Suspection d'un virus.
Résolu
pwet59
Messages postés
107
Date d'inscription
Statut
Membre
Dernière intervention
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
Je suspecte la présence d'un virus sur mon PC.
Ma connexion Internet est lente. Certains jours, j'utilise Internet pendant 10 minutes puis même étant toujours connecté, les pages ne s'affichent plus.
Mon PC est très long à s'éteindre. Je ne suis plus quoi faire. C'est très embêtant.
Dois-je vous poster un rapport HijackThis ?
Merci à vous.
Je suspecte la présence d'un virus sur mon PC.
Ma connexion Internet est lente. Certains jours, j'utilise Internet pendant 10 minutes puis même étant toujours connecté, les pages ne s'affichent plus.
Mon PC est très long à s'éteindre. Je ne suis plus quoi faire. C'est très embêtant.
Dois-je vous poster un rapport HijackThis ?
Merci à vous.
A voir également:
- Suspection d'un virus.
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Undisclosed-recipients virus - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Impossible de terminer l'opération car le fichier contient un virus - Forum Virus
101 réponses
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
C'est bon, le scan BitDefender a été fait depuis belle lurette et posté sur ce topic depuis belle lurette aussi..
C'est bon, le scan BitDefender a été fait depuis belle lurette et posté sur ce topic depuis belle lurette aussi.. hein ?
Il y a eu un bug sur le forum je n'avai qu'une seule page sur notre soucis hors qu'on en est à 4!
@+
Il y a eu un bug sur le forum je n'avai qu'une seule page sur notre soucis hors qu'on en est à 4!
@+
Certains jours, j'utilise Internet pendant 10 minutes puis même étant toujours connecté, les pages ne s'affichent plus.
Mon PC est très long à s'éteindre.
Quoique l'extinction, ça s'est un peu amélioré.
J'ai fait un rapport Diaghelp :
DiagHelp version v1.4 - http://www.malekal.com
excute le 23/06/2008 à 21:14:05,85
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\Windows\prefetch\CHCP.COM-61043047.pf -->23/06/2008 21:14:04
C:\Windows\prefetch\DLLHOST.EXE-5E46FA0D.pf -->23/06/2008 21:13:55
C:\Windows\prefetch\WMPNSCFG.EXE-FC0D39BF.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\SPMGR.EXE-AC500AB9.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\NTOSBOOT-B00DFAAD.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\AVAST.SETUP-499863F4.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\AgGlFgAppHistory.db -->23/06/2008 21:10:14
C:\Windows\prefetch\AgGlFaultHistory.db -->23/06/2008 21:10:14
C:\Windows\prefetch\PfSvPerfStats.bin -->23/06/2008 21:10:13
C:\Windows\prefetch\AgRobust.db -->23/06/2008 21:10:13
C:\Windows\System32\drivers\vsconfig.xml -->23/06/2008 21:13:13
C:\Windows\System32\drivers\vsconfig(73).xml -->08/06/2008 12:04:30
C:\Windows\System32\drivers\SYMEVENT.INF -->31/05/2008 10:51:52
C:\Windows\System32\drivers\SYMEVENT.CAT -->31/05/2008 10:51:52
C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf -->24/05/2008 18:13:22
C:\Windows\System32\drivers\aswSP.sys -->16/05/2008 01:20:32
C:\Windows\System32\drivers\aswMonFlt.sys -->16/05/2008 01:18:00
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->23/06/2008 21:12:56
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->23/06/2008 21:12:56
C:\Windows\System32\PerfStringBackup.INI -->23/06/2008 20:57:32
C:\Windows\System32\perfh00C.dat -->23/06/2008 20:57:32
C:\Windows\System32\perfh009.dat -->23/06/2008 20:57:32
C:\Windows\System32\perfc00C.dat -->23/06/2008 20:57:32
C:\Windows\System32\perfc009.dat -->23/06/2008 20:57:32
C:\Windows\System32\temp.reg -->23/06/2008 16:30:31
C:\Windows\System32\TuneUpDefragService.exe -->23/06/2008 01:20:52
C:\Windows\System32\jupdate-1.6.0_06-b02.log -->22/06/2008 21:21:44
C:\Windows\System32\mlfcache.dat -->22/06/2008 14:46:32
C:\Windows\System32\config.nt -->20/06/2008 10:53:20
C:\Windows\System32\FNTCACHE.DAT -->10/06/2008 22:43:55
C:\Windows\System32\vsconfig.xml -->04/06/2008 10:24:02
C:\Windows\System32\mrt.exe -->30/05/2008 01:35:11
C:\Windows\System32\uxtuneup.dll -->29/05/2008 09:28:54
C:\Windows\System32\authuitu.dll -->29/05/2008 09:28:52
C:\Windows\System32\ifxcardm.dll -->23/05/2008 17:31:51
C:\Windows\System32\axaltocm.dll -->23/05/2008 17:31:50
C:\Windows\System32\aswBoot.exe -->16/05/2008 01:24:43
C:\Windows\System32\AvastSS.scr -->16/05/2008 01:12:36
C:\Windows\System32\quartz.dll -->26/04/2008 10:08:15
C:\Windows\System32\wininet.dll -->25/04/2008 06:35:23
C:\Windows\System32\urlmon.dll -->25/04/2008 06:35:19
C:\Windows\System32\mstime.dll -->25/04/2008 06:35:16
C:\Windows\bootstat.dat -->23/06/2008 21:12:45
C:\Windows\WindowsUpdate.log -->23/06/2008 21:10:12
C:\Windows\bthservsdp.dat -->23/06/2008 21:10:12
C:\Windows\QTFont.qfn -->22/06/2008 14:55:15
C:\Windows\system.ini -->10/06/2008 23:53:17
C:\Windows\WindowsShell.Manifest -->23/05/2008 18:12:28
C:\Windows\QTFont.for -->02/05/2008 18:43:11
C:\Windows\nsreg.dat -->19/04/2008 11:48:53
C:\Windows\ODBCINST.INI -->15/04/2008 23:28:30
C:\Windows\regedit.exe -->19/01/2008 09:33:24
C:\Windows\notepad.exe -->19/01/2008 09:33:18
C:\Windows\HelpPane.exe -->19/01/2008 09:33:11
C:\Windows\fveupdate.exe -->19/01/2008 09:33:11
C:\Windows\explorer.exe -->19/01/2008 09:33:10
C:\Windows\bfsvc.exe -->19/01/2008 09:33:01
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1760
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x00fb0000 0x2cd000 6.00.6001.18000 C:\Windows\Explorer.EXE
0x77ed0000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x77790000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x767a0000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x76870000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x769d0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x766f0000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x77a40000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x77cb0000 0x58000 6.00.6001.18000 C:\Windows\system32\SHLWAPI.dll
0x76c80000 0xb0f000 6.00.6001.18000 C:\Windows\system32\SHELL32.dll
0x77d60000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x76a20000 0x8d000 6.00.6001.18000 C:\Windows\system32\OLEAUT32.dll
0x73ae0000 0x107000 6.00.6001.18000 C:\Windows\system32\SHDOCVW.dll
0x75590000 0x3f000 6.00.6001.18000 C:\Windows\system32\UxTheme.dll
0x75950000 0x1a000 6.00.6001.18000 C:\Windows\system32\POWRPROF.dll
0x74320000 0xc000 6.00.6001.18000 C:\Windows\system32\dwmapi.dll
0x74cb0000 0x1ab000 5.02.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll
0x75f20000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x74bf0000 0xba000 6.00.6001.18000 C:\Windows\system32\PROPSYS.dll
0x73990000 0x146000 6.00.6001.18000 C:\Windows\system32\BROWSEUI.dll
0x77eb0000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.dll
0x76620000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x75560000 0x30000 6.00.6001.18000 C:\Windows\system32\DUser.dll
0x76790000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x77870000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x75370000 0x19e000 6.10.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
0x74350000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x73890000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x764b0000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x76940000 0x84000 2001.12.6931.18000 C:\Windows\system32\CLBCatQ.DLL
0x759f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x73780000 0xb2000 6.00.6001.18000 C:\Windows\system32\timedate.cpl
0x74b00000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x76100000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x76580000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x74ee0000 0x39000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x71090000 0x53000 6.00.6001.18000 C:\Windows\System32\actxprxy.dll
0x764d0000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x71470000 0x1b000 11.00.6001.7000 C:\PROGRA~1\WI4EB4~1\wmpband.dll
0x76060000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
0x714d0000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x75ab0000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x74e80000 0x16000 6.00.6001.18000 C:\Windows\System32\shacct.dll
0x760e0000 0x11000 6.00.6001.18000 C:\Windows\System32\SAMLIB.dll
0x76450000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x71040000 0x41000 6.00.6001.18000 C:\Windows\System32\msshsq.dll
0x70390000 0xc6000 6.00.6001.18000 C:\Windows\System32\NaturalLanguage6.dll
0x75f60000 0xf1000 6.00.6001.18000 C:\Windows\System32\CRYPT32.dll
0x760c0000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x75080000 0x1e8000 6.00.6001.18000 C:\Windows\system32\authui.dll
0x75940000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x77af0000 0x129000 7.00.6001.18063 C:\Windows\system32\urlmon.dll
0x77c60000 0x45000 7.00.6001.18000 C:\Windows\system32\iertutil.dll
0x75970000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77d10000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77c20000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77c50000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x6f6d0000 0x5ce000 7.00.6001.18000 C:\Windows\system32\ieframe.dll
0x74f20000 0x32000 6.00.6001.18000 C:\Windows\system32\WINMM.dll
0x710f0000 0x16000 6.00.6001.18000 C:\Windows\system32\thumbcache.dll
0x73c00000 0x2f000 6.00.6001.18000 C:\Windows\system32\wdmaud.drv
0x73bf0000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x74b60000 0x27000 6.00.6001.18000 C:\Windows\system32\MMDevAPI.DLL
0x74ed0000 0x7000 6.00.6001.18000 C:\Windows\system32\AVRT.dll
0x70ff0000 0x4a000 6.00.6001.18000 C:\Windows\system32\ntshrui.dll
0x71460000 0xb000 6.00.6001.18000 C:\Windows\system32\cscapi.dll
0x76ab0000 0x18a000 6.00.6001.18000 C:\Windows\system32\SETUPAPI.dll
0x75770000 0x2d000 6.00.6001.18000 C:\Windows\system32\WINTRUST.dll
0x76c40000 0x29000 6.00.6001.18000 C:\Windows\system32\imagehlp.dll
0x71140000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
0x75ce0000 0x8000 6.00.6001.18000 C:\Windows\system32\VERSION.dll
0x6ffb0000 0x202000 4.00.6001.18000 C:\Windows\system32\msi.dll
0x73960000 0x21000 6.00.6001.18000 C:\Windows\system32\AUDIOSES.DLL
0x738f0000 0x66000 6.00.6001.18000 C:\Windows\system32\audioeng.dll
0x71130000 0x9000 6.00.6001.18000 C:\Windows\system32\ExplorerFrame.dll
0x77970000 0xd0000 7.00.6001.18063 C:\Windows\system32\WININET.dll
0x76c70000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x738e0000 0x9000 6.00.6001.18000 C:\Windows\system32\msacm32.drv
0x738c0000 0x14000 6.00.6001.18000 C:\Windows\system32\MSACM32.dll
0x738b0000 0x7000 6.00.6001.18000 C:\Windows\system32\midimap.dll
0x6e3d0000 0x92000 6.00.6001.18000 C:\Windows\system32\stobject.dll
0x6e310000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x75750000 0xa000 6.00.6001.18000 C:\Windows\system32\WTSAPI32.dll
0x757a0000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x6f180000 0x28c000 6.00.6001.18000 C:\Windows\System32\NLSData000c.dll
