A voir également:
- Divers bugs rapport hijack
- Plan rapport de stage - Guide
- Impossible d'afficher le rapport de tableau croisé dynamique sur un rapport existant ✓ - Forum Excel
- Problém affichage du tableau croisé dynamique - Forum Excel
- Envoyer un rapport de bug à mi pour analyse - Forum Xiaomi
- Mise en forme conditionnelle excel par rapport à une autre cellule - Guide
4 réponses
Le rapport que j'avais oublié!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:02:32, on 09/06/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\WTablet\TabUserW.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\remoterm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe
C:\Program Files\Pinnacle\Shared Files\Programs\PclePvr\VideoControl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [PMCLoader] C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\Windows\system32\Tablet.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA Corporation - (no file)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:02:32, on 09/06/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\WTablet\TabUserW.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\remoterm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe
C:\Program Files\Pinnacle\Shared Files\Programs\PclePvr\VideoControl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [PMCLoader] C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\Windows\system32\Tablet.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA Corporation - (no file)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Utilisateur anonyme
9 juin 2008 à 20:12
9 juin 2008 à 20:12
Salut fais ceci
*Télécharge HijackThis: http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
*Puis fais "Install" puis "I accept" puis tu cliques sur "Do a system scan and save a logfile".
*L'analyse se fait un bloc-note s'ouvrira tu fais copier/coller dans le forum.
*Télécharge HijackThis: http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
*Puis fais "Install" puis "I accept" puis tu cliques sur "Do a system scan and save a logfile".
*L'analyse se fait un bloc-note s'ouvrira tu fais copier/coller dans le forum.
Bien sur je l'ai dit dans un message plus haut, il n'a trouvé aucun virus mais le rapport pèse trop lourd pour le poster sur le forum.
Ok maintenant fais une mise a jour de Spybot pour cela ouvre "Spybot" puis cliques sur "Recherche de mise a jour" puis tu clique sur "Continuer" puis des mises a jour seront cochés (tu les laisses) puis tu cliques sur "Télécharger" puis tu attends. Apres avoir fait tout cela tu fais un scan avec Spybot en mode sans échec. Tu ouvres "Spybot" puis cliques sur "Vérifier Tout" puis si il détecté des trucs a la fin tu cliques sur "Corriger les problèmes" puis tu cliques sur "Oui pour autoriser Spybot à nettoyer les mouchards". Puis tu redémarre en mode normal puis tu me postes un rapport.
aucun mouchard repéré, je t'nevoi un rapport des autorisation peut être que ça pourra t'aider
22/11/2007 18:45:28 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\temp\"") ajouté(e) in System Startup global entry!
22/11/2007 18:46:06 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
22/11/2007 18:50:18 Autorisé(e) (based on user decision) value "PMCRemote" (new data: "C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe") ajouté(e) in System Startup user entry!
22/11/2007 18:54:04 Autorisé(e) (based on user decision) value "LaunchList" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\LaunchList2.exe") ajouté(e) in System Startup user entry!
22/11/2007 18:59:32 Autorisé(e) (based on user decision) value "LaunchList" (new data: "") supprimé(e) in System Startup user entry!
22/11/2007 18:59:38 Autorisé(e) (based on user decision) value "PMCRemote" (new data: "") modifié(e) in System Startup user entry!
22/11/2007 19:00:31 Autorisé(e) (based on user whitelist) value "PMCRemote" (new data: "C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe") modifié(e) in System Startup user entry!
22/11/2007 19:16:49 Autorisé(e) (based on user decision) value "PMCLoader" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks") ajouté(e) in System Startup user entry!
23/11/2007 17:08:13 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\temp\"") ajouté(e) in System Startup global entry!
23/11/2007 17:08:16 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
23/11/2007 17:10:14 Autorisé(e) (based on user decision) value "LaunchList" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\LaunchList2.exe") ajouté(e) in System Startup user entry!
23/11/2007 17:10:25 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{F38AD~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{F38AD~1\reboot.ini") ajouté(e) in System Startup global entry!
23/11/2007 17:15:34 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
23/11/2007 17:15:42 Autorisé(e) (based on user decision) value "PMCLoader" (new data: "") supprimé(e) in System Startup user entry!
23/11/2007 17:16:31 Autorisé(e) (based on user decision) value "LaunchList" (new data: "") supprimé(e) in System Startup user entry!
23/11/2007 17:48:25 Autorisé(e) (based on user whitelist) value "PMCLoader" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks") ajouté(e) in System Startup user entry!
29/11/2007 13:54:14 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
05/12/2007 18:12:15 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") ajouté(e) in System Startup user entry!
06/12/2007 18:05:05 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
23/12/2007 12:50:21 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
23/12/2007 12:50:26 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
25/12/2007 06:11:16 Autorisé(e) (based on user decision) value "CTSyncU.exe" (new data: ""C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"") ajouté(e) in System Startup user entry!
25/12/2007 06:13:27 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{D24DD~1\SETUP.EXE -rebootC:\PROGRA~1\INSTAL~1\{D24DD~1\reboot.ini -l0x40c") ajouté(e) in System Startup global entry!
