ComboFix 09-12-01.01 - benoît POMERAT 01/12/2009 19:07.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.894.322 [GMT 1:00]
Lancé depuis: c:\documents and settings\benoît POMERAT\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091201-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\recycler\S-1-5-21-1123561945-920026266-1177238915-1003
c:\windows\msetup
c:\windows\msetup\MSetup.exe
C:\zPharaoh.exe
D:\zPharaoh.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-01 au 2009-12-01 ))))))))))))))))))))))))))))))))))))
.
2009-11-30 22:00 . 2009-11-30 22:00 0 ----a-w- c:\windows\nsreg.dat
2009-11-30 21:45 . 2009-12-01 18:00 32768 ----a-w- c:\documents and settings\tazebama.dll
2009-11-30 09:03 . 2009-11-30 09:03 -------- d-----w- c:\program files\RegistryBooster
2009-11-30 06:56 . 2009-11-30 06:06 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-30 06:05 . 2009-11-30 06:05 242984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-30 06:05 . 2009-11-30 06:05 5908024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-11-30 06:05 . 2009-11-30 06:05 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-30 06:05 . 2009-11-30 06:05 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-30 06:05 . 2009-11-30 06:05 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-30 06:05 . 2009-11-30 06:05 641632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-30 06:04 . 2009-11-30 06:05 816272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-30 06:04 . 2009-11-30 06:04 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-30 06:04 . 2009-11-30 06:04 1638640 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-30 06:04 . 2009-11-30 06:04 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-30 06:04 . 2009-11-30 06:04 1184912 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-11-30 06:03 . 2009-11-30 18:41 3081375 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-30 06:02 . 2009-11-30 06:02 -------- d-----w- c:\program files\Lavasoft
2009-11-30 06:02 . 2009-11-30 06:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-30 06:00 . 2009-11-30 06:00 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-11-30 06:00 . 2009-11-30 06:00 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2009-11-30 06:00 . 2009-09-28 18:34 83288 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-11-30 06:00 . 2009-09-28 18:34 47416 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2009-11-30 06:00 . 2009-09-28 18:34 28984 ----a-w- c:\windows\system32\LMIport.dll
2009-11-30 06:00 . 2008-08-11 11:41 47640 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-11-30 06:00 . 2009-09-28 18:34 87352 ----a-w- c:\windows\system32\LMIinit.dll
2009-11-30 05:59 . 2009-11-30 23:15 -------- d-----w- c:\program files\LogMeIn
2009-11-29 22:45 . 2009-11-30 07:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-11-29 22:45 . 2009-11-29 22:45 -------- d-----w- c:\program files\Yahoo!
2009-11-29 22:45 . 2009-11-29 22:45 -------- d-----w- c:\program files\CCleaner
2009-11-29 22:33 . 2009-11-29 22:33 164 ----a-w- c:\windows\install.dat
2009-11-29 22:08 . 2009-11-30 06:03 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-29 21:37 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 21:37 . 2009-11-29 21:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 21:37 . 2009-11-29 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-29 21:37 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 20:01 . 2009-11-29 22:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-29 20:01 . 2009-11-29 20:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-29 16:33 . 2009-11-29 16:33 -------- d-----w- c:\documents and settings\SYSTEM
2009-11-29 11:23 . 2009-11-29 11:23 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-11-29 11:23 . 2009-11-29 11:23 -------- d-----w- c:\program files\McAfee Security Scan
2009-11-29 11:23 . 2009-11-29 16:42 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-29 11:23 . 2009-11-29 16:42 -------- d-----w- c:\program files\NOS
2009-11-19 07:43 . 2009-11-19 07:43 -------- d-----w- C:\BrowserPlusPlugins
2009-11-14 18:33 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-14 18:33 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-14 18:33 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-14 18:33 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-14 18:33 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-14 18:33 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-14 18:33 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-14 18:33 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-14 18:32 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-14 18:32 . 2003-03-18 21:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-11-14 18:32 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-11-14 18:32 . 2003-02-21 04:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-11-14 18:32 . 2009-11-14 18:32 -------- d-----w- c:\program files\Alwil Software
2009-11-14 16:47 . 2009-03-24 15:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-10 17:26 . 2009-11-10 17:26 -------- d-----w- c:\documents and settings\amis\Bluetooth Software
2009-11-09 17:22 . 2009-11-09 17:22 -------- d-----w- c:\program files\Marvell
2009-11-08 15:31 . 2009-11-08 15:31 -------- d-----w- c:\documents and settings\caroline POMERAT\Application Data\dvdcss
2009-11-08 15:24 . 2009-11-08 15:56 -------- d-----w- c:\documents and settings\caroline POMERAT\Application Data\vlc
2009-11-05 10:03 . 2009-11-05 10:03 -------- d-----w- c:\windows\Sun
2009-11-05 10:02 . 2009-11-05 10:02 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-03 16:45 . 2009-11-03 16:45 -------- d-sh--w- c:\documents and settings\caroline POMERAT\PrivacIE
2009-11-03 16:44 . 2009-11-03 16:44 -------- d-sh--w- c:\documents and settings\caroline POMERAT\IETldCache
2009-11-03 11:26 . 2009-11-03 11:26 -------- d-----w- c:\windows\ie8updates