0x6c400000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x74410000 0x45000 2001.12.6931.18000 C:\Windows\system32\es.dll
0x6fea0000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x6fe70000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x74af0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x75880000 0x66000 6.00.6001.18000 C:\Windows\system32\FirewallAPI.dll
0x6c0f0000 0x30b000 6.00.6001.18000 C:\Windows\System32\netshell.dll
0x75ec0000 0x19000 6.00.6001.18000 C:\Windows\System32\IPHLPAPI.DLL
0x75e80000 0x35000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc.DLL
0x76180000 0x2c000 6.00.6001.18000 C:\Windows\System32\DNSAPI.dll
0x763f0000 0x7000 6.00.6001.18000 C:\Windows\System32\WINNSI.DLL
0x75e50000 0x21000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc6.DLL
0x74b30000 0xf000 6.00.6001.18000 C:\Windows\System32\nlaapi.dll
0x6f4e0000 0x1bf000 6.00.6001.18000 C:\Windows\system32\pnidui.dll
0x72a70000 0x17000 6.00.6001.18000 C:\Windows\system32\QUtil.dll
0x75ee0000 0x40000 6.00.6001.18000 C:\Windows\system32\wevtapi.dll
0x73270000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x71fe0000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x72660000 0x27000 6.00.6001.18000 C:\Windows\system32\FunDisc.dll
0x70740000 0x9000 6.00.6000.16386 C:\Windows\system32\fdproxy.dll
0x723d0000 0x126000 8.100.1043.0000 C:\Windows\System32\msxml3.dll
0x72a10000 0x12000 6.00.6001.18000 C:\Windows\system32\Wlanapi.dll
0x734a0000 0x17c000 6.00.6001.18000 C:\Windows\system32\OneX.DLL
0x738a0000 0xe000 6.00.6001.18000 C:\Windows\system32\eappprxy.dll
0x732b0000 0x24000 6.00.6001.18000 C:\Windows\system32\eappcfg.dll
0x75db0000 0x45000 6.00.6001.18000 C:\Windows\system32\bcrypt.dll
0x6fed0000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x6f150000 0x23000 6.00.6001.18000 C:\Windows\system32\wpdshserviceobj.dll
0x72e20000 0x5f000 6.00.6001.18000 C:\Windows\system32\WINHTTP.dll
0x6f100000 0x43000 6.00.6001.18000 C:\Windows\System32\srchadmin.dll
0x6f0c0000 0x3c000 7.00.6001.18000 C:\Windows\system32\webcheck.dll
0x6cde0000 0x21c000 6.00.6001.18000 C:\Windows\System32\SyncCenter.dll
0x6fcb0000 0x39000 6.00.6001.18000 C:\Windows\system32\wscntfy.dll
0x73260000 0xb000 6.00.6001.18000 C:\Windows\system32\WSCAPI.dll
0x71820000 0xb000 6.00.6001.18000 C:\Windows\system32\mssprxy.dll
0x72a30000 0x2e000 6.00.6001.18000 C:\Windows\System32\QAgent.dll
0x72d20000 0x96000 6.00.6001.18000 C:\Windows\System32\fwpuclnt.dll
0x67080000 0x1c000 3.00.0010.0000 C:\Program Files\FileZilla FTP Client\fzshellext.dll
0x6e2b0000 0x51000 6.00.6001.18000 C:\Windows\system32\imapi2.dll
0x75c70000 0x3b000 6.00.6001.18000 C:\Windows\system32\mswsock.dll
0x75930000 0x5000 6.00.6001.18000 C:\Windows\System32\wshtcpip.dll
0x10000000 0x2e000 6.01.0000.1205 C:\Windows\system32\btncopy.dll
0x75cd0000 0x5000 6.00.6001.18000 C:\Windows\System32\wship6.dll
0x73130000 0xf000 6.00.6001.18000 C:\Windows\system32\napinsp.dll
0x72f20000 0x12000 6.00.6001.18000 C:\Windows\system32\pnrpnsp.dll
0x73120000 0xc000 6.00.6000.16386 C:\Windows\system32\wshbth.dll
0x72f50000 0x8000 6.00.6000.16386 C:\Windows\System32\winrnr.dll
0x16080000 0x25000 1.00.0004.0012 C:\Program Files\Bonjour\mdnsNSP.dll
0x73140000 0x6000 6.00.6000.16386 C:\Windows\system32\rasadhlp.dll
0x76390000 0x5f000 6.00.6001.18000 C:\Windows\system32\SXS.DLL
0x706c0000 0x2b000 6.00.6001.18000 C:\Windows\system32\PortableDeviceTypes.dll
0x71870000 0x46000 6.00.6001.18000 C:\Windows\system32\PortableDeviceApi.dll
0x6cce0000 0xf9000 6.00.6001.18000 C:\Windows\system32\bthprops.cpl
0x6e250000 0x60000 6.00.6001.18000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x75050000 0x2f000 1.02.1009.0000 C:\Windows\system32\xmllite.dll
0x6e640000 0x13000 6.00.6001.18000 C:\Windows\System32\ntlanman.dll
0x6fe20000 0x8000 6.00.6000.16386 C:\Windows\System32\drprov.dll
0x6fca0000 0xf000 6.00.6000.16386 C:\Windows\System32\davclnt.dll
0x02980000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
0x02990000 0x9000 2.00.0000.0004 C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll
0x6e4b0000 0x2e000 6.00.6001.18000 C:\Windows\system32\syncui.dll
0x6f0a0000 0x16000 6.00.6001.18000 C:\Windows\system32\SYNCENG.dll
0x029e0000 0x2a000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
0x64f00000 0x12000 4.08.1201.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
0x02a10000 0x13000 4.57.0000.0000 C:\Program Files\7-Zip\7-zip.dll
0x721e0000 0x6000 6.00.6000.16386 C:\Windows\system32\dciman32.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 976
Command line: winlogon.exe
Base Size Version Path
0x00920000 0x50000 6.00.6001.18000 C:\Windows\system32\winlogon.exe
0x77ed0000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x77790000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x767a0000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x76870000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x766f0000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x769d0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x77a40000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x764b0000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x757a0000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x76580000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x764d0000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x77eb0000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
0x76620000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x76790000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x77870000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x76450000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x75970000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77d10000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77c20000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77c50000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x760e0000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
0x77d60000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x55580000 0xb000 2.00.0000.0012 c:\windows\system32\uxtuneup.dll
0x755d0000 0xdc000 6.00.6001.18000 C:\Windows\system32\dbghelp.dll
0x75590000 0x3f000 6.00.6001.18000 C:\Windows\system32\uxtheme.dll
0x748e0000 0x3e000 6.00.6001.18000 C:\Windows\system32\shsvcs.dll
0x759f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x74350000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x76100000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x75f20000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x76060000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Windows\system32
19/01/2008 09:33 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 68 911 308 800 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Windows\Downloaded Program Files
22/06/2008 16:54 <REP> .
22/06/2008 16:54 <REP> ..
07/12/2004 17:07 32 bdcore.dll
25/05/2006 01:21 118 784 bdupd.dll
18/09/2006 23:26 65 desktop.ini
25/05/2006 01:21 53 248 ipsupd.dll
08/08/2006 11:45 576 kavwebscan.inf
16/03/2005 12:34 7 407 lang.ini
07/12/2004 17:07 32 libfn.dll
13/02/2008 17:55 130 live.ini
29/10/2007 16:45 1 244 oscan8.inf
25/10/2007 16:54 471 040 oscan8.ocx
14/03/2005 14:58 7 073 scanoptions.tsi
11 fichier(s) 659 631 octets
Total des fichiers listés :
11 fichier(s) 659 631 octets
2 Rép(s) 68 911 308 800 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
REGEDIT4
[iexplore.exe]
"ExecuteOptions"=dword:00000001
REGEDIT4
[taskmgr.exe]
exports des policies
REGEDIT4
[System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
"DisableRegistryTools"=dword:00000000
"HideLegacyLogonScripts"=dword:00000000
"HideLogoffScripts"=dword:00000000
"RunLogonScriptSync"=dword:00000001
"RunStartupScriptSync"=dword:00000000
"HideStartupScripts"=dword:00000000
[System\UIPI]
[System\UIPI\Clipboard]
[System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-23 21:14:37
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0019c1ea150f]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0019c1ea150f]
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files
23/06/2008 01:20 <REP> .
23/06/2008 01:20 <REP> ..
19/04/2008 12:40 <REP> 7-Zip
17/08/2007 15:37 <REP> Activation Assistant for the 2007 Microsoft Office suites
10/06/2008 22:33 <REP> Adobe
20/06/2008 10:53 <REP> Alwil Software
01/05/2008 19:53 <REP> Apple Software Update
08/09/2007 03:33 <REP> ArcSoft
10/06/2008 22:35 <REP> Bonjour
19/04/2008 12:08 <REP> CCleaner
01/06/2008 10:58 <REP> CDBurnerXP
23/06/2008 01:20 <REP> Common Files
10/04/2008 15:25 <REP> CONEXANT
17/08/2007 15:40 <REP> DivX
10/05/2008 21:40 <REP> eMule
20/04/2008 21:07 <REP> ffdshow
12/06/2008 22:47 <REP> FileZilla FTP Client
14/06/2008 22:53 <REP> Glary Utilities
10/06/2008 22:11 <REP> Google
17/08/2007 15:42 <REP> Google BAE
15/06/2008 00:10 <REP> GRISOFT
11/04/2008 12:57 <REP> IDT
17/08/2007 15:43 <REP> Intel
22/06/2008 23:01 <REP> Internet Explorer
08/09/2007 04:01 <REP> InterVideo
11/05/2008 10:10 <REP> Inventel
01/05/2008 19:57 <REP> iPod
01/05/2008 19:57 <REP> iTunes
22/06/2008 21:21 <REP> Java
08/06/2008 11:55 <REP> jv16 PowerTools
10/04/2008 17:14 <REP> Lecteur CANALPLAY
14/05/2008 14:13 <REP> Malwarebytes' Anti-Malware
19/04/2008 13:12 <REP> Messenger Plus! Live
02/11/2006 14:37 <REP> Microsoft Games
17/08/2007 15:42 <REP> Microsoft Office
21/05/2008 15:13 <REP> Microsoft Silverlight
17/08/2007 15:42 <REP> Microsoft Works
17/08/2007 15:35 <REP> Microsoft.NET
23/05/2008 18:02 <REP> Movie Maker
14/06/2008 22:59 <REP> Mozilla Firefox
02/11/2006 14:37 <REP> MSBuild
17/08/2007 13:55 <REP> MSXML 4.0
11/06/2008 12:31 <REP> No-IP
13/05/2008 23:19 <REP> Orange
17/08/2007 15:42 <REP> Picasa2
19/04/2008 14:57 <REP> QuickTime
17/08/2007 14:21 <REP> Realtek
02/11/2006 14:37 <REP> Reference Assemblies
08/09/2007 03:36 <REP> Roxio
22/06/2008 16:29 <REP> Safari
11/05/2008 11:28 <REP> Securitoo
11/04/2008 12:57 <REP> Sigmatel
08/09/2007 03:38 <REP> Skype
19/06/2008 23:25 <REP> Sony
11/04/2008 12:47 <REP> Sony Corporation
20/06/2008 11:37 <REP> Sophos
17/08/2007 14:41 <REP> Synaptics
13/06/2008 09:56 <REP> Tenable
02/05/2008 20:32 <REP> Trend Micro
07/05/2008 22:39 <REP> TubeMaster
23/06/2008 01:20 <REP> TuneUp Utilities 2008
07/05/2008 22:45 <REP> UnH Solutions
23/06/2008 01:11 <REP> Uniblue
17/08/2007 14:34 <REP> WIDCOMM
23/05/2008 18:02 <REP> Windows Calendar
23/05/2008 18:02 <REP> Windows Collaboration
23/05/2008 18:02 <REP> Windows Defender
23/05/2008 18:02 <REP> Windows Journal
19/04/2008 13:05 <REP> Windows Live
11/06/2008 11:43 <REP> Windows Mail
23/05/2008 18:02 <REP> Windows Media Player
17/08/2007 12:10 <REP> Windows NT
23/05/2008 18:02 <REP> Windows Photo Gallery
23/05/2008 18:02 <REP> Windows Sidebar
22/06/2008 21:24 <REP> ZebHelpProcess 2
11/06/2008 19:57 <REP> Zeb-Utility
04/06/2008 10:23 <REP> Zone Labs
0 fichier(s) 0 octets
77 Rép(s) 68 892 999 680 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files\fichiers communs
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files\common files
23/06/2008 01:20 <REP> .
23/06/2008 01:20 <REP> ..