25/12/2007 06:15:21 Autorisé(e) (based on user decision) value "InetReg" (new data: ""C:\Program Files\Creative\Enregistrement du produit\French\InetReg.exe" /PreProcess=RegFlash.exe /PortableDevice /Delay=6") ajouté(e) in System Startup user entry!
25/12/2007 06:16:07 Autorisé(e) (based on user decision) value "CTAutoUpdate" (new data: ""C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe" /RunFromInstaller") ajouté(e) in System Startup user entry!
25/12/2007 06:16:31 Autorisé(e) (based on user decision) value "CTPostBootSequencer" (new data: ""C:\Users\Qentin\AppData\Local\Temp\CTPBSEQ.EXE" /reglaunch /self_destruct") ajouté(e) in System Startup user entry!
25/12/2007 06:16:33 Autorisé(e) (based on user decision) value "InetReg" (new data: "") supprimé(e) in System Startup user entry!
25/12/2007 06:16:34 Autorisé(e) (based on user decision) value "CTAutoUpdate" (new data: "") supprimé(e) in System Startup user entry!
25/12/2007 06:19:36 Autorisé(e) (based on user decision) value "CTPostBootSequencer" (new data: "") supprimé(e) in System Startup user entry!
25/12/2007 06:19:39 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
25/12/2007 06:20:23 Autorisé(e) (based on user decision) value "CTRegRun" (new data: "C:\Windows\CTRegRun.EXE") ajouté(e) in System Startup user entry!
25/12/2007 15:36:48 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "C:\Program Files\HP\HP Software Update\HPWUCli.exe") ajouté(e) in System Startup user entry!
25/12/2007 15:36:50 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "") supprimé(e) in System Startup user entry!
07/01/2008 14:46:10 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
07/01/2008 14:46:12 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
07/01/2008 14:52:29 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP001.TMP\"") ajouté(e) in System Startup global entry!
07/01/2008 14:52:30 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
08/01/2008 12:04:12 Autorisé(e) (based on user decision) value "CTRegRun" (new data: "") supprimé(e) in System Startup user entry!
13/01/2008 22:53:38 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
13/01/2008 22:53:39 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
18/01/2008 23:57:46 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
18/01/2008 23:57:50 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
18/01/2008 23:58:55 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
18/01/2008 23:58:56 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
20/01/2008 15:16:39 Autorisé(e) (based on user decision) value "{7E853D72-626A-48EC-A868-BA8D5E23E045}" (new data: "") supprimé(e) in Browser Helper Object!
20/01/2008 15:27:45 Autorisé(e) (based on user decision) value "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" (new data: "") supprimé(e) in Global browser toolbar!
20/01/2008 15:27:46 Autorisé(e) (based on user decision) value "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" (new data: "") supprimé(e) in Browser Helper Object!
28/01/2008 12:29:38 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
28/01/2008 12:29:41 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
28/01/2008 22:19:58 Autorisé(e) (based on user decision) value "Veoh" (new data: ""C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide") ajouté(e) in System Startup user entry!
28/01/2008 22:20:00 Autorisé(e) (based on user decision) value "" (new data: "") ajouté(e) in System Startup user entry!
28/01/2008 22:20:01 Autorisé(e) (based on user decision) value "{D0943516-5076-4020-A3B5-AEFAF26AB263}" (new data: "Veoh Video Finder") ajouté(e) in Global browser toolbar!
29/01/2008 14:04:04 Autorisé(e) (based on user decision) value "QuickTime Task" (new data: ""C:\Program Files\QuickTime\QTTask.exe" -atboottime") ajouté(e) in System Startup global entry!
03/02/2008 19:05:23 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") ajouté(e) in System Startup user entry!
04/02/2008 12:06:07 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "") supprimé(e) in System Startup user entry!
11/02/2008 13:25:19 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
11/02/2008 13:25:20 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
21/02/2008 12:29:35 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "C:\Program Files\HP\HP Software Update\HPWUCli.exe") ajouté(e) in System Startup user entry!
21/02/2008 12:40:19 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "") supprimé(e) in System Startup user entry!
24/02/2008 17:32:34 Autorisé(e) (based on user decision) value "Speech Recognition" (new data: ""C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup") ajouté(e) in System Startup user entry!
26/02/2008 17:15:44 Autorisé(e) (based on user decision) value "236745dc4f54538f794532999d5814a" (new data: "msiexec.exe /x {926DEB4E-2B0A-4C5C-AE4A-BF6C06949702} /passive /qn /norestart ADOBE_SETUP=1 PROPERTY_FILE="C:\Users\Qentin\AppData\Local\Temp\adb2993.tmp"") ajouté(e) in System Startup global entry!
26/02/2008 17:20:38 Autorisé(e) (based on user decision) value "236745dc4f54538f794532999d5814a" (new data: "") supprimé(e) in System Startup global entry!
26/02/2008 17:51:17 Autorisé(e) (based on user decision) value "Acrobat Assistant 8.0" (new data: ""C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"") ajouté(e) in System Startup global entry!
26/02/2008 17:51:19 Autorisé(e) (based on user decision) value "" (new data: "") ajouté(e) in System Startup global entry!
26/02/2008 17:51:21 Autorisé(e) (based on user decision) value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "hex:00") ajouté(e) in Global browser toolbar!
