Harcelé par un pirate
Résolu/Fermé
Bonjour,
mes cher amis je postule car j ai un enorme soucis de pc et je ni comprend rien! je suis harcelé par un pirate qui me desinstal tout sur mon pc et qui me laisse des mess en anglais et il se vente ! quel pauvre nul.... j ai un pc neuf que j ai acheté en decembre 2007 et kaspersky internet security 7 et j utilise mon pc que pour joué a world of warcraft!!! mais le soucis est que ce pauvre nul qui n a rien d autre a faire de ces journee me desinstalle tout y compris kaspersky!! en bref il a l air trop fort pour moi et me fait deprimé car j ai reformaté au moin 15 fois et sa continu! j utilise internet par cable donc pas de wifi d activé sur ma free! donc si quelqu un voudrais bien m aidez se serais sympa car la je deprime d etre impuissante!!!!!!
mes cher amis je postule car j ai un enorme soucis de pc et je ni comprend rien! je suis harcelé par un pirate qui me desinstal tout sur mon pc et qui me laisse des mess en anglais et il se vente ! quel pauvre nul.... j ai un pc neuf que j ai acheté en decembre 2007 et kaspersky internet security 7 et j utilise mon pc que pour joué a world of warcraft!!! mais le soucis est que ce pauvre nul qui n a rien d autre a faire de ces journee me desinstalle tout y compris kaspersky!! en bref il a l air trop fort pour moi et me fait deprimé car j ai reformaté au moin 15 fois et sa continu! j utilise internet par cable donc pas de wifi d activé sur ma free! donc si quelqu un voudrais bien m aidez se serais sympa car la je deprime d etre impuissante!!!!!!
Configuration: Windows Vista Internet Explorer 7.0
61 réponses
-
salu' pour suivre
-
ContributeurTu as activé le pare-feu Windows?
-
oui mais le faite d'avoir 100G ou autre ne gange rien
as tu un pare-feu? -
Salut, fais des analyses anti spyware et anti virus active ton pare feu ou installe en un. un pirate peut contrôler ton ordinateur en installant un programme sur ton ordinateur a ton insu. c'est étrange que en formatant 15 fois il puisse toujours avoir accé à ton ordis. A mon avis c'est quelqu'un que tu connais qui fais sa
-
Bonsoir,
Dans exécuter tapes "cmd". Une fenêtre apparaît et tapes "netstat -a > C:\connect.txt"
Télécharge avast, spybot, et RegistryBooster et coupe ta connexion.
Ensuite installe-les.
Redémarre en Mode sans échec et fais un scan avec tout les logiciels pour voir quels fichiers font un pont entre toi et le pirate.
Redémarre et reconnecte ton modem, ton adresse IP aura changé et ses fichiers pour t'espionner auront disparu.
Il ne pourra plus te pister et se connecter à toi.
Si jamais ces logiciels ne marchent pas en mode sans échec, tu peux faire à la limite en mode normal mais non-connecté à Internet.
http://www.infos-du-net.com/telecharger/Booster-Registry,0301-4656.html
https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/25899.html
https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html
@+-
ok je vais faire se que tu me dit merci de m aidez car je ni comprend rien et je ne peut plus utilisé kaspersky car je l ai activé trop de fois et il n est plus valide et je l ai acheté ya deux mois et je n ai plus de ticket de caisse pour prouvé mon achat donc la je n ai plus de par feu quoi faire?
-
-
utilise le pare-feu windows
-
-
@-Shadow-Même pas =P
Le pare-feu Windows , ne contrôle que les données entrantes , les sortantes ... non.
-
-
Avast a un pare-feu intégré. Pas de problème de ce côté-là.
De plus il est gratuit et il faut juste s'enregistrer dans un délai de 40 jours. -
Possible, car s'il est en p2p alors il y a de fortes chances que tu aies été infectée.
-
voyez la gendarmerie national les militaires sont la pour vous aidez surtout avec une repetition de harcelement
-
y a t il quelqu un sur lyon pour me debarassé de tout ces truc qui me bloque?
-
aide et assistance contre les virus et pirates mais c est payant au mieux presentez vous a la gendarmerie national la plus proche !
-
Contributeur sécuritéSalut,
Peux-tu éditer un rapport Hijackthis ?
http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
Démo en image
http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
Fais un scan et poste l'analyse.
FillPCA -
Pour registry booster, ne corrige pas les erreurs de DLL partagées.
-
meme hijackthis ne marche pas......j ai pas de chance c est trop injuste
-
Contributeur sécuritéSalut,
Ne t'inquiète pas, on va faire autrement et on va trouver.
* Télécharge PCA (d'Evosla) : http://ww25.evosla.com/pca_cpt.php?agr=pca_securite
* Dézippe-le dans un répertoire dédié comme c:\PCA au moyen d'un clic droit (Extraire...),
* Clique sur l'onglet "diagnostic du PC" puis "analyser".
* Laisse l'analyse se dérouler. Cela ne prend que quelques secondes.
* Clique sur "enregistrer le rapport" en bas à droite et sauvegarde-le sur le bureau.
* Edite le contenu de ce rapport dans ta prochaine réponse. Il se nomme PCA_LOG.txt
