Bonjour,
Bon y'a du nouveau.
J'ai passé une bonne partie de la nuit à essayer d'éradiquer ce 'VirusGarde'.
Voila ce que j'ai fait.
1) Chargement et éxécution de AVG AntiSpyware
2) Nettoyage de ce qui a été détecté
Identification de l'infection le 2/10/2007 à 1h14 sous la session 'Maryam'
3) Recherche effectuée sur tous les fichiers modifiés et/ou créés entre le 2/10/2007 à 01h12 et le 3/10/2007
4)Réatribution des droits admins via Vilma Reg Explorer
5) Nettoyage manuel de tous les fichiers suspects trouvés
6)Exécution pour les 3 sessions de la totalité des opérations que nous avons déjà réalisés ensemble
7)exécution de RegCleaner puis CCleaner.
8)Scan complet avec Symantec center
9)Suppression des mails
Voili. J'en suis là et RAS pour l'instant.
Ci dessous les 2 rapports demandés pour la session thierry en espérant que tu ne détectes rien d'autre de suspect.
---------------------------------------------------------------------------
"Silent Runners.vbs", revision 52,
http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
"Yahoo! Pager" = ""C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet" ["Yahoo! Inc."]
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" ["Google Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"LaunchApp" = "Alaunch" ["Acer Inc."]
"IgfxTray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
"SynTPLpr" = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" ["Synaptics, Inc."]
"SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
"PCMService" = ""C:\Program Files\Arcade\PCMService.exe"" ["CyberLink Corp."]
"IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS]
"MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data]
"PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS]
"PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"EPM-DM" = "c:\acer\epm\epm-dm.exe" ["Acer Inc"]
"ePowerManagement" = "C:\Acer\ePM\ePM.exe boot" ["Acer Value Labs, Taiwan"]
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"SNPSTD2" = "C:\WINDOWS\vsnpstd2.exe" [empty string]
"vptray" = "C:\Program Files\NavNT\vptray.exe" ["Symantec Corporation"]
"OpwareSE2" = ""C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"" ["ScanSoft, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["GRISOFT s.r.o."]
HKLM\Software\Microsoft\Active Setup\Installed Components\
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
\StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
-> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
"{2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0}" = "EPM-PO Shell Extension"
-> {HKLM...CLSID} = "EPM-PO Shell Extensions"
\InProcServer32\(Default) = "epm-po.dll" ["Acer Labs USA"]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {HKLM...CLSID} = "YMailShellExt Class"
\InProcServer32\(Default) = "C:\PROGRA~1\YAHOO!\COMMON\ymmapi.dll" ["Yahoo! Inc."]
"{5ECD31F0-F91A-11D4-B3CA-00D0B70A09D2}" = "Extension Shell PC Soft"
-> {HKLM...CLSID} = "Extension Shell PC Soft"
\InProcServer32\(Default) = "WDShell" [file not found]
"{BDA77241-42F6-11d0-85E2-00AA001FE28C}" = "LDVP Shell Extensions"
-> {HKLM...CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{5ECD31F0-F91A-11d4-B3CA-00D0B70A09D2}" = "WDSHELL.DLL"
-> {HKLM...CLSID} = "Extension Shell PC Soft"
\InProcServer32\(Default) = "WDShell" [file not found]
<<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["GRISOFT s.r.o."]
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
<<!>> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
<<!>> NavLogon\DLLName = "C:\WINDOWS\system32\NavLogon.dll" [null data]
HKLM\Software\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{5ECD31F0-F91A-11D4-B3CA-00D0B70A09D2}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Extension Shell PC Soft"
\InProcServer32\(Default) = "WDShell" [file not found]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["GRISOFT s.r.o."]
LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"
-> {HKLM...CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
PowerArchiver\(Default) = "{d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}"
-> {HKLM...CLSID} = "PowerArchiver Shell Extensions"
\InProcServer32\(Default) = "C:\Program Files\PowerArchiver\PASHLEXT.DLL" ["ConeXware, Inc."]
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {HKLM...CLSID} = "YMailShellExt Class"
\InProcServer32\(Default) = "C:\PROGRA~1\YAHOO!\COMMON\ymmapi.dll" ["Yahoo! Inc."]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["GRISOFT s.r.o."]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"
-> {HKLM...CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
PowerArchiver\(Default) = "{d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}"
-> {HKLM...CLSID} = "PowerArchiver Shell Extensions"
\InProcServer32\(Default) = "C:\Program Files\PowerArchiver\PASHLEXT.DLL" ["ConeXware, Inc."]