26/02/2008 17:51:22 Autorisé(e) (based on user decision) value "{AE7CD045-E861-484f-8273-0445EE161910}" (new data: "") ajouté(e) in Browser Helper Object!
26/02/2008 17:51:23 Autorisé(e) (based on user decision) value "{182EC0BE-5110-49C8-A062-BEB1D02A220B}" (new data: "") ajouté(e) in Global browser toolbar!
26/02/2008 17:51:28 Autorisé(e) (based on user decision) value "Ajouter au fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:30 Autorisé(e) (based on user decision) value "Convertir en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:31 Autorisé(e) (based on user decision) value "Convertir la cible du lien en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:31 Autorisé(e) (based on user decision) value "Convertir la cible du lien en un fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:31 Autorisé(e) (based on user decision) value "Convertir la sélection en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:32 Autorisé(e) (based on user decision) value "Convertir la sélection en un fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:32 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:34 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en un fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:57:53 Autorisé(e) (based on user decision) value "Adobe_ID0EYTHM" (new data: "C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE") ajouté(e) in System Startup global entry!
26/02/2008 17:57:54 Autorisé(e) (based on user decision) value "{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}" (new data: "0") ajouté(e) in Global browser toolbar!
26/02/2008 17:57:55 Autorisé(e) (based on user decision) value "{074C1DC5-9320-4A9A-947D-C042949C6216}" (new data: "") ajouté(e) in Browser Helper Object!
27/02/2008 16:11:04 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en fichier Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
27/02/2008 16:11:07 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en Adobe PDF" (new data: "") supprimé(e) in Browser menu extension!
27/02/2008 16:11:10 Autorisé(e) (based on user decision) value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "hex:39,35,83,47,C5,D0,25,41,9F,A8,08,19,E2,EA,AC,93") ajouté(e) in User-specific browser toolbar!
28/02/2008 17:28:41 Autorisé(e) (based on user decision) value "PMCRemote" (new data: "") supprimé(e) in System Startup user entry!
28/02/2008 17:29:39 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{F38AD~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{F38AD~1\reboot.ini") ajouté(e) in System Startup global entry!
28/02/2008 17:45:48 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
28/02/2008 17:46:27 Autorisé(e) (based on user decision) value "Speech Recognition" (new data: "") supprimé(e) in System Startup user entry!
03/03/2008 23:29:29 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
03/03/2008 23:29:31 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
04/03/2008 14:02:15 Autorisé(e) (based on user decision) value "Adobe Photo Downloader" (new data: ""C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe"") ajouté(e) in System Startup global entry!
04/03/2008 22:20:15 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe") ajouté(e) in System Startup user entry!
04/03/2008 23:21:51 Autorisé(e) (based on user whitelist) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") ajouté(e) in System Startup user entry!
05/03/2008 07:33:02 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "") supprimé(e) in System Startup user entry!
05/03/2008 18:39:46 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
10/03/2008 20:30:48 Autorisé(e) (based on user whitelist) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") ajouté(e) in System Startup user entry!
11/03/2008 19:35:51 Autorisé(e) (based on user decision) value "TkBellExe" (new data: ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot") ajouté(e) in System Startup global entry!
11/03/2008 19:36:31 Autorisé(e) (based on user decision) value "{3049C3E9-B461-4BC5-8870-4C09146192CA}" (new data: "") ajouté(e) in Browser Helper Object!
11/03/2008 19:39:30 Autorisé(e) (based on user decision) value "{3049C3E9-B461-4BC5-8870-4C09146192CA}" (new data: "") supprimé(e) in Browser Helper Object!
11/03/2008 19:39:32 Autorisé(e) (based on user decision) value "TkBellExe" (new data: ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot") modifié(e) in System Startup global entry!
12/03/2008 20:46:57 Autorisé(e) (based on user decision) value "Veoh" (new data: "") supprimé(e) in System Startup user entry!
18/03/2008 19:11:45 Autorisé(e) (based on user decision) value "AdobeUpdater" (new data: "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe") ajouté(e) in System Startup user entry!
27/03/2008 22:47:26 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
28/03/2008 11:00:25 Autorisé(e) (based on user decision) value "AlcoholAutomount" (new data: ""C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount") ajouté(e) in System Startup user entry!
02/04/2008 23:14:04 Autorisé(e) (based on user decision) value "QuickTime Task" (new data: "") supprimé(e) in System Startup global entry!
02/04/2008 23:15:49 Autorisé(e) (based on user decision) value "QuickTime Task" (new data: ""C:\Program Files\QuickTime\QTTask.exe" -atboottime") ajouté(e) in System Startup global entry!
02/04/2008 23:18:16 Autorisé(e) (based on user decision) value "iTunesHelper" (new data: ""C:\Program Files\iTunes\iTunesHelper.exe"") ajouté(e) in System Startup global entry!
02/04/2008 23:51:28 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
02/04/2008 23:51:29 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
03/04/2008 00:09:16 Autorisé(e) (based on user decision) value "AdobeUpdater" (new data: "") supprimé(e) in System Startup user entry!
03/04/2008 00:10:06 Autorisé(e) (based on user decision) value "Adobe Photo Downloader" (new data: "") supprimé(e) in System Startup global entry!