FillPCA
-
ok merci voila le raport
# PCA Sécurité V 1.0.2, (fichier LOG).
# Rapport du :01/03/2008 09:57:34
Windows Vista (TM) Home Premium
==>> Processus <==
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\lenna\AppData\Local\Temp\Temp1_pca[1].zip\pca.exe
//pages de démarrage et de recherche d'Internet Explorer
RO - HKLM\Software\Microsoft\Internet Explorer\Main\Start Page = https://www.msn.com/fr-fr/
RO - HKLM\Software\Microsoft\Internet Explorer\Main\Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
RO - HKCU\Software\Microsoft\Internet Explorer\Main\Start Page = https://www.google.fr/?gws_rd=ssl
RO - HKCU\Software\Microsoft\Internet Explorer\Toolbar\LinksFolderName = Links
R1 - HKLM\Software\Microsoft\Internet Explorer\Main\Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main\Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main\Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
//applications lancées depuis system.ini,win.ini
//03 - Browser Helper Objects (BHOs)
//04 - applications chargées automatiquement
04 - HKLM\..\RUN: [Windows Defender] - %ProgramFiles%\Windows Defender\MSASCui.exe -hide
04 - HKLM\..\RUN: [NvSvc] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
04 - HKLM\..\RUN: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
04 - HKLM\..\RUN: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
04 - HKLM\..\RUN: [IAAnotif] - "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
04 - HKLU\..\RUN: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKLU\..\RUN: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 - HKLM\..\RunServices: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKLM\..\RunServices: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 - HKLU\..\RunServices: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKLU\..\RunServices: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 - HKUS\S-1-5-21-2039199306-4239844254-2581247415-1000\..\RUN: [Sidebar] - %ProgramFiles%\Windows Defender\MSASCui.exe -hide
04 - HKUS\S-1-5-21-2039199306-4239844254-2581247415-1000\..\RUN: [WindowsWelcomeCenter] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
//05 - Accès au panneau de contrôle d'Internet Explorer (control.ini)
//06- interdiction à l' accès au options (Internet Explorer)
//07 - blocage de l'exécution de Regedit
//08 - lignes supplémentaires dans le menu contextuel d'Internet Explorer
//09 - boutons situés sur la barre d'outils principale d'Internet Explorer
//O10 - Pirates de Winsock
O10 - fichier inconnu - winsock lsp : @%SystemRoot%\system32\nlasvc.dll,-1000 - %SystemRoot%\system32\NLAapi.dll
O10 - fichier inconnu - winsock lsp : @%SystemRoot%\system32\napinsp.dll,-1000 - %SystemRoot%\system32\napinsp.dll
O10 - fichier inconnu - winsock lsp : @%SystemRoot%\system32\pnrpnsp.dll,-1000 - %SystemRoot%\system32\pnrpnsp.dll
O10 - fichier inconnu - winsock lsp : @%SystemRoot%\system32\pnrpnsp.dll,-1001 - %SystemRoot%\system32\pnrpnsp.dll
//O11 - Onglet supplémentaire dans les options avancées d'Internet Explorer)
O11 - Options group: [INTERNATIONAL] - International*
//O12 - IE plugins
//013 : DefaultPrefix
//014 - Option : (Rétablir les paramètres Web)
//015 - Zone de confiance d'Internet Explorer
//O16 - Objets ActiveX
O16 - DPF : Shockwave Flash Object - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\Windows\system32\Macromed\Flash\Flash9e.ocx
//O17 - piratage de domaine Lop.com
//O18 - protocoles additionnels
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} -
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} -
//O19 - feuille de style de l'utilisateur
//O20 - valeur de Registre AppInit_DLLs et les sous-clés Winlogon Notify
//O21 - ShellServiceObjectDelayLoad
//O22 - SharedTaskScheduler
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll
//O23 - services de XP,NT, 2000, et 2003
O23 - Service: [@%SystemRoot%\system32\Alg.exe,-112] - %SystemRoot%\System32\alg.exe
O23 - Service: [avast! Antivirus] - "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
O23 - Service: [Microsoft .NET Framework NGEN v2.0.50727_X86] - %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
O23 - Service: [@comres.dll,-947] - %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
O23 - Service: [@dfsrres.dll,-101] - %SystemRoot%\system32\DFSR.exe
O23 - Service: [@%SystemRoot%\ehome\ehrecvr.exe,-101] - %systemroot%\ehome\ehRecvr.exe
O23 - Service: [@%SystemRoot%\ehome\ehsched.exe,-101] - %systemroot%\ehome\ehsched.exe
O23 - Service: [@%SystemRoot%\system32\PresentationHost.exe,-3309] - %systemroot%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
O23 - Service: [Intel(R) Matrix Storage Event Monitor] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: [@comres.dll,-2797] - %SystemRoot%\System32\msdtc.exe
O23 - Service: [@%SystemRoot%\system32\msimsg.dll,-27] - %systemroot%\system32\msiexec /V
O23 - Service: [@%systemroot%\system32\Locator.exe,-2] - %SystemRoot%\system32\locator.exe
O23 - Service: [@%SystemRoot%\system32\sdrsvc.dll,-107] - %SystemRoot%\system32\svchost.exe -k SDRSVC
O23 - Service: [@%SystemRoot%\system32\SLsvc.exe,-101] - %SystemRoot%\system32\SLsvc.exe
O23 - Service: [@%SystemRoot%\system32\snmptrap.exe,-3] - %SystemRoot%\System32\snmptrap.exe
O23 - Service: [@%systemroot%\system32\spoolsv.exe,-1] - %SystemRoot%\System32\spoolsv.exe
O23 - Service: [@%SystemRoot%\system32\wiaservc.dll,-9] - %SystemRoot%\system32\svchost.exe -k imgsvc
O23 - Service: [@%SystemRoot%\System32\swprv.dll,-103] - %SystemRoot%\System32\svchost.exe -k swprv
O23 - Service: [@%SystemRoot%\servicing\TrustedInstaller.exe,-100] - %SystemRoot%\servicing\TrustedInstaller.exe
O23 - Service: [@%SystemRoot%\system32\ui0detect.exe,-101] - %SystemRoot%\system32\UI0Detect.exe
O23 - Service: [@%SystemRoot%\system32\vds.exe,-100] - %SystemRoot%\System32\vds.exe
O23 - Service: [@%systemroot%\system32\vssvc.exe,-102] - %systemroot%\system32\vssvc.exe
O23 - Service: [@%Systemroot%\system32\wbem\wmiapsrv.exe,-110] - %systemroot%\system32\wbem\WmiApSrv.exe
O23 - Service: [@%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101] - "%ProgramFiles%\Windows Media Player\wmpnetwk.exe"
O23 - Service: [@%systemroot%\system32\SearchIndexer.exe,-103] - %systemroot%\system32\SearchIndexer.exe /Embedding
O23 - Service: [X10 Device Network Service] - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe -
Contributeur sécuritéSalut,
J'aimerais savoir une chose. Ton Kaspersky, tu l'as acheté ou tu as utilisé un crack ?
1/ Commence par désactiver l'UAC. Regarde ici : https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html
2/ * Télécharge Elibagla en bas de cette page sur ton Bureau. Pour cela, clique sur "Descargar Elibagla" : http://www.zonavirus.com/datos/descargas/95/elibagla.asp
* Lance-le de préférence en mode sans échec, ou en mode normal si le mode sans échec ne fonctionne pas.
* Bagle peut bloquer le mode sans échec, donc il ne faut absolument pas forcer le mode sans échec en passant par MSconfig. Cela peut provoquer un redémarrage en boucles du PC.
* Patiente pendant la durée du Scan.
* Copie-colle le contenu du rapport qui doit se trouver ici : C:\Infosat.txt
FillPCA -
Contributeur sécuritéOK. Peux-tu faire ce qui est demandé pour vérification ?
FillPCA-
oui j ai desactivé au niveau du compte d administrateur et la je fais le scann que tu me dis de faire,merci de m aidez je ni comprend rien et j espere que je fais bien se que tu me dis de faire...du coup je n ai plus d anti virus ni de par feu car il ma tout desinstallé! quel pauvre nul se pirate je n avais que wow et kaspersky sur 1000go je ne vois pas l interet pour lui!
-
Sat Mar 01 10:33:38 2008
EliBagle v11.09 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
Sat Mar 01 10:33:44 2008
EliBagle v11.09 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
Nº Total de Directorios: 8994
Nº Total de Ficheros: 51967
Nº de Ficheros Analizados: 9565
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
-
-
Contributeur sécuritéRe,
OK. On exclut donc cette piste et on creuse.
