de nos services
AVG Anti-Rootkit Free
BufferChm
CC_ccProxyExt
ccCommon
ccPxyCore
Conexant HD Audio
Correctif pour Windows XP (KB896256)
Correctif pour Windows XP (KB914440)
Correctif Windows XP - KB873333
Correctif Windows XP - KB873339
Correctif Windows XP - KB883667
Correctif Windows XP - KB884575
Correctif Windows XP - KB885250
Correctif Windows XP - KB885464
Correctif Windows XP - KB885835
Correctif Windows XP - KB885836
Correctif Windows XP - KB885855
Correctif Windows XP - KB885884
Correctif Windows XP - KB886185
Correctif Windows XP - KB887472
Correctif Windows XP - KB888113
Correctif Windows XP - KB888239
Correctif Windows XP - KB888302
Correctif Windows XP - KB888402
Correctif Windows XP - KB889673
Correctif Windows XP - KB890859
Correctif Windows XP - KB891781
Correctif Windows XP - KB892559
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Destinations
DeviceManagementQFolder
FullDPAppQFolder
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
HP Help and Support
HP Imaging Device Functions 6.0
HP Integrated Module with Bluetooth wireless technology
HP Photosmart Premier Software 6.0
HP QuickPlay 2.0
HP Software Update
HP User Guides--System Recovery
HP User Guides 0011
HP Wireless Assistant 2.00 C1
HpSdpAppCoreApp
ImTOO MPEG Encoder
InstantShareDevices
Intel(R) PRO Network Connections Drivers
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 2
Lecteur Windows Media 10
LightScribe 1.4.56.1
LiveUpdate 3.0 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Works
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
Mise à jour de sécurité pour Windows XP (KB890046)
Mise à jour de sécurité pour Windows XP (KB893066)
Mise à jour de sécurité pour Windows XP (KB893756)
Mise à jour de sécurité pour Windows XP (KB896358)
Mise à jour de sécurité pour Windows XP (KB896422)
Mise à jour de sécurité pour Windows XP (KB896423)
Mise à jour de sécurité pour Windows XP (KB896428)
Mise à jour de sécurité pour Windows XP (KB899587)
Mise à jour de sécurité pour Windows XP (KB899591)
Mise à jour de sécurité pour Windows XP (KB900725)
Mise à jour de sécurité pour Windows XP (KB901017)
Mise à jour de sécurité pour Windows XP (KB901214)
Mise à jour de sécurité pour Windows XP (KB902400)
Mise à jour de sécurité pour Windows XP (KB903235)
Mise à jour de sécurité pour Windows XP (KB904706)
Mise à jour de sécurité pour Windows XP (KB905414)
Mise à jour de sécurité pour Windows XP (KB905749)
Mise à jour de sécurité pour Windows XP (KB908519)
Mise à jour de sécurité pour Windows XP (KB911562)
Mise à jour de sécurité pour Windows XP (KB911927)
Mise à jour de sécurité pour Windows XP (KB913580)
Mise à jour de sécurité pour Windows XP (KB914388)
Mise à jour de sécurité pour Windows XP (KB914389)
Mise à jour de sécurité pour Windows XP (KB917344)
Mise à jour de sécurité pour Windows XP (KB917953)
Mise à jour de sécurité pour Windows XP (KB918118)
Mise à jour de sécurité pour Windows XP (KB918439)
Mise à jour de sécurité pour Windows XP (KB919007)
Mise à jour de sécurité pour Windows XP (KB920213)
Mise à jour de sécurité pour Windows XP (KB920670)
Mise à jour de sécurité pour Windows XP (KB920683)
Mise à jour de sécurité pour Windows XP (KB920685)
Mise à jour de sécurité pour Windows XP (KB921503)
Mise à jour de sécurité pour Windows XP (KB922819)
Mise à jour de sécurité pour Windows XP (KB923191)
Mise à jour de sécurité pour Windows XP (KB923414)
Mise à jour de sécurité pour Windows XP (KB923689)
Mise à jour de sécurité pour Windows XP (KB923980)
Mise à jour de sécurité pour Windows XP (KB924270)
Mise à jour de sécurité pour Windows XP (KB924496)
Mise à jour de sécurité pour Windows XP (KB924667)
Mise à jour de sécurité pour Windows XP (KB925902)
Mise à jour de sécurité pour Windows XP (KB926255)
Mise à jour de sécurité pour Windows XP (KB926436)
Mise à jour de sécurité pour Windows XP (KB927779)
Mise à jour de sécurité pour Windows XP (KB927802)
Mise à jour de sécurité pour Windows XP (KB928255)
Mise à jour de sécurité pour Windows XP (KB928843)
Mise à jour de sécurité pour Windows XP (KB929123)
Mise à jour de sécurité pour Windows XP (KB930178)
Mise à jour de sécurité pour Windows XP (KB931261)
Mise à jour de sécurité pour Windows XP (KB931784)
Mise à jour de sécurité pour Windows XP (KB932168)
Mise à jour de sécurité pour Windows XP (KB935839)
Mise à jour de sécurité pour Windows XP (KB935840)
Mise à jour de sécurité pour Windows XP (KB936021)
Mise à jour de sécurité pour Windows XP (KB937143)
Mise à jour de sécurité pour Windows XP (KB938127)
Mise à jour de sécurité pour Windows XP (KB938829)
Mise à jour pour Windows XP (KB894391)
Mise à jour pour Windows XP (KB896727)
Mise à jour pour Windows XP (KB898461)
Mise à jour pour Windows XP (KB900485)
Mise à jour pour Windows XP (KB904942)
Mise à jour pour Windows XP (KB908531)
Mise à jour pour Windows XP (KB910437)
Mise à jour pour Windows XP (KB911280)
Mise à jour pour Windows XP (KB916595)
Mise à jour pour Windows XP (KB920872)
Mise à jour pour Windows XP (KB922582)
Mise à jour pour Windows XP (KB927891)
Mise à jour pour Windows XP (KB930916)
Mise à jour pour Windows XP (KB933360)
Mise à jour pour Windows XP (KB936357)
Mise à jour pour Windows XP (KB938828)
MSRedist
MSXML 4.0 SP2 (KB936181)
Norton AntiSpam
Norton AntiVirus 2006
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2006 (Symantec Corporation)
Norton Protection Center
Norton WMI Update
Norton WMI Update
NVIDIA Drivers
OptionalContentQFolder
PhotoGallery
Quick Launch Buttons 5.20 F2
RandMap
SkinsHP1
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
Sophos Anti-Rootkit 1.3.1
SPBBC
Spybot - Search & Destroy
SymNet
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
Unload
VideoLAN VLC media player 0.8.6a
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format Runtime
WinRAR archiver
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\Program Files
05/09/2007 18:44 <REP> .
05/09/2007 18:44 <REP> ..
03/09/2007 05:32 <REP> Adobe
27/02/2006 13:29 <REP> ComPlus Applications
03/09/2007 05:32 <REP> CONEXANT
04/09/2007 19:04 <REP> Fichiers communs
05/09/2007 19:58 <REP> Google
03/09/2007 17:44 <REP> GRISOFT
03/09/2007 05:33 <REP> Hewlett-Packard
03/09/2007 05:34 <REP> HP
02/09/2007 21:50 <REP> HPQ
05/09/2007 18:44 <REP> ImTOO
03/09/2007 05:34 <REP> Intel
04/09/2007 19:27 <REP> Internet Explorer
03/09/2007 21:47 <REP> Java
03/09/2007 05:35 <REP> Messenger
03/09/2007 05:35 <REP> microsoft frontpage
03/09/2007 05:35 <REP> Microsoft Office
03/09/2007 05:35 <REP> Microsoft Works
03/09/2007 05:35 <REP> Movie Maker
03/09/2007 05:35 <REP> MSN
03/09/2007 05:35 <REP> MSN Gaming Zone
03/09/2007 14:26 <REP> MSN Messenger
02/09/2007 23:23 <REP> MSXML 4.0
03/09/2007 05:35 <REP> NetMeeting
02/09/2007 22:12 <REP> Norton Internet Security
03/09/2007 05:35 <REP> Online Services
02/09/2007 23:54 <REP> Outlook Express
05/09/2007 18:44 <REP> QuickTime
03/09/2007 05:36 <REP> Services en ligne
03/09/2007 05:36 <REP> Sonic
02/09/2007 23:11 <REP> Sophos
05/09/2007 16:54 <REP> Spybot - Search & Destroy
02/09/2007 22:36 <REP> Symantec
03/09/2007 05:37 <REP> Synaptics
03/09/2007 21:45 <REP> VideoLAN
02/09/2007 21:55 <REP> WIDCOMM
02/09/2007 23:55 <REP> Windows Media Player
03/09/2007 05:37 <REP> Windows NT
04/09/2007 18:10 <REP> WinRAR
03/09/2007 05:37 <REP> xerox
0 fichier(s) 0 octets
41 Rép(s) 62 534 090 752 octets libres
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\Program Files\fichiers communs
04/09/2007 19:04 <REP> .