03/04/2008 16:06:16 Autorisé(e) (based on user decision) value "AlcoholAutomount" (new data: "") supprimé(e) in System Startup user entry!
22/04/2008 13:36:42 Autorisé(e) (based on user decision) value "{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}" (new data: "") ajouté(e) in ActiveX Distribution Unit!
22/04/2008 13:36:50 Autorisé(e) (based on user decision) value "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (new data: "") ajouté(e) in Internet Explorer searches!
22/04/2008 13:36:53 Autorisé(e) (based on user decision) value "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (new data: "hex:00") ajouté(e) in Global browser toolbar!
22/04/2008 13:36:56 Autorisé(e) (based on user decision) value "{02478D38-C3F9-4EFB-9B51-7695ECA05670}" (new data: "") ajouté(e) in Browser Helper Object!
22/04/2008 13:49:01 Autorisé(e) (based on user decision) value "PMCLoader" (new data: "") supprimé(e) in System Startup user entry!
23/04/2008 13:16:27 Autorisé(e) (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") modifié(e) in Session manager!
24/04/2008 12:42:02 Autorisé(e) (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") modifié(e) in Session manager!
27/04/2008 22:24:14 Autorisé(e) (based on user decision) value "ITBarLayout" (new data: "hex:11,00,00,00,00,00,00,00,00,00,00,00,04,00,00,00,1F,00,0F,00,00,00,00,00,01,00,00,00,00,00,00,00,A0,0F,00,00,05,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,A0,0F,00,00,04,00,00,00,01,00,00,00,A0,0F,00,00,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,16,35,94,D0,76,50,20,40,A3,B5,AE,FA,F2,6A,B2,63,39,35,83,47,C5,D0,25,41,9F,A8,08,19,E2,EA,AC,93,E4,DD,7B,51,A7,E3,70,45,B2,1E,2B,52,B6,13,9F,C7,32,BD,99,EF,FB,C1,D2,11,89,2F,00,90,27,1D,4F,88,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,") ajouté(e) in User-specific browser toolbar!
29/04/2008 12:00:43 Autorisé(e) (based on user decision) value "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (new data: "") supprimé(e) in Global browser toolbar!
29/04/2008 12:00:43 Autorisé(e) (based on user whitelist) value "{02478D38-C3F9-4EFB-9B51-7695ECA05670}" (new data: "") supprimé(e) in Browser Helper Object!
29/04/2008 12:00:57 Autorisé(e) (based on user decision) value "{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}" (new data: "") supprimé(e) in ActiveX Distribution Unit!
05/05/2008 07:25:48 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
05/05/2008 07:25:49 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
15/05/2008 19:20:23 Autorisé(e) (based on user decision) value "GrpConv" (new data: "grpconv -o") ajouté(e) in System Startup global entry!
15/05/2008 19:20:25 Autorisé(e) (based on user decision) value "GrpConv" (new data: "") supprimé(e) in System Startup global entry!
22/05/2008 13:48:46 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{F38AD~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{F38AD~1\reboot.ini") ajouté(e) in System Startup global entry!
22/05/2008 15:25:31 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
22/05/2008 15:25:33 Autorisé(e) (based on user whitelist) value "PMCRemote" (new data: "C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe") ajouté(e) in System Startup user entry!
22/05/2008 15:25:34 Autorisé(e) (based on user decision) value "LaunchList" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\LaunchList2.exe") ajouté(e) in System Startup user entry!
22/05/2008 15:30:26 Autorisé(e) (based on user decision) value "LaunchList" (new data: "") supprimé(e) in System Startup user entry!
22/05/2008 15:43:36 Autorisé(e) (based on user whitelist) value "PMCLoader" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks") ajouté(e) in System Startup user entry!
03/06/2008 22:02:43 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
03/06/2008 22:02:44 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
09/06/2008 11:41:12 Autorisé(e) (based on user decision) value "BootExecute" (new data: "") supprimé(e) in Session manager!
09/06/2008 11:41:13 Autorisé(e) (based on user decision) value "ExcludeFromKnownDlls" (new data: "") supprimé(e) in Session manager!
09/06/2008 18:14:09 Autorisé(e) (based on user decision) value "Local Page" (new data: "") supprimé(e) in Browser page!
14/06/2008 20:38:58 Autorisé(e) (based on user decision) value "TOSCDSPD" (new data: "") supprimé(e) in System Startup user entry!
14/06/2008 20:39:02 Autorisé(e) (based on user decision) value "RtHDVCpl" (new data: "") supprimé(e) in System Startup global entry!
14/06/2008 20:39:03 Autorisé(e) (based on user decision) value "HWSetup" (new data: "") supprimé(e) in System Startup global entry!
14/06/2008 20:39:03 Autorisé(e) (based on user decision) value "NDSTray.exe" (new data: "") supprimé(e) in System Startup global entry!
14/06/2008 20:39:04 Autorisé(e) (based on user decision) value "Kernel and Hardware Abstraction Layer" (new data: "") supprimé(e) in System Startup global entry!
22/11/2007 18:45:28 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\temp\"") ajouté(e) in System Startup global entry!