Si les manips qui suivent ne s'effectuent pas correctemment, fais un clic droit sur le programme et choisis "Exécuter en tant qu'administrateur".
1/ * Télécharge DiagHelp.zip sur ton bureau(Merci Malekal) : http://www.malekal.com/download/DiagHelp.zip
Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
* Ne double-clique pas dessus !! Fais un clic droit sur le fichier et extraire tout.
* Un nouveau dossier chercher va être créé.
* Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
* Une fenêtre va s'ouvrir, choisis l'option 1
* L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.
* Pendant l'analyse après le rapport CATCHME sur l'écran rouge, tu dois appuyer sue entrée pour que l'outil continue ses recherches. Suis les consignes écrites.
* Une fenêtre avec le rapport s'ouvre alors. Copie/colle son contenu. (Il se trouve aussi ici : c:\resultat.txt)
* Double-clique sur ce fichier, Fais CTRL+A puis CTRL+C.
* Dans ta prochaine réponse, colle le rapport en faisant CTRL+V.
2/ # Télécharge SREng (de Smallfrogs) : http://www.kztechs.com/eng/download.html
# Dézippe tout son contenu sur ton bureau (clic droit >Extraire ici).
# Ouvre le dossier SReng2 et double-clique sur SREngPS.exe.
# Clique sur "smart scan".
# Clique sur le bouton "scan".
# Quand l'analyse est terminée, clique sur le bouton "save reports".
# Sauvegarde alors le rapport sur ton bureau.
# Copie/colle le contenu du rapport SREnglLOG.log dans ta prochaine réponse.
Edite ces deux rapports.
-
[CODE]
2008-03-01,11:05:24
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows Vista Home Premium Edition (Build 6000) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun> [(Verified)Microsoft Windows]
<WindowsWelcomeCenter><rundll32.exe oobefldr.dll,ShowWelcomeCenter> [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Windows Defender><%ProgramFiles%\Windows Defender\MSASCui.exe -hide> [(Verified)Microsoft Windows]
<NvSvc><RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvCplDaemon><RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IAAnotif><"C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"> [(Verified)Intel Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe> [(Verified)Microsoft Windows]
<Userinit><C:\Windows\system32\userinit.exe,> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Windows Mail 7><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE> [N/A]
==================================
Startup Folders
N/A
==================================
Services
[Intel(R) Matrix Storage Event Monitor / IAANTMON][Running/Auto Start]
<C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe><Intel Corporation>
[X10 Device Network Service / x10nets][Running/Auto Start]
<C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe><X10>
==================================
Drivers
[adp94xx / adp94xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
[adpahci / adpahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu160m.sys><Adaptec, Inc.>
[adpu320 / adpu320][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
[aliide / aliide][Stopped/Disabled]
<\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
[amdide / amdide][Stopped/Disabled]
<\SystemRoot\system32\drivers\amdide.sys><Microsoft Corporation>
[arc / arc][Stopped/Disabled]
<\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[arcsas / arcsas][Stopped/Disabled]
<\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
[blbdrive / blbdrive][Stopped/Disabled]
<\SystemRoot\system32\drivers\blbdrive.sys><N/A>
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltlo.sys><Brother Industries, Ltd.>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltup.sys><Brother Industries, Ltd.>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserid.sys><Brother Industries Ltd.>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserwdm.sys><Brother Industries Ltd.>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brusbmdm.sys><Brother Industries Ltd.>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brusbser.sys><Brother Industries Ltd.>
[cmdide / cmdide][Stopped/Disabled]
<\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
[Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Running/Manual Start]
<system32\DRIVERS\e1e6032.sys><Intel Corporation>
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
<system32\DRIVERS\E1G60I32.sys><Intel Corporation>
[elxstor / elxstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[Service de pilote de carte VIA famille Rhine 10/100Mo Fast Ethernet / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HpCISSs / HpCISSs][Stopped/Disabled]
<\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[Intel RAID Controller / iaStor][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\iaStor.sys><Intel Corporation>
[Contrôleur RAID Intel Vista / iaStorV][Running/Boot Start]
<\SystemRoot\system32\drivers\iastorv.sys><Intel Corporation>
[iirsp / iirsp][Stopped/Disabled]
<\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteatapi.sys><Integrated Technology Express, Inc.>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteraid.sys><Integrated Technology Express, Inc.>
[lnsfw1 / lnsfw1][Running/System Start]
<system32\drivers\lnsfw1.sys><>
[LSI_FC / LSI_FC][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_fc.sys><LSI Logic>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[megasas / megasas][Stopped/Disabled]
<\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[Mraid35x / Mraid35x][Stopped/Disabled]
<\SystemRoot\system32\drivers\mraid35x.sys><LSI Logic Corporation>
[nfrd960 / nfrd960][Stopped/Disabled]
<\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
<\SystemRoot\system32\drivers\ntrigdigi.sys><N-trig Innovative Technologies>
[nvlddmkm / nvlddmkm][Running/Manual Start]
<system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
[nvraid / nvraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
[nvstor / nvstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
<system32\DRIVERS\nwlnkflt.sys><N/A>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
<system32\DRIVERS\nwlnkfwd.sys><N/A>
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
[R300 / R300][Stopped/Manual Start]
<system32\DRIVERS\atikmdag.sys><ATI Technologies Inc.>
[Look 'n' Stop Driver / SFilter][Running/Manual Start]
<system32\DRIVERS\lnsfw.sys><>
[SiSRaid2 / SiSRaid2][Stopped/Disabled]
<\SystemRoot\system32\drivers\sisraid2.sys><Silicon Integrated Systems Corp.>
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
<\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
[Symc8xx / Symc8xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\symc8xx.sys><LSI Logic>
[Sym_hi / Sym_hi][Stopped/Disabled]
<\SystemRoot\system32\drivers\sym_hi.sys><LSI Logic>
[Sym_u3 / Sym_u3][Stopped/Disabled]
<\SystemRoot\system32\drivers\sym_u3.sys><LSI Logic>
[uliahci / uliahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\uliahci.sys><ULi Electronics Inc.>
[UlSata / UlSata][Stopped/Disabled]
<\SystemRoot\system32\drivers\ulsata.sys><Promise Technology, Inc.>
[ulsata2 / ulsata2][Stopped/Disabled]
<\SystemRoot\system32\drivers\ulsata2.sys><Promise Technology, Inc.>
[viaide / viaide][Stopped/Disabled]
<\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
[vsmraid / vsmraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
[X10 Hid Device / X10Hid][Running/Manual Start]
<System32\Drivers\x10hid.sys><X10 Wireless Technology, Inc.>
==================================
Browser Add-ons