2009-11-03 08:20 . 2009-08-29 07:56 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-03 08:20 . 2009-08-29 07:56 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-11-03 08:20 . 2009-08-29 07:56 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-03 08:20 . 2009-08-29 07:56 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-03 08:20 . 2009-08-29 07:56 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-03 08:20 . 2009-08-29 07:56 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-11-03 08:20 . 2009-11-03 08:20 21840 ----a-w- c:\windows\system32\SIntfNT.dll
2009-11-03 08:20 . 2009-11-03 08:20 17212 ----a-w- c:\windows\system32\SIntf32.dll
2009-11-03 08:20 . 2009-11-03 08:20 12067 ----a-w- c:\windows\system32\SIntf16.dll
2009-11-02 12:29 . 2009-11-02 12:29 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-02 11:30 . 2009-11-02 11:30 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-11-02 10:09 . 2009-11-02 10:09 -------- d-----w- c:\program files\VideoLAN
2009-11-02 09:22 . 2009-11-02 09:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-11-02 08:27 . 2009-11-02 08:29 -------- dc-h--w- c:\windows\ie8
2009-11-02 07:38 . 2009-03-26 15:37 409600 ----a-w- c:\windows\system32\s3iset32_2_00_96.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-30 19:09 . 2009-03-27 18:50 2864 ----a-w- c:\windows\system32\winsock.dll
2009-11-29 11:25 . 2009-03-27 12:33 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-21 17:32 . 2009-03-27 12:26 -------- d-----w- c:\program files\Samsung
2009-11-21 17:32 . 2009-03-27 12:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-11 12:32 . 2009-03-27 18:50 368314 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-11 12:32 . 2009-03-27 18:50 49054 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-09 19:15 . 2009-10-29 12:20 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-11-05 10:02 . 2009-03-27 12:23 -------- d-----w- c:\program files\Java
2009-10-31 07:52 . 2009-10-31 07:52 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-10-29 17:16 . 2009-10-29 17:16 43200 ----a-w- c:\documents and settings\caroline POMERAT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 17:13 . 2009-10-29 17:13 -------- d-----w- c:\documents and settings\caroline POMERAT\Application Data\MSNInstaller
2009-10-29 16:58 . 2009-10-29 16:58 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-10-29 15:53 . 2009-03-27 12:30 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-10-29 15:31 . 2009-10-29 15:31 -------- d-----w- c:\program files\Microsoft.NET
2009-10-29 11:37 . 2009-03-27 12:18 76507 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-29 09:20 . 2009-10-29 09:20 -------- d-----w- c:\program files\CyberLink
2009-10-29 09:20 . 2009-10-29 09:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Temp
2009-10-29 09:18 . 2009-10-29 09:18 -------- d-----w- c:\program files\WIDCOMM
2009-10-29 09:18 . 2009-10-29 09:18 0 ----a-w- c:\windows\system32\drivers\144D_SAMSUNG_N_NC20_09MQ.mrk
2009-09-23 12:55 . 2009-11-30 06:06 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-11 14:18 . 2009-03-27 18:50 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:04 . 2009-03-27 18:50 58880 ----a-w- c:\windows\system32\msasn1.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-27 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-30 305807]
"EDS"="c:\program files\Samsung\Samsung EDS\EDSAgent.exe" [2007-12-20 659456]
"Chrome3"="c:\program files\s3graphics\chrome3\Chrome3.exe" [2009-04-30 1274368]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-28 1044480]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2008-11-27 2768896]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2006-05-14 151552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-11-17 17676288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-17 580200]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-28 18:34 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [30/11/2009 07:06 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [14/11/2009 19:33 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [14/11/2009 19:33 20560]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [27/03/2009 13:23 4300]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12:17 1184912]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [11/08/2008 12:41 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [30/11/2009 07:00 47640]
R2 S3Funkey;S3Funkey;c:\program files\s3graphics\chrome3\S3Funkey.svc [30/04/2009 14:18 444416]
R2 S3LoadSv;S3LoadSv;c:\program files\s3graphics\chrome3\s3loadsv.svc [30/04/2009 14:18 387072]
R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [27/03/2009 19:50 14336]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [14/01/2008 19:01 30208]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [27/03/2009 19:53 581632]
R3 vcrdrx32;VIA MSP Cardreader Host Controller;c:\windows\system32\drivers\vcrdrx32.sys [27/03/2009 19:54 90752]
R3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\drivers\VMC326.sys [27/03/2009 13:28 238464]
S3 SUEPD;SUE NDIS Protocol Driver;c:\windows\system32\drivers\SUE_PD.sys [01/08/2006 15:57 19840]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
yksvcs REG_MULTI_SZ yksvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenu du dossier 'Tâches planifiées'
2009-12-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 06:04]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://fr.my.yahoo.com/
uSearch Page =
hxxp://www.google.com
uSearch Bar =
hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext =
hxxp://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Envoyer à Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\benoît POMERAT\Application Data\Mozilla\Firefox\Profiles\5ub2umt3.default\
FF - plugin: c:\browserplusplugins\35c4ce3dc0119b5e07a1be2d07ff7a0d\npybrowserplus_2.4.21.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-VTTimer - VTTimer.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-Ad-Aware - c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program files\NOS\bin\getPlus_Helper.dll
AddRemove-Yahoo! BrowserPlus - c:\documents and settings\benoît POMERAT\Local Settings\Application Data\Yahoo!\BrowserPlus\BrowserPlusUninstaller.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-01 19:15
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\LMIinit.dll
.