11/05/2008 11:26 <REP> Acronis
10/06/2008 22:33 <REP> Adobe
01/05/2008 19:56 <REP> Apple
02/05/2008 19:05 <REP> Borland Shared
17/08/2007 15:35 <REP> DESIGNER
11/05/2008 11:34 <REP> France Telecom
08/09/2007 03:33 <REP> InstallShield
08/09/2007 04:01 <REP> InterVideo
17/08/2007 15:45 <REP> Java
19/04/2008 12:42 <REP> Macrovision Shared
19/04/2008 13:05 <REP> microsoft shared
17/08/2007 15:40 <REP> PX Storage Engine
08/09/2007 03:36 <REP> Roxio Shared
02/11/2006 13:18 <REP> Services
08/09/2007 03:38 <REP> Skype
08/09/2007 03:36 <REP> Sonic Shared
16/05/2008 20:02 <REP> Sony Shared
02/11/2006 13:18 <REP> SpeechEngines
04/06/2008 10:16 <REP> Symantec Shared
23/05/2008 18:02 <REP> System
23/06/2008 01:20 <REP> Wise Installation Wizard
0 fichier(s) 0 octets
23 Rép(s) 68 892 999 680 octets libres
c:\Users\Yohann\Documents\DRIVERS\EP0000144470.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000144835.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000144842.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000145798.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000146911.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000148249.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000148661.exe
c:\Users\Yohann\Documents\DRIVERS\ITAOTH-01453102-UN.exe
c:\Users\Yohann\Documents\DRIVERS\NVDVID-01587600-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOACCU-01363007-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAMAF-01590304-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAMST-01593102-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVCF-01581004-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVCX-01594900-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVEP-01580500-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVMB-01581501-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578801-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578803-UN.exe
c:\Users\Yohann\Documents\DRIVERS\STDAUD-01487701-UN.exe
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_PC-de-Yohann.tar.gz a l'adresse http://upload.malekal.com
Mon PC est très long à s'éteindre.
Quoique l'extinction, ça s'est un peu amélioré.
J'ai fait un rapport Diaghelp :
DiagHelp version v1.4 - http://www.malekal.com
excute le 23/06/2008 à 21:14:05,85
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\Windows\prefetch\CHCP.COM-61043047.pf -->23/06/2008 21:14:04
C:\Windows\prefetch\DLLHOST.EXE-5E46FA0D.pf -->23/06/2008 21:13:55
C:\Windows\prefetch\WMPNSCFG.EXE-FC0D39BF.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\SPMGR.EXE-AC500AB9.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\NTOSBOOT-B00DFAAD.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\AVAST.SETUP-499863F4.pf -->23/06/2008 21:13:49
C:\Windows\prefetch\AgGlFgAppHistory.db -->23/06/2008 21:10:14
C:\Windows\prefetch\AgGlFaultHistory.db -->23/06/2008 21:10:14
C:\Windows\prefetch\PfSvPerfStats.bin -->23/06/2008 21:10:13
C:\Windows\prefetch\AgRobust.db -->23/06/2008 21:10:13
C:\Windows\System32\drivers\vsconfig.xml -->23/06/2008 21:13:13
C:\Windows\System32\drivers\vsconfig(73).xml -->08/06/2008 12:04:30
C:\Windows\System32\drivers\SYMEVENT.INF -->31/05/2008 10:51:52
C:\Windows\System32\drivers\SYMEVENT.CAT -->31/05/2008 10:51:52
C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf -->24/05/2008 18:13:22
C:\Windows\System32\drivers\aswSP.sys -->16/05/2008 01:20:32
C:\Windows\System32\drivers\aswMonFlt.sys -->16/05/2008 01:18:00
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->23/06/2008 21:12:56
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->23/06/2008 21:12:56
C:\Windows\System32\PerfStringBackup.INI -->23/06/2008 20:57:32
C:\Windows\System32\perfh00C.dat -->23/06/2008 20:57:32
C:\Windows\System32\perfh009.dat -->23/06/2008 20:57:32
C:\Windows\System32\perfc00C.dat -->23/06/2008 20:57:32
C:\Windows\System32\perfc009.dat -->23/06/2008 20:57:32
C:\Windows\System32\temp.reg -->23/06/2008 16:30:31
C:\Windows\System32\TuneUpDefragService.exe -->23/06/2008 01:20:52
C:\Windows\System32\jupdate-1.6.0_06-b02.log -->22/06/2008 21:21:44
C:\Windows\System32\mlfcache.dat -->22/06/2008 14:46:32
C:\Windows\System32\config.nt -->20/06/2008 10:53:20
C:\Windows\System32\FNTCACHE.DAT -->10/06/2008 22:43:55
C:\Windows\System32\vsconfig.xml -->04/06/2008 10:24:02
C:\Windows\System32\mrt.exe -->30/05/2008 01:35:11
C:\Windows\System32\uxtuneup.dll -->29/05/2008 09:28:54
C:\Windows\System32\authuitu.dll -->29/05/2008 09:28:52
C:\Windows\System32\ifxcardm.dll -->23/05/2008 17:31:51
C:\Windows\System32\axaltocm.dll -->23/05/2008 17:31:50
C:\Windows\System32\aswBoot.exe -->16/05/2008 01:24:43
C:\Windows\System32\AvastSS.scr -->16/05/2008 01:12:36
C:\Windows\System32\quartz.dll -->26/04/2008 10:08:15
C:\Windows\System32\wininet.dll -->25/04/2008 06:35:23
C:\Windows\System32\urlmon.dll -->25/04/2008 06:35:19
C:\Windows\System32\mstime.dll -->25/04/2008 06:35:16
C:\Windows\bootstat.dat -->23/06/2008 21:12:45
C:\Windows\WindowsUpdate.log -->23/06/2008 21:10:12
C:\Windows\bthservsdp.dat -->23/06/2008 21:10:12
C:\Windows\QTFont.qfn -->22/06/2008 14:55:15
C:\Windows\system.ini -->10/06/2008 23:53:17
C:\Windows\WindowsShell.Manifest -->23/05/2008 18:12:28
C:\Windows\QTFont.for -->02/05/2008 18:43:11
C:\Windows\nsreg.dat -->19/04/2008 11:48:53
C:\Windows\ODBCINST.INI -->15/04/2008 23:28:30
C:\Windows\regedit.exe -->19/01/2008 09:33:24
C:\Windows\notepad.exe -->19/01/2008 09:33:18
C:\Windows\HelpPane.exe -->19/01/2008 09:33:11
C:\Windows\fveupdate.exe -->19/01/2008 09:33:11
C:\Windows\explorer.exe -->19/01/2008 09:33:10
C:\Windows\bfsvc.exe -->19/01/2008 09:33:01
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1760
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x00fb0000 0x2cd000 6.00.6001.18000 C:\Windows\Explorer.EXE
0x77ed0000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x77790000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x767a0000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x76870000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x769d0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x766f0000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x77a40000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x77cb0000 0x58000 6.00.6001.18000 C:\Windows\system32\SHLWAPI.dll
0x76c80000 0xb0f000 6.00.6001.18000 C:\Windows\system32\SHELL32.dll
0x77d60000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x76a20000 0x8d000 6.00.6001.18000 C:\Windows\system32\OLEAUT32.dll
0x73ae0000 0x107000 6.00.6001.18000 C:\Windows\system32\SHDOCVW.dll
0x75590000 0x3f000 6.00.6001.18000 C:\Windows\system32\UxTheme.dll
0x75950000 0x1a000 6.00.6001.18000 C:\Windows\system32\POWRPROF.dll
0x74320000 0xc000 6.00.6001.18000 C:\Windows\system32\dwmapi.dll
0x74cb0000 0x1ab000 5.02.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll
0x75f20000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x74bf0000 0xba000 6.00.6001.18000 C:\Windows\system32\PROPSYS.dll
0x73990000 0x146000 6.00.6001.18000 C:\Windows\system32\BROWSEUI.dll
0x77eb0000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.dll
0x76620000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x75560000 0x30000 6.00.6001.18000 C:\Windows\system32\DUser.dll
0x76790000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x77870000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x75370000 0x19e000 6.10.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
0x74350000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x73890000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x764b0000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x76940000 0x84000 2001.12.6931.18000 C:\Windows\system32\CLBCatQ.DLL
0x759f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x73780000 0xb2000 6.00.6001.18000 C:\Windows\system32\timedate.cpl
0x74b00000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x76100000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x76580000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x74ee0000 0x39000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x71090000 0x53000 6.00.6001.18000 C:\Windows\System32\actxprxy.dll
0x764d0000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x71470000 0x1b000 11.00.6001.7000 C:\PROGRA~1\WI4EB4~1\wmpband.dll
0x76060000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
0x714d0000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x75ab0000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x74e80000 0x16000 6.00.6001.18000 C:\Windows\System32\shacct.dll
0x760e0000 0x11000 6.00.6001.18000 C:\Windows\System32\SAMLIB.dll
0x76450000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x71040000 0x41000 6.00.6001.18000 C:\Windows\System32\msshsq.dll
0x70390000 0xc6000 6.00.6001.18000 C:\Windows\System32\NaturalLanguage6.dll
0x75f60000 0xf1000 6.00.6001.18000 C:\Windows\System32\CRYPT32.dll
0x760c0000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x75080000 0x1e8000 6.00.6001.18000 C:\Windows\system32\authui.dll
0x75940000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x77af0000 0x129000 7.00.6001.18063 C:\Windows\system32\urlmon.dll
0x77c60000 0x45000 7.00.6001.18000 C:\Windows\system32\iertutil.dll
0x75970000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77d10000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77c20000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77c50000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x6f6d0000 0x5ce000 7.00.6001.18000 C:\Windows\system32\ieframe.dll
0x74f20000 0x32000 6.00.6001.18000 C:\Windows\system32\WINMM.dll
0x710f0000 0x16000 6.00.6001.18000 C:\Windows\system32\thumbcache.dll
0x73c00000 0x2f000 6.00.6001.18000 C:\Windows\system32\wdmaud.drv
0x73bf0000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x74b60000 0x27000 6.00.6001.18000 C:\Windows\system32\MMDevAPI.DLL
0x74ed0000 0x7000 6.00.6001.18000 C:\Windows\system32\AVRT.dll
0x70ff0000 0x4a000 6.00.6001.18000 C:\Windows\system32\ntshrui.dll
0x71460000 0xb000 6.00.6001.18000 C:\Windows\system32\cscapi.dll
0x76ab0000 0x18a000 6.00.6001.18000 C:\Windows\system32\SETUPAPI.dll
0x75770000 0x2d000 6.00.6001.18000 C:\Windows\system32\WINTRUST.dll
0x76c40000 0x29000 6.00.6001.18000 C:\Windows\system32\imagehlp.dll
0x71140000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
0x75ce0000 0x8000 6.00.6001.18000 C:\Windows\system32\VERSION.dll
0x6ffb0000 0x202000 4.00.6001.18000 C:\Windows\system32\msi.dll
0x73960000 0x21000 6.00.6001.18000 C:\Windows\system32\AUDIOSES.DLL
0x738f0000 0x66000 6.00.6001.18000 C:\Windows\system32\audioeng.dll
0x71130000 0x9000 6.00.6001.18000 C:\Windows\system32\ExplorerFrame.dll
0x77970000 0xd0000 7.00.6001.18063 C:\Windows\system32\WININET.dll
0x76c70000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x738e0000 0x9000 6.00.6001.18000 C:\Windows\system32\msacm32.drv
0x738c0000 0x14000 6.00.6001.18000 C:\Windows\system32\MSACM32.dll
0x738b0000 0x7000 6.00.6001.18000 C:\Windows\system32\midimap.dll
0x6e3d0000 0x92000 6.00.6001.18000 C:\Windows\system32\stobject.dll
0x6e310000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x75750000 0xa000 6.00.6001.18000 C:\Windows\system32\WTSAPI32.dll