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[Yahoo! Toolbar avec bloqueur de fenêtres pop-up]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[YInstStarter Class]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} <C:\PROGRA~1\Yahoo!\Common\yinsthelper.dll, Yahoo! Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.>
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[InformationCardSigninHelper Class]
{19916E01-B44E-4E31-94A4-4696DF46157B} <C:\Windows\system32\icardie.dll, Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, N/A>
[HtmlDlgSafeHelper Class]
{3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\Windows\system32\mshtmled.dll, Microsoft Corporation>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, N/A>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\Windows\system32\ieframe.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.>
[Yahoo! Toolbar avec bloqueur de fenêtres pop-up]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[XML DOM Document 3.0]
{F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, N/A>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, N/A>
==================================
Running Processes
[PID: 392 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 456 / SYSTEM][C:\Windows\system32\csrss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 500 / SYSTEM][C:\Windows\system32\wininit.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 512 / SYSTEM][C:\Windows\system32\csrss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 544 / SYSTEM][C:\Windows\system32\services.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 556 / SYSTEM][C:\Windows\system32\lsass.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 568 / SYSTEM][C:\Windows\system32\lsm.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 704 / SYSTEM][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 764 / SERVICE RÉSEAU][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 812 / SYSTEM][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{57B1FF37-C7C5-498B-8607-ACD9936A114C}\mpengine.dll] [Microsoft Corporation, 1.1.3301.0]
[PID: 844 / SERVICE LOCAL][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 876 / SYSTEM][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 888 / SYSTEM][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 964 / SYSTEM][C:\Windows\system32\winlogon.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1060 / SERVICE RÉSEAU][C:\Windows\system32\SLsvc.exe] [Microsoft Corporation, 6.0.6000.16509 (vista_gdr.070620-1500)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1104 / SERVICE LOCAL][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1204 / SERVICE RÉSEAU][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1416 / SYSTEM][C:\Windows\System32\spoolsv.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1440 / SERVICE LOCAL][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1904 / lenna][C:\Windows\system32\Dwm.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1940 / lenna][C:\Windows\system32\taskeng.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 320 / lenna][C:\Windows\Explorer.EXE] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll] [Microsoft Corporation, 5.2.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 712 / lenna][C:\Windows\System32\rundll32.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\system32\NvMcTray.dll] [NVIDIA Corporation, 7.15.11.5828]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\System32\nvapi.dll] [NVIDIA Corporation, 7.15.11.5828]
[PID: 492 / lenna][C:\Windows\System32\rundll32.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\System32\NVSVC.DLL] [NVIDIA Corporation, 7.15.11.5828]
[C:\Windows\System32\nvapi.dll] [NVIDIA Corporation, 7.15.11.5828]
[PID: 1020 / lenna][C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\IAAMon_FRA.dll] [Intel Corporation, 7.5.0.1017]
[PID: 1124 / lenna][C:\Program Files\Windows Sidebar\sidebar.exe] [Microsoft Corporation, 6.0.6000.16615 (vista_gdr.071215-2230)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll] [Microsoft Corporation, 5.2.6000.16386 (vista_rtm.061101-2205)]
[PID: 752 / SYSTEM][C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\PlugInRAID_FRA.dll] [Intel Corporation, 7.5.0.1017]
[PID: 2148 / SERVICE RÉSEAU][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2172 / SERVICE LOCAL][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 2212 / SYSTEM][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2272 / SYSTEM][C:\Windows\system32\SearchIndexer.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 2328 / SYSTEM][C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe] [X10, 1, 0, 0, 1]
[C:\PROGRA~1\COMMON~1\X10\Common\x10net.DLL] [X10 Wireless Technology, Inc., 3, 0, 0, 209]
[C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 2560 / SERVICE LOCAL][C:\Windows\system32\WUDFHost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 3200 / SYSTEM][C:\Windows\system32\taskeng.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 3832 / lenna][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll] [Microsoft Corporation, 5.2.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\system32\nvd3dum.dll] [NVIDIA Corporation, 7.15.11.5828]
[C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.312_none_10b2ee7b9bffc2c7\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.312]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll] [Yahoo! Inc., 2006, 11, 29, 1]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\pubmod.dll] [Yahoo! Inc., 2006, 11, 27, 1]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll] [Yahoo! Inc., 2006.1.25.01]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\YTMsgr.dll] [Yahoo!, Inc., 2006, 11, 29, 1]
[PID: 2692 / lenna][C:\Windows\system32\conime.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2936 / lenna][C:\Users\lenna\Desktop\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Users\lenna\Desktop\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["%SystemRoot%\hh.exe" %1]
.HLP OK. [%SystemRoot%\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
::1 localhost
==================================
Process Privileges Scan
N/A
==================================
API HOOK
N/A
==================================
Hidden Process
N/A
==================================
/CODE -
[CODE]
2008-03-01,11:05:24
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows Vista Home Premium Edition (Build 6000) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun> [(Verified)Microsoft Windows]
<WindowsWelcomeCenter><rundll32.exe oobefldr.dll,ShowWelcomeCenter> [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Windows Defender><%ProgramFiles%\Windows Defender\MSASCui.exe -hide> [(Verified)Microsoft Windows]
<NvSvc><RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvCplDaemon><RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IAAnotif><"C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"> [(Verified)Intel Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe> [(Verified)Microsoft Windows]
<Userinit><C:\Windows\system32\userinit.exe,> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Windows Mail 7><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE> [N/A]
==================================
Startup Folders
N/A
==================================
Services
[Intel(R) Matrix Storage Event Monitor / IAANTMON][Running/Auto Start]
<C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe><Intel Corporation>
[X10 Device Network Service / x10nets][Running/Auto Start]