Heure de fin: 2009-12-01 19:17
ComboFix-quarantined-files.txt 2009-12-01 18:17
Avant-CF: 65 097 687 040 octets libres
Après-CF: 65 503 678 464 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - 6E151056AFF70C3696CA0C516BC006A0
############################## | UsbFix V6.059 |
User : benoît POMERAT (Administrateurs) # SAMSUNG
Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
Start at: 19:39:10 | 01/12/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact :
FindyKill.Contact@gmail.com
VIA Nano processor U2250@1300+MHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1368 [VPS 091201-0] 4.8.1368 [ (!) Disabled | Updated ]
C:\ -> Disque fixe local # 70,04 Go (60,98 Go free) # NTFS
D:\ -> Disque fixe local # 73 Go (72,63 Go free) # NTFS
E:\ -> Disque amovible # 980,72 Mo (685,5 Mo free) # FAT
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 632
C:\WINDOWS\system32\csrss.exe 708
C:\WINDOWS\system32\winlogon.exe 732
C:\WINDOWS\system32\services.exe 776
C:\WINDOWS\system32\lsass.exe 788
C:\WINDOWS\system32\svchost.exe 944
C:\WINDOWS\system32\svchost.exe 1012
C:\WINDOWS\System32\svchost.exe 1052
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 1092
C:\WINDOWS\system32\svchost.exe 1184
C:\WINDOWS\system32\svchost.exe 1248
C:\WINDOWS\System32\svchost.exe 1268
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1388
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1404
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1472
C:\WINDOWS\system32\spoolsv.exe 1860
C:\WINDOWS\system32\svchost.exe 1136
C:\Program Files\Java\jre6\bin\jqs.exe 1240
C:\Program Files\LogMeIn\x86\RaMaint.exe 1360
C:\Program Files\LogMeIn\x86\LogMeIn.exe 1752
C:\Program Files\LogMeIn\x86\LMIGuardian.exe 1888
C:\Program Files\s3graphics\chrome3\s3funkey.svc 1920
C:\Program Files\s3graphics\chrome3\s3loadsv.svc 2004
C:\WINDOWS\system32\svchost.exe 168
C:\WINDOWS\RTHDCPL.EXE 328
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe 424
C:\Program Files\s3graphics\chrome3\Chrome3.exe 452
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 484
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 672
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe 1904
C:\WINDOWS\system32\ctfmon.exe 2064
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2072
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe 2220
C:\Program Files\LogMeIn\x86\LMIGuardian.exe 2232
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe 2248
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe 2264
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE 2668
C:\WINDOWS\system32\wbem\unsecapp.exe 2836
C:\WINDOWS\system32\wbem\wmiprvse.exe 2884
C:\WINDOWS\system32\wbem\wmiapsrv.exe 3088
C:\WINDOWS\System32\alg.exe 3260
C:\Program Files\s3graphics\chrome3\s3funkey.svc 3528
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 3212
C:\WINDOWS\system32\wscntfy.exe 2092
C:\WINDOWS\system32\wuauclt.exe 1612
C:\WINDOWS\explorer.exe 3356
C:\Program Files\LogMeIn\x86\LogMeIn.exe 2976
C:\Documents and Settings\tazebama.dl_ 3884
C:\WINDOWS\system32\wbem\wmiprvse.exe 5128
################## | Fichiers # Dossiers infectieux |
C:\autorun.inf
C:\autorun.inf -> fichier appelé : "C:\zPharaoh.exe" ( Présent ! )
D:\autorun.inf
D:\autorun.inf -> fichier appelé : "D:\zPharaoh.exe" ( Présent ! )
E:\autorun.inf
E:\autorun.inf -> fichier appelé : "E:\zPharaoh.exe" ( Présent ! )
################## | Spyware.OnlineGames |
################## | Mabezat |
C:\Documents and Settings\hook.dl_
C:\Documents and Settings\tazebama.dl_
C:\Documents and Settings\tazebama.dll
C:\DOCUME~1\BENOTP~1\APPLIC~1\tazebama\zPharaoh.dat
C:\DOCUME~1\BENOTP~1\APPLIC~1\tazebama
C:\zPharaoh.exe
D:\zPharaoh.exe
E:\zPharaoh.exe
C:\zPharaoh.exe
C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
C:\Documents and Settings\benoît POMERAT\Bureau\ComboFix.exe
C:\Documents and Settings\benoît POMERAT\Bureau\Firefox Setup 3.0.15.exe
C:\Documents and Settings\benoît POMERAT\Bureau\HiJackThis.exe
C:\Documents and Settings\benoît POMERAT\Bureau\lavasoft_adawarefree.exe
C:\Documents and Settings\benoît POMERAT\Bureau\registrybooster.exe
C:\Documents and Settings\benoît POMERAT\Bureau\SpySweeperSNRSetup_FR.exe
C:\Documents and Settings\benoît POMERAT\Bureau\programmes ordi\ccsetup224.exe
C:\Program Files\CCleaner\uninst.exe
C:\Program Files\CyberLink\Shared files\EffectExtractor.exe
C:\Program Files\CyberLink\YouCam\BigBang\CLUpdater.exe
C:\Program Files\CyberLink\YouCam\Language\youcam-tutorial.exe
C:\Program Files\CyberLink\YouCam\MUITransfer\muistartmenu.exe
C:\Program Files\CyberLink\YouCam\OLRSubmission\OLRStateCheck.exe
C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AcrobatUpdater.exe
C:\Program Files\Fichiers communs\Adobe\ARM\1.0\ReaderUpdater.exe
C:\Program Files\Fichiers communs\Adobe\Updater6\AdobeUpdaterInstallMgr.exe
C:\Program Files\Fichiers communs\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Fichiers communs\InstallShield\Driver\7\Intel 32\IDriver.exe
C:\Program Files\Fichiers communs\InstallShield\Engine\6\Intel 32\IKernel.exe
C:\Program Files\Fichiers communs\Microsoft Shared\DW\DW20.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\DW\DWTRIG20.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\MODI\11.0\MSPVIEW.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\MSInfo\OINFOP11.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\11\DFUICOM.EXE
C:\Program Files\Fichiers communs\System\MSMAPI\1036\CNFNOT32.EXE
C:\Program Files\Fichiers communs\System\MSMAPI\1036\SCANOST.EXE
C:\Program Files\Fichiers communs\System\MSMAPI\1036\SCANPST.EXE
C:\Program Files\Google\Common\Google Updater\googleupdaterservice.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarUser_32_1D643E0FC0BE74CC.exe
C:\Program Files\Google\Google Toolbar\Component\GoogleUpdaterService_5898FABCFA121C11.exe
C:\Program Files\Google\Google Toolbar\Component\SearchWithGoogleUpdate_C5C67DF5D46FB314.exe
C:\Program Files\Google\GoogleToolbarNotifier\swg-5.3.4501.1418\SearchWithGoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\swg-5.4.4525.1752\SearchWithGoogleUpdate.exe
C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe
C:\Program Files\InstallShield Installation Information\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}\setup.exe
C:\Program Files\InstallShield Installation Information\{17283B95-21A8-4996-97DA-547A48DB266F}\setup.exe
C:\Program Files\InstallShield Installation Information\{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}\setup.exe
C:\Program Files\InstallShield Installation Information\{6F730513-8688-4C3C-90A3-6B9792CE2EF3}\setup.exe