04/09/2007 19:04 <REP> ..
04/09/2007 19:04 <REP> Adobe
03/09/2007 05:32 <REP> HP
03/09/2007 05:32 <REP> InstallShield
03/09/2007 05:32 <REP> Java
03/09/2007 05:32 <REP> LightScribe
02/09/2007 22:20 <REP> Microsoft Shared
03/09/2007 05:33 <REP> MSSoap
03/09/2007 05:33 <REP> ODBC
03/09/2007 05:33 <REP> Services
03/09/2007 05:33 <REP> Sonic Shared
03/09/2007 05:33 <REP> SpeechEngines
03/09/2007 05:33 <REP> SureThing Shared
05/09/2007 19:45 <REP> Symantec Shared
02/09/2007 23:54 <REP> System
03/09/2007 05:33 <REP> TiVo Shared
0 fichier(s) 0 octets
17 Rép(s) 62 534 090 752 octets libres
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
03/09/2007 05:32 <REP> .
03/09/2007 05:32 <REP> ..
18/05/2001 10:57 561 209 MSONSEXT.DLL
03/06/1999 07:09 122 937 MSOWS409.DLL
07/03/2001 02:00 127 033 MSOWS40c.DLL
3 fichier(s) 811 179 octets
2 Rép(s) 62 534 090 752 octets libres
Attention : C:\autorun.inf existe
[AutoRun]
open=ntde1ect.com
;shell\open=Open(&O)
shell\open\Command=ntde1ect.com
shell\open\Default=1
;shell\explore=Manager(&X)
shell\explore\Command=ntde1ect.com
c:\Documents and Settings\Admin\.housecall6.6\patch.exe
c:\Documents and Settings\Admin\.housecall6.6\tsc.exe
c:\Documents and Settings\Admin\Bureau\avg-anti-rootkit_avg_anti-rootkit_1.1.0.42_anglais_34515.exe
c:\Documents and Settings\Admin\Bureau\avgarkt-setup-1.1.0.42.exe
c:\Documents and Settings\Admin\Bureau\HijackThis.exe
c:\Documents and Settings\Admin\Bureau\sarsfx.exe
c:\Documents and Settings\Admin\Bureau\spybotsd15.exe
c:\Documents and Settings\Admin\Bureau\SREngPS.EXE
c:\Documents and Settings\Admin\Bureau\DiagHelp\catchme.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\diff.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\dumphive.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\find2.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\Fport.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\grep.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\KProcCheck.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\LFiles.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\md5sums.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\pslist.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\streams.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\swreg.exe
c:\Documents and Settings\Admin\Bureau\Helios\Helios\HELIOS.exe
c:\Documents and Settings\Admin\Bureau\RootkitRevealer\RootkitRevealer.exe
c:\Documents and Settings\Admin\Local Settings\Temp\FlashPlayerUpdate.exe
c:\Documents and Settings\Admin\Local Settings\Temp\Install_Messenger.exe
c:\Documents and Settings\Admin\Local Settings\Temp\LPNFEGEKCG.exe
c:\Documents and Settings\Admin\Local Settings\Temp\shfbqn.exe
c:\Documents and Settings\Admin\Local Settings\Temp\TI.exe
c:\Documents and Settings\Admin\Local Settings\Temp\vmfjxb.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
****** Fin du rapport DiagHelp
On va donc proceder a un rapport par post ^^
DiagHelp version v1.2 - http://www.malekal.com
excute le 05/09/2007 à 20:00:25,67
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->05/09/2007 20:00:22
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->05/09/2007 20:00:19
C:\WINDOWS\prefetch\WMIPRVSE.EXE-28F301A9.pf -->05/09/2007 20:00:08
C:\WINDOWS\prefetch\WUAUCLT.EXE-399A8E72.pf -->05/09/2007 20:00:06
C:\WINDOWS\prefetch\NTDE1ECT.COM-35094B9D.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\MSMSGS.EXE-2B6052DE.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\HPQTOA~1.EXE-39311BAA.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\EXPLORER.EXE-082F38A9.pf -->05/09/2007 20:00:03
C:\WINDOWS\prefetch\NTOSBOOT-B00DFAAD.pf -->05/09/2007 20:00:02
C:\WINDOWS\System32\drivers\SYMEVENT.INF -->02/09/2007 22:36:01
C:\WINDOWS\System32\drivers\SYMEVENT.CAT -->02/09/2007 22:36:01
C:\WINDOWS\System32\drivers\SYMEVENT.SYS -->02/09/2007 22:36:00
C:\WINDOWS\System32\drivers\103C_HP_NTBK_HP Pavilion dv8000 (EW920EA#ABF)_YN_0Pavi_QCND6122J30_E398803052_46_I30A6_SHP_V56.24_BF.09_T060313_WXH2_L40C_M1023_J80_7Intel_8T2300_91.66_#060227_N80861092_(EW920EA#ABF)_XMOBILE_CN10_Z_2F.09_G10DE01D8.MRK -->02/09/2007 21:53:25
C:\WINDOWS\System32\drivers\update.sys -->23/04/2007 12:32:54
C:\WINDOWS\System32\drivers\ntfs.sys -->09/02/2007 13:10:35
C:\WINDOWS\System32\drivers\avgarkt.sys -->31/01/2007 15:33:46
C:\WINDOWS\System32\avpo0.dll -->05/09/2007 19:59:14
C:\WINDOWS\System32\nvapps.xml -->05/09/2007 19:59:12
C:\WINDOWS\System32\PerfStringBackup.INI -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfh00C.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfh009.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfc00C.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\perfc009.dat -->05/09/2007 18:00:44
C:\WINDOWS\System32\Thumbs.db -->05/09/2007 17:01:06
C:\WINDOWS\System32\jupdate-1.6.0_02-b06.log -->03/09/2007 21:47:25
C:\WINDOWS\System32\wpa.dbl -->03/09/2007 21:44:35
C:\WINDOWS\System32\TZLog.log -->02/09/2007 23:51:34
C:\WINDOWS\System32\FNTCACHE.DAT -->02/09/2007 23:31:05
C:\WINDOWS\System32\S32EVNT1.DLL -->02/09/2007 22:36:00
C:\WINDOWS\System32\$winnt$.inf -->02/09/2007 21:52:06
C:\WINDOWS\System32\avpo.exe -->28/08/2007 20:50:12
C:\WINDOWS\System32\SAVRKBootTasks.sys -->14/08/2007 09:12:18
C:\WINDOWS\System32\MRT.exe -->02/08/2007 21:34:12
C:\WINDOWS\System32\wuaucpl.cpl.mui -->30/07/2007 19:20:06
C:\WINDOWS\System32\wuapi.dll.mui -->30/07/2007 19:19:52
C:\WINDOWS\System32\wuaueng.dll -->30/07/2007 19:19:42
C:\WINDOWS\System32\wuapi.dll -->30/07/2007 19:19:36
C:\WINDOWS\System32\wucltui.dll -->30/07/2007 19:19:32
C:\WINDOWS\System32\wuweb.dll -->30/07/2007 19:19:28
C:\WINDOWS\System32\wuaucpl.cpl -->30/07/2007 19:19:28
C:\WINDOWS\System32\cdm.dll -->30/07/2007 19:19:20
C:\WINDOWS\WindowsUpdate.log -->05/09/2007 19:59:54
C:\WINDOWS\0.log -->05/09/2007 19:59:09
C:\WINDOWS\bootstat.dat -->05/09/2007 19:59:01
C:\WINDOWS\SchedLgU.Txt -->05/09/2007 19:58:03
C:\WINDOWS\ntbtlog.txt -->05/09/2007 17:32:19
C:\WINDOWS\wiaservc.log -->04/09/2007 23:19:25
C:\WINDOWS\wiadebug.log -->04/09/2007 23:19:25
C:\WINDOWS\tsoc.log -->04/09/2007 19:27:50
C:\WINDOWS\setupapi.log -->04/09/2007 19:27:50
C:\WINDOWS\ocmsn.log -->04/09/2007 19:27:50
C:\WINDOWS\ocgen.log -->04/09/2007 19:27:50
C:\WINDOWS\ntdtcsetup.log -->04/09/2007 19:27:50
C:\WINDOWS\msgsocm.log -->04/09/2007 19:27:50
C:\WINDOWS\KB937143-IE7.log -->04/09/2007 19:27:50
C:\WINDOWS\imsins.log -->04/09/2007 19:27:50
MD5 des fichiers sensibles
tcpip.sys 1dbf125862891817f374f407626967f4
ndis.sys 558635d3af1c7546d26067d5d9b6959e
null.sys 73c1e1f395918bc2c6dd67af7591a3ad
svchost.exe 1bd6c2f707a275cb7c16fd99fe0f31ca
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\WINDOWS\system32
05/08/2004 10:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 62 534 307 840 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\WINDOWS\Downloaded Program Files
03/09/2007 14:22 <REP> .