<C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe><X10>
==================================
Drivers
[adp94xx / adp94xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
[adpahci / adpahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu160m.sys><Adaptec, Inc.>
[adpu320 / adpu320][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
[aliide / aliide][Stopped/Disabled]
<\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
[amdide / amdide][Stopped/Disabled]
<\SystemRoot\system32\drivers\amdide.sys><Microsoft Corporation>
[arc / arc][Stopped/Disabled]
<\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[arcsas / arcsas][Stopped/Disabled]
<\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
[blbdrive / blbdrive][Stopped/Disabled]
<\SystemRoot\system32\drivers\blbdrive.sys><N/A>
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltlo.sys><Brother Industries, Ltd.>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltup.sys><Brother Industries, Ltd.>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserid.sys><Brother Industries Ltd.>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserwdm.sys><Brother Industries Ltd.>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brusbmdm.sys><Brother Industries Ltd.>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brusbser.sys><Brother Industries Ltd.>
[cmdide / cmdide][Stopped/Disabled]
<\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
[Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Running/Manual Start]
<system32\DRIVERS\e1e6032.sys><Intel Corporation>
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
<system32\DRIVERS\E1G60I32.sys><Intel Corporation>
[elxstor / elxstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[Service de pilote de carte VIA famille Rhine 10/100Mo Fast Ethernet / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HpCISSs / HpCISSs][Stopped/Disabled]
<\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[Intel RAID Controller / iaStor][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\iaStor.sys><Intel Corporation>
[Contrôleur RAID Intel Vista / iaStorV][Running/Boot Start]
<\SystemRoot\system32\drivers\iastorv.sys><Intel Corporation>
[iirsp / iirsp][Stopped/Disabled]
<\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteatapi.sys><Integrated Technology Express, Inc.>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteraid.sys><Integrated Technology Express, Inc.>
[lnsfw1 / lnsfw1][Running/System Start]
<system32\drivers\lnsfw1.sys><>
[LSI_FC / LSI_FC][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_fc.sys><LSI Logic>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[megasas / megasas][Stopped/Disabled]
<\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[Mraid35x / Mraid35x][Stopped/Disabled]
<\SystemRoot\system32\drivers\mraid35x.sys><LSI Logic Corporation>
[nfrd960 / nfrd960][Stopped/Disabled]
<\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
<\SystemRoot\system32\drivers\ntrigdigi.sys><N-trig Innovative Technologies>
[nvlddmkm / nvlddmkm][Running/Manual Start]
<system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
[nvraid / nvraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
[nvstor / nvstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
<system32\DRIVERS\nwlnkflt.sys><N/A>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
<system32\DRIVERS\nwlnkfwd.sys><N/A>
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
[R300 / R300][Stopped/Manual Start]
<system32\DRIVERS\atikmdag.sys><ATI Technologies Inc.>
[Look 'n' Stop Driver / SFilter][Running/Manual Start]
<system32\DRIVERS\lnsfw.sys><>
[SiSRaid2 / SiSRaid2][Stopped/Disabled]
<\SystemRoot\system32\drivers\sisraid2.sys><Silicon Integrated Systems Corp.>
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
<\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
[Symc8xx / Symc8xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\symc8xx.sys><LSI Logic>
[Sym_hi / Sym_hi][Stopped/Disabled]
<\SystemRoot\system32\drivers\sym_hi.sys><LSI Logic>
[Sym_u3 / Sym_u3][Stopped/Disabled]
<\SystemRoot\system32\drivers\sym_u3.sys><LSI Logic>
[uliahci / uliahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\uliahci.sys><ULi Electronics Inc.>
[UlSata / UlSata][Stopped/Disabled]
<\SystemRoot\system32\drivers\ulsata.sys><Promise Technology, Inc.>
[ulsata2 / ulsata2][Stopped/Disabled]
<\SystemRoot\system32\drivers\ulsata2.sys><Promise Technology, Inc.>
[viaide / viaide][Stopped/Disabled]
<\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
[vsmraid / vsmraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
[X10 Hid Device / X10Hid][Running/Manual Start]
<System32\Drivers\x10hid.sys><X10 Wireless Technology, Inc.>
==================================
Browser Add-ons
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[Yahoo! Toolbar avec bloqueur de fenêtres pop-up]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[YInstStarter Class]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} <C:\PROGRA~1\Yahoo!\Common\yinsthelper.dll, Yahoo! Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.>
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[InformationCardSigninHelper Class]
{19916E01-B44E-4E31-94A4-4696DF46157B} <C:\Windows\system32\icardie.dll, Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, N/A>
[HtmlDlgSafeHelper Class]
{3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\Windows\system32\mshtmled.dll, Microsoft Corporation>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, N/A>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\Windows\system32\ieframe.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.>
[Yahoo! Toolbar avec bloqueur de fenêtres pop-up]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[XML DOM Document 3.0]
{F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, N/A>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, N/A>
==================================
Running Processes
[PID: 392 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 456 / SYSTEM][C:\Windows\system32\csrss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 500 / SYSTEM][C:\Windows\system32\wininit.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 512 / SYSTEM][C:\Windows\system32\csrss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 544 / SYSTEM][C:\Windows\system32\services.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 556 / SYSTEM][C:\Windows\system32\lsass.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 568 / SYSTEM][C:\Windows\system32\lsm.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 704 / SYSTEM][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 764 / SERVICE RÉSEAU][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 812 / SYSTEM][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{57B1FF37-C7C5-498B-8607-ACD9936A114C}\mpengine.dll] [Microsoft Corporation, 1.1.3301.0]