C:\Program Files\InstallShield Installation Information\{71A51B59-E7D3-11DB-A386-005056C00008}\setup.exe
C:\Program Files\InstallShield Installation Information\{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}\Setup.exe
C:\Program Files\InstallShield Installation Information\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}\setup.exe
C:\Program Files\InstallShield Installation Information\{BD723E53-A42C-4702-AA04-1D74A0311590}\setup.exe
C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe
C:\Program Files\InstallShield Installation Information\{F4F41D14-E0DD-4FB4-AA09-A14225C769BD}\setup.exe
C:\Program Files\Java\jre1.5.0\bin\java.exe
C:\Program Files\Java\jre1.5.0\bin\javacpl.exe
C:\Program Files\Java\jre1.5.0\bin\javaw.exe
C:\Program Files\Java\jre1.5.0\bin\javaws.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Java\jre1.5.0\bin\keytool.exe
C:\Program Files\Java\jre1.5.0\bin\kinit.exe
C:\Program Files\Java\jre1.5.0\bin\klist.exe
C:\Program Files\Java\jre1.5.0\bin\ktab.exe
C:\Program Files\Java\jre1.5.0\bin\orbd.exe
C:\Program Files\Java\jre1.5.0\bin\pack200.exe
C:\Program Files\Java\jre1.5.0\bin\policytool.exe
C:\Program Files\Java\jre1.5.0\bin\rmid.exe
C:\Program Files\Java\jre1.5.0\bin\rmiregistry.exe
C:\Program Files\Java\jre1.5.0\bin\servertool.exe
C:\Program Files\Java\jre1.5.0\bin\tnameserv.exe
C:\Program Files\Java\jre6\bin\java-rmi.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Java\jre6\bin\javacpl.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Java\jre6\bin\javaws.exe
C:\Program Files\Java\jre6\bin\jbroker.exe
C:\Program Files\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\jqsnotify.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Java\jre6\bin\jureg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\keytool.exe
C:\Program Files\Java\jre6\bin\kinit.exe
C:\Program Files\Java\jre6\bin\klist.exe
C:\Program Files\Java\jre6\bin\ktab.exe
C:\Program Files\Java\jre6\bin\orbd.exe
C:\Program Files\Java\jre6\bin\pack200.exe
C:\Program Files\Java\jre6\bin\policytool.exe
C:\Program Files\Java\jre6\bin\rmid.exe
C:\Program Files\Java\jre6\bin\rmiregistry.exe
C:\Program Files\Java\jre6\bin\servertool.exe
C:\Program Files\Java\jre6\bin\ssvagent.exe
C:\Program Files\Java\jre6\bin\tnameserv.exe
C:\Program Files\Lavasoft\Ad-Aware\Download Guard for Internet Explorer.exe
C:\Program Files\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\AutoStart Manager.exe
C:\Program Files\Lavasoft\Ad-Aware\ToolBox\LT\HostFileEditor.exe
C:\Program Files\Lavasoft\Ad-Aware\ToolBox\LT\ProcessWatch.exe
C:\Program Files\LogMeIn\x86\LogMeInToolkit.exe
C:\Program Files\LogMeIn\x86\openssl.exe
C:\Program Files\LogMeIn\x86\rainst.exe
C:\Program Files\LogMeIn\x86\RA_SC.exe
C:\Program Files\LogMeIn\x86\zip.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe
C:\Program Files\Marvell\Miniport Driver\installu.exe
C:\Program Files\Marvell\Miniport Driver\Uninst.exe
C:\Program Files\McAfee Security Scan\uninstall.exe
C:\Program Files\McAfee Security Scan\1.0.150\mcuicnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\OFFICE11\DSSM.EXE
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Microsoft Office\OFFICE11\GRAPH.EXE
C:\Program Files\Microsoft Office\OFFICE11\INFOPATH.EXE
C:\Program Files\Microsoft Office\OFFICE11\MSACCESS.EXE
C:\Program Files\Microsoft Office\OFFICE11\MSOHTMED.EXE
C:\Program Files\Microsoft Office\OFFICE11\MSPUB.EXE
C:\Program Files\Microsoft Office\OFFICE11\MSTORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OIS.EXE
C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
C:\Program Files\Microsoft Office\OFFICE11\PROFLWIZ.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Office\OFFICE11\1036\MSOHELP.EXE
C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
C:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
C:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
C:\Program Files\MSN\MsnInstaller\msninst.exe
C:\Program Files\Realtek\Audio\Drivers\RtlUpd.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\Alcmtr.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\AlcWzrd.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\MicCal.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\RTHDCPL.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\RtkAudioService.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\RTLCPL.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\RtlUpd.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\SkyTel.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\SoundMan.exe
C:\Program Files\Realtek\Audio\Drivers\WDM\vncutil.exe
C:\Program Files\RegistryBooster\registrybooster.exe
C:\Program Files\RegistryBooster\unins000.exe
C:\Program Files\S3\Chrome9HC\s3minset.exe
C:\Program Files\s3graphics\chrome3\s3loadsv.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Easy Display Manager\DMLauncher_XP.exe
C:\Program Files\Samsung\Easy Display Manager\dmloader.exe
C:\Program Files\Samsung\Easy Display Manager\EDM-BatteryWarning.exe
C:\Program Files\Samsung\Easy Display Manager\HotKeyOption.exe
C:\Program Files\Samsung\Easy Display Manager\wlan.exe
C:\Program Files\Samsung\Easy Network Manager\ENM.exe
C:\Program Files\Samsung\Easy Network Manager\HelpLaunch.exe
C:\Program Files\Samsung\Easy Network Manager\MakeAdHoc.exe
C:\Program Files\Samsung\Easy Network Manager\Support\InstallHelper.exe
C:\Program Files\Samsung\Easy Network Manager\Support\UninstallHelper.exe
C:\Program Files\Samsung\Samsung Battery Manager\KStartMem.exe
C:\Program Files\Samsung\Samsung Battery Manager\PSMode.exe
C:\Program Files\Samsung\Samsung Magic Doctor\KStartMem.exe
C:\Program Files\Samsung\Samsung Magic Doctor\RegSIS.exe
C:\Program Files\Samsung\Samsung Magic Doctor\Specinfo.exe
C:\Program Files\Samsung\Samsung Magic Doctor\OneclickSTS\FixWZC.exe
C:\Program Files\Samsung\Samsung Recovery Solution III\GoRecovery.exe
C:\Program Files\Samsung\Samsung Recovery Solution III\InstDrv.exe
C:\Program Files\Samsung\Samsung Recovery Solution III\KStartMem.exe
C:\Program Files\Samsung\Samsung Recovery Solution III\Manager1.exe
C:\Program Files\Samsung\Samsung Recovery Solution III\WCScheduler.exe
C:\Program Files\Samsung\Samsung Update Plus\supbackground.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPClientApp.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPHelp.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPNotifier.exe
C:\Program Files\Samsung\Samsung Update Plus\Archives\IT00000384\setup.exe