22/11/2007 18:46:06 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
22/11/2007 18:50:18 Autorisé(e) (based on user decision) value "PMCRemote" (new data: "C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe") ajouté(e) in System Startup user entry!
22/11/2007 18:54:04 Autorisé(e) (based on user decision) value "LaunchList" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\LaunchList2.exe") ajouté(e) in System Startup user entry!
22/11/2007 18:59:32 Autorisé(e) (based on user decision) value "LaunchList" (new data: "") supprimé(e) in System Startup user entry!
22/11/2007 18:59:38 Autorisé(e) (based on user decision) value "PMCRemote" (new data: "") modifié(e) in System Startup user entry!
22/11/2007 19:00:31 Autorisé(e) (based on user whitelist) value "PMCRemote" (new data: "C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe") modifié(e) in System Startup user entry!
22/11/2007 19:16:49 Autorisé(e) (based on user decision) value "PMCLoader" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks") ajouté(e) in System Startup user entry!
23/11/2007 17:08:13 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\temp\"") ajouté(e) in System Startup global entry!
23/11/2007 17:08:16 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
23/11/2007 17:10:14 Autorisé(e) (based on user decision) value "LaunchList" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\LaunchList2.exe") ajouté(e) in System Startup user entry!
23/11/2007 17:10:25 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{F38AD~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{F38AD~1\reboot.ini") ajouté(e) in System Startup global entry!
23/11/2007 17:15:34 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
23/11/2007 17:15:42 Autorisé(e) (based on user decision) value "PMCLoader" (new data: "") supprimé(e) in System Startup user entry!
23/11/2007 17:16:31 Autorisé(e) (based on user decision) value "LaunchList" (new data: "") supprimé(e) in System Startup user entry!
23/11/2007 17:48:25 Autorisé(e) (based on user whitelist) value "PMCLoader" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks") ajouté(e) in System Startup user entry!
29/11/2007 13:54:14 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
05/12/2007 18:12:15 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") ajouté(e) in System Startup user entry!
06/12/2007 18:05:05 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
23/12/2007 12:50:21 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
23/12/2007 12:50:26 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
25/12/2007 06:11:16 Autorisé(e) (based on user decision) value "CTSyncU.exe" (new data: ""C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"") ajouté(e) in System Startup user entry!
25/12/2007 06:13:27 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{D24DD~1\SETUP.EXE -rebootC:\PROGRA~1\INSTAL~1\{D24DD~1\reboot.ini -l0x40c") ajouté(e) in System Startup global entry!
25/12/2007 06:15:21 Autorisé(e) (based on user decision) value "InetReg" (new data: ""C:\Program Files\Creative\Enregistrement du produit\French\InetReg.exe" /PreProcess=RegFlash.exe /PortableDevice /Delay=6") ajouté(e) in System Startup user entry!
25/12/2007 06:16:07 Autorisé(e) (based on user decision) value "CTAutoUpdate" (new data: ""C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe" /RunFromInstaller") ajouté(e) in System Startup user entry!
25/12/2007 06:16:31 Autorisé(e) (based on user decision) value "CTPostBootSequencer" (new data: ""C:\Users\Qentin\AppData\Local\Temp\CTPBSEQ.EXE" /reglaunch /self_destruct") ajouté(e) in System Startup user entry!
25/12/2007 06:16:33 Autorisé(e) (based on user decision) value "InetReg" (new data: "") supprimé(e) in System Startup user entry!
25/12/2007 06:16:34 Autorisé(e) (based on user decision) value "CTAutoUpdate" (new data: "") supprimé(e) in System Startup user entry!
25/12/2007 06:19:36 Autorisé(e) (based on user decision) value "CTPostBootSequencer" (new data: "") supprimé(e) in System Startup user entry!
25/12/2007 06:19:39 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
25/12/2007 06:20:23 Autorisé(e) (based on user decision) value "CTRegRun" (new data: "C:\Windows\CTRegRun.EXE") ajouté(e) in System Startup user entry!
25/12/2007 15:36:48 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "C:\Program Files\HP\HP Software Update\HPWUCli.exe") ajouté(e) in System Startup user entry!
25/12/2007 15:36:50 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "") supprimé(e) in System Startup user entry!
07/01/2008 14:46:10 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
07/01/2008 14:46:12 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
07/01/2008 14:52:29 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP001.TMP\"") ajouté(e) in System Startup global entry!
07/01/2008 14:52:30 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
08/01/2008 12:04:12 Autorisé(e) (based on user decision) value "CTRegRun" (new data: "") supprimé(e) in System Startup user entry!
13/01/2008 22:53:38 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
13/01/2008 22:53:39 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
18/01/2008 23:57:46 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
18/01/2008 23:57:50 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
18/01/2008 23:58:55 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
18/01/2008 23:58:56 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
20/01/2008 15:16:39 Autorisé(e) (based on user decision) value "{7E853D72-626A-48EC-A868-BA8D5E23E045}" (new data: "") supprimé(e) in Browser Helper Object!
20/01/2008 15:27:45 Autorisé(e) (based on user decision) value "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" (new data: "") supprimé(e) in Global browser toolbar!
20/01/2008 15:27:46 Autorisé(e) (based on user decision) value "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" (new data: "") supprimé(e) in Browser Helper Object!