[PID: 844 / SERVICE LOCAL][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 876 / SYSTEM][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 888 / SYSTEM][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 964 / SYSTEM][C:\Windows\system32\winlogon.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1060 / SERVICE RÉSEAU][C:\Windows\system32\SLsvc.exe] [Microsoft Corporation, 6.0.6000.16509 (vista_gdr.070620-1500)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1104 / SERVICE LOCAL][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1204 / SERVICE RÉSEAU][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1416 / SYSTEM][C:\Windows\System32\spoolsv.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1440 / SERVICE LOCAL][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1904 / lenna][C:\Windows\system32\Dwm.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1940 / lenna][C:\Windows\system32\taskeng.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 320 / lenna][C:\Windows\Explorer.EXE] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll] [Microsoft Corporation, 5.2.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 712 / lenna][C:\Windows\System32\rundll32.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\system32\NvMcTray.dll] [NVIDIA Corporation, 7.15.11.5828]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\System32\nvapi.dll] [NVIDIA Corporation, 7.15.11.5828]
[PID: 492 / lenna][C:\Windows\System32\rundll32.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\System32\NVSVC.DLL] [NVIDIA Corporation, 7.15.11.5828]
[C:\Windows\System32\nvapi.dll] [NVIDIA Corporation, 7.15.11.5828]
[PID: 1020 / lenna][C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\IAAMon_FRA.dll] [Intel Corporation, 7.5.0.1017]
[PID: 1124 / lenna][C:\Program Files\Windows Sidebar\sidebar.exe] [Microsoft Corporation, 6.0.6000.16615 (vista_gdr.071215-2230)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll] [Microsoft Corporation, 5.2.6000.16386 (vista_rtm.061101-2205)]
[PID: 752 / SYSTEM][C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll] [Intel Corporation, 7.5.0.1017]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Program Files\Intel\Intel Matrix Storage Manager\PlugInRAID_FRA.dll] [Intel Corporation, 7.5.0.1017]
[PID: 2148 / SERVICE RÉSEAU][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2172 / SERVICE LOCAL][C:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 2212 / SYSTEM][C:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2272 / SYSTEM][C:\Windows\system32\SearchIndexer.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 2328 / SYSTEM][C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe] [X10, 1, 0, 0, 1]
[C:\PROGRA~1\COMMON~1\X10\Common\x10net.DLL] [X10 Wireless Technology, Inc., 3, 0, 0, 209]
[C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 2560 / SERVICE LOCAL][C:\Windows\system32\WUDFHost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 3200 / SYSTEM][C:\Windows\system32\taskeng.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 3832 / lenna][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll] [Microsoft Corporation, 5.2.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Windows\system32\nvd3dum.dll] [NVIDIA Corporation, 7.15.11.5828]
[C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.312_none_10b2ee7b9bffc2c7\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.312]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll] [Yahoo! Inc., 2006, 11, 29, 1]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\pubmod.dll] [Yahoo! Inc., 2006, 11, 27, 1]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll] [Yahoo! Inc., 2006.1.25.01]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\YTMsgr.dll] [Yahoo!, Inc., 2006, 11, 29, 1]
[PID: 2692 / lenna][C:\Windows\system32\conime.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2936 / lenna][C:\Users\lenna\Desktop\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\COMCTL32.dll] [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[C:\Users\lenna\Desktop\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["%SystemRoot%\hh.exe" %1]
.HLP OK. [%SystemRoot%\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
::1 localhost
==================================
Process Privileges Scan
N/A
==================================
API HOOK
N/A
==================================
Hidden Process
N/A
==================================
/CODE -
-
-
DiagHelp version v1.4 - http://www.malekal.com
excute le 01/03/2008 à 10:53:52,05
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\Windows\prefetch\CHCP.COM-950EAF32.pf -->01/03/2008 10:53:50
C:\Windows\prefetch\IEXPLORE.EXE-1B894AFB.pf -->01/03/2008 10:53:14
C:\Windows\prefetch\FIND.EXE-162DFE58.pf -->01/03/2008 10:52:31
C:\Windows\prefetch\GZIP.EXE-B35ACAFC.pf -->01/03/2008 10:52:28
C:\Windows\prefetch\NTVDM.EXE-42770598.pf -->01/03/2008 10:52:27
C:\Windows\prefetch\KPROCCHECK.EXE-B9827383.pf -->01/03/2008 10:52:26
C:\Windows\prefetch\CATCHME.EXE-02C6DF1B.pf -->01/03/2008 10:52:25
C:\Windows\prefetch\DUMPHIVE.EXE-2A0F13BC.pf -->01/03/2008 10:52:18
C:\Windows\prefetch\CMD.EXE-89305D47.pf -->01/03/2008 10:52:18
C:\Windows\prefetch\SWREG.EXE-18BD52B2.pf -->01/03/2008 10:52:13
C:\Windows\System32\drivers\lnsfw1.sys -->28/02/2008 21:41:12
C:\Windows\System32\drivers\lnsfw.sys -->28/02/2008 21:41:12
C:\Windows\System32\drivers\klin.dat -->28/02/2008 21:36:18
C:\Windows\System32\drivers\klick.dat -->28/02/2008 21:36:18
C:\Windows\System32\drivers\wanarp.sys -->28/02/2008 21:19:03
C:\Windows\System32\drivers\ndproxy.sys -->28/02/2008 21:19:03
C:\Windows\System32\drivers\ndistapi.sys -->28/02/2008 21:19:03
C:\Windows\System32\PerfStringBackup.INI -->01/03/2008 10:36:06
C:\Windows\System32\perfh00C.dat -->01/03/2008 10:36:06
C:\Windows\System32\perfh009.dat -->01/03/2008 10:36:06
C:\Windows\System32\perfc00C.dat -->01/03/2008 10:36:06
C:\Windows\System32\perfc009.dat -->01/03/2008 10:36:06
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->01/03/2008 10:31:13
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->01/03/2008 10:31:13
C:\Windows\System32\config.nt -->29/02/2008 19:37:17
C:\Windows\System32\FNTCACHE.DAT -->28/02/2008 22:31:01
C:\Windows\System32\fwapi.dll -->28/02/2008 21:41:12
C:\Windows\System32\riched32.dll -->28/02/2008 21:19:05
C:\Windows\System32\riched20.dll -->28/02/2008 21:19:05
C:\Windows\System32\rasser.dll -->28/02/2008 21:19:03
C:\Windows\System32\rasdiag.dll -->28/02/2008 21:19:03
C:\Windows\System32\rasctrnm.h -->28/02/2008 21:19:03
C:\Windows\System32\rascfg.dll -->28/02/2008 21:19:03
C:\Windows\System32\ndptsp.tsp -->28/02/2008 21:19:03
C:\Windows\System32\kmddsp.tsp -->28/02/2008 21:19:03
C:\Windows\System32\rasmxs.dll -->28/02/2008 21:19:02
C:\Windows\System32\netcfgx.dll -->28/02/2008 21:19:02
C:\Windows\System32\msftedit.dll -->28/02/2008 21:19:02
C:\Windows\System32\icsunattend.exe -->28/02/2008 21:19:02
C:\Windows\System32\wshqos.dll -->28/02/2008 21:19:01
C:\Windows\System32\traffic.dll -->28/02/2008 21:19:01
C:\Windows\System32\pacerprf.dll -->28/02/2008 21:19:01
C:\Windows\WindowsUpdate.log -->01/03/2008 10:34:08
C:\Windows\bootstat.dat -->01/03/2008 10:31:11
C:\Windows\WindowsShell.Manifest -->28/02/2008 22:33:03
C:\Windows\explorer.exe -->28/02/2008 21:17:45
C:\Windows\win.ini -->02/11/2006 14:04:04
C:\Windows\WMSysPr9.prx -->02/11/2006 13:35:57
C:\Windows\twunk_32.exe -->02/11/2006 13:34:41
C:\Windows\twunk_16.exe -->02/11/2006 13:34:41
C:\Windows\twain_32.dll -->02/11/2006 13:34:41
C:\Windows\twain.dll -->02/11/2006 13:34:41
C:\Windows\notepad.exe -->02/11/2006 13:34:36
C:\Windows\winhlp32.exe -->02/11/2006 10:45:57
C:\Windows\regedit.exe -->02/11/2006 10:45:35
C:\Windows\hh.exe -->02/11/2006 10:45:13
C:\Windows\HelpPane.exe -->02/11/2006 10:45:13
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 320
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x00440000 0x2cd000 6.00.6000.16549 C:\Windows\Explorer.EXE
0x77320000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
0x75d50000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