C:\Program Files\Samsung\Samsung Update Plus\Archives\IT00000384\SSetup.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_chs\samsungmanual_chs.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_cht\samsungmanual_cht.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_dan\samsungmanual_dan.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_dut\samsungmanual_dut.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_eng\samsungmanual_eng.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_fin\samsungmanual_fin.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_fra\samsungmanual_fra.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_ger\samsungmanual_ger.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_ita\samsungmanual_ita.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_kor\samsungmanual_kor.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_nor\samsungmanual_nor.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_pol\samsungmanual_pol.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_rus\samsungmanual_rus.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_spn\samsungmanual_spn.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_swe\samsungmanual_swe.exe
C:\Program Files\Samsung\SamsungManual\samsungmanual_tur\samsungmanual_tur.exe
C:\Program Files\Spybot - Search & Destroy\blindman.exe
C:\Program Files\Spybot - Search & Destroy\SDFiles.exe
C:\Program Files\Spybot - Search & Destroy\SDMain.exe
C:\Program Files\Spybot - Search & Destroy\SDShred.exe
C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Spybot - Search & Destroy\unins000.exe
C:\Program Files\Spybot - Search & Destroy\Update.exe
C:\Program Files\Spybot - Search & Destroy\Updates\advcheck165.exe
C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.exe
C:\Program Files\Synaptics\SynTP\InstNT.exe
C:\Program Files\Synaptics\SynTP\SynMood.exe
C:\Program Files\Synaptics\SynTP\SynZMetr.exe
C:\Program Files\Synaptics\SynTP\Tutorial.exe
C:\Program Files\Synaptics\SynTP\Media\InstNT.exe
C:\Program Files\Synaptics\SynTP\Media\SynMood.exe
C:\Program Files\Synaptics\SynTP\Media\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\Media\SynZMetr.exe
C:\Program Files\Synaptics\SynTP\Media\Tutorial.exe
C:\Program Files\VideoLAN\VLC\uninstall.exe
C:\Program Files\Vimicro Corporation\VMC326\DriverBackup\isvmsetup.exe
C:\Program Files\Vimicro Corporation\VMC326\DriverBackup\vuvcterm.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtwHfConfig.exe
C:\Program Files\WIDCOMM\Bluetooth Software\gzip.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0006902.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0006903.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0007931.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0007933.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0010938.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011957.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011958.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011959.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011960.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011961.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011962.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011974.EXE
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011975.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011977.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011978.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011979.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011980.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011981.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011989.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011999.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012000.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012106.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012107.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012108.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP26\A0012594.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP26\A0012595.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP26\A0012596.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP26\A0012597.exe
C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP26\A0012791.exe
D:\zPharaoh.exe
D:\MSOCache\MSOCache .exe
D:\MSOCache\WinrRarSerialInstall.exe
D:\MSOCache\All Users\All Users .exe
D:\MSOCache\All Users\Make Windows Original.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\9000040c-6000-11D3-8CFE-0150048383C9 .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\Office2003 CD-Key.doc.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\FILES .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\Office2007 Serial.txt.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\KasperSky6.0 Key.doc.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\PFILES .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\COMMON .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\InstallMSN11En.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\Crack_GoogleEarthPro.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\MSSHARED .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\AmericanOnLine.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\DW .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\DW20.EXE
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\DWTRIG20.EXE
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\1036\1036 .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\1036\msjavx86.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\Lock Folder.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\MSOFFICE .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\FloppyDiskPartion.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\OFFICE11 .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\1036\1036 .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\1036\HP_LaserJetAllInOneConfig.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\JetAudio dump.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\SETUP .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\InstallMSN11Ar.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\WINDOWS .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\INF\INF .exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\INF\Microsoft Windows Network.exe
D:\RECYCLER\RECYCLER .exe
D:\RECYCLER\WinrRarSerialInstall.exe
D:\RECYCLER\S-1-5-21-951959548-2110113444-66279279-1005\NokiaN73Tools.exe
D:\RECYCLER\S-1-5-21-951959548-2110113444-66279279-1005\S-1-5-21-951959548-2110113444-66279279-1005 .exe