0x757a0000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x6f180000 0x28c000 6.00.6001.18000 C:\Windows\System32\NLSData000c.dll
0x6c400000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x74410000 0x45000 2001.12.6931.18000 C:\Windows\system32\es.dll
0x6fea0000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x6fe70000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x74af0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x75880000 0x66000 6.00.6001.18000 C:\Windows\system32\FirewallAPI.dll
0x6c0f0000 0x30b000 6.00.6001.18000 C:\Windows\System32\netshell.dll
0x75ec0000 0x19000 6.00.6001.18000 C:\Windows\System32\IPHLPAPI.DLL
0x75e80000 0x35000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc.DLL
0x76180000 0x2c000 6.00.6001.18000 C:\Windows\System32\DNSAPI.dll
0x763f0000 0x7000 6.00.6001.18000 C:\Windows\System32\WINNSI.DLL
0x75e50000 0x21000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc6.DLL
0x74b30000 0xf000 6.00.6001.18000 C:\Windows\System32\nlaapi.dll
0x6f4e0000 0x1bf000 6.00.6001.18000 C:\Windows\system32\pnidui.dll
0x72a70000 0x17000 6.00.6001.18000 C:\Windows\system32\QUtil.dll
0x75ee0000 0x40000 6.00.6001.18000 C:\Windows\system32\wevtapi.dll
0x73270000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x71fe0000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x72660000 0x27000 6.00.6001.18000 C:\Windows\system32\FunDisc.dll
0x70740000 0x9000 6.00.6000.16386 C:\Windows\system32\fdproxy.dll
0x723d0000 0x126000 8.100.1043.0000 C:\Windows\System32\msxml3.dll
0x72a10000 0x12000 6.00.6001.18000 C:\Windows\system32\Wlanapi.dll
0x734a0000 0x17c000 6.00.6001.18000 C:\Windows\system32\OneX.DLL
0x738a0000 0xe000 6.00.6001.18000 C:\Windows\system32\eappprxy.dll
0x732b0000 0x24000 6.00.6001.18000 C:\Windows\system32\eappcfg.dll
0x75db0000 0x45000 6.00.6001.18000 C:\Windows\system32\bcrypt.dll
0x6fed0000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x6f150000 0x23000 6.00.6001.18000 C:\Windows\system32\wpdshserviceobj.dll
0x72e20000 0x5f000 6.00.6001.18000 C:\Windows\system32\WINHTTP.dll
0x6f100000 0x43000 6.00.6001.18000 C:\Windows\System32\srchadmin.dll
0x6f0c0000 0x3c000 7.00.6001.18000 C:\Windows\system32\webcheck.dll
0x6cde0000 0x21c000 6.00.6001.18000 C:\Windows\System32\SyncCenter.dll
0x6fcb0000 0x39000 6.00.6001.18000 C:\Windows\system32\wscntfy.dll
0x73260000 0xb000 6.00.6001.18000 C:\Windows\system32\WSCAPI.dll
0x71820000 0xb000 6.00.6001.18000 C:\Windows\system32\mssprxy.dll
0x72a30000 0x2e000 6.00.6001.18000 C:\Windows\System32\QAgent.dll
0x72d20000 0x96000 6.00.6001.18000 C:\Windows\System32\fwpuclnt.dll
0x67080000 0x1c000 3.00.0010.0000 C:\Program Files\FileZilla FTP Client\fzshellext.dll
0x6e2b0000 0x51000 6.00.6001.18000 C:\Windows\system32\imapi2.dll
0x75c70000 0x3b000 6.00.6001.18000 C:\Windows\system32\mswsock.dll
0x75930000 0x5000 6.00.6001.18000 C:\Windows\System32\wshtcpip.dll
0x10000000 0x2e000 6.01.0000.1205 C:\Windows\system32\btncopy.dll
0x75cd0000 0x5000 6.00.6001.18000 C:\Windows\System32\wship6.dll
0x73130000 0xf000 6.00.6001.18000 C:\Windows\system32\napinsp.dll
0x72f20000 0x12000 6.00.6001.18000 C:\Windows\system32\pnrpnsp.dll
0x73120000 0xc000 6.00.6000.16386 C:\Windows\system32\wshbth.dll
0x72f50000 0x8000 6.00.6000.16386 C:\Windows\System32\winrnr.dll
0x16080000 0x25000 1.00.0004.0012 C:\Program Files\Bonjour\mdnsNSP.dll
0x73140000 0x6000 6.00.6000.16386 C:\Windows\system32\rasadhlp.dll
0x76390000 0x5f000 6.00.6001.18000 C:\Windows\system32\SXS.DLL
0x706c0000 0x2b000 6.00.6001.18000 C:\Windows\system32\PortableDeviceTypes.dll
0x71870000 0x46000 6.00.6001.18000 C:\Windows\system32\PortableDeviceApi.dll
0x6cce0000 0xf9000 6.00.6001.18000 C:\Windows\system32\bthprops.cpl
0x6e250000 0x60000 6.00.6001.18000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x75050000 0x2f000 1.02.1009.0000 C:\Windows\system32\xmllite.dll
0x6e640000 0x13000 6.00.6001.18000 C:\Windows\System32\ntlanman.dll
0x6fe20000 0x8000 6.00.6000.16386 C:\Windows\System32\drprov.dll
0x6fca0000 0xf000 6.00.6000.16386 C:\Windows\System32\davclnt.dll
0x02980000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
0x02990000 0x9000 2.00.0000.0004 C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll
0x6e4b0000 0x2e000 6.00.6001.18000 C:\Windows\system32\syncui.dll
0x6f0a0000 0x16000 6.00.6001.18000 C:\Windows\system32\SYNCENG.dll
0x029e0000 0x2a000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
0x64f00000 0x12000 4.08.1201.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
0x02a10000 0x13000 4.57.0000.0000 C:\Program Files\7-Zip\7-zip.dll
0x721e0000 0x6000 6.00.6000.16386 C:\Windows\system32\dciman32.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 976
Command line: winlogon.exe
Base Size Version Path
0x00920000 0x50000 6.00.6001.18000 C:\Windows\system32\winlogon.exe
0x77ed0000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x77790000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x767a0000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x76870000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x766f0000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x769d0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x77a40000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x764b0000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x757a0000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x76580000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x764d0000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x77eb0000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
0x76620000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x76790000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x77870000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x76450000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x75970000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77d10000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77c20000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77c50000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x760e0000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
0x77d60000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x55580000 0xb000 2.00.0000.0012 c:\windows\system32\uxtuneup.dll
0x755d0000 0xdc000 6.00.6001.18000 C:\Windows\system32\dbghelp.dll
0x75590000 0x3f000 6.00.6001.18000 C:\Windows\system32\uxtheme.dll
0x748e0000 0x3e000 6.00.6001.18000 C:\Windows\system32\shsvcs.dll
0x759f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x74350000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x76100000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x75f20000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x76060000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Windows\system32
19/01/2008 09:33 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 68 911 308 800 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Windows\Downloaded Program Files
22/06/2008 16:54 <REP> .
22/06/2008 16:54 <REP> ..
07/12/2004 17:07 32 bdcore.dll
25/05/2006 01:21 118 784 bdupd.dll
18/09/2006 23:26 65 desktop.ini
25/05/2006 01:21 53 248 ipsupd.dll
08/08/2006 11:45 576 kavwebscan.inf
16/03/2005 12:34 7 407 lang.ini
07/12/2004 17:07 32 libfn.dll
13/02/2008 17:55 130 live.ini
29/10/2007 16:45 1 244 oscan8.inf
25/10/2007 16:54 471 040 oscan8.ocx
14/03/2005 14:58 7 073 scanoptions.tsi
11 fichier(s) 659 631 octets
Total des fichiers listés :
11 fichier(s) 659 631 octets
2 Rép(s) 68 911 308 800 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
REGEDIT4
[iexplore.exe]
"ExecuteOptions"=dword:00000001
REGEDIT4
[taskmgr.exe]
exports des policies
REGEDIT4
[System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
"DisableRegistryTools"=dword:00000000
"HideLegacyLogonScripts"=dword:00000000
"HideLogoffScripts"=dword:00000000
"RunLogonScriptSync"=dword:00000001
"RunStartupScriptSync"=dword:00000000
"HideStartupScripts"=dword:00000000
[System\UIPI]
[System\UIPI\Clipboard]
[System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-23 21:14:37
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0019c1ea150f]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0019c1ea150f]
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files
23/06/2008 01:20 <REP> .
23/06/2008 01:20 <REP> ..
19/04/2008 12:40 <REP> 7-Zip
17/08/2007 15:37 <REP> Activation Assistant for the 2007 Microsoft Office suites
10/06/2008 22:33 <REP> Adobe
20/06/2008 10:53 <REP> Alwil Software
01/05/2008 19:53 <REP> Apple Software Update
08/09/2007 03:33 <REP> ArcSoft
10/06/2008 22:35 <REP> Bonjour
19/04/2008 12:08 <REP> CCleaner
01/06/2008 10:58 <REP> CDBurnerXP
23/06/2008 01:20 <REP> Common Files
10/04/2008 15:25 <REP> CONEXANT
17/08/2007 15:40 <REP> DivX
10/05/2008 21:40 <REP> eMule
20/04/2008 21:07 <REP> ffdshow
12/06/2008 22:47 <REP> FileZilla FTP Client
14/06/2008 22:53 <REP> Glary Utilities
10/06/2008 22:11 <REP> Google
17/08/2007 15:42 <REP> Google BAE
15/06/2008 00:10 <REP> GRISOFT
11/04/2008 12:57 <REP> IDT
17/08/2007 15:43 <REP> Intel
22/06/2008 23:01 <REP> Internet Explorer
08/09/2007 04:01 <REP> InterVideo
11/05/2008 10:10 <REP> Inventel
01/05/2008 19:57 <REP> iPod
01/05/2008 19:57 <REP> iTunes
22/06/2008 21:21 <REP> Java
08/06/2008 11:55 <REP> jv16 PowerTools
10/04/2008 17:14 <REP> Lecteur CANALPLAY
14/05/2008 14:13 <REP> Malwarebytes' Anti-Malware
19/04/2008 13:12 <REP> Messenger Plus! Live
02/11/2006 14:37 <REP> Microsoft Games
17/08/2007 15:42 <REP> Microsoft Office
21/05/2008 15:13 <REP> Microsoft Silverlight
17/08/2007 15:42 <REP> Microsoft Works
17/08/2007 15:35 <REP> Microsoft.NET
23/05/2008 18:02 <REP> Movie Maker
14/06/2008 22:59 <REP> Mozilla Firefox
02/11/2006 14:37 <REP> MSBuild
17/08/2007 13:55 <REP> MSXML 4.0
11/06/2008 12:31 <REP> No-IP
13/05/2008 23:19 <REP> Orange
17/08/2007 15:42 <REP> Picasa2
19/04/2008 14:57 <REP> QuickTime
17/08/2007 14:21 <REP> Realtek
02/11/2006 14:37 <REP> Reference Assemblies
08/09/2007 03:36 <REP> Roxio
22/06/2008 16:29 <REP> Safari
11/05/2008 11:28 <REP> Securitoo
11/04/2008 12:57 <REP> Sigmatel
08/09/2007 03:38 <REP> Skype
19/06/2008 23:25 <REP> Sony
11/04/2008 12:47 <REP> Sony Corporation
20/06/2008 11:37 <REP> Sophos
17/08/2007 14:41 <REP> Synaptics
13/06/2008 09:56 <REP> Tenable
02/05/2008 20:32 <REP> Trend Micro
07/05/2008 22:39 <REP> TubeMaster
23/06/2008 01:20 <REP> TuneUp Utilities 2008
07/05/2008 22:45 <REP> UnH Solutions
23/06/2008 01:11 <REP> Uniblue
17/08/2007 14:34 <REP> WIDCOMM
23/05/2008 18:02 <REP> Windows Calendar
23/05/2008 18:02 <REP> Windows Collaboration
23/05/2008 18:02 <REP> Windows Defender
23/05/2008 18:02 <REP> Windows Journal
19/04/2008 13:05 <REP> Windows Live
11/06/2008 11:43 <REP> Windows Mail
23/05/2008 18:02 <REP> Windows Media Player
17/08/2007 12:10 <REP> Windows NT
23/05/2008 18:02 <REP> Windows Photo Gallery
23/05/2008 18:02 <REP> Windows Sidebar
22/06/2008 21:24 <REP> ZebHelpProcess 2
11/06/2008 19:57 <REP> Zeb-Utility
04/06/2008 10:23 <REP> Zone Labs
0 fichier(s) 0 octets
77 Rép(s) 68 892 999 680 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files\fichiers communs
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files\common files
23/06/2008 01:20 <REP> .