0x77190000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
0x770c0000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
0x76180000 0x4b000 6.00.6000.16386 C:\Windows\system32\GDI32.dll
0x76d20000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
0x76dc0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
0x761f0000 0x55000 6.00.6000.16386 C:\Windows\system32\SHLWAPI.dll
0x76250000 0xace000 6.00.6000.16513 C:\Windows\system32\SHELL32.dll
0x75f00000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
0x77000000 0x8c000 6.00.6000.16609 C:\Windows\system32\OLEAUT32.dll
0x727b0000 0x107000 6.00.6000.16386 C:\Windows\system32\SHDOCVW.dll
0x745d0000 0x3f000 6.00.6000.16386 C:\Windows\system32\UxTheme.dll
0x74f40000 0x1a000 6.00.6000.16386 C:\Windows\system32\POWRPROF.dll
0x73260000 0xc000 6.00.6000.16386 C:\Windows\system32\dwmapi.dll
0x73a00000 0x1aa000 5.02.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll
0x75630000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
0x74610000 0xb7000 6.00.6000.16386 C:\Windows\system32\PROPSYS.dll
0x72660000 0x145000 6.00.6000.16386 C:\Windows\system32\BROWSEUI.dll
0x761d0000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.dll
0x77250000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
0x74720000 0x30000 6.00.6000.16386 C:\Windows\system32\DUser.dll
0x77450000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
0x774e0000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
0x74990000 0x194000 6.10.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
0x73490000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
0x72a30000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x75a70000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
0x75c30000 0x84000 2001.12.6930.16386 C:\Windows\system32\CLBCatQ.DLL
0x75200000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
0x725a0000 0xb2000 6.00.6000.16549 C:\Windows\system32\timedate.cpl
0x74be0000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x758e0000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
0x75bd0000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x736b0000 0x38000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x724e0000 0x53000 6.00.6000.16386 C:\Windows\system32\actxprxy.dll
0x75a90000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
0x72540000 0x2b000 6.00.6000.16386 C:\Windows\system32\msutb.dll
0x75000000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x756b0000 0x11000 6.00.6000.16386 C:\Windows\System32\SAMLIB.dll
0x75a10000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
0x72460000 0x38000 6.00.6000.16386 C:\Windows\System32\msshsq.dll
0x722c0000 0xc5000 6.00.6000.16386 C:\Windows\System32\NaturalLanguage6.dll
0x754f0000 0xf1000 6.00.6000.16425 C:\Windows\System32\CRYPT32.dll
0x75690000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x71da0000 0x28c000 6.00.6000.16386 C:\Windows\System32\NLSData000c.dll
0x711a0000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x73d60000 0x1e7000 6.00.6000.16513 C:\Windows\system32\authui.dll
0x74b40000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x76050000 0x127000 7.00.6000.16609 C:\Windows\system32\urlmon.dll
0x75be0000 0x45000 7.00.6000.16386 C:\Windows\system32\iertutil.dll
0x76e70000 0x189000 6.00.6000.16609 C:\Windows\system32\SETUPAPI.dll
0x74f60000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
0x75cc0000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
0x77090000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
0x77440000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
0x74d90000 0x2d000 6.00.6000.16386 C:\Windows\system32\WINTRUST.dll
0x75d20000 0x29000 6.00.6000.16470 C:\Windows\system32\imagehlp.dll
0x717d0000 0x5cd000 7.00.6000.16609 C:\Windows\system32\ieframe.dll
0x72a60000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x75e30000 0xcf000 7.00.6000.16609 C:\Windows\system32\WININET.dll
0x75d10000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x736f0000 0x33000 6.00.6000.16386 C:\Windows\system32\WINMM.dll
0x73620000 0x30000 6.00.6000.16386 C:\Windows\system32\wdmaud.drv
0x736a0000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x75290000 0x7000 6.00.6000.16386 C:\Windows\system32\AVRT.dll
0x74ca0000 0x27000 6.00.6000.16386 C:\Windows\system32\MMDevAPI.DLL
0x735c0000 0x21000 6.00.6000.16386 C:\Windows\System32\audioses.dll
0x73550000 0x66000 6.00.6000.16386 C:\Windows\System32\audioeng.dll
0x729f0000 0x9000 6.00.6000.16386 C:\Windows\system32\ExplorerFrame.dll
0x75950000 0x5f000 6.00.6000.16386 C:\Windows\system32\SXS.DLL
0x70d60000 0x212000 6.00.6000.16386 C:\Windows\system32\oobefldr.dll
0x73690000 0x9000 6.00.6000.16386 C:\Windows\system32\msacm32.drv
0x73600000 0x15000 6.00.6000.16386 C:\Windows\system32\MSACM32.dll
0x735f0000 0x7000 6.00.6000.16386 C:\Windows\system32\midimap.dll
0x70480000 0x4a000 6.00.6000.16386 C:\Windows\system32\ntshrui.dll
0x70970000 0xa000 6.00.6000.16386 C:\Windows\system32\cscapi.dll
0x728c0000 0x126000 8.90.1101.0000 C:\Windows\System32\msxml3.dll
0x737c0000 0x30000 6.00.6000.16386 C:\Windows\system32\MLANG.dll
0x6f2f0000 0x62000 6.00.6000.16386 C:\Windows\system32\mscms.dll
0x72dd0000 0x41000 6.00.6000.16386 C:\Windows\system32\WINSPOOL.DRV
0x6f230000 0x60000 6.00.6000.16386 C:\Windows\system32\WinSATAPI.dll
0x74e50000 0x14000 6.00.6000.16386 C:\Windows\system32\Cabinet.dll
0x6ee80000 0x92000 6.00.6000.16386 C:\Windows\system32\stobject.dll
0x6f370000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x74f30000 0x9000 6.00.6000.16553 C:\Windows\system32\WTSAPI32.dll
0x74c00000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
0x746d0000 0x45000 2001.12.6930.16386 C:\Windows\system32\es.dll
0x6fb30000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x6fb00000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x74c80000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x6e7f0000 0x30b000 6.00.6000.16386 C:\Windows\System32\netshell.dll
0x75490000 0x19000 6.00.6000.16386 C:\Windows\System32\IPHLPAPI.DLL
0x75450000 0x35000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc.DLL
0x756e0000 0x2b000 6.00.6000.16386 C:\Windows\System32\DNSAPI.dll
0x75610000 0x7000 6.00.6000.16386 C:\Windows\System32\WINNSI.DLL
0x75430000 0x20000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc6.DLL
0x74f20000 0xf000 6.00.6000.16386 C:\Windows\System32\nlaapi.dll
0x74e70000 0x63000 6.00.6000.16501 C:\Windows\system32\FirewallAPI.dll
0x75400000 0x8000 6.00.6000.16386 C:\Windows\system32\VERSION.dll
0x6ec50000 0x1bf000 6.00.6000.16386 C:\Windows\system32\pnidui.dll
0x73740000 0x17000 6.00.6000.16386 C:\Windows\system32\QUtil.dll
0x754b0000 0x3e000 6.00.6000.16386 C:\Windows\system32\wevtapi.dll
0x73780000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x70310000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x72580000 0xe000 6.00.6000.16551 C:\Windows\system32\Wlanapi.dll
0x723d0000 0x2d000 6.00.6000.16386 C:\Windows\system32\OneX.DLL
0x72570000 0xd000 6.00.6000.16386 C:\Windows\system32\eappprxy.dll
0x723a0000 0x28000 6.00.6000.16386 C:\Windows\system32\eappcfg.dll
0x75360000 0x44000 6.00.6000.16386 C:\Windows\system32\bcrypt.dll
0x702e0000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x6eb90000 0x23000 6.00.6000.16386 C:\Windows\system32\wpdshserviceobj.dll
0x73d00000 0x5f000 6.00.6000.16386 C:\Windows\system32\WINHTTP.dll
0x6eb10000 0x40000 6.00.6000.16386 C:\Windows\System32\srchadmin.dll
0x6e6e0000 0x3c000 7.00.6000.16386 C:\Windows\system32\webcheck.dll