28/01/2008 12:29:38 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
28/01/2008 12:29:41 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
28/01/2008 22:19:58 Autorisé(e) (based on user decision) value "Veoh" (new data: ""C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide") ajouté(e) in System Startup user entry!
28/01/2008 22:20:00 Autorisé(e) (based on user decision) value "" (new data: "") ajouté(e) in System Startup user entry!
28/01/2008 22:20:01 Autorisé(e) (based on user decision) value "{D0943516-5076-4020-A3B5-AEFAF26AB263}" (new data: "Veoh Video Finder") ajouté(e) in Global browser toolbar!
29/01/2008 14:04:04 Autorisé(e) (based on user decision) value "QuickTime Task" (new data: ""C:\Program Files\QuickTime\QTTask.exe" -atboottime") ajouté(e) in System Startup global entry!
03/02/2008 19:05:23 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") ajouté(e) in System Startup user entry!
04/02/2008 12:06:07 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "") supprimé(e) in System Startup user entry!
11/02/2008 13:25:19 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
11/02/2008 13:25:20 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
21/02/2008 12:29:35 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "C:\Program Files\HP\HP Software Update\HPWUCli.exe") ajouté(e) in System Startup user entry!
21/02/2008 12:40:19 Autorisé(e) (based on user decision) value "HPSoftwareUpdate" (new data: "") supprimé(e) in System Startup user entry!
24/02/2008 17:32:34 Autorisé(e) (based on user decision) value "Speech Recognition" (new data: ""C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup") ajouté(e) in System Startup user entry!
26/02/2008 17:15:44 Autorisé(e) (based on user decision) value "236745dc4f54538f794532999d5814a" (new data: "msiexec.exe /x {926DEB4E-2B0A-4C5C-AE4A-BF6C06949702} /passive /qn /norestart ADOBE_SETUP=1 PROPERTY_FILE="C:\Users\Qentin\AppData\Local\Temp\adb2993.tmp"") ajouté(e) in System Startup global entry!
26/02/2008 17:20:38 Autorisé(e) (based on user decision) value "236745dc4f54538f794532999d5814a" (new data: "") supprimé(e) in System Startup global entry!
26/02/2008 17:51:17 Autorisé(e) (based on user decision) value "Acrobat Assistant 8.0" (new data: ""C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"") ajouté(e) in System Startup global entry!
26/02/2008 17:51:19 Autorisé(e) (based on user decision) value "" (new data: "") ajouté(e) in System Startup global entry!
26/02/2008 17:51:21 Autorisé(e) (based on user decision) value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "hex:00") ajouté(e) in Global browser toolbar!
26/02/2008 17:51:22 Autorisé(e) (based on user decision) value "{AE7CD045-E861-484f-8273-0445EE161910}" (new data: "") ajouté(e) in Browser Helper Object!
26/02/2008 17:51:23 Autorisé(e) (based on user decision) value "{182EC0BE-5110-49C8-A062-BEB1D02A220B}" (new data: "") ajouté(e) in Global browser toolbar!
26/02/2008 17:51:28 Autorisé(e) (based on user decision) value "Ajouter au fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:30 Autorisé(e) (based on user decision) value "Convertir en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:31 Autorisé(e) (based on user decision) value "Convertir la cible du lien en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:31 Autorisé(e) (based on user decision) value "Convertir la cible du lien en un fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:31 Autorisé(e) (based on user decision) value "Convertir la sélection en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:32 Autorisé(e) (based on user decision) value "Convertir la sélection en un fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:32 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:51:34 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en un fichier PDF existant" (new data: "") ajouté(e) in Browser menu extension!
26/02/2008 17:57:53 Autorisé(e) (based on user decision) value "Adobe_ID0EYTHM" (new data: "C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE") ajouté(e) in System Startup global entry!
26/02/2008 17:57:54 Autorisé(e) (based on user decision) value "{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}" (new data: "0") ajouté(e) in Global browser toolbar!
26/02/2008 17:57:55 Autorisé(e) (based on user decision) value "{074C1DC5-9320-4A9A-947D-C042949C6216}" (new data: "") ajouté(e) in Browser Helper Object!
27/02/2008 16:11:04 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en fichier Adobe PDF" (new data: "") ajouté(e) in Browser menu extension!
27/02/2008 16:11:07 Autorisé(e) (based on user decision) value "Convertir les liens sélectionnés en Adobe PDF" (new data: "") supprimé(e) in Browser menu extension!
27/02/2008 16:11:10 Autorisé(e) (based on user decision) value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "hex:39,35,83,47,C5,D0,25,41,9F,A8,08,19,E2,EA,AC,93") ajouté(e) in User-specific browser toolbar!
28/02/2008 17:28:41 Autorisé(e) (based on user decision) value "PMCRemote" (new data: "") supprimé(e) in System Startup user entry!
28/02/2008 17:29:39 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{F38AD~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{F38AD~1\reboot.ini") ajouté(e) in System Startup global entry!
28/02/2008 17:45:48 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
28/02/2008 17:46:27 Autorisé(e) (based on user decision) value "Speech Recognition" (new data: "") supprimé(e) in System Startup user entry!