D:\RECYCLER\S-1-5-21-951959548-2110113444-66279279-1006\Make Windows Original.exe
D:\RECYCLER\S-1-5-21-951959548-2110113444-66279279-1006\S-1-5-21-951959548-2110113444-66279279-1006 .exe
E:\EMF.exe
E:\zPharaoh.exe
E:\Documents Formateur\Documents Formateur .exe
E:\Documents Formateur\WinrRarSerialInstall.exe
E:\files\files .exe
E:\files\NokiaN73Tools.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\MSOCache\WinrRarSerialInstall.exe
D:\MSOCache\All Users\Make Windows Original.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\InstallMSN11En.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\Crack_GoogleEarthPro.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\AmericanOnLine.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\1036\msjavx86.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\Lock Folder.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\FloppyDiskPartion.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\1036\HP_LaserJetAllInOneConfig.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\JetAudio dump.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\InstallMSN11Ar.exe
D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\INF\Microsoft Windows Network.exe
D:\RECYCLER\WinrRarSerialInstall.exe
D:\RECYCLER\S-1-5-21-951959548-2110113444-66279279-1005\NokiaN73Tools.exe
D:\RECYCLER\S-1-5-21-951959548-2110113444-66279279-1006\Make Windows Original.exe
E:\Documents Formateur\WinrRarSerialInstall.exe
E:\files\NokiaN73Tools.exe
################## | Registre # Clés infectieuses |
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
################## | Registre # Mountpoints2 |
################## | Cracks / Keygens / Serials |
"D:\MSOCache\WinrRarSerialInstall.exe"
28/11/2009 09:06 |Size 155031 |Crc32 e02a5f3d |Md5 ae4f6b2d9b169fe2f4249d28e517ef18
"D:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\Crack_GoogleEarthPro.exe"
28/11/2009 09:06 |Size 154961 |Crc32 81bf71f8 |Md5 5abd2ef0194685d783a2cf1076a645ad
"D:\RECYCLER\WinrRarSerialInstall.exe"
01/12/2009 19:23 |Size 155031 |Crc32 e02a5f3d |Md5 ae4f6b2d9b169fe2f4249d28e517ef18
"E:\Documents Formateur\WinrRarSerialInstall.exe"
27/11/2009 20:05 |Size 155031 |Crc32 e02a5f3d |Md5 ae4f6b2d9b169fe2f4249d28e517ef18
################## | ! Fin du rapport # UsbFix V6.059 ! |
############################## | UsbFix V6.059 |
User : benoît POMERAT (Administrateurs) # SAMSUNG
Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
Start at: 20:40:45 | 01/12/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact :
FindyKill.Contact@gmail.com
VIA Nano processor U2250@1300+MHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1368 [VPS 091201-0] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque fixe local # 70,04 Go (60,95 Go free) # NTFS
D:\ -> Disque fixe local # 73 Go (72,63 Go free) # NTFS
E:\ -> Disque amovible # 980,72 Mo (685,5 Mo free) # FAT
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 632
C:\WINDOWS\system32\csrss.exe 704
C:\WINDOWS\system32\winlogon.exe 728
C:\WINDOWS\system32\services.exe 772
C:\WINDOWS\system32\lsass.exe 784
C:\WINDOWS\system32\svchost.exe 940
C:\WINDOWS\system32\svchost.exe 1008
C:\WINDOWS\System32\svchost.exe 1048
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 1080
C:\WINDOWS\system32\svchost.exe 1180
C:\WINDOWS\system32\svchost.exe 1244
C:\WINDOWS\System32\svchost.exe 1264
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1384
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1400
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1468
C:\WINDOWS\Explorer.EXE 1772
C:\WINDOWS\system32\spoolsv.exe 228
C:\WINDOWS\system32\svchost.exe 1356
C:\Program Files\Java\jre6\bin\jqs.exe 1536
C:\Program Files\LogMeIn\x86\RaMaint.exe 1664
C:\Program Files\Alwil Software\Avast4\setup\avast.setup 1692
C:\Program Files\LogMeIn\x86\LogMeIn.exe 1764
C:\Program Files\LogMeIn\x86\LMIGuardian.exe 1860
C:\Program Files\s3graphics\chrome3\s3funkey.svc 1920
C:\Program Files\s3graphics\chrome3\s3loadsv.svc 392
C:\WINDOWS\system32\svchost.exe 436
C:\WINDOWS\system32\wuauclt.exe 1120
C:\WINDOWS\system32\wbem\wmiprvse.exe 1160
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 1816
C:\WINDOWS\system32\wbem\unsecapp.exe 2064
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 2056
C:\WINDOWS\system32\wbem\wmiprvse.exe 2148
C:\WINDOWS\system32\wbem\wmiapsrv.exe 2212
C:\WINDOWS\System32\alg.exe 2388
################## | Fichiers # Dossiers infectieux |
Non supprimé ! C:\autorun.inf
Non supprimé ! D:\autorun.inf
Non supprimé ! E:\autorun.inf
################## | Spyware.OnlineGames |
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0006902.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011962.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP26\A0012594.exe
################## | Mabezat |
Supprimé ! C:\Documents and Settings\hook.dl_
Supprimé ! C:\Documents and Settings\tazebama.dl_
Supprimé ! C:\Documents and Settings\tazebama.dll
Supprimé ! C:\DOCUME~1\BENOTP~1\APPLIC~1\tazebama\zPharaoh.dat
Supprimé ! C:\DOCUME~1\BENOTP~1\APPLIC~1\tazebama
Supprimé ! C:\zPharaoh.exe
Supprimé ! D:\zPharaoh.exe
Supprimé ! E:\zPharaoh.exe
Supprimé ! C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\ComboFix.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\Firefox Setup 3.0.15.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\HiJackThis.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\lavasoft_adawarefree.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\registrybooster.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\SpySweeperSNRSetup_FR.exe
Supprimé ! C:\Documents and Settings\benoŒt POMERAT\Bureau\programmes ordi\ccsetup224.exe
Supprimé ! C:\Program Files\CCleaner\uninst.exe
Supprimé ! C:\Program Files\CyberLink\Shared files\EffectExtractor.exe
Supprimé ! C:\Program Files\CyberLink\YouCam\BigBang\CLUpdater.exe
Supprimé ! C:\Program Files\CyberLink\YouCam\Language\youcam-tutorial.exe
Supprimé ! C:\Program Files\CyberLink\YouCam\MUITransfer\muistartmenu.exe
Supprimé ! C:\Program Files\CyberLink\YouCam\OLRSubmission\OLRStateCheck.exe
Supprimé ! C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AcrobatUpdater.exe
Supprimé ! C:\Program Files\Fichiers communs\Adobe\ARM\1.0\ReaderUpdater.exe
Supprimé ! C:\Program Files\Fichiers communs\Adobe\Updater6\AdobeUpdaterInstallMgr.exe
Supprimé ! C:\Program Files\Fichiers communs\Adobe\Updater6\Adobe_Updater.exe
Supprimé ! C:\Program Files\Fichiers communs\InstallShield\Driver\7\Intel 32\IDriver.exe
Supprimé ! C:\Program Files\Fichiers communs\InstallShield\Engine\6\Intel 32\IKernel.exe
Supprimé ! C:\Program Files\Fichiers communs\Microsoft Shared\DW\DW20.EXE