23/06/2008 01:20 <REP> ..
11/05/2008 11:26 <REP> Acronis
10/06/2008 22:33 <REP> Adobe
01/05/2008 19:56 <REP> Apple
02/05/2008 19:05 <REP> Borland Shared
17/08/2007 15:35 <REP> DESIGNER
11/05/2008 11:34 <REP> France Telecom
08/09/2007 03:33 <REP> InstallShield
08/09/2007 04:01 <REP> InterVideo
17/08/2007 15:45 <REP> Java
19/04/2008 12:42 <REP> Macrovision Shared
19/04/2008 13:05 <REP> microsoft shared
17/08/2007 15:40 <REP> PX Storage Engine
08/09/2007 03:36 <REP> Roxio Shared
02/11/2006 13:18 <REP> Services
08/09/2007 03:38 <REP> Skype
08/09/2007 03:36 <REP> Sonic Shared
16/05/2008 20:02 <REP> Sony Shared
02/11/2006 13:18 <REP> SpeechEngines
04/06/2008 10:16 <REP> Symantec Shared
23/05/2008 18:02 <REP> System
23/06/2008 01:20 <REP> Wise Installation Wizard
0 fichier(s) 0 octets
23 Rép(s) 68 892 999 680 octets libres
c:\Users\Yohann\Documents\DRIVERS\EP0000144470.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000144835.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000144842.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000145798.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000146911.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000148249.exe
c:\Users\Yohann\Documents\DRIVERS\EP0000148661.exe
c:\Users\Yohann\Documents\DRIVERS\ITAOTH-01453102-UN.exe
c:\Users\Yohann\Documents\DRIVERS\NVDVID-01587600-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOACCU-01363007-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAMAF-01590304-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAMST-01593102-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVCF-01581004-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVCX-01594900-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVEP-01580500-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVMB-01581501-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578801-UN.exe
c:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578803-UN.exe
c:\Users\Yohann\Documents\DRIVERS\STDAUD-01487701-UN.exe
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_PC-de-Yohann.tar.gz a l'adresse http://upload.malekal.com
Voilà DiagHelp option 2 :
FPort v2.0 - TCP/IP Process to Port Mapper
Copyright 2000 by Foundstone, Inc.
https://www.mcafee.com/en-us/index.html
You must have administrator privileges to run fport - exiting...
PsList 1.26 - Process Information Lister
Copyright (C) 1999-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
Process information for PC-DE-YOHANN:
Name Pid Pri Thd Hnd VM WS Priv
Idle 0 0 2 0 0 24 0
System 4 8 144 3236 6336 2816 0
smss 476 11 4 28 4468 716 288
csrss 604 13 10 768 96404 4764 1552
wininit 656 13 3 99 42536 3792 1228
services 704 9 7 288 46900 6712 2552
svchost 860 8 6 309 42112 5776 2556
mobsync 4744 8 7 134 70936 6524 3312
svchost 964 8 6 366 40168 6056 3096
svchost 1004 8 16 371 104672 25324 39100
spoolsv 1088 8 18 299 92824 9452 5524
svchost 1120 8 25 460 78688 11784 16948
audiodg 1252 8 6 114 47348 10704 12764
svchost 1172 8 42 613 155964 52692 50452
dwm 1800 13 7 128 157952 45504 81708
WUDFHost 3072 8 7 215 61508 5796 3356
svchost 1184 8 57 1095 127860 22816 18944
taskeng 1508 8 18 373 93980 10524 9456
VAIOUpdt 3364 6 7 115 76344 6456 4492
Switcher 3372 6 4 110 74892 6404 3508
taskeng 2536 6 7 130 55676 5380 1972
SLsvc 1300 8 5 92 54356 8824 5076
svchost 1312 8 33 305 75792 14576 11068
wmpnetwk 1324 8 20 454 136280 20164 14104
svchost 1352 8 44 573 85672 12472 7424
svchost 1524 8 27 528 96140 13004 12600
vsmon 1644 8 27 485 131336 19640 21608
usnsvc 1760 8 5 70 29456 3448 1000
aswUpdSv 2008 8 3 30 32708 408 840
ashServ 2024 13 31 338 147048 21440 21964
AppleMobileDeviceService 2124 8 3 63 39152 3312 2012
guard 2148 8 11 99 94772 2184 42764
mDNSResponder 2164 8 4 78 33620 3524 1120
svchost 2176 8 3 85 34224 3396 2148
FTRTSVC 2212 8 3 34 25820 2744 804
IAANTmon 2272 8 6 163 55736 5612 3052
iviRegMgr 2372 8 3 50 31140 3156 876
NMSAccessU 2408 8 3 36 35176 2544 836
svchost 2440 8 6 123 35764 4480 1612
stacsv 2464 8 9 149 51172 5988 8304
svchost 2548 8 8 151 60432 6552 3648
VESMgr 2576 8 16 330 92908 11624 7092
VESMgrSub 3028 8 15 192 85956 8724 5432
SPMgr 3656 8 6 120 78676 7416 8204
VCSW 2660 8 18 165 78648 6940 3688
svchost 2708 8 4 42 15068 2012 536
SearchIndexer 2744 8 18 871 154428 12704 41508
SearchProtocolHost 1900 4 7 295 71204 9128 5332
SearchFilterHost 2876 4 5 93 51652 4628 2856
XAudio 2796 8 2 37 22452 2416 756
VzCdbSvc 2844 8 9 610 64684 10280 8500
VzFw 3172 8 5 92 61744 8600 6648
ashMaiSv 3688 8 9 127 71092 1364 3368
ashWebSv 3716 8 18 113 110336 3808 17316
lsass 720 9 11 648 48840 8028 3256
lsm 732 8 10 190 30932 3800 1764
csrss 668 13 11 382 97648 8188 1868
winlogon 892 13 4 126 55048 5636 3292
explorer 1840 8 35 693 233124 46896 36296
msnmsgr 1064 8 40 802 261132 12664 46964
wmpnscfg 3000 8 7 108 53100 4812 1676
zlclient 4048 8 9 172 93576 5300 9620
ashDisp 4056 8 8 91 74764 1800 3344
jusched 4064 8 2 45 50196 3108 1072
cmd 5472 8 1 21 22688 2248 1724
conime 5488 8 1 31 49508 3260 848
pslist 5536 13 1 150 57044 4216 1868
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1840
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x00060000 0x2cd000 6.00.6001.18000 C:\Windows\Explorer.EXE
0x77630000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x76430000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x76510000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x762d0000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x75ea0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x76130000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x76080000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x76730000 0x58000 6.00.6001.18000 C:\Windows\system32\SHLWAPI.dll
0x76b20000 0xb0f000 6.00.6001.18000 C:\Windows\system32\SHELL32.dll
0x765e0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x75ef0000 0x8d000 6.00.6001.18000 C:\Windows\system32\OLEAUT32.dll
0x72bd0000 0x107000 6.00.6001.18000 C:\Windows\system32\SHDOCVW.dll
0x74e30000 0x3f000 6.00.6001.18000 C:\Windows\system32\UxTheme.dll
0x751f0000 0x1a000 6.00.6001.18000 C:\Windows\system32\POWRPROF.dll
0x73320000 0xc000 6.00.6001.18000 C:\Windows\system32\dwmapi.dll
0x746c0000 0x1ab000 5.02.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll
0x75820000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x74400000 0xba000 6.00.6001.18000 C:\Windows\system32\PROPSYS.dll
0x72a80000 0x146000 6.00.6001.18000 C:\Windows\system32\BROWSEUI.dll
0x77830000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.dll
0x76200000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x74e00000 0x30000 6.00.6001.18000 C:\Windows\system32\DUser.dll
0x777d0000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x76000000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x74c10000 0x19e000 6.10.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
0x73b00000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x73210000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x75d40000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x763a0000 0x84000 2001.12.6931.18000 C:\Windows\system32\CLBCatQ.DLL
0x752f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x72950000 0xb2000 6.00.6001.18000 C:\Windows\system32\timedate.cpl
0x74360000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x759e0000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x77760000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x74880000 0x39000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x70020000 0x53000 6.00.6001.18000 C:\Windows\System32\actxprxy.dll
0x75d60000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x700a0000 0x1b000 11.00.6001.7000 C:\PROGRA~1\WI4EB4~1\wmpband.dll
0x75960000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
0x700d0000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x753b0000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x74660000 0x16000 6.00.6001.18000 C:\Windows\System32\shacct.dll
0x75c90000 0x11000 6.00.6001.18000 C:\Windows\System32\SAMLIB.dll
0x75ce0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x6fbd0000 0x41000 6.00.6001.18000 C:\Windows\System32\msshsq.dll
0x6f870000 0xc6000 6.00.6001.18000 C:\Windows\System32\NaturalLanguage6.dll
0x75860000 0xf1000 6.00.6001.18000 C:\Windows\System32\CRYPT32.dll
0x759c0000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x74a20000 0x1e8000 6.00.6001.18000 C:\Windows\system32\authui.dll
0x751d0000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x769f0000 0x129000 7.00.6001.18063 C:\Windows\system32\urlmon.dll
0x777e0000 0x45000 7.00.6001.18000 C:\Windows\system32\iertutil.dll
0x75210000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77780000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77850000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77880000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x6ed80000 0x5ce000 7.00.6001.18000 C:\Windows\system32\ieframe.dll
0x748c0000 0x32000 6.00.6001.18000 C:\Windows\system32\WINMM.dll
0x745c0000 0x2f000 6.00.6001.18000 C:\Windows\system32\wdmaud.drv
0x74390000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x74630000 0x27000 6.00.6001.18000 C:\Windows\system32\MMDevAPI.DLL
0x746b0000 0x7000 6.00.6001.18000 C:\Windows\system32\AVRT.dll
0x76860000 0x18a000 6.00.6001.18000 C:\Windows\system32\SETUPAPI.dll
0x75010000 0x2d000 6.00.6001.18000 C:\Windows\system32\WINTRUST.dll
0x761d0000 0x29000 6.00.6001.18000 C:\Windows\system32\imagehlp.dll
0x6fb80000 0x4a000 6.00.6001.18000 C:\Windows\system32\ntshrui.dll
0x6fff0000 0xb000 6.00.6001.18000 C:\Windows\system32\cscapi.dll
0x74300000 0x21000 6.00.6001.18000 C:\Windows\system32\AUDIOSES.DLL
0x74290000 0x66000 6.00.6001.18000 C:\Windows\system32\audioeng.dll
0x6fc60000 0x9000 6.00.6001.18000 C:\Windows\system32\ExplorerFrame.dll
0x76790000 0xd0000 7.00.6001.18063 C:\Windows\system32\WININET.dll
0x77770000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x74280000 0x9000 6.00.6001.18000 C:\Windows\system32\msacm32.drv
0x741f0000 0x14000 6.00.6001.18000 C:\Windows\system32\MSACM32.dll
0x74250000 0x7000 6.00.6001.18000 C:\Windows\system32\midimap.dll
0x74df0000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
0x751e0000 0x8000 6.00.6001.18000 C:\Windows\system32\VERSION.dll
0x6f660000 0x202000 4.00.6001.18000 C:\Windows\system32\msi.dll
0x6e3b0000 0x28c000 6.00.6001.18000 C:\Windows\System32\NLSData000c.dll
0x6d7b0000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x6e950000 0x92000 6.00.6001.18000 C:\Windows\system32\stobject.dll
0x6e890000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x74870000 0xa000 6.00.6001.18000 C:\Windows\system32\WTSAPI32.dll
0x75160000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x740a0000 0x45000 2001.12.6931.18000 C:\Windows\system32\es.dll
0x6e340000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x6e310000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x741e0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x750f0000 0x66000 6.00.6001.18000 C:\Windows\system32\FirewallAPI.dll
0x6d4a0000 0x30b000 6.00.6001.18000 C:\Windows\System32\netshell.dll
0x757c0000 0x19000 6.00.6001.18000 C:\Windows\System32\IPHLPAPI.DLL
0x75780000 0x35000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc.DLL
0x75cb0000 0x2c000 6.00.6001.18000 C:\Windows\System32\DNSAPI.dll
0x75c80000 0x7000 6.00.6001.18000 C:\Windows\System32\WINNSI.DLL
0x75750000 0x21000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc6.DLL
0x74380000 0xf000 6.00.6001.18000 C:\Windows\System32\nlaapi.dll
0x6dfe0000 0x1bf000 6.00.6001.18000 C:\Windows\system32\pnidui.dll
0x70b90000 0x17000 6.00.6001.18000 C:\Windows\system32\QUtil.dll
0x757e0000 0x40000 6.00.6001.18000 C:\Windows\system32\wevtapi.dll
0x73330000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x72140000 0x27000 6.00.6001.18000 C:\Windows\system32\FunDisc.dll
0x700c0000 0x9000 6.00.6000.16386 C:\Windows\system32\fdproxy.dll
0x71ee0000 0x126000 8.100.1043.0000 C:\Windows\System32\msxml3.dll