03/03/2008 23:29:29 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
03/03/2008 23:29:31 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
04/03/2008 14:02:15 Autorisé(e) (based on user decision) value "Adobe Photo Downloader" (new data: ""C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe"") ajouté(e) in System Startup global entry!
04/03/2008 22:20:15 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe") ajouté(e) in System Startup user entry!
04/03/2008 23:21:51 Autorisé(e) (based on user whitelist) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") ajouté(e) in System Startup user entry!
05/03/2008 07:33:02 Autorisé(e) (based on user decision) value "FlashPlayerUpdate" (new data: "") supprimé(e) in System Startup user entry!
05/03/2008 18:39:46 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
10/03/2008 20:30:48 Autorisé(e) (based on user whitelist) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") ajouté(e) in System Startup user entry!
11/03/2008 19:35:51 Autorisé(e) (based on user decision) value "TkBellExe" (new data: ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot") ajouté(e) in System Startup global entry!
11/03/2008 19:36:31 Autorisé(e) (based on user decision) value "{3049C3E9-B461-4BC5-8870-4C09146192CA}" (new data: "") ajouté(e) in Browser Helper Object!
11/03/2008 19:39:30 Autorisé(e) (based on user decision) value "{3049C3E9-B461-4BC5-8870-4C09146192CA}" (new data: "") supprimé(e) in Browser Helper Object!
11/03/2008 19:39:32 Autorisé(e) (based on user decision) value "TkBellExe" (new data: ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot") modifié(e) in System Startup global entry!
12/03/2008 20:46:57 Autorisé(e) (based on user decision) value "Veoh" (new data: "") supprimé(e) in System Startup user entry!
18/03/2008 19:11:45 Autorisé(e) (based on user decision) value "AdobeUpdater" (new data: "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe") ajouté(e) in System Startup user entry!
27/03/2008 22:47:26 Autorisé(e) (based on user decision) value "WMPNSCFG" (new data: "") supprimé(e) in System Startup user entry!
28/03/2008 11:00:25 Autorisé(e) (based on user decision) value "AlcoholAutomount" (new data: ""C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount") ajouté(e) in System Startup user entry!
02/04/2008 23:14:04 Autorisé(e) (based on user decision) value "QuickTime Task" (new data: "") supprimé(e) in System Startup global entry!
02/04/2008 23:15:49 Autorisé(e) (based on user decision) value "QuickTime Task" (new data: ""C:\Program Files\QuickTime\QTTask.exe" -atboottime") ajouté(e) in System Startup global entry!
02/04/2008 23:18:16 Autorisé(e) (based on user decision) value "iTunesHelper" (new data: ""C:\Program Files\iTunes\iTunesHelper.exe"") ajouté(e) in System Startup global entry!
02/04/2008 23:51:28 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
02/04/2008 23:51:29 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
03/04/2008 00:09:16 Autorisé(e) (based on user decision) value "AdobeUpdater" (new data: "") supprimé(e) in System Startup user entry!
03/04/2008 00:10:06 Autorisé(e) (based on user decision) value "Adobe Photo Downloader" (new data: "") supprimé(e) in System Startup global entry!
03/04/2008 16:06:16 Autorisé(e) (based on user decision) value "AlcoholAutomount" (new data: "") supprimé(e) in System Startup user entry!
22/04/2008 13:36:42 Autorisé(e) (based on user decision) value "{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}" (new data: "") ajouté(e) in ActiveX Distribution Unit!
22/04/2008 13:36:50 Autorisé(e) (based on user decision) value "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (new data: "") ajouté(e) in Internet Explorer searches!
22/04/2008 13:36:53 Autorisé(e) (based on user decision) value "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (new data: "hex:00") ajouté(e) in Global browser toolbar!
22/04/2008 13:36:56 Autorisé(e) (based on user decision) value "{02478D38-C3F9-4EFB-9B51-7695ECA05670}" (new data: "") ajouté(e) in Browser Helper Object!
22/04/2008 13:49:01 Autorisé(e) (based on user decision) value "PMCLoader" (new data: "") supprimé(e) in System Startup user entry!
23/04/2008 13:16:27 Autorisé(e) (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") modifié(e) in Session manager!
24/04/2008 12:42:02 Autorisé(e) (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") modifié(e) in Session manager!
27/04/2008 22:24:14 Autorisé(e) (based on user decision) value "ITBarLayout" (new data: "hex:11,00,00,00,00,00,00,00,00,00,00,00,04,00,00,00,1F,00,0F,00,00,00,00,00,01,00,00,00,00,00,00,00,A0,0F,00,00,05,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,A0,0F,00,00,04,00,00,00,01,00,00,00,A0,0F,00,00,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,16,35,94,D0,76,50,20,40,A3,B5,AE,FA,F2,6A,B2,63,39,35,83,47,C5,D0,25,41,9F,A8,08,19,E2,EA,AC,93,E4,DD,7B,51,A7,E3,70,45,B2,1E,2B,52,B6,13,9F,C7,32,BD,99,EF,FB,C1,D2,11,89,2F,00,90,27,1D,4F,88,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,") ajouté(e) in User-specific browser toolbar!
29/04/2008 12:00:43 Autorisé(e) (based on user decision) value "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (new data: "") supprimé(e) in Global browser toolbar!