Supprimé ! C:\Program Files\Fichiers communs\Microsoft Shared\DW\DWTRIG20.EXE
Supprimé ! C:\Program Files\Fichiers communs\Microsoft Shared\MODI\11.0\MSPVIEW.EXE
Supprimé ! C:\Program Files\Fichiers communs\Microsoft Shared\MSInfo\OINFOP11.EXE
Supprimé ! C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\11\DFUICOM.EXE
Supprimé ! C:\Program Files\Fichiers communs\System\MSMAPI\1036\CNFNOT32.EXE
Supprimé ! C:\Program Files\Fichiers communs\System\MSMAPI\1036\SCANOST.EXE
Supprimé ! C:\Program Files\Fichiers communs\System\MSMAPI\1036\SCANPST.EXE
Supprimé ! C:\Program Files\Google\Common\Google Updater\googleupdaterservice.exe
Supprimé ! C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
Supprimé ! C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe
Supprimé ! C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarUser_32_1D643E0FC0BE74CC.exe
Supprimé ! C:\Program Files\Google\Google Toolbar\Component\GoogleUpdaterService_5898FABCFA121C11.exe
Supprimé ! C:\Program Files\Google\Google Toolbar\Component\SearchWithGoogleUpdate_C5C67DF5D46FB314.exe
Supprimé ! C:\Program Files\Google\GoogleToolbarNotifier\swg-5.3.4501.1418\SearchWithGoogleUpdate.exe
Supprimé ! C:\Program Files\Google\GoogleToolbarNotifier\swg-5.4.4525.1752\SearchWithGoogleUpdate.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{17283B95-21A8-4996-97DA-547A48DB266F}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{6F730513-8688-4C3C-90A3-6B9792CE2EF3}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{71A51B59-E7D3-11DB-A386-005056C00008}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}\Setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{BD723E53-A42C-4702-AA04-1D74A0311590}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe
Supprimé ! C:\Program Files\InstallShield Installation Information\{F4F41D14-E0DD-4FB4-AA09-A14225C769BD}\setup.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\java.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\javacpl.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\javaw.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\javaws.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\jusched.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\keytool.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\kinit.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\klist.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\ktab.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\orbd.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\pack200.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\policytool.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\rmid.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\rmiregistry.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\servertool.exe
Supprimé ! C:\Program Files\Java\jre1.5.0\bin\tnameserv.exe
Supprimé ! C:\Program Files\Java\jre6\bin\java-rmi.exe
Supprimé ! C:\Program Files\Java\jre6\bin\javacpl.exe
Supprimé ! C:\Program Files\Java\jre6\bin\javaw.exe
Supprimé ! C:\Program Files\Java\jre6\bin\javaws.exe
Supprimé ! C:\Program Files\Java\jre6\bin\jbroker.exe
Supprimé ! C:\Program Files\Java\jre6\bin\jp2launcher.exe
Supprimé ! C:\Program Files\Java\jre6\bin\jqsnotify.exe
Supprimé ! C:\Program Files\Java\jre6\bin\jucheck.exe
Supprimé ! C:\Program Files\Java\jre6\bin\jureg.exe
Supprimé ! C:\Program Files\Java\jre6\bin\jusched.exe
Supprimé ! C:\Program Files\Java\jre6\bin\keytool.exe
Supprimé ! C:\Program Files\Java\jre6\bin\kinit.exe
Supprimé ! C:\Program Files\Java\jre6\bin\klist.exe
Supprimé ! C:\Program Files\Java\jre6\bin\ktab.exe
Supprimé ! C:\Program Files\Java\jre6\bin\orbd.exe
Supprimé ! C:\Program Files\Java\jre6\bin\pack200.exe
Supprimé ! C:\Program Files\Java\jre6\bin\policytool.exe
Supprimé ! C:\Program Files\Java\jre6\bin\rmid.exe
Supprimé ! C:\Program Files\Java\jre6\bin\rmiregistry.exe
Supprimé ! C:\Program Files\Java\jre6\bin\servertool.exe
Supprimé ! C:\Program Files\Java\jre6\bin\ssvagent.exe
Supprimé ! C:\Program Files\Java\jre6\bin\tnameserv.exe
Supprimé ! C:\Program Files\Lavasoft\Ad-Aware\Download Guard for Internet Explorer.exe
Supprimé ! C:\Program Files\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\AutoStart Manager.exe
Supprimé ! C:\Program Files\Lavasoft\Ad-Aware\ToolBox\LT\HostFileEditor.exe
Supprimé ! C:\Program Files\Lavasoft\Ad-Aware\ToolBox\LT\ProcessWatch.exe
Supprimé ! C:\Program Files\LogMeIn\x86\LogMeInToolkit.exe
Supprimé ! C:\Program Files\LogMeIn\x86\openssl.exe
Supprimé ! C:\Program Files\LogMeIn\x86\rainst.exe
Supprimé ! C:\Program Files\LogMeIn\x86\RA_SC.exe
Supprimé ! C:\Program Files\LogMeIn\x86\zip.exe
Supprimé ! C:\Program Files\LogMeIn\x86\update\raupdate.exe
Supprimé ! C:\Program Files\LogMeIn\x86\update\x86__LogMeInToolkit.exe
Supprimé ! C:\Program Files\LogMeIn\x86\update\x86__openssl.exe
Supprimé ! C:\Program Files\LogMeIn\x86\update\x86__rainst.exe
Supprimé ! C:\Program Files\LogMeIn\x86\update\x86__ra_sc.exe
Supprimé ! C:\Program Files\LogMeIn\x86\update\x86__zip.exe
Supprimé ! C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
Supprimé ! C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe
Supprimé ! C:\Program Files\Marvell\Miniport Driver\installu.exe
Supprimé ! C:\Program Files\Marvell\Miniport Driver\Uninst.exe
Supprimé ! C:\Program Files\McAfee Security Scan\uninstall.exe
Supprimé ! C:\Program Files\McAfee Security Scan\1.0.150\mcuicnt.exe
Supprimé ! C:\Program Files\Messenger\msmsgs.exe
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\DSSM.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\GRAPH.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\INFOPATH.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\MSACCESS.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\MSOHTMED.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\MSPUB.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\MSTORE.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\OIS.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\PROFLWIZ.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
Supprimé ! C:\Program Files\Microsoft Office\OFFICE11\1036\MSOHELP.EXE
Supprimé ! C:\Program Files\Mozilla Firefox\updater.exe
Supprimé ! C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Supprimé ! C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
Supprimé ! C:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
Supprimé ! C:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