03/09/2007 14:22 <REP> ..
17/08/2004 11:16 65 desktop.ini
25/07/2002 19:13 24 576 dwusplay.dll
25/07/2002 19:13 196 608 dwusplay.exe
14/10/2006 00:16 723 hcImpl.inf
23/05/2007 18:26 385 536 Housecall_ActiveX.dll
27/07/2004 17:48 323 584 isusweb.dll
02/11/2005 18:01 1 777 xscan.inf
02/11/2005 18:07 435 712 xscan53.ocx
8 fichier(s) 1 368 581 octets
Total des fichiers listés :
8 fichier(s) 1 368 581 octets
2 Rép(s) 62 534 307 840 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL France"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-05 20:00:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
152 - SPBBCSvc.exe
172 - symlcsvc.exe
436 - wuauclt.exe
548 - spoolsv.exe
652 - btwdins.exe
732 - NAVAPSVC.EXE
736 - NSCSRVCE.EXE
772 - nvsvc32.exe
836 - AluSchedulerSvc
868 - rundll32.exe
884 - csrss.exe
912 - winlogon.exe
956 - services.exe
972 - lsass.exe
1128 - svchost.exe
1196 - svchost.exe
1236 - svchost.exe
1360 - svchost.exe
1384 - svchost.exe
1408 - wdfmgr.exe
1536 - hpqwmiex.exe
1608 - CCSETMGR.EXE
1676 - hpwuSchd2.exe
1712 - notepad.exe
1748 - SynTPEnh.exe
1764 - HP Wireless Ass
1772 - explorer.exe
1848 - CCEVTMGR.EXE
1940 - CCPROXY.EXE
2024 - SNDSrvc.exe
2056 - CCAPP.EXE
2112 - QPService.exe
2124 - eabservr.exe
2172 - iexplore.exe
2340 - ctfmon.exe
2416 - msnmsgr.exe
2420 - wmiprvse.exe
2424 - TeaTimer.exe
2444 - LUCOMS~1.EXE
2552 - BTTray.exe
2736 - cmd.exe
2848 - BTStackServer.e
2852 - SAVScan.exe
3180 - hpqimzone.exe
3532 - msmsgs.exe
3652 - HPQTOA~1.EXE
4032 - alg.exe
Total number of processes = 48
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806E2000 - \WINDOWS\system32\hal.dll
F7B12000 - \WINDOWS\system32\KDCOM.DLL
F7A22000 - \WINDOWS\system32\BOOTVID.dll
F74E2000 - ACPI.sys
F7B14000 - \WINDOWS\system32\DRIVERS\WMILIB.SYS
F74D1000 - pci.sys
F7612000 - isapnp.sys
F7622000 - ohci1394.sys
F7632000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
F7B16000 - avgarkt.sys
F7A26000 - compbatt.sys
F7A2A000 - \WINDOWS\system32\DRIVERS\BATTC.SYS
F7BDA000 - pciide.sys
F7892000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F7B18000 - intelide.sys
F7B1A000 - viaide.sys
F7B1C000 - aliide.sys
F74B3000 - pcmcia.sys
F7642000 - MountMgr.sys
F7494000 - ftdisk.sys
F7A2E000 - ACPIEC.sys
F7BDB000 - \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F789A000 - PartMgr.sys
F7652000 - VolSnap.sys
F747C000 - atapi.sys
F73A6000 - iaStor.sys
F7662000 - disk.sys
F7672000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F7386000 - fltMgr.sys
F78A2000 - PxHelp20.sys
F736F000 - KSecDD.sys
F72E2000 - Ntfs.sys
F72B5000 - NDIS.sys
F72A4000 - serial.sys
F7289000 - Mup.sys
F7782000 - \SystemRoot\system32\DRIVERS\intelppm.sys
F724D000 - \SystemRoot\system32\DRIVERS\wmiacpi.sys
BA04F000 - \SystemRoot\system32\DRIVERS\nv4_mini.sys
BA03B000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
BA016000 - \SystemRoot\system32\DRIVERS\HDAudBus.sys
B9EB9000 - \SystemRoot\system32\DRIVERS\w39n51.sys
F791A000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
B9E96000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F7922000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F7792000 - \SystemRoot\system32\DRIVERS\nic1394.sys
B9E6E000 - \SystemRoot\system32\drivers\tifm21.sys
B9E5D000 - \SystemRoot\system32\DRIVERS\sdbus.sys
B9E36000 - \SystemRoot\system32\DRIVERS\e100b325.sys
BAFC8000 - \SystemRoot\system32\DRIVERS\CmBatt.sys
F77A2000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F792A000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
B9E07000 - \SystemRoot\system32\DRIVERS\SynTP.sys
F7B56000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F798A000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F7882000 - \SystemRoot\system32\DRIVERS\imapi.sys
F76F2000 - \SystemRoot\system32\DRIVERS\cdrom.sys
B941D000 - \SystemRoot\system32\DRIVERS\redbook.sys
B7E65000 - \SystemRoot\system32\DRIVERS\ks.sys
B4528000 - \SystemRoot\system32\DRIVERS\btkrnl.sys
F7D37000 - \SystemRoot\system32\DRIVERS\audstub.sys
B630E000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F7AEE000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
B2F86000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
B62FE000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
B62EE000 - \SystemRoot\system32\DRIVERS\raspptp.sys
B80B9000 - \SystemRoot\system32\DRIVERS\TDI.SYS
B2F75000 - \SystemRoot\system32\DRIVERS\psched.sys
B62DE000 - \SystemRoot\system32\DRIVERS\msgpc.sys
B80B1000 - \SystemRoot\system32\DRIVERS\ptilink.sys
B80A9000 - \SystemRoot\system32\DRIVERS\raspti.sys
B62BE000 - \SystemRoot\system32\DRIVERS\termdd.sys
F7BB2000 - \SystemRoot\system32\DRIVERS\swenum.sys
B2F1C000 - \SystemRoot\system32\DRIVERS\update.sys
F7B02000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
B1A9C000 - \SystemRoot\System32\Drivers\NDProxy.SYS
AEC51000 - \SystemRoot\system32\drivers\CHDAud.sys
AEC2D000 - \SystemRoot\system32\drivers\portcls.sys
B1A8C000 - \SystemRoot\system32\drivers\drmk.sys
AEBFB000 - \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
AEAFE000 - \SystemRoot\system32\DRIVERS\HSF_DPV.sys
AEA4E000 - \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
B1F8F000 - \SystemRoot\System32\Drivers\Modem.SYS
ABD2A000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F7B76000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
AB88A000 - \SystemRoot\System32\Drivers\Null.SYS
F7B78000 - \SystemRoot\System32\Drivers\Beep.SYS
AB889000 - \SystemRoot\System32\DRIVERS\AvgArCln.sys
B63A5000 - \SystemRoot\System32\drivers\vga.sys
F7B7A000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7B7C000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
B639D000 - \SystemRoot\System32\Drivers\Msfs.SYS
B6395000 - \SystemRoot\System32\Drivers\Npfs.SYS
AC039000 - \SystemRoot\system32\DRIVERS\rasacd.sys
AB168000 - \SystemRoot\system32\DRIVERS\ipsec.sys
AB110000 - \SystemRoot\system32\DRIVERS\tcpip.sys
AB0EF000 - \SystemRoot\system32\DRIVERS\ipnat.sys
AB0B4000 - \SystemRoot\System32\Drivers\SYMTDI.SYS
ABD0A000 - \SystemRoot\system32\DRIVERS\wanarp.sys
AB091000 - \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
ABCFA000 - \SystemRoot\system32\DRIVERS\arp1394.sys
ABCEA000 - \SystemRoot\System32\Drivers\SYMREDRV.SYS
B638D000 - \SystemRoot\System32\Drivers\SYMDNS.SYS
ABCDA000 - \SystemRoot\System32\Drivers\SYMNDIS.SYS
AB068000 - \SystemRoot\System32\Drivers\SYMFW.SYS
ABCCA000 - \SystemRoot\System32\Drivers\SYMIDS.SYS