Group Policies {policy setting}:
--------------------------------
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
"DisableRegistryTools" = (REG_DWORD) hex:0x00000000
{Prevent access to registry editing tools}
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Windows\Web\Wallpaper\Acer.bmp"
Startup items in "Thierry" & "All Users" startup folders:
---------------------------------------------------------
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
"NkbMonitor.exe" -> shortcut to: "C:\Program Files\Nikon\PictureProject\NkbMonitor.exe" ["Nikon Corporation"]
"LUMIX Simple Viewer" -> shortcut to: "C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe" ["Matsushita Electric Industrial Co., Ltd."]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 04, 07 - 18
%SystemRoot%\system32\rsvpsp.dll [MS], 05 - 06
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
-> {HKLM...CLSID} = "Easy-WebPrint"
\InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar avec bloqueur de fenêtres pop-up"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Rechercher"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Console Java (Sun)"
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}"
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Recherche"
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["GRISOFT s.r.o."]
C-DillaCdaC11BA, C-DillaCdaC11BA, "C:\WINDOWS\system32\drivers\CDAC11BA.EXE" ["Macrovision"]
DefWatch, DefWatch, ""C:\Program Files\NavNT\defwatch.exe"" ["Symantec Corporation"]
EvtEng, EvtEng, "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe" ["Intel Corporation"]
Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS]
Norton AntiVirus Client, Norton AntiVirus Server, ""C:\Program Files\NavNT\rtvscan.exe"" ["Symantec Corporation"]
Notebook Manager Service, anbmService, "C:\Acer\eManager\anbmServ.exe" ["OSA Technologies Inc."]
RegSrvc, RegSrvc, "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe" ["Intel Corporation"]
Spectrum24 Event Monitor, S24EventMonitor, "C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe" ["Intel Corporation "]
Print Monitors:
---------------
HKLM\System\CurrentControlSet\Control\Print\Monitors\
Canon BJ Language Monitor MP150\Driver = "CNMLM7K.DLL" ["CANON INC."]
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]
---------- (launch time: 2007-10-11 16:56:27)
<<!>>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 49 seconds, including 25 seconds for message boxes)
===============================================================================
DiagHelp version v1.2 -
http://www.malekal.com
excute le 11/10/2007 à 17:17:54,10
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-17EDBDC9.pf -->11/10/2007 17:17:54
C:\WINDOWS\prefetch\NOTEPAD.EXE-2F2D61E1.pf -->11/10/2007 17:17:10
C:\WINDOWS\prefetch\VERCLSID.EXE-28F52AD2.pf -->11/10/2007 17:13:12
C:\WINDOWS\prefetch\WINWORD.EXE-33AEA629.pf -->11/10/2007 16:59:24
C:\WINDOWS\prefetch\IEXPLORE.EXE-2D97EBE6.pf -->11/10/2007 16:57:54
C:\WINDOWS\prefetch\WMIPRVSE.EXE-0D449B4F.pf -->11/10/2007 16:57:06
C:\WINDOWS\prefetch\WSCRIPT.EXE-0C5C5251.pf -->11/10/2007 16:56:38
C:\WINDOWS\prefetch\WUAUCLT.EXE-1360D60A.pf -->11/10/2007 16:50:08
C:\WINDOWS\prefetch\IMAPI.EXE-201490BB.pf -->11/10/2007 16:50:06