0x6f6c0000 0x21c000 6.00.6000.16386 C:\Windows\System32\SyncCenter.dll
0x6eb50000 0x39000 6.00.6000.16386 C:\Windows\system32\wscntfy.dll
0x73730000 0xb000 6.00.6000.16386 C:\Windows\system32\WSCAPI.dll
0x6fd10000 0xb000 6.00.6000.16386 C:\Windows\system32\mssprxy.dll
0x6e620000 0x51000 6.00.6000.16386 C:\Windows\system32\imapi2.dll
0x73790000 0x2b000 6.00.6000.16386 C:\Windows\system32\PortableDeviceTypes.dll
0x70740000 0x46000 6.00.6000.16386 C:\Windows\system32\PortableDeviceApi.dll
0x6fd20000 0x2c000 6.00.6000.16386 C:\Windows\System32\QAgent.dll
0x73c10000 0x8a000 6.00.6000.16386 C:\Windows\System32\fwpuclnt.dll
0x6d270000 0xf9000 6.00.6000.16386 C:\Windows\system32\bthprops.cpl
0x6cdd0000 0x12f000 2001.12.6930.16386 C:\Windows\system32\comsvcs.dll
0x755f0000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
0x70230000 0x12000 6.00.6000.16386 C:\Windows\system32\thumbcache.dll
0x6d450000 0x56000 6.00.6000.16386 C:\Windows\system32\zipfldr.dll
0x73650000 0x15000 1.01.1505.0000 C:\Program Files\Windows Defender\MpOav.dll
0x6e580000 0x60000 6.00.6000.16386 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x74470000 0x22000 1.01.1002.0000 C:\Windows\system32\xmllite.dll
0x6c3e0000 0x223000 6.00.6000.16386 C:\Windows\system32\NetworkExplorer.dll
0x730f0000 0x8000 4.00.6000.16386 C:\Windows\system32\MSISIP.DLL
0x6e3e0000 0x11000 5.07.0000.6000 C:\Windows\system32\wshext.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 964
Command line: winlogon.exe
Base Size Version Path
0x00ad0000 0x4e000 6.00.6000.16386 C:\Windows\system32\winlogon.exe
0x77320000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
0x75d50000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
0x77190000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
0x770c0000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
0x76d20000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
0x76180000 0x4b000 6.00.6000.16386 C:\Windows\system32\GDI32.dll
0x76dc0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
0x75a70000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
0x74c00000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
0x75bd0000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x75a90000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
0x761d0000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.DLL
0x77250000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
0x77450000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
0x774e0000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
0x75a10000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
0x74f60000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
0x75cc0000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
0x77090000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
0x77440000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
0x756b0000 0x11000 6.00.6000.16386 C:\Windows\system32\SAMLIB.dll
0x75f00000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
0x74810000 0x3e000 6.00.6000.16386 C:\Windows\system32\SHSVCS.dll
0x745d0000 0x3f000 6.00.6000.16386 C:\Windows\system32\uxtheme.dll
0x75200000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
0x73490000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
0x758e0000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
0x75630000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
0x755f0000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 20C5-CF1A
Répertoire de C:\Windows\system32
02/11/2006 10:45 7 680 csrss.exe
1 fichier(s) 7 680 octets
0 Rép(s) 967 977 013 248 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 20C5-CF1A
Répertoire de C:\Windows\Downloaded Program Files
01/03/2008 09:45 <REP> .
01/03/2008 09:45 <REP> ..
18/09/2006 22:26 65 desktop.ini
20/11/2007 16:04 1 523 536 FP_AX_CAB_INSTALLER.exe
20/11/2007 15:50 247 swflash.inf
3 fichier(s) 1 523 848 octets
Total des fichiers listés :
3 fichier(s) 1 523 848 octets
2 Rép(s) 967 977 013 248 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
dword:00000000 présent dans la clef HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon - Possible infection [b]Trojan.DNS/Wareout/b
Liste des fichiers en exception sur le pare-feu XP SP2
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
exports des policies
REGEDIT4
[System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
[System\UIPI]
[System\UIPI\Clipboard]
[System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 10:54:00
Windows 6.0.6000 NTFS
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 20C5-CF1A
Répertoire de C:\Program Files
01/03/2008 10:44 <REP> .
01/03/2008 10:44 <REP> ..
29/02/2008 19:37 <REP> Alwil Software
01/03/2008 10:44 <REP> CCleaner
29/02/2008 17:55 <REP> Common Files
28/02/2008 19:42 <REP> Intel
28/02/2008 22:29 <REP> Internet Explorer
28/02/2008 19:31 <REP> Marvell
02/11/2006 13:37 <REP> Microsoft Games
02/11/2006 13:42 <REP> Movie Maker
02/11/2006 13:37 <REP> MSBuild
02/11/2006 13:37 <REP> MSN
02/11/2006 13:37 <REP> Reference Assemblies
28/02/2008 21:41 <REP> Soft4Ever
01/03/2008 10:31 <REP> Spybot - Search & Destroy
29/02/2008 21:28 <REP> Trend Micro
28/02/2008 22:29 <REP> Windows Calendar
02/11/2006 13:42 <REP> Windows Collaboration
28/02/2008 22:29 <REP> Windows Defender
02/11/2006 13:42 <REP> Windows Journal
28/02/2008 22:29 <REP> Windows Mail
28/02/2008 22:29 <REP> Windows Media Player
28/02/2008 19:23 <REP> Windows NT
02/11/2006 13:42 <REP> Windows Photo Gallery
28/02/2008 22:29 <REP> Windows Sidebar
01/03/2008 10:44 <REP> Yahoo!
0 fichier(s) 0 octets
26 Rép(s) 967 976 747 008 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 20C5-CF1A
Répertoire de C:\Program Files\fichiers communs
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 20C5-CF1A
Répertoire de C:\Program Files\common files
29/02/2008 17:55 <REP> .
29/02/2008 17:55 <REP> ..
28/02/2008 19:37 <REP> InstallShield
02/11/2006 13:42 <REP> microsoft shared
02/11/2006 12:18 <REP> Services
02/11/2006 12:18 <REP> SpeechEngines
28/02/2008 22:29 <REP> System
28/02/2008 19:34 <REP> X10
0 fichier(s) 0 octets
8 Rép(s) 967 976 747 008 octets libres
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\catchme.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\diff.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\dumphive.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\FilesInfoCmd.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\find2.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\Fport.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\grep.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\gzip.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\KProcCheck.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\LFiles.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\LISTDLLS.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\md5sums.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\pslist.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\sigcheck.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\streams.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\swreg.exe
c:\Users\lenna\Documents\DiagHelp[1]\DiagHelp\tar.exe
c:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.3.2.7741-to-2.3.3.7799-frFR-downloader.exe
c:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.3.2.7741-to-2.3.3.7799-frFR-patch.exe
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_PC-de-lenna.tar.gz a l'adresse http://upload.malekal.com
- 1
- 2
- 3
- 4
Suivant