AB037000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20070828.001\symidsco.sys
AB00F000 - \SystemRoot\system32\DRIVERS\netbt.sys
AAFED000 - \SystemRoot\System32\drivers\afd.sys
ABCBA000 - \SystemRoot\system32\DRIVERS\netbios.sys
B637D000 - \??\C:\WINDOWS\system32\SAVRKBootTasks.sys
AAF8B000 - \??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys
AAF77000 - \??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS
AAF4C000 - \SystemRoot\system32\DRIVERS\rdbss.sys
AAEDD000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
AB562000 - \SystemRoot\System32\Drivers\Fips.SYS
AAE7A000 - \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys
AAE5B000 - \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
F7B7E000 - \??\C:\WINDOWS\system32\drivers\EABFiltr.sys
AAE38000 - \SystemRoot\System32\Drivers\Fastfat.SYS
B583C000 - \SystemRoot\system32\DRIVERS\USBSTOR.SYS
AB22A000 - \SystemRoot\system32\DRIVERS\hidusb.sys
AB522000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
AB1D3000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
AB512000 - \SystemRoot\System32\Drivers\Cdfs.SYS
AB4F2000 - \SystemRoot\System32\Drivers\btwusb.sys
AB222000 - \SystemRoot\system32\DRIVERS\mouhid.sys
AAD62000 - \SystemRoot\System32\Drivers\dump_iaStor.sys
BF800000 - \SystemRoot\System32\win32k.sys
AB766000 - \SystemRoot\System32\drivers\Dxapi.sys
AB1AB000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F7CDD000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\nv4_disp.dll
B2C78000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
A7258000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
A71DE000 - \SystemRoot\system32\DRIVERS\srv.sys
A72D1000 - \SystemRoot\system32\DRIVERS\mdmxsdk.sys
A7101000 - \SystemRoot\system32\drivers\wdmaud.sys
B16AA000 - \SystemRoot\system32\drivers\sysaudio.sys
B80A1000 - \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
A6EE1000 - \??\C:\WINDOWS\system32\drivers\tmcomm.sys
A6C31000 - \??\c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS
A6B37000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NavEx15.Sys
A6B24000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20070902.006\NAVENG.Sys
A69F3000 - \SystemRoot\System32\Drivers\HTTP.sys
AB882000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 147
Liste des programmes installes
Adobe Flash Player ActiveX
Adobe Reader 6.0.1 - Français
Amélioration de nos services
Amélioration de nos services
AVG Anti-Rootkit Free
BufferChm
CC_ccProxyExt
ccCommon
ccPxyCore
Conexant HD Audio
Correctif pour Windows XP (KB896256)
Correctif pour Windows XP (KB914440)
Correctif Windows XP - KB873333
Correctif Windows XP - KB873339
Correctif Windows XP - KB883667
Correctif Windows XP - KB884575
Correctif Windows XP - KB885250
Correctif Windows XP - KB885464
Correctif Windows XP - KB885835
Correctif Windows XP - KB885836
Correctif Windows XP - KB885855
Correctif Windows XP - KB885884
Correctif Windows XP - KB886185
Correctif Windows XP - KB887472
Correctif Windows XP - KB888113
Correctif Windows XP - KB888239
Correctif Windows XP - KB888302
Correctif Windows XP - KB888402
Correctif Windows XP - KB889673
Correctif Windows XP - KB890859
Correctif Windows XP - KB891781
Correctif Windows XP - KB892559
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Destinations
DeviceManagementQFolder
FullDPAppQFolder
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
HP Help and Support
HP Imaging Device Functions 6.0
HP Integrated Module with Bluetooth wireless technology
HP Photosmart Premier Software 6.0
HP QuickPlay 2.0
HP Software Update
HP User Guides--System Recovery
HP User Guides 0011
HP Wireless Assistant 2.00 C1
HpSdpAppCoreApp
ImTOO MPEG Encoder
InstantShareDevices
Intel(R) PRO Network Connections Drivers
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 2
Lecteur Windows Media 10
LightScribe 1.4.56.1
LiveUpdate 3.0 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Works
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
Mise à jour de sécurité pour Windows XP (KB890046)
Mise à jour de sécurité pour Windows XP (KB893066)
Mise à jour de sécurité pour Windows XP (KB893756)
Mise à jour de sécurité pour Windows XP (KB896358)
Mise à jour de sécurité pour Windows XP (KB896422)
Mise à jour de sécurité pour Windows XP (KB896423)
Mise à jour de sécurité pour Windows XP (KB896428)
Mise à jour de sécurité pour Windows XP (KB899587)
Mise à jour de sécurité pour Windows XP (KB899591)
Mise à jour de sécurité pour Windows XP (KB900725)
Mise à jour de sécurité pour Windows XP (KB901017)
Mise à jour de sécurité pour Windows XP (KB901214)
Mise à jour de sécurité pour Windows XP (KB902400)
Mise à jour de sécurité pour Windows XP (KB903235)
Mise à jour de sécurité pour Windows XP (KB904706)
Mise à jour de sécurité pour Windows XP (KB905414)
Mise à jour de sécurité pour Windows XP (KB905749)
Mise à jour de sécurité pour Windows XP (KB908519)
Mise à jour de sécurité pour Windows XP (KB911562)
Mise à jour de sécurité pour Windows XP (KB911927)
Mise à jour de sécurité pour Windows XP (KB913580)
Mise à jour de sécurité pour Windows XP (KB914388)
Mise à jour de sécurité pour Windows XP (KB914389)
Mise à jour de sécurité pour Windows XP (KB917344)
Mise à jour de sécurité pour Windows XP (KB917953)
Mise à jour de sécurité pour Windows XP (KB918118)
Mise à jour de sécurité pour Windows XP (KB918439)
Mise à jour de sécurité pour Windows XP (KB919007)
Mise à jour de sécurité pour Windows XP (KB920213)
Mise à jour de sécurité pour Windows XP (KB920670)
Mise à jour de sécurité pour Windows XP (KB920683)
Mise à jour de sécurité pour Windows XP (KB920685)
Mise à jour de sécurité pour Windows XP (KB921503)
Mise à jour de sécurité pour Windows XP (KB922819)
Mise à jour de sécurité pour Windows XP (KB923191)
Mise à jour de sécurité pour Windows XP (KB923414)
Mise à jour de sécurité pour Windows XP (KB923689)
Mise à jour de sécurité pour Windows XP (KB923980)
Mise à jour de sécurité pour Windows XP (KB924270)
Mise à jour de sécurité pour Windows XP (KB924496)
Mise à jour de sécurité pour Windows XP (KB924667)
Mise à jour de sécurité pour Windows XP (KB925902)
Mise à jour de sécurité pour Windows XP (KB926255)
Mise à jour de sécurité pour Windows XP (KB926436)
Mise à jour de sécurité pour Windows XP (KB927779)
Mise à jour de sécurité pour Windows XP (KB927802)
Mise à jour de sécurité pour Windows XP (KB928255)
Mise à jour de sécurité pour Windows XP (KB928843)