C:\WINDOWS\prefetch\NTOSBOOT-B00DFAAD.pf -->11/10/2007 16:50:06
C:\WINDOWS\System32\drivers\CO_Mon.sys -->11/10/2007 03:19:28
C:\WINDOWS\System32\drivers\hosts -->02/10/2007 22:56:58
C:\WINDOWS\System32\drivers\AvgAsCln.sys -->30/05/2007 14:10:42
C:\WINDOWS\System32\drivers\update.sys -->23/04/2007 12:32:54
C:\WINDOWS\System32\drivers\ntfs.sys -->09/02/2007 13:10:36
C:\WINDOWS\System32\drivers\wpdusb.sys -->18/10/2006 20:00:00
C:\WINDOWS\System32\drivers\WudfRd.sys -->28/09/2006 19:00:34
C:\WINDOWS\System32\wpa.dbl -->11/10/2007 16:49:26
C:\WINDOWS\System32\amcompat.tlb -->11/10/2007 02:59:32
C:\WINDOWS\System32\nscompat.tlb -->11/10/2007 02:59:32
C:\WINDOWS\System32\tmp.txt -->11/10/2007 02:12:06
C:\WINDOWS\System32\tmp.reg -->11/10/2007 02:12:06
C:\WINDOWS\System32\eRLog.ini -->11/10/2007 02:01:44
C:\WINDOWS\System32\rmoc3260.dll -->05/10/2007 00:07:34
C:\WINDOWS\System32\pndx5032.dll -->05/10/2007 00:07:16
C:\WINDOWS\System32\pndx5016.dll -->05/10/2007 00:07:16
C:\WINDOWS\System32\pncrt.dll -->05/10/2007 00:07:14
C:\WINDOWS\System32\WS2Fix.exe -->04/10/2007 00:36:46
C:\WINDOWS\System32\MRT.exe -->28/09/2007 07:19:40
C:\WINDOWS\System32\VCCLSID.exe -->06/09/2007 00:22:24
C:\WINDOWS\System32\jupdate-1.6.0_02-b06.log -->03/09/2007 00:02:14
C:\WINDOWS\System32\TZLog.log -->31/08/2007 11:31:06
C:\WINDOWS\System32\inetcomm.dll -->21/08/2007 08:17:24
C:\WINDOWS\System32\occache.dll -->20/08/2007 11:59:32
C:\WINDOWS\System32\url.dll -->20/08/2007 11:59:32
C:\WINDOWS\System32\urlmon.dll -->20/08/2007 11:59:32
C:\WINDOWS\System32\webcheck.dll -->20/08/2007 11:59:32
C:\WINDOWS\System32\wininet.dll -->20/08/2007 11:59:32
C:\WINDOWS\System32\extmgr.dll -->20/08/2007 11:59:30
C:\WINDOWS\System32\dxtrans.dll -->20/08/2007 11:59:30
C:\WINDOWS\System32\iedkcs32.dll -->20/08/2007 11:59:30
C:\WINDOWS\System32\iernonce.dll -->20/08/2007 11:59:30
C:\WINDOWS\setupapi.log -->11/10/2007 16:58:12
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt -->11/10/2007 16:49:20
C:\WINDOWS\wiadebug.log -->11/10/2007 16:49:02
C:\WINDOWS\0.log -->11/10/2007 16:48:34
C:\WINDOWS\bootstat.dat -->11/10/2007 16:48:26
C:\WINDOWS\WindowsUpdate.log -->11/10/2007 13:07:46
C:\WINDOWS\SchedLgU.Txt -->11/10/2007 13:07:44
C:\WINDOWS\wiaservc.log -->11/10/2007 13:07:44
C:\WINDOWS\NeroDigital.ini -->11/10/2007 03:08:42
C:\WINDOWS\catchme.exe -->28/09/2007 09:06:10
C:\WINDOWS\Thumbs.db -->12/09/2007 22:21:14
C:\WINDOWS\win.ini -->20/07/2007 19:47:08
C:\WINDOWS\NirCmd.exe -->17/06/2007 00:11:58
C:\WINDOWS\explorer.exe -->13/06/2007 15:22:28
C:\WINDOWS\WMSysPr9.prx -->19/04/2007 15:28:00
MD5 des fichiers sensibles
tcpip.sys 1dbf125862891817f374f407626967f4
ndis.sys 558635d3af1c7546d26067d5d9b6959e
null.sys 73c1e1f395918bc2c6dd67af7591a3ad
svchost.exe 1bd6c2f707a275cb7c16fd99fe0f31ca
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\WINDOWS\system
24/12/1998 17:15 345 983 RCDsetup.exe
27/08/1996 02:12 4 176 QTNOTIFY.EXE
2 fichier(s) 350 159 octets
0 Rép(s) 8 993 275 904 octets libres
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\WINDOWS\system32
05/08/2004 05:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 8 993 275 904 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\WINDOWS\Downloaded Program Files
30/03/2005 23:36 <REP> .
30/03/2005 23:36 <REP> ..