0x71380000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x70b60000 0x12000 6.00.6001.18000 C:\Windows\system32\Wlanapi.dll
0x733f0000 0x17c000 6.00.6001.18000 C:\Windows\system32\OneX.DLL
0x741d0000 0xe000 6.00.6001.18000 C:\Windows\system32\eappprxy.dll
0x73570000 0x24000 6.00.6001.18000 C:\Windows\system32\eappcfg.dll
0x75690000 0x45000 6.00.6001.18000 C:\Windows\system32\bcrypt.dll
0x6f400000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x6deb0000 0x23000 6.00.6001.18000 C:\Windows\system32\wpdshserviceobj.dll
0x72540000 0x5f000 6.00.6001.18000 C:\Windows\system32\WINHTTP.dll
0x6de10000 0x43000 6.00.6001.18000 C:\Windows\System32\srchadmin.dll
0x67080000 0x1c000 3.00.0010.0000 C:\Program Files\FileZilla FTP Client\fzshellext.dll
0x6ddd0000 0x3c000 7.00.6001.18000 C:\Windows\system32\webcheck.dll
0x6d060000 0x21c000 6.00.6001.18000 C:\Windows\System32\SyncCenter.dll
0x6de70000 0x39000 6.00.6001.18000 C:\Windows\system32\wscntfy.dll
0x732d0000 0xb000 6.00.6001.18000 C:\Windows\system32\WSCAPI.dll
0x10000000 0x2e000 6.01.0000.1205 C:\Windows\system32\btncopy.dll
0x6d380000 0x51000 6.00.6001.18000 C:\Windows\system32\imapi2.dll
0x706d0000 0xb000 6.00.6001.18000 C:\Windows\system32\mssprxy.dll
0x706e0000 0x2b000 6.00.6001.18000 C:\Windows\system32\PortableDeviceTypes.dll
0x71270000 0x46000 6.00.6001.18000 C:\Windows\system32\PortableDeviceApi.dll
0x75c20000 0x5f000 6.00.6001.18000 C:\Windows\system32\SXS.DLL
0x70990000 0x2e000 6.00.6001.18000 C:\Windows\System32\QAgent.dll
0x725a0000 0x96000 6.00.6001.18000 C:\Windows\System32\fwpuclnt.dll
0x6cde0000 0xf9000 6.00.6001.18000 C:\Windows\system32\bthprops.cpl
0x6d420000 0x13000 6.00.6001.18000 C:\Windows\System32\ntlanman.dll
0x6fb50000 0x8000 6.00.6000.16386 C:\Windows\System32\drprov.dll
0x70b40000 0xf000 6.00.6000.16386 C:\Windows\System32\davclnt.dll
0x74610000 0x15000 6.00.6001.18000 C:\Windows\system32\Cabinet.dll
0x022b0000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
0x022c0000 0x9000 2.00.0000.0004 C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll
0x6b560000 0x2e000 6.00.6001.18000 C:\Windows\system32\syncui.dll
0x6cdc0000 0x16000 6.00.6001.18000 C:\Windows\system32\SYNCENG.dll
0x02b80000 0x2a000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
0x64f00000 0x12000 4.08.1201.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
0x03020000 0x13000 4.57.0000.0000 C:\Program Files\7-Zip\7-zip.dll
0x75570000 0x3b000 6.00.6001.18000 C:\Windows\system32\mswsock.dll
0x750e0000 0x5000 6.00.6001.18000 C:\Windows\System32\wshtcpip.dll
0x755d0000 0x5000 6.00.6001.18000 C:\Windows\System32\wship6.dll
0x728b0000 0xf000 6.00.6001.18000 C:\Windows\system32\napinsp.dll
0x72870000 0x12000 6.00.6001.18000 C:\Windows\system32\pnrpnsp.dll
0x728a0000 0xc000 6.00.6000.16386 C:\Windows\system32\wshbth.dll
0x72890000 0x8000 6.00.6000.16386 C:\Windows\System32\winrnr.dll
0x16080000 0x25000 1.00.0004.0012 C:\Program Files\Bonjour\mdnsNSP.dll
0x728c0000 0x6000 6.00.6000.16386 C:\Windows\system32\rasadhlp.dll
0x6b200000 0x60000 6.00.6001.18000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x749f0000 0x2f000 1.02.1009.0000 C:\Windows\system32\xmllite.dll
0x70000000 0x16000 6.00.6001.18000 C:\Windows\system32\thumbcache.dll
0x08f10000 0x82e000 7.15.0011.0128 C:\Windows\system32\nvcpl.dll
0x75f80000 0x73000 6.00.6001.18000 C:\Windows\system32\comdlg32.dll
0x720c0000 0x42000 6.00.6001.18000 C:\Windows\system32\WINSPOOL.DRV
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 892
Command line: winlogon.exe
Base Size Version Path
0x00fa0000 0x50000 6.00.6001.18000 C:\Windows\system32\winlogon.exe
0x77630000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x76430000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x76510000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x762d0000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x76130000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x75ea0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x76080000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x75d40000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x75160000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x77760000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x75d60000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x77830000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
0x76200000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x777d0000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x76000000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x75ce0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x75210000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77780000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77850000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77880000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x75c90000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
0x765e0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x55580000 0xb000 2.00.0000.0012 c:\windows\system32\uxtuneup.dll
0x74e70000 0xdc000 6.00.6001.18000 C:\Windows\system32\dbghelp.dll
0x74e30000 0x3f000 6.00.6001.18000 C:\Windows\system32\uxtheme.dll
0x74210000 0x3e000 6.00.6001.18000 C:\Windows\system32\shsvcs.dll
0x752f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x73b00000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x759e0000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x75820000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x75960000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
No matching processes were found.
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
services.exe pid: 704
Command line: C:\Windows\system32\services.exe
Base Size Version Path
0x00ed0000 0x47000 6.00.6001.18000 C:\Windows\system32\services.exe
0x77630000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x76430000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x76510000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x762d0000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x76130000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x75ea0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x76080000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x75d60000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x75d40000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x752a0000 0x4e000 6.00.6001.18000 C:\Windows\system32\SCESRV.dll
0x75720000 0x16000 6.00.6001.18000 C:\Windows\system32\AUTHZ.dll
0x759e0000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x77760000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x755e0000 0xf000 6.00.6001.18000 C:\Windows\system32\NCObjAPI.DLL
0x77830000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
0x76200000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x777d0000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x76000000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x75670000 0x7000 6.00.6001.18000 C:\Windows\system32\credssp.dll
0x75860000 0xf1000 6.00.6001.18000 C:\Windows\system32\CRYPT32.dll
0x759c0000 0x12000 6.00.6000.16386 C:\Windows\system32\MSASN1.dll
0x75360000 0x44000 6.00.6001.18000 C:\Windows\system32\schannel.dll
0x75ce0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x75210000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77780000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77850000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77880000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x75c90000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
0x765e0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x75570000 0x3b000 6.00.6001.18000 C:\Windows\system32\mswsock.dll
0x750e0000 0x5000 6.00.6001.18000 C:\Windows\System32\wshtcpip.dll
0x755d0000 0x5000 6.00.6001.18000 C:\Windows\System32\wship6.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files
23/06/2008 01:20 <REP> .
23/06/2008 01:20 <REP> ..
19/04/2008 12:40 <REP> 7-Zip
17/08/2007 15:37 <REP> Activation Assistant for the 2007 Microsoft Office suites
10/06/2008 22:33 <REP> Adobe
20/06/2008 10:53 <REP> Alwil Software
01/05/2008 19:53 <REP> Apple Software Update
08/09/2007 03:33 <REP> ArcSoft
10/06/2008 22:35 <REP> Bonjour
19/04/2008 12:08 <REP> CCleaner
01/06/2008 10:58 <REP> CDBurnerXP
23/06/2008 01:20 <REP> Common Files
10/04/2008 15:25 <REP> CONEXANT
17/08/2007 15:40 <REP> DivX
10/05/2008 21:40 <REP> eMule
20/04/2008 21:07 <REP> ffdshow
12/06/2008 22:47 <REP> FileZilla FTP Client
14/06/2008 22:53 <REP> Glary Utilities
10/06/2008 22:11 <REP> Google
17/08/2007 15:42 <REP> Google BAE
15/06/2008 00:10 <REP> GRISOFT
11/04/2008 12:57 <REP> IDT
17/08/2007 15:43 <REP> Intel
22/06/2008 23:01 <REP> Internet Explorer
08/09/2007 04:01 <REP> InterVideo
11/05/2008 10:10 <REP> Inventel
01/05/2008 19:57 <REP> iPod
01/05/2008 19:57 <REP> iTunes
22/06/2008 21:21 <REP> Java
08/06/2008 11:55 <REP> jv16 PowerTools
10/04/2008 17:14 <REP> Lecteur CANALPLAY
14/05/2008 14:13 <REP> Malwarebytes' Anti-Malware
19/04/2008 13:12 <REP> Messenger Plus! Live
02/11/2006 14:37 <REP> Microsoft Games
17/08/2007 15:42 <REP> Microsoft Office
21/05/2008 15:13 <REP> Microsoft Silverlight
17/08/2007 15:42 <REP> Microsoft Works
17/08/2007 15:35 <REP> Microsoft.NET
23/05/2008 18:02 <REP> Movie Maker
14/06/2008 22:59 <REP> Mozilla Firefox
02/11/2006 14:37 <REP> MSBuild
17/08/2007 13:55 <REP> MSXML 4.0
11/06/2008 12:31 <REP> No-IP
13/05/2008 23:19 <REP> Orange
17/08/2007 15:42 <REP> Picasa2
19/04/2008 14:57 <REP> QuickTime
17/08/2007 14:21 <REP> Realtek
02/11/2006 14:37 <REP> Reference Assemblies
08/09/2007 03:36 <REP> Roxio
22/06/2008 16:29 <REP> Safari
11/05/2008 11:28 <REP> Securitoo
11/04/2008 12:57 <REP> Sigmatel
08/09/2007 03:38 <REP> Skype
19/06/2008 23:25 <REP> Sony
11/04/2008 12:47 <REP> Sony Corporation
20/06/2008 11:37 <REP> Sophos
17/08/2007 14:41 <REP> Synaptics
13/06/2008 09:56 <REP> Tenable
02/05/2008 20:32 <REP> Trend Micro
07/05/2008 22:39 <REP> TubeMaster
23/06/2008 01:20 <REP> TuneUp Utilities 2008
07/05/2008 22:45 <REP> UnH Solutions
23/06/2008 01:11 <REP> Uniblue
17/08/2007 14:34 <REP> WIDCOMM
23/05/2008 18:02 <REP> Windows Calendar
23/05/2008 18:02 <REP> Windows Collaboration
23/05/2008 18:02 <REP> Windows Defender
23/05/2008 18:02 <REP> Windows Journal
19/04/2008 13:05 <REP> Windows Live
11/06/2008 11:43 <REP> Windows Mail
23/05/2008 18:02 <REP> Windows Media Player
17/08/2007 12:10 <REP> Windows NT
23/05/2008 18:02 <REP> Windows Photo Gallery
23/05/2008 18:02 <REP> Windows Sidebar
11/06/2008 19:57 <REP> Zeb-Utility
23/06/2008 21:22 <REP> ZebHelpProcess 2
04/06/2008 10:23 <REP> Zone Labs
0 fichier(s) 0 octets
77 Rép(s) 68 903 948 288 octets libres
C:\Users\Yohann\Documents\DRIVERS\EP0000144470.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000144835.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000144842.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000145798.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000146911.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000148249.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000148661.exe
C:\Users\Yohann\Documents\DRIVERS\ITAOTH-01453102-UN.exe
C:\Users\Yohann\Documents\DRIVERS\NVDVID-01587600-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOACCU-01363007-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAMAF-01590304-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAMST-01593102-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVCF-01581004-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVCX-01594900-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVEP-01580500-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVMB-01581501-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578801-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578803-UN.exe
C:\Users\Yohann\Documents\DRIVERS\STDAUD-01487701-UN.exe
FPort v2.0 - TCP/IP Process to Port Mapper
Copyright 2000 by Foundstone, Inc.
https://www.mcafee.com/en-us/index.html
You must have administrator privileges to run fport - exiting...