29/04/2008 12:00:43 Autorisé(e) (based on user whitelist) value "{02478D38-C3F9-4EFB-9B51-7695ECA05670}" (new data: "") supprimé(e) in Browser Helper Object!
29/04/2008 12:00:57 Autorisé(e) (based on user decision) value "{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}" (new data: "") supprimé(e) in ActiveX Distribution Unit!
05/05/2008 07:25:48 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
05/05/2008 07:25:49 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
15/05/2008 19:20:23 Autorisé(e) (based on user decision) value "GrpConv" (new data: "grpconv -o") ajouté(e) in System Startup global entry!
15/05/2008 19:20:25 Autorisé(e) (based on user decision) value "GrpConv" (new data: "") supprimé(e) in System Startup global entry!
22/05/2008 13:48:46 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~1\INSTAL~1\{F38AD~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{F38AD~1\reboot.ini") ajouté(e) in System Startup global entry!
22/05/2008 15:25:31 Autorisé(e) (based on user decision) value "InstallShieldSetup" (new data: "") supprimé(e) in System Startup global entry!
22/05/2008 15:25:33 Autorisé(e) (based on user whitelist) value "PMCRemote" (new data: "C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe") ajouté(e) in System Startup user entry!
22/05/2008 15:25:34 Autorisé(e) (based on user decision) value "LaunchList" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\LaunchList2.exe") ajouté(e) in System Startup user entry!
22/05/2008 15:30:26 Autorisé(e) (based on user decision) value "LaunchList" (new data: "") supprimé(e) in System Startup user entry!
22/05/2008 15:43:36 Autorisé(e) (based on user whitelist) value "PMCLoader" (new data: "C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks") ajouté(e) in System Startup user entry!
03/06/2008 22:02:43 Autorisé(e) (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qentin\AppData\Local\Temp\IXP000.TMP\"") ajouté(e) in System Startup global entry!
03/06/2008 22:02:44 Autorisé(e) (based on user whitelist) value "wextract_cleanup0" (new data: "") supprimé(e) in System Startup global entry!
09/06/2008 11:41:12 Autorisé(e) (based on user decision) value "BootExecute" (new data: "") supprimé(e) in Session manager!
09/06/2008 11:41:13 Autorisé(e) (based on user decision) value "ExcludeFromKnownDlls" (new data: "") supprimé(e) in Session manager!
09/06/2008 18:14:09 Autorisé(e) (based on user decision) value "Local Page" (new data: "") supprimé(e) in Browser page!
14/06/2008 20:38:58 Autorisé(e) (based on user decision) value "TOSCDSPD" (new data: "") supprimé(e) in System Startup user entry!
14/06/2008 20:39:02 Autorisé(e) (based on user decision) value "RtHDVCpl" (new data: "") supprimé(e) in System Startup global entry!
14/06/2008 20:39:03 Autorisé(e) (based on user decision) value "HWSetup" (new data: "") supprimé(e) in System Startup global entry!
14/06/2008 20:39:03 Autorisé(e) (based on user decision) value "NDSTray.exe" (new data: "") supprimé(e) in System Startup global entry!
14/06/2008 20:39:04 Autorisé(e) (based on user decision) value "Kernel and Hardware Abstraction Layer" (new data: "") supprimé(e) in System Startup global entry!
Utilisateur anonyme
14 juin 2008 à 21:09
14 juin 2008 à 21:09
1) Télécharge Malwarebytes' Anti-Malware.
*Télécharge et installe Malwarebyte's Anti-Malware
*http://www.commentcamarche.net/telecharger/telechargement 34055379 malwarebyte s anti malware
*A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
*Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
*Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
*Laisse les Mises à jour se télécharger
*** Referme le programme ***
2) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
3) Scan avec Malwarebyte's Anti-Malware
*Lance Malwarebyte's Anti-Malware
*Puis vs dans l'onglet "Recherche" puis coche "Exécuter un examen complet" puis "Rechercher sélectionne tes disques durs" puis clique sur "Lancer l’examen"
*A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
*Suppression des éléments détectés >>>> clique sur Supprimer la sélection
*S'il t'es demandé de redémarrer >>> clique sur "Yes"
*--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
*Télécharge et installe Malwarebyte's Anti-Malware
*http://www.commentcamarche.net/telecharger/telechargement 34055379 malwarebyte s anti malware
*A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
*Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
*Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
*Laisse les Mises à jour se télécharger
*** Referme le programme ***
2) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
3) Scan avec Malwarebyte's Anti-Malware
*Lance Malwarebyte's Anti-Malware
*Puis vs dans l'onglet "Recherche" puis coche "Exécuter un examen complet" puis "Rechercher sélectionne tes disques durs" puis clique sur "Lancer l’examen"
*A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
*Suppression des éléments détectés >>>> clique sur Supprimer la sélection
*S'il t'es demandé de redémarrer >>> clique sur "Yes"
*--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
9 juin 2008 à 20:13
Comment redémarrer en mode sans échec:
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparait rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
12 juin 2008 à 17:43
Merci de bien vouloir m'aider!
12 juin 2008 à 17:48
Comment redémarrer en mode sans échec:
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparait rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
13 juin 2008 à 20:24
14 juin 2008 à 19:27