Mise à jour de sécurité pour Windows XP (KB929123)
Mise à jour de sécurité pour Windows XP (KB930178)
Mise à jour de sécurité pour Windows XP (KB931261)
Mise à jour de sécurité pour Windows XP (KB931784)
Mise à jour de sécurité pour Windows XP (KB932168)
Mise à jour de sécurité pour Windows XP (KB935839)
Mise à jour de sécurité pour Windows XP (KB935840)
Mise à jour de sécurité pour Windows XP (KB936021)
Mise à jour de sécurité pour Windows XP (KB937143)
Mise à jour de sécurité pour Windows XP (KB938127)
Mise à jour de sécurité pour Windows XP (KB938829)
Mise à jour pour Windows XP (KB894391)
Mise à jour pour Windows XP (KB896727)
Mise à jour pour Windows XP (KB898461)
Mise à jour pour Windows XP (KB900485)
Mise à jour pour Windows XP (KB904942)
Mise à jour pour Windows XP (KB908531)
Mise à jour pour Windows XP (KB910437)
Mise à jour pour Windows XP (KB911280)
Mise à jour pour Windows XP (KB916595)
Mise à jour pour Windows XP (KB920872)
Mise à jour pour Windows XP (KB922582)
Mise à jour pour Windows XP (KB927891)
Mise à jour pour Windows XP (KB930916)
Mise à jour pour Windows XP (KB933360)
Mise à jour pour Windows XP (KB936357)
Mise à jour pour Windows XP (KB938828)
MSRedist
MSXML 4.0 SP2 (KB936181)
Norton AntiSpam
Norton AntiVirus 2006
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2006 (Symantec Corporation)
Norton Protection Center
Norton WMI Update
Norton WMI Update
NVIDIA Drivers
OptionalContentQFolder
PhotoGallery
Quick Launch Buttons 5.20 F2
RandMap
SkinsHP1
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
Sophos Anti-Rootkit 1.3.1
SPBBC
Spybot - Search & Destroy
SymNet
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
Unload
VideoLAN VLC media player 0.8.6a
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format Runtime
WinRAR archiver
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\Program Files
05/09/2007 18:44 <REP> .
05/09/2007 18:44 <REP> ..
03/09/2007 05:32 <REP> Adobe
27/02/2006 13:29 <REP> ComPlus Applications
03/09/2007 05:32 <REP> CONEXANT
04/09/2007 19:04 <REP> Fichiers communs
05/09/2007 19:58 <REP> Google
03/09/2007 17:44 <REP> GRISOFT
03/09/2007 05:33 <REP> Hewlett-Packard
03/09/2007 05:34 <REP> HP
02/09/2007 21:50 <REP> HPQ
05/09/2007 18:44 <REP> ImTOO
03/09/2007 05:34 <REP> Intel
04/09/2007 19:27 <REP> Internet Explorer
03/09/2007 21:47 <REP> Java
03/09/2007 05:35 <REP> Messenger
03/09/2007 05:35 <REP> microsoft frontpage
03/09/2007 05:35 <REP> Microsoft Office
03/09/2007 05:35 <REP> Microsoft Works
03/09/2007 05:35 <REP> Movie Maker
03/09/2007 05:35 <REP> MSN
03/09/2007 05:35 <REP> MSN Gaming Zone
03/09/2007 14:26 <REP> MSN Messenger
02/09/2007 23:23 <REP> MSXML 4.0
03/09/2007 05:35 <REP> NetMeeting
02/09/2007 22:12 <REP> Norton Internet Security
03/09/2007 05:35 <REP> Online Services
02/09/2007 23:54 <REP> Outlook Express
05/09/2007 18:44 <REP> QuickTime
03/09/2007 05:36 <REP> Services en ligne
03/09/2007 05:36 <REP> Sonic
02/09/2007 23:11 <REP> Sophos
05/09/2007 16:54 <REP> Spybot - Search & Destroy
02/09/2007 22:36 <REP> Symantec
03/09/2007 05:37 <REP> Synaptics
03/09/2007 21:45 <REP> VideoLAN
02/09/2007 21:55 <REP> WIDCOMM
02/09/2007 23:55 <REP> Windows Media Player
03/09/2007 05:37 <REP> Windows NT
04/09/2007 18:10 <REP> WinRAR
03/09/2007 05:37 <REP> xerox
0 fichier(s) 0 octets
41 Rép(s) 62 534 090 752 octets libres
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\Program Files\fichiers communs
04/09/2007 19:04 <REP> .
04/09/2007 19:04 <REP> ..
04/09/2007 19:04 <REP> Adobe
03/09/2007 05:32 <REP> HP
03/09/2007 05:32 <REP> InstallShield
03/09/2007 05:32 <REP> Java
03/09/2007 05:32 <REP> LightScribe
02/09/2007 22:20 <REP> Microsoft Shared
03/09/2007 05:33 <REP> MSSoap
03/09/2007 05:33 <REP> ODBC
03/09/2007 05:33 <REP> Services
03/09/2007 05:33 <REP> Sonic Shared
03/09/2007 05:33 <REP> SpeechEngines
03/09/2007 05:33 <REP> SureThing Shared
05/09/2007 19:45 <REP> Symantec Shared
02/09/2007 23:54 <REP> System
03/09/2007 05:33 <REP> TiVo Shared
0 fichier(s) 0 octets
17 Rép(s) 62 534 090 752 octets libres
Le volume dans le lecteur C s'appelle OS
Le numéro de série du volume est 70B6-4F1C
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
03/09/2007 05:32 <REP> .
03/09/2007 05:32 <REP> ..
18/05/2001 10:57 561 209 MSONSEXT.DLL
03/06/1999 07:09 122 937 MSOWS409.DLL
07/03/2001 02:00 127 033 MSOWS40c.DLL
3 fichier(s) 811 179 octets
2 Rép(s) 62 534 090 752 octets libres
Attention : C:\autorun.inf existe
[AutoRun]
open=ntde1ect.com
;shell\open=Open(&O)
shell\open\Command=ntde1ect.com
shell\open\Default=1
;shell\explore=Manager(&X)
shell\explore\Command=ntde1ect.com
c:\Documents and Settings\Admin\.housecall6.6\patch.exe
c:\Documents and Settings\Admin\.housecall6.6\tsc.exe
c:\Documents and Settings\Admin\Bureau\avg-anti-rootkit_avg_anti-rootkit_1.1.0.42_anglais_34515.exe
c:\Documents and Settings\Admin\Bureau\avgarkt-setup-1.1.0.42.exe
c:\Documents and Settings\Admin\Bureau\HijackThis.exe
c:\Documents and Settings\Admin\Bureau\sarsfx.exe
c:\Documents and Settings\Admin\Bureau\spybotsd15.exe
c:\Documents and Settings\Admin\Bureau\SREngPS.EXE
c:\Documents and Settings\Admin\Bureau\DiagHelp\catchme.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\diff.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\dumphive.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\find2.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\Fport.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\grep.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\KProcCheck.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\LFiles.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\md5sums.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\pslist.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\streams.exe
c:\Documents and Settings\Admin\Bureau\DiagHelp\swreg.exe
c:\Documents and Settings\Admin\Bureau\Helios\Helios\HELIOS.exe
c:\Documents and Settings\Admin\Bureau\RootkitRevealer\RootkitRevealer.exe
c:\Documents and Settings\Admin\Local Settings\Temp\FlashPlayerUpdate.exe
c:\Documents and Settings\Admin\Local Settings\Temp\Install_Messenger.exe
c:\Documents and Settings\Admin\Local Settings\Temp\LPNFEGEKCG.exe
c:\Documents and Settings\Admin\Local Settings\Temp\shfbqn.exe
c:\Documents and Settings\Admin\Local Settings\Temp\TI.exe
c:\Documents and Settings\Admin\Local Settings\Temp\vmfjxb.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
****** Fin du rapport DiagHelp
OK.