PsList 1.26 - Process Information Lister
Copyright (C) 1999-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
Process information for PC-DE-YOHANN:
Name Pid Pri Thd Hnd VM WS Priv
Idle 0 0 2 0 0 24 0
System 4 8 144 3236 6336 2816 0
smss 476 11 4 28 4468 716 288
csrss 604 13 10 768 96404 4764 1552
wininit 656 13 3 99 42536 3792 1228
services 704 9 7 288 46900 6712 2552
svchost 860 8 6 309 42112 5776 2556
mobsync 4744 8 7 134 70936 6524 3312
svchost 964 8 6 366 40168 6056 3096
svchost 1004 8 16 371 104672 25324 39100
spoolsv 1088 8 18 299 92824 9452 5524
svchost 1120 8 25 460 78688 11784 16948
audiodg 1252 8 6 114 47348 10704 12764
svchost 1172 8 42 613 155964 52692 50452
dwm 1800 13 7 128 157952 45504 81708
WUDFHost 3072 8 7 215 61508 5796 3356
svchost 1184 8 57 1095 127860 22816 18944
taskeng 1508 8 18 373 93980 10524 9456
VAIOUpdt 3364 6 7 115 76344 6456 4492
Switcher 3372 6 4 110 74892 6404 3508
taskeng 2536 6 7 130 55676 5380 1972
SLsvc 1300 8 5 92 54356 8824 5076
svchost 1312 8 33 305 75792 14576 11068
wmpnetwk 1324 8 20 454 136280 20164 14104
svchost 1352 8 44 573 85672 12472 7424
svchost 1524 8 27 528 96140 13004 12600
vsmon 1644 8 27 485 131336 19640 21608
usnsvc 1760 8 5 70 29456 3448 1000
aswUpdSv 2008 8 3 30 32708 408 840
ashServ 2024 13 31 338 147048 21440 21964
AppleMobileDeviceService 2124 8 3 63 39152 3312 2012
guard 2148 8 11 99 94772 2184 42764
mDNSResponder 2164 8 4 78 33620 3524 1120
svchost 2176 8 3 85 34224 3396 2148
FTRTSVC 2212 8 3 34 25820 2744 804
IAANTmon 2272 8 6 163 55736 5612 3052
iviRegMgr 2372 8 3 50 31140 3156 876
NMSAccessU 2408 8 3 36 35176 2544 836
svchost 2440 8 6 123 35764 4480 1612
stacsv 2464 8 9 149 51172 5988 8304
svchost 2548 8 8 151 60432 6552 3648
VESMgr 2576 8 16 330 92908 11624 7092
VESMgrSub 3028 8 15 192 85956 8724 5432
SPMgr 3656 8 6 120 78676 7416 8204
VCSW 2660 8 18 165 78648 6940 3688
svchost 2708 8 4 42 15068 2012 536
SearchIndexer 2744 8 18 871 154428 12704 41508
SearchProtocolHost 1900 4 7 295 71204 9128 5332
SearchFilterHost 2876 4 5 93 51652 4628 2856
XAudio 2796 8 2 37 22452 2416 756
VzCdbSvc 2844 8 9 610 64684 10280 8500
VzFw 3172 8 5 92 61744 8600 6648
ashMaiSv 3688 8 9 127 71092 1364 3368
ashWebSv 3716 8 18 113 110336 3808 17316
lsass 720 9 11 648 48840 8028 3256
lsm 732 8 10 190 30932 3800 1764
csrss 668 13 11 382 97648 8188 1868
winlogon 892 13 4 126 55048 5636 3292
explorer 1840 8 35 693 233124 46896 36296
msnmsgr 1064 8 40 802 261132 12664 46964
wmpnscfg 3000 8 7 108 53100 4812 1676
zlclient 4048 8 9 172 93576 5300 9620
ashDisp 4056 8 8 91 74764 1800 3344
jusched 4064 8 2 45 50196 3108 1072
cmd 5472 8 1 21 22688 2248 1724
conime 5488 8 1 31 49508 3260 848
pslist 5536 13 1 150 57044 4216 1868
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1840
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x00060000 0x2cd000 6.00.6001.18000 C:\Windows\Explorer.EXE
0x77630000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x76430000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x76510000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x762d0000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x75ea0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x76130000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x76080000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x76730000 0x58000 6.00.6001.18000 C:\Windows\system32\SHLWAPI.dll
0x76b20000 0xb0f000 6.00.6001.18000 C:\Windows\system32\SHELL32.dll
0x765e0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x75ef0000 0x8d000 6.00.6001.18000 C:\Windows\system32\OLEAUT32.dll
0x72bd0000 0x107000 6.00.6001.18000 C:\Windows\system32\SHDOCVW.dll
0x74e30000 0x3f000 6.00.6001.18000 C:\Windows\system32\UxTheme.dll
0x751f0000 0x1a000 6.00.6001.18000 C:\Windows\system32\POWRPROF.dll
0x73320000 0xc000 6.00.6001.18000 C:\Windows\system32\dwmapi.dll
0x746c0000 0x1ab000 5.02.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll
0x75820000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x74400000 0xba000 6.00.6001.18000 C:\Windows\system32\PROPSYS.dll
0x72a80000 0x146000 6.00.6001.18000 C:\Windows\system32\BROWSEUI.dll
0x77830000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.dll
0x76200000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x74e00000 0x30000 6.00.6001.18000 C:\Windows\system32\DUser.dll
0x777d0000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x76000000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x74c10000 0x19e000 6.10.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
0x73b00000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x73210000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x75d40000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x763a0000 0x84000 2001.12.6931.18000 C:\Windows\system32\CLBCatQ.DLL
0x752f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x72950000 0xb2000 6.00.6001.18000 C:\Windows\system32\timedate.cpl
0x74360000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x759e0000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x77760000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x74880000 0x39000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x70020000 0x53000 6.00.6001.18000 C:\Windows\System32\actxprxy.dll
0x75d60000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x700a0000 0x1b000 11.00.6001.7000 C:\PROGRA~1\WI4EB4~1\wmpband.dll
0x75960000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
0x700d0000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x753b0000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x74660000 0x16000 6.00.6001.18000 C:\Windows\System32\shacct.dll
0x75c90000 0x11000 6.00.6001.18000 C:\Windows\System32\SAMLIB.dll
0x75ce0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x6fbd0000 0x41000 6.00.6001.18000 C:\Windows\System32\msshsq.dll
0x6f870000 0xc6000 6.00.6001.18000 C:\Windows\System32\NaturalLanguage6.dll
0x75860000 0xf1000 6.00.6001.18000 C:\Windows\System32\CRYPT32.dll
0x759c0000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x74a20000 0x1e8000 6.00.6001.18000 C:\Windows\system32\authui.dll
0x751d0000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x769f0000 0x129000 7.00.6001.18063 C:\Windows\system32\urlmon.dll
0x777e0000 0x45000 7.00.6001.18000 C:\Windows\system32\iertutil.dll
0x75210000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77780000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77850000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77880000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x6ed80000 0x5ce000 7.00.6001.18000 C:\Windows\system32\ieframe.dll
0x748c0000 0x32000 6.00.6001.18000 C:\Windows\system32\WINMM.dll
0x745c0000 0x2f000 6.00.6001.18000 C:\Windows\system32\wdmaud.drv
0x74390000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x74630000 0x27000 6.00.6001.18000 C:\Windows\system32\MMDevAPI.DLL
0x746b0000 0x7000 6.00.6001.18000 C:\Windows\system32\AVRT.dll
0x76860000 0x18a000 6.00.6001.18000 C:\Windows\system32\SETUPAPI.dll
0x75010000 0x2d000 6.00.6001.18000 C:\Windows\system32\WINTRUST.dll
0x761d0000 0x29000 6.00.6001.18000 C:\Windows\system32\imagehlp.dll
0x6fb80000 0x4a000 6.00.6001.18000 C:\Windows\system32\ntshrui.dll
0x6fff0000 0xb000 6.00.6001.18000 C:\Windows\system32\cscapi.dll
0x74300000 0x21000 6.00.6001.18000 C:\Windows\system32\AUDIOSES.DLL
0x74290000 0x66000 6.00.6001.18000 C:\Windows\system32\audioeng.dll
0x6fc60000 0x9000 6.00.6001.18000 C:\Windows\system32\ExplorerFrame.dll
0x76790000 0xd0000 7.00.6001.18063 C:\Windows\system32\WININET.dll
0x77770000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x74280000 0x9000 6.00.6001.18000 C:\Windows\system32\msacm32.drv
0x741f0000 0x14000 6.00.6001.18000 C:\Windows\system32\MSACM32.dll
0x74250000 0x7000 6.00.6001.18000 C:\Windows\system32\midimap.dll
0x74df0000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
0x751e0000 0x8000 6.00.6001.18000 C:\Windows\system32\VERSION.dll
0x6f660000 0x202000 4.00.6001.18000 C:\Windows\system32\msi.dll
0x6e3b0000 0x28c000 6.00.6001.18000 C:\Windows\System32\NLSData000c.dll
0x6d7b0000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x6e950000 0x92000 6.00.6001.18000 C:\Windows\system32\stobject.dll
0x6e890000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x74870000 0xa000 6.00.6001.18000 C:\Windows\system32\WTSAPI32.dll
0x75160000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x740a0000 0x45000 2001.12.6931.18000 C:\Windows\system32\es.dll
0x6e340000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x6e310000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x741e0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x750f0000 0x66000 6.00.6001.18000 C:\Windows\system32\FirewallAPI.dll
0x6d4a0000 0x30b000 6.00.6001.18000 C:\Windows\System32\netshell.dll
0x757c0000 0x19000 6.00.6001.18000 C:\Windows\System32\IPHLPAPI.DLL
0x75780000 0x35000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc.DLL
0x75cb0000 0x2c000 6.00.6001.18000 C:\Windows\System32\DNSAPI.dll
0x75c80000 0x7000 6.00.6001.18000 C:\Windows\System32\WINNSI.DLL
0x75750000 0x21000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc6.DLL
0x74380000 0xf000 6.00.6001.18000 C:\Windows\System32\nlaapi.dll
0x6dfe0000 0x1bf000 6.00.6001.18000 C:\Windows\system32\pnidui.dll
0x70b90000 0x17000 6.00.6001.18000 C:\Windows\system32\QUtil.dll
0x757e0000 0x40000 6.00.6001.18000 C:\Windows\system32\wevtapi.dll
0x73330000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x72140000 0x27000 6.00.6001.18000 C:\Windows\system32\FunDisc.dll
0x700c0000 0x9000 6.00.6000.16386 C:\Windows\system32\fdproxy.dll
0x71ee0000 0x126000 8.100.1043.0000 C:\Windows\System32\msxml3.dll
0x71380000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x70b60000 0x12000 6.00.6001.18000 C:\Windows\system32\Wlanapi.dll
0x733f0000 0x17c000 6.00.6001.18000 C:\Windows\system32\OneX.DLL
0x741d0000 0xe000 6.00.6001.18000 C:\Windows\system32\eappprxy.dll
0x73570000 0x24000 6.00.6001.18000 C:\Windows\system32\eappcfg.dll
0x75690000 0x45000 6.00.6001.18000 C:\Windows\system32\bcrypt.dll
0x6f400000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x6deb0000 0x23000 6.00.6001.18000 C:\Windows\system32\wpdshserviceobj.dll
0x72540000 0x5f000 6.00.6001.18000 C:\Windows\system32\WINHTTP.dll
0x6de10000 0x43000 6.00.6001.18000 C:\Windows\System32\srchadmin.dll
0x67080000 0x1c000 3.00.0010.0000 C:\Program Files\FileZilla FTP Client\fzshellext.dll
0x6ddd0000 0x3c000 7.00.6001.18000 C:\Windows\system32\webcheck.dll
0x6d060000 0x21c000 6.00.6001.18000 C:\Windows\System32\SyncCenter.dll
0x6de70000 0x39000 6.00.6001.18000 C:\Windows\system32\wscntfy.dll
0x732d0000 0xb000 6.00.6001.18000 C:\Windows\system32\WSCAPI.dll
0x10000000 0x2e000 6.01.0000.1205 C:\Windows\system32\btncopy.dll
0x6d380000 0x51000 6.00.6001.18000 C:\Windows\system32\imapi2.dll
0x706d0000 0xb000 6.00.6001.18000 C:\Windows\system32\mssprxy.dll
0x706e0000 0x2b000 6.00.6001.18000 C:\Windows\system32\PortableDeviceTypes.dll
0x71270000 0x46000 6.00.6001.18000 C:\Windows\system32\PortableDeviceApi.dll
0x75c20000 0x5f000 6.00.6001.18000 C:\Windows\system32\SXS.DLL
0x70990000 0x2e000 6.00.6001.18000 C:\Windows\System32\QAgent.dll
0x725a0000 0x96000 6.00.6001.18000 C:\Windows\System32\fwpuclnt.dll