Supprimé ! C:\Program Files\MSN\MsnInstaller\msninst.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\RtlUpd.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\Alcmtr.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\AlcWzrd.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\MicCal.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\RTHDCPL.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\RtkAudioService.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\RTLCPL.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\RtlUpd.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\SkyTel.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\SoundMan.exe
Supprimé ! C:\Program Files\Realtek\Audio\Drivers\WDM\vncutil.exe
Supprimé ! C:\Program Files\RegistryBooster\registrybooster.exe
Supprimé ! C:\Program Files\RegistryBooster\unins000.exe
Supprimé ! C:\Program Files\S3\Chrome9HC\s3minset.exe
Supprimé ! C:\Program Files\s3graphics\chrome3\s3loadsv.exe
Supprimé ! C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
Supprimé ! C:\Program Files\Samsung\Easy Display Manager\DMLauncher_XP.exe
Supprimé ! C:\Program Files\Samsung\Easy Display Manager\dmloader.exe
Supprimé ! C:\Program Files\Samsung\Easy Display Manager\EDM-BatteryWarning.exe
Supprimé ! C:\Program Files\Samsung\Easy Display Manager\HotKeyOption.exe
Supprimé ! C:\Program Files\Samsung\Easy Display Manager\wlan.exe
Supprimé ! C:\Program Files\Samsung\Easy Network Manager\ENM.exe
Supprimé ! C:\Program Files\Samsung\Easy Network Manager\HelpLaunch.exe
Supprimé ! C:\Program Files\Samsung\Easy Network Manager\MakeAdHoc.exe
Supprimé ! C:\Program Files\Samsung\Easy Network Manager\Support\InstallHelper.exe
Supprimé ! C:\Program Files\Samsung\Easy Network Manager\Support\UninstallHelper.exe
Supprimé ! C:\Program Files\Samsung\MagicKBD\PerformanceManager.exe
Supprimé ! C:\Program Files\Samsung\Samsung Battery Manager\KStartMem.exe
Supprimé ! C:\Program Files\Samsung\Samsung Battery Manager\PSMode.exe
Supprimé ! C:\Program Files\Samsung\Samsung Magic Doctor\KStartMem.exe
Supprimé ! C:\Program Files\Samsung\Samsung Magic Doctor\RegSIS.exe
Supprimé ! C:\Program Files\Samsung\Samsung Magic Doctor\Specinfo.exe
Supprimé ! C:\Program Files\Samsung\Samsung Magic Doctor\OneclickSTS\FixWZC.exe
Supprimé ! C:\Program Files\Samsung\Samsung Recovery Solution III\GoRecovery.exe
Supprimé ! C:\Program Files\Samsung\Samsung Recovery Solution III\InstDrv.exe
Supprimé ! C:\Program Files\Samsung\Samsung Recovery Solution III\KStartMem.exe
Supprimé ! C:\Program Files\Samsung\Samsung Recovery Solution III\Manager1.exe
Supprimé ! C:\Program Files\Samsung\Samsung Recovery Solution III\WCScheduler.exe
Supprimé ! C:\Program Files\Samsung\Samsung Update Plus\supbackground.exe
Supprimé ! C:\Program Files\Samsung\Samsung Update Plus\SUPClientApp.exe
Supprimé ! C:\Program Files\Samsung\Samsung Update Plus\SUPHelp.exe
Supprimé ! C:\Program Files\Samsung\Samsung Update Plus\SUPNotifier.exe
Supprimé ! C:\Program Files\Samsung\Samsung Update Plus\Archives\IT00000384\setup.exe
Supprimé ! C:\Program Files\Samsung\Samsung Update Plus\Archives\IT00000384\SSetup.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_chs\samsungmanual_chs.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_cht\samsungmanual_cht.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_dan\samsungmanual_dan.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_dut\samsungmanual_dut.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_eng\samsungmanual_eng.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_fin\samsungmanual_fin.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_fra\samsungmanual_fra.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_ger\samsungmanual_ger.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_ita\samsungmanual_ita.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_kor\samsungmanual_kor.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_nor\samsungmanual_nor.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_pol\samsungmanual_pol.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_rus\samsungmanual_rus.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_spn\samsungmanual_spn.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_swe\samsungmanual_swe.exe
Supprimé ! C:\Program Files\Samsung\SamsungManual\samsungmanual_tur\samsungmanual_tur.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\InstNT.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\SynMood.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\SynZMetr.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\Tutorial.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\Media\InstNT.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\Media\SynMood.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\Media\SynTPEnh.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\Media\SynZMetr.exe
Supprimé ! C:\Program Files\Synaptics\SynTP\Media\Tutorial.exe
Supprimé ! C:\Program Files\VideoLAN\VLC\uninstall.exe
Supprimé ! C:\Program Files\Vimicro Corporation\VMC326\DriverBackup\isvmsetup.exe
Supprimé ! C:\Program Files\Vimicro Corporation\VMC326\DriverBackup\vuvcterm.exe
Supprimé ! C:\Program Files\WIDCOMM\Bluetooth Software\BtwHfConfig.exe
Supprimé ! C:\Program Files\WIDCOMM\Bluetooth Software\gzip.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0006903.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0007931.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0007933.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0010938.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011957.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011958.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011959.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011960.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011961.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011974.EXE
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011975.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011977.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011978.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011979.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011980.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011981.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011989.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0011999.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012000.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012106.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012107.exe
Supprimé ! C:\System Volume Information\_restore{B8351707-18C8-4C75-85F9-DF984B93B760}\RP25\A0012108.exe