1/ * Ouvrir l'explorateur windows (Démarrer>programmes>Accessoires>Explorateur windows ou Démarrer>programmes>Explorateur windows).
* Cliquer sur outils>options des dossiers>affichage.
* Sélectionner :
o afficher les fichiers et dossiers cachés,
o décocher "masquer les extensions des fichiers dont le type est connu",
o décocher masquer les fichiers protégés du système d'exploitation (recommandé)".
* "appliquer" et "ok"
2/ * Peux-tu tester ceci : c:\Documents and Settings\Admin\Local Settings\Temp\LPNFEGEKCG.exe
* Clique sur ce lien : http://www.virustotal.com/en/indexf.html
* Clique sur parcourir et indique le chemin du fichier que j’ai désigné.
* Clique sur send. Au bout de quelques minutes, un rapport est généré. Poste-le dans ta prochaine réponse.
Même chose pour ceci : c:\Documents and Settings\Admin\Local Settings\Temp\TI.exe
FillPCA
1/ * Ouvrir l'explorateur windows (Démarrer>programmes>Accessoires>Explorateur windows ou Démarrer>programmes>Explorateur windows).
* Cliquer sur outils>options des dossiers>affichage.
* Sélectionner :
o afficher les fichiers et dossiers cachés,
o décocher "masquer les extensions des fichiers dont le type est connu",
o décocher masquer les fichiers protégés du système d'exploitation (recommandé)".
* "appliquer" et "ok"
2/ * Peux-tu tester ceci : c:\Documents and Settings\Admin\Local Settings\Temp\LPNFEGEKCG.exe
* Clique sur ce lien : http://www.virustotal.com/en/indexf.html
* Clique sur parcourir et indique le chemin du fichier que j’ai désigné.
* Clique sur send. Au bout de quelques minutes, un rapport est généré. Poste-le dans ta prochaine réponse.
Même chose pour ceci : c:\Documents and Settings\Admin\Local Settings\Temp\TI.exe
FillPCA
Comme demandé :
Fichier LPNFEGEKCG.exe reçu le 2007.09.05 21:21:00 (CET)
Situation actuelle: terminé
Résultat: 0/32 (0%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2007.9.5.0 2007.09.05 -
AntiVir 7.6.0.5 2007.09.05 -
Authentium 4.93.8 2007.09.05 -
Avast 4.7.1029.0 2007.09.05 -
AVG 7.5.0.485 2007.09.05 -
BitDefender 7.2 2007.09.05 -
CAT-QuickHeal 9.00 2007.09.05 -
ClamAV 0.91.2 2007.09.05 -
DrWeb 4.33 2007.09.05 -
eSafe 7.0.15.0 2007.09.04 -
eTrust-Vet 31.1.5111 2007.09.05 -
Ewido 4.0 2007.09.05 -
FileAdvisor 1 2007.09.05 -
Fortinet 3.11.0.0 2007.09.05 -
F-Prot 4.3.2.48 2007.09.05 -
F-Secure 6.70.13030.0 2007.09.05 -
Ikarus T3.1.1.12 2007.09.05 -
Kaspersky 4.0.2.24 2007.09.05 -
McAfee 5113 2007.09.05 -
Microsoft 1.2803 2007.09.05 -
NOD32v2 2507 2007.09.05 -
Norman 5.80.02 2007.09.05 -
Panda 9.0.0.4 2007.09.05 -
Prevx1 V2 2007.09.05 -
Rising 19.39.22.00 2007.09.05 -
Sophos 4.21.0 2007.09.05 -
Sunbelt 2.2.907.0 2007.09.05 -
Symantec 10 2007.09.05 -
TheHacker 6.1.9.178 2007.09.05 -
VBA32 3.12.2.3 2007.09.04 -
VirusBuster 4.3.26:9 2007.09.05 -
Webwasher-Gateway 6.0.1 2007.09.05 -
Information additionnelle
File size: 539520 bytes
MD5: 0cd9d8f11ec956db0454be4f64623734
SHA1: 3a0e5d84c030172ea905d335cdd9b57c68b77730
packers: BINARYRES
_________________________________
Fichier TI.exe reçu le 2007.09.05 21:39:25 (CET)
Situation actuelle: terminé
Résultat: 0/32 (0%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2007.9.5.0 2007.09.05 -
AntiVir 7.6.0.5 2007.09.05 -
Authentium 4.93.8 2007.09.05 -
Avast 4.7.1029.0 2007.09.05 -
AVG 7.5.0.485 2007.09.05 -
BitDefender 7.2 2007.09.05 -
CAT-QuickHeal 9.00 2007.09.05 -
ClamAV 0.91.2 2007.09.05 -
DrWeb 4.33 2007.09.05 -
eSafe 7.0.15.0 2007.09.04 -
eTrust-Vet 31.1.5111 2007.09.05 -
Ewido 4.0 2007.09.05 -
FileAdvisor 1 2007.09.05 -
Fortinet 3.11.0.0 2007.09.05 -
F-Prot 4.3.2.48 2007.09.05 -
F-Secure 6.70.13030.0 2007.09.05 -
Ikarus T3.1.1.12 2007.09.05 -
Kaspersky 4.0.2.24 2007.09.05 -
McAfee 5113 2007.09.05 -
Microsoft 1.2803 2007.09.05 -
NOD32v2 2507 2007.09.05 -
Norman 5.80.02 2007.09.05 -
Panda 9.0.0.4 2007.09.05 -
Prevx1 V2 2007.09.05 -
Rising 19.39.22.00 2007.09.05 -
Sophos 4.21.0 2007.09.05 -
Sunbelt 2.2.907.0 2007.09.05 -
Symantec 10 2007.09.05 -
TheHacker 6.1.9.178 2007.09.05 -
VBA32 3.12.2.3 2007.09.04 -
VirusBuster 4.3.26:9 2007.09.05 -
Webwasher-Gateway 6.0.1 2007.09.05 -
Information additionnelle
File size: 514944 bytes
MD5: 831cca7813e152ddc9d3dca1a93756bf
SHA1: 870e092dbd2adebc88fe0923abf091bd78317410
packers: BINARYRES
Inquietant non ? xD
Fichier LPNFEGEKCG.exe reçu le 2007.09.05 21:21:00 (CET)
Situation actuelle: terminé
Résultat: 0/32 (0%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2007.9.5.0 2007.09.05 -
AntiVir 7.6.0.5 2007.09.05 -
Authentium 4.93.8 2007.09.05 -
Avast 4.7.1029.0 2007.09.05 -
AVG 7.5.0.485 2007.09.05 -
BitDefender 7.2 2007.09.05 -
CAT-QuickHeal 9.00 2007.09.05 -
ClamAV 0.91.2 2007.09.05 -
DrWeb 4.33 2007.09.05 -
eSafe 7.0.15.0 2007.09.04 -
eTrust-Vet 31.1.5111 2007.09.05 -
Ewido 4.0 2007.09.05 -
FileAdvisor 1 2007.09.05 -
Fortinet 3.11.0.0 2007.09.05 -
F-Prot 4.3.2.48 2007.09.05 -
F-Secure 6.70.13030.0 2007.09.05 -
Ikarus T3.1.1.12 2007.09.05 -
Kaspersky 4.0.2.24 2007.09.05 -
McAfee 5113 2007.09.05 -
Microsoft 1.2803 2007.09.05 -
NOD32v2 2507 2007.09.05 -
Norman 5.80.02 2007.09.05 -
Panda 9.0.0.4 2007.09.05 -
Prevx1 V2 2007.09.05 -
Rising 19.39.22.00 2007.09.05 -
Sophos 4.21.0 2007.09.05 -
Sunbelt 2.2.907.0 2007.09.05 -
Symantec 10 2007.09.05 -
TheHacker 6.1.9.178 2007.09.05 -
VBA32 3.12.2.3 2007.09.04 -
VirusBuster 4.3.26:9 2007.09.05 -
Webwasher-Gateway 6.0.1 2007.09.05 -
Information additionnelle
File size: 539520 bytes
MD5: 0cd9d8f11ec956db0454be4f64623734
SHA1: 3a0e5d84c030172ea905d335cdd9b57c68b77730
packers: BINARYRES
_________________________________
Fichier TI.exe reçu le 2007.09.05 21:39:25 (CET)
Situation actuelle: terminé
Résultat: 0/32 (0%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2007.9.5.0 2007.09.05 -
AntiVir 7.6.0.5 2007.09.05 -
Authentium 4.93.8 2007.09.05 -
Avast 4.7.1029.0 2007.09.05 -
AVG 7.5.0.485 2007.09.05 -
BitDefender 7.2 2007.09.05 -
CAT-QuickHeal 9.00 2007.09.05 -
ClamAV 0.91.2 2007.09.05 -