0x6cde0000 0xf9000 6.00.6001.18000 C:\Windows\system32\bthprops.cpl
0x6d420000 0x13000 6.00.6001.18000 C:\Windows\System32\ntlanman.dll
0x6fb50000 0x8000 6.00.6000.16386 C:\Windows\System32\drprov.dll
0x70b40000 0xf000 6.00.6000.16386 C:\Windows\System32\davclnt.dll
0x74610000 0x15000 6.00.6001.18000 C:\Windows\system32\Cabinet.dll
0x022b0000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
0x022c0000 0x9000 2.00.0000.0004 C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll
0x6b560000 0x2e000 6.00.6001.18000 C:\Windows\system32\syncui.dll
0x6cdc0000 0x16000 6.00.6001.18000 C:\Windows\system32\SYNCENG.dll
0x02b80000 0x2a000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
0x64f00000 0x12000 4.08.1201.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
0x03020000 0x13000 4.57.0000.0000 C:\Program Files\7-Zip\7-zip.dll
0x75570000 0x3b000 6.00.6001.18000 C:\Windows\system32\mswsock.dll
0x750e0000 0x5000 6.00.6001.18000 C:\Windows\System32\wshtcpip.dll
0x755d0000 0x5000 6.00.6001.18000 C:\Windows\System32\wship6.dll
0x728b0000 0xf000 6.00.6001.18000 C:\Windows\system32\napinsp.dll
0x72870000 0x12000 6.00.6001.18000 C:\Windows\system32\pnrpnsp.dll
0x728a0000 0xc000 6.00.6000.16386 C:\Windows\system32\wshbth.dll
0x72890000 0x8000 6.00.6000.16386 C:\Windows\System32\winrnr.dll
0x16080000 0x25000 1.00.0004.0012 C:\Program Files\Bonjour\mdnsNSP.dll
0x728c0000 0x6000 6.00.6000.16386 C:\Windows\system32\rasadhlp.dll
0x6b200000 0x60000 6.00.6001.18000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x749f0000 0x2f000 1.02.1009.0000 C:\Windows\system32\xmllite.dll
0x70000000 0x16000 6.00.6001.18000 C:\Windows\system32\thumbcache.dll
0x08f10000 0x82e000 7.15.0011.0128 C:\Windows\system32\nvcpl.dll
0x75f80000 0x73000 6.00.6001.18000 C:\Windows\system32\comdlg32.dll
0x720c0000 0x42000 6.00.6001.18000 C:\Windows\system32\WINSPOOL.DRV
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 892
Command line: winlogon.exe
Base Size Version Path
0x00fa0000 0x50000 6.00.6001.18000 C:\Windows\system32\winlogon.exe
0x77630000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x76430000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x76510000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x762d0000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x76130000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x75ea0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x76080000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x75d40000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x75160000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
0x77760000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x75d60000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x77830000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
0x76200000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x777d0000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x76000000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x75ce0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x75210000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77780000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77850000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77880000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x75c90000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
0x765e0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x55580000 0xb000 2.00.0000.0012 c:\windows\system32\uxtuneup.dll
0x74e70000 0xdc000 6.00.6001.18000 C:\Windows\system32\dbghelp.dll
0x74e30000 0x3f000 6.00.6001.18000 C:\Windows\system32\uxtheme.dll
0x74210000 0x3e000 6.00.6001.18000 C:\Windows\system32\shsvcs.dll
0x752f0000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
0x73b00000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
0x759e0000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x75820000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
0x75960000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
No matching processes were found.
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
services.exe pid: 704
Command line: C:\Windows\system32\services.exe
Base Size Version Path
0x00ed0000 0x47000 6.00.6001.18000 C:\Windows\system32\services.exe
0x77630000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
0x76430000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
0x76510000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
0x762d0000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
0x76130000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
0x75ea0000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
0x76080000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
0x75d60000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
0x75d40000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
0x752a0000 0x4e000 6.00.6001.18000 C:\Windows\system32\SCESRV.dll
0x75720000 0x16000 6.00.6001.18000 C:\Windows\system32\AUTHZ.dll
0x759e0000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
0x77760000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x755e0000 0xf000 6.00.6001.18000 C:\Windows\system32\NCObjAPI.DLL
0x77830000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
0x76200000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
0x777d0000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
0x76000000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
0x75670000 0x7000 6.00.6001.18000 C:\Windows\system32\credssp.dll
0x75860000 0xf1000 6.00.6001.18000 C:\Windows\system32\CRYPT32.dll
0x759c0000 0x12000 6.00.6000.16386 C:\Windows\system32\MSASN1.dll
0x75360000 0x44000 6.00.6001.18000 C:\Windows\system32\schannel.dll
0x75ce0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
0x75210000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
0x77780000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
0x77850000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
0x77880000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
0x75c90000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
0x765e0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
0x75570000 0x3b000 6.00.6001.18000 C:\Windows\system32\mswsock.dll
0x750e0000 0x5000 6.00.6001.18000 C:\Windows\System32\wshtcpip.dll
0x755d0000 0x5000 6.00.6001.18000 C:\Windows\System32\wship6.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 78E1-9011
Répertoire de C:\Program Files
23/06/2008 01:20 <REP> .
23/06/2008 01:20 <REP> ..
19/04/2008 12:40 <REP> 7-Zip
17/08/2007 15:37 <REP> Activation Assistant for the 2007 Microsoft Office suites
10/06/2008 22:33 <REP> Adobe
20/06/2008 10:53 <REP> Alwil Software
01/05/2008 19:53 <REP> Apple Software Update
08/09/2007 03:33 <REP> ArcSoft
10/06/2008 22:35 <REP> Bonjour
19/04/2008 12:08 <REP> CCleaner
01/06/2008 10:58 <REP> CDBurnerXP
23/06/2008 01:20 <REP> Common Files
10/04/2008 15:25 <REP> CONEXANT
17/08/2007 15:40 <REP> DivX
10/05/2008 21:40 <REP> eMule
20/04/2008 21:07 <REP> ffdshow
12/06/2008 22:47 <REP> FileZilla FTP Client
14/06/2008 22:53 <REP> Glary Utilities
10/06/2008 22:11 <REP> Google
17/08/2007 15:42 <REP> Google BAE
15/06/2008 00:10 <REP> GRISOFT
11/04/2008 12:57 <REP> IDT
17/08/2007 15:43 <REP> Intel
22/06/2008 23:01 <REP> Internet Explorer
08/09/2007 04:01 <REP> InterVideo
11/05/2008 10:10 <REP> Inventel
01/05/2008 19:57 <REP> iPod
01/05/2008 19:57 <REP> iTunes
22/06/2008 21:21 <REP> Java
08/06/2008 11:55 <REP> jv16 PowerTools
10/04/2008 17:14 <REP> Lecteur CANALPLAY
14/05/2008 14:13 <REP> Malwarebytes' Anti-Malware
19/04/2008 13:12 <REP> Messenger Plus! Live
02/11/2006 14:37 <REP> Microsoft Games
17/08/2007 15:42 <REP> Microsoft Office
21/05/2008 15:13 <REP> Microsoft Silverlight
17/08/2007 15:42 <REP> Microsoft Works
17/08/2007 15:35 <REP> Microsoft.NET
23/05/2008 18:02 <REP> Movie Maker
14/06/2008 22:59 <REP> Mozilla Firefox
02/11/2006 14:37 <REP> MSBuild
17/08/2007 13:55 <REP> MSXML 4.0
11/06/2008 12:31 <REP> No-IP
13/05/2008 23:19 <REP> Orange
17/08/2007 15:42 <REP> Picasa2
19/04/2008 14:57 <REP> QuickTime
17/08/2007 14:21 <REP> Realtek
02/11/2006 14:37 <REP> Reference Assemblies
08/09/2007 03:36 <REP> Roxio
22/06/2008 16:29 <REP> Safari
11/05/2008 11:28 <REP> Securitoo
11/04/2008 12:57 <REP> Sigmatel
08/09/2007 03:38 <REP> Skype
19/06/2008 23:25 <REP> Sony
11/04/2008 12:47 <REP> Sony Corporation
20/06/2008 11:37 <REP> Sophos
17/08/2007 14:41 <REP> Synaptics
13/06/2008 09:56 <REP> Tenable
02/05/2008 20:32 <REP> Trend Micro
07/05/2008 22:39 <REP> TubeMaster
23/06/2008 01:20 <REP> TuneUp Utilities 2008
07/05/2008 22:45 <REP> UnH Solutions
23/06/2008 01:11 <REP> Uniblue
17/08/2007 14:34 <REP> WIDCOMM
23/05/2008 18:02 <REP> Windows Calendar
23/05/2008 18:02 <REP> Windows Collaboration
23/05/2008 18:02 <REP> Windows Defender
23/05/2008 18:02 <REP> Windows Journal
19/04/2008 13:05 <REP> Windows Live
11/06/2008 11:43 <REP> Windows Mail
23/05/2008 18:02 <REP> Windows Media Player
17/08/2007 12:10 <REP> Windows NT
23/05/2008 18:02 <REP> Windows Photo Gallery
23/05/2008 18:02 <REP> Windows Sidebar
11/06/2008 19:57 <REP> Zeb-Utility
23/06/2008 21:22 <REP> ZebHelpProcess 2
04/06/2008 10:23 <REP> Zone Labs
0 fichier(s) 0 octets
77 Rép(s) 68 903 948 288 octets libres
C:\Users\Yohann\Documents\DRIVERS\EP0000144470.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000144835.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000144842.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000145798.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000146911.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000148249.exe
C:\Users\Yohann\Documents\DRIVERS\EP0000148661.exe
C:\Users\Yohann\Documents\DRIVERS\ITAOTH-01453102-UN.exe
C:\Users\Yohann\Documents\DRIVERS\NVDVID-01587600-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOACCU-01363007-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAMAF-01590304-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAMST-01593102-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVCF-01581004-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVCX-01594900-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVEP-01580500-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVMB-01581501-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578801-UN.exe
C:\Users\Yohann\Documents\DRIVERS\SOAVRC-01578803-UN.exe
C:\Users\Yohann\Documents\DRIVERS\STDAUD-01487701-UN.exe
Voilà, c'est fait.
J'aime beaucoup ce nouveau style..
En regardant mon rapport DiagHelp, j'ai vu que authuitu.dll c'était Vundo, vous en pensez quoi ?
J'aime beaucoup ce nouveau style..
En regardant mon rapport DiagHelp, j'ai vu que authuitu.dll c'était Vundo, vous en pensez quoi ?
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 745
Type de recherche: Examen complet (C:\|F:\|G:\|)
Eléments examinés: 160176
Temps écoulé: 27 minute(s), 39 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\poof (Rootkit.Agent) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Version de la base de données: 745
Type de recherche: Examen complet (C:\|F:\|G:\|)
Eléments examinés: 160176
Temps écoulé: 27 minute(s), 39 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\poof (Rootkit.Agent) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)