DrWeb 4.33 2007.09.05 -
eSafe 7.0.15.0 2007.09.04 -
eTrust-Vet 31.1.5111 2007.09.05 -
Ewido 4.0 2007.09.05 -
FileAdvisor 1 2007.09.05 -
Fortinet 3.11.0.0 2007.09.05 -
F-Prot 4.3.2.48 2007.09.05 -
F-Secure 6.70.13030.0 2007.09.05 -
Ikarus T3.1.1.12 2007.09.05 -
Kaspersky 4.0.2.24 2007.09.05 -
McAfee 5113 2007.09.05 -
Microsoft 1.2803 2007.09.05 -
NOD32v2 2507 2007.09.05 -
Norman 5.80.02 2007.09.05 -
Panda 9.0.0.4 2007.09.05 -
Prevx1 V2 2007.09.05 -
Rising 19.39.22.00 2007.09.05 -
Sophos 4.21.0 2007.09.05 -
Sunbelt 2.2.907.0 2007.09.05 -
Symantec 10 2007.09.05 -
TheHacker 6.1.9.178 2007.09.05 -
VBA32 3.12.2.3 2007.09.04 -
VirusBuster 4.3.26:9 2007.09.05 -
Webwasher-Gateway 6.0.1 2007.09.05 -
Information additionnelle
File size: 514944 bytes
MD5: 831cca7813e152ddc9d3dca1a93756bf
SHA1: 870e092dbd2adebc88fe0923abf091bd78317410
packers: BINARYRES
Inquietant non ? xD
Re,
Non. Pour cela, c'est bon. Je m'en doutais mais je voulais en être certain.
1/
* Télécharge OTMoveIt (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
* Double-clique sur OTMoveIt.exe pour lancer le programme,
* Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List Of Files/Folders to be moved" :
C:\WINDOWS\system32\avpo.exe
C:\WINDOWS\system32\avpo0.dll
* Clique sur MoveIt! pour lancer la suppression,
* Le résultat appraraîtra dans le cadre Results.
* Clique sur Exit pour fermer le programme.
* Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
* Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.
2/ Ouvre Hijackthis>"Do a scan and save a log file" et coche ceci :
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
Clique sur fix/réparer.
3/ Ouvre le Bloc-note
et copie-colle les lignes entre --- ci-dessous (y compris la ligne vide à la fin)
-----------------------------------------------------------------------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
--------------------------------------------------------------------------------------------------------------
Enregistre ce fichier sur ton bureau (Nom du fichier : "Fixme.reg " -sans inclure les guillemets- ; Type : Tous les fichiers).
Double-clique sur Fixme.reg et clique sur Oui lorsqu'on te demande confirmation pour Fusionner.
Lorsque tu reçois un message du bon déroulement, supprime le fichier Fixme.reg.
4/ Clique sur démarrer>Exécuter>cmd et tape ceci :
sc stop qaeynkipoilkjhgvd
sc delete qaeynkipoilkjhgvd
5/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download
Ouvre Ccleaner, clique sur "lancer le nettoyage".
6/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
Tu l'installes.
Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
7/ Edite les rapports suivants :
OTMoveIt, AVGantispyware, nouveau rapport Hijackthis, nouveau rapport SREng (ce dernier peut être publié en deux fois).
FillPCA
Non. Pour cela, c'est bon. Je m'en doutais mais je voulais en être certain.
1/
* Télécharge OTMoveIt (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
* Double-clique sur OTMoveIt.exe pour lancer le programme,
* Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List Of Files/Folders to be moved" :
C:\WINDOWS\system32\avpo.exe
C:\WINDOWS\system32\avpo0.dll
* Clique sur MoveIt! pour lancer la suppression,
* Le résultat appraraîtra dans le cadre Results.
* Clique sur Exit pour fermer le programme.
* Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
* Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.
2/ Ouvre Hijackthis>"Do a scan and save a log file" et coche ceci :
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
Clique sur fix/réparer.
3/ Ouvre le Bloc-note
et copie-colle les lignes entre --- ci-dessous (y compris la ligne vide à la fin)
-----------------------------------------------------------------------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
--------------------------------------------------------------------------------------------------------------
Enregistre ce fichier sur ton bureau (Nom du fichier : "Fixme.reg " -sans inclure les guillemets- ; Type : Tous les fichiers).
Double-clique sur Fixme.reg et clique sur Oui lorsqu'on te demande confirmation pour Fusionner.
Lorsque tu reçois un message du bon déroulement, supprime le fichier Fixme.reg.
4/ Clique sur démarrer>Exécuter>cmd et tape ceci :
sc stop qaeynkipoilkjhgvd
sc delete qaeynkipoilkjhgvd
5/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download
Ouvre Ccleaner, clique sur "lancer le nettoyage".
6/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
Tu l'installes.
Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
7/ Edite les rapports suivants :
OTMoveIt, AVGantispyware, nouveau rapport Hijackthis, nouveau rapport SREng (ce dernier peut être publié en deux fois).
FillPCA
Bonjour,
Plus de nouvelle. J'aurais pourtant apprécié que tu aies la courtoisie de me dire où tu en étais.
FillPCA
Plus de nouvelle. J'aurais pourtant apprécié que tu aies la courtoisie de me dire où tu en étais.
FillPCA
Oui, c'est vrai . Je m'en excuse ...
J'ai finalement choisis la solution la plus simple à mes yeux, j'ai donc formaté mon PC (sortie d'usine).
Cela m'a permis de faire le ménage sur mes PC et DDE ^^
En tout cas j'ai beaucoup apprécié ton aide <3
Encore merci, Azeal
J'ai finalement choisis la solution la plus simple à mes yeux, j'ai donc formaté mon PC (sortie d'usine).
Cela m'a permis de faire le ménage sur mes PC et DDE ^^
En tout cas j'ai beaucoup apprécié ton aide <3
Encore merci, Azeal
ce trojan se fout sur tous les disque dur interne , externe (clef usb, carte memoire, compris) en somme cest une plaie ...
en le virant on est meme pas sur de pouvoir retrouver un systeme "normal"
en le virant on est meme pas sur de pouvoir retrouver un systeme "normal"
Salut les gars,
J'ai eu et j'ai encore actuellement ce trojan/virus puisque sur un réseau !
J'ignore si j'ai exactement la même versio que vous mais voici comment je m'en sort actuellement.
1 - exécuter REGEDIT,
2 - Trouver la clé dans laquel est inscrit AMVO.EXE (genre amma = amvo.exe) (HKCU\Sofware\Microsoft\Windows\CurrentVersion\Run)
3 - Effacer cette clé complètement !
Puisque ma variante m'empêche de rendre les fichiers cachés et systems visibles, allons-y en DOS
4 - Démarrer une fenêtre DOS (Exécuter CMD)
5 - "CD\" pour aller à la racine du HD infecté
6 - "ATTRIB" affiche tous les fichiers de la racine, cachés ou non, system ou non
Vous devriez retrouver dans la liste: au moins "autorun.inf" accompagné d'un ou des fichiers suivants: "h.cmd", "2ifetri.cmd", "n1deiect.???" et plusieurs autres possibles selon la durée de l'infection ! On les reconnais facilement, ils sont tous bizarres ! attention de ne pas confondre... NTDETECT. ??? est un bon fichier et MSIO.SYS et IO.SYS sont également bons.
7 - "ATTRIB -H -R -S AUTORUN.INF"
8 - "DEL AUTORUN.INF"
Répétez les étapes 7 et 8 pour chacun des fichiers puis redémarrer l'ordi - très important.
9 - Executer REGEDIT
10 - Trouver la clé qui permet de débarrer le menu permettant d'afficher les fichiers systems (HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\Showall)
11 - Changer la valeur de la variable CheckedValue pour "1" au lieu de "0" . Cela réactive le menu si on veut.
a partir d'ici, la plupart des symptomes du trojan sont disparus... un bon anti-virus, très à jour peut probablement finir le travail mais on peut l'aider en s'assurant de certaines choses. Dans mon cas McAfee 8.5 avec m-a-j 5222 fonctionne (rendu a 5224).
12 - Dans les options des dossiers, faites afficher les fichiers cachés et systems aussi
13 - Aller dans \windows\system32 et effacer AMVO.EXE et AMVO0.dll,... AMVO*.*
14 - Dans \Documents and settings\"nom de l'utilisateur"\local settings\Temp , effacez tous les fichiers .dll .cmd .exe que vous y trouvez, je recommande personnellement de tout effacer, comme ca on est certain et c'est seulement un dossier Temp alors on est pas supposer rien briser !
Pour la dernière partie, ca se peux que moi j'avais un package de virus alors c'est possible que vous n'avez rien à cet endroit. C'est le plus "tricky" je dirais !
15 - il faut revenir à la racine du disque et voir le dossier "System Volume Information" (la visualisation des fichiers systems doit toujours etre active)
16 - Windows risque de ne pas vouloir vous laisser y entrer... c'est là que ca se complique ! vous devez vous donner les droit d'accès pour pouvoir y aller. Bouton de droit sur le dossier, partage et sécurité, onglet sécurité. Il n'y a que le SYSTEM qui a droit d'acces à ce dossier, il s'agit d'ajouter votre utilisateur à la liste d'accès.
17 - il se peux que l'onglet SECURITÉ ne soit pas là... je sais pas pourquoi, je suppose que c'est parce que vous n'êtes pas entré dans windows avec un compte administrateur du poste. À ca moment, l'antivirus devrait être capable d'y acceder quand meme.
18 - Ce dossier contient tous les fichiers de points de restauration du systeme, évidemment, les effacer fait que vous n'aurez plus de point de restauration pour le moment mais cartain fichier/clé ont potentiellement des infections !
Voilà. j'en suis rendu là dans ma chasse à ce trojan - question de calmer le tout j'ai désactiver la restauration system de windows et j'ai désactivé dans les polices de groupe le démarrage automatique de tous les lecteurs (fonction de windows qui lit automatiquement AUTORUN.INF de n'importe quel disque ou clé USB qui s'ammène !)
J'ignore pour le moment si j'aurai des surprises supplémentaires... pour le moment les machines auxquels j'ai appliqué ca semblent stablent reste à voir si ca reviendra.
Seb-ass !
J'ai eu et j'ai encore actuellement ce trojan/virus puisque sur un réseau !
J'ignore si j'ai exactement la même versio que vous mais voici comment je m'en sort actuellement.
1 - exécuter REGEDIT,
2 - Trouver la clé dans laquel est inscrit AMVO.EXE (genre amma = amvo.exe) (HKCU\Sofware\Microsoft\Windows\CurrentVersion\Run)
3 - Effacer cette clé complètement !
Puisque ma variante m'empêche de rendre les fichiers cachés et systems visibles, allons-y en DOS
4 - Démarrer une fenêtre DOS (Exécuter CMD)
5 - "CD\" pour aller à la racine du HD infecté
6 - "ATTRIB" affiche tous les fichiers de la racine, cachés ou non, system ou non
Vous devriez retrouver dans la liste: au moins "autorun.inf" accompagné d'un ou des fichiers suivants: "h.cmd", "2ifetri.cmd", "n1deiect.???" et plusieurs autres possibles selon la durée de l'infection ! On les reconnais facilement, ils sont tous bizarres ! attention de ne pas confondre... NTDETECT. ??? est un bon fichier et MSIO.SYS et IO.SYS sont également bons.
7 - "ATTRIB -H -R -S AUTORUN.INF"
8 - "DEL AUTORUN.INF"
Répétez les étapes 7 et 8 pour chacun des fichiers puis redémarrer l'ordi - très important.
9 - Executer REGEDIT
10 - Trouver la clé qui permet de débarrer le menu permettant d'afficher les fichiers systems (HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\Showall)
11 - Changer la valeur de la variable CheckedValue pour "1" au lieu de "0" . Cela réactive le menu si on veut.
a partir d'ici, la plupart des symptomes du trojan sont disparus... un bon anti-virus, très à jour peut probablement finir le travail mais on peut l'aider en s'assurant de certaines choses. Dans mon cas McAfee 8.5 avec m-a-j 5222 fonctionne (rendu a 5224).
12 - Dans les options des dossiers, faites afficher les fichiers cachés et systems aussi
13 - Aller dans \windows\system32 et effacer AMVO.EXE et AMVO0.dll,... AMVO*.*
14 - Dans \Documents and settings\"nom de l'utilisateur"\local settings\Temp , effacez tous les fichiers .dll .cmd .exe que vous y trouvez, je recommande personnellement de tout effacer, comme ca on est certain et c'est seulement un dossier Temp alors on est pas supposer rien briser !
Pour la dernière partie, ca se peux que moi j'avais un package de virus alors c'est possible que vous n'avez rien à cet endroit. C'est le plus "tricky" je dirais !
15 - il faut revenir à la racine du disque et voir le dossier "System Volume Information" (la visualisation des fichiers systems doit toujours etre active)
16 - Windows risque de ne pas vouloir vous laisser y entrer... c'est là que ca se complique ! vous devez vous donner les droit d'accès pour pouvoir y aller. Bouton de droit sur le dossier, partage et sécurité, onglet sécurité. Il n'y a que le SYSTEM qui a droit d'acces à ce dossier, il s'agit d'ajouter votre utilisateur à la liste d'accès.
17 - il se peux que l'onglet SECURITÉ ne soit pas là... je sais pas pourquoi, je suppose que c'est parce que vous n'êtes pas entré dans windows avec un compte administrateur du poste. À ca moment, l'antivirus devrait être capable d'y acceder quand meme.
18 - Ce dossier contient tous les fichiers de points de restauration du systeme, évidemment, les effacer fait que vous n'aurez plus de point de restauration pour le moment mais cartain fichier/clé ont potentiellement des infections !
Voilà. j'en suis rendu là dans ma chasse à ce trojan - question de calmer le tout j'ai désactiver la restauration system de windows et j'ai désactivé dans les polices de groupe le démarrage automatique de tous les lecteurs (fonction de windows qui lit automatiquement AUTORUN.INF de n'importe quel disque ou clé USB qui s'ammène !)
J'ignore pour le moment si j'aurai des surprises supplémentaires... pour le moment les machines auxquels j'ai appliqué ca semblent stablent reste à voir si ca reviendra.
Seb-ass !