11/10/2007 02:59 65 desktop.ini
22/06/2006 11:41 5 032 swflash.inf
17/05/2006 14:32 161 480 rufsi.dll
17/05/2006 14:29 241 CabSA.inf
26/09/2007 01:00 124 272 naveng32.dll
26/09/2007 01:00 914 800 navex32a.dll
26/09/2007 01:00 2 504 catalog.dat
26/09/2007 01:00 284 016 ecmsvr32.dll
26/09/2007 01:00 6 899 ecbootil.vxd
26/09/2007 01:00 32 virscant.dat
26/09/2007 01:00 994 246 virscan1.dat
26/09/2007 01:00 570 834 virscan2.dat
26/09/2007 01:00 150 248 virscan3.dat
26/09/2007 01:00 320 253 virscan4.dat
26/09/2007 01:00 4 599 786 virscan5.dat
26/09/2007 01:00 391 801 virscan6.dat
26/09/2007 01:00 12 625 198 virscan7.dat
26/09/2007 01:00 1 819 101 virscan8.dat
26/09/2007 01:00 5 064 300 virscan9.dat
26/09/2007 01:00 224 zdone.dat
26/09/2007 01:00 106 244 virscan.inf
26/09/2007 01:00 97 744 scrauth.dat
26/09/2007 01:00 453 tinf.dat
26/09/2007 01:00 148 tinfidx.dat
26/09/2007 01:00 1 957 tinfl.dat
26/09/2007 01:00 67 619 tscan1.dat
26/09/2007 01:00 3 240 tscan1hd.dat
26/09/2007 01:00 1 061 symaveng.inf
26/09/2007 01:00 11 875 symaveng.cat
26/09/2007 01:00 398 092 tcdefs.dat
26/09/2007 01:00 1 829 031 tcscan7.dat
26/09/2007 01:00 400 127 tcscan8.dat
26/09/2007 01:00 923 305 tcscan9.dat
26/09/2007 01:00 4 778 v.grd
26/09/2007 01:00 2 267 v.sig
17/05/2006 14:26 537 704 AXXPEE.dll
17/05/2006 14:26 42 112 ecmldr32.dll
17/05/2006 14:28 6 850 navapi.vxd
17/05/2006 14:28 201 896 navapi32.dll
17/05/2006 14:32 198 304 avsniffdlgs.dll
17/05/2006 14:32 231 072 avsniff.dll
17/05/2006 14:29 878 avsniff.inf
11/10/2007 03:26 2 072 vscanmsx.dat
43 fichier(s) 33 104 161 octets
Total des fichiers listés :
43 fichier(s) 33 104 161 octets
2 Rép(s) 8 993 275 904 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-11 17:18:45
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
188 - CMD.EXE
208 - GOOGLETOOLBARNO
256 - GUARD.EXE
472 - CDAC11BA.EXE
572 - ATI2EVXX.EXE
704 - NKBMONITOR.EXE
712 - EXPLORER.EXE
780 - MDM.EXE
812 - CSRSS.EXE
828 - RTVSCAN.EXE
848 - WINLOGON.EXE
892 - SERVICES.EXE
904 - LSASS.EXE
1048 - ATI2EVXX.EXE
1084 - SVCHOST.EXE
1136 - PHLEAUTORUN.EXE
1168 - SVCHOST.EXE
1308 - SVCHOST.EXE
1360 - EVTENG.EXE
1580 - SVCHOST.EXE
1624 - VSNPSTD2.EXE
1660 - SYNTPLPR.EXE
1696 - SVCHOST.EXE
1720 - SYNTPENH.EXE
1808 - ATIPTAXX.EXE
1816 - EPM-DM.EXE
1852 - ANBMSERV.EXE
1916 - VPTRAY.EXE
2016 - CTFMON.EXE
2772 - IEXPLORE.EXE
3600 - ALG.EXE
Total number of processes = 32
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806CE000 - \WINDOWS\system32\hal.dll
F7B12000 - \WINDOWS\system32\KDCOM.DLL
F7A22000 - \WINDOWS\system32\BOOTVID.dll
F74E2000 - ACPI.sys
F7B14000 - \WINDOWS\system32\DRIVERS\WMILIB.SYS
F74D1000 - pci.sys
F7612000 - isapnp.sys
F7622000 - ohci1394.sys
F7632000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
F7A26000 - compbatt.sys
F7A2A000 - \WINDOWS\system32\DRIVERS\BATTC.SYS
F7BDA000 - pciide.sys
F7892000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F7B16000 - intelide.sys
F74B3000 - pcmcia.sys
F7642000 - MountMgr.sys
F7494000 - ftdisk.sys
F7A2E000 - ACPIEC.sys
F7BDB000 - \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F789A000 - PartMgr.sys
F7652000 - VolSnap.sys
F747C000 - atapi.sys
F7662000 - disk.sys
F7672000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F745C000 - fltMgr.sys
F744A000 - sr.sys
F7427000 - Fastfat.sys
F7410000 - KSecDD.sys
F73E3000 - NDIS.sys
F73C8000 - Mup.sys
F7692000 - \SystemRoot\system32\DRIVERS\nic1394.sys
F76A2000 - \SystemRoot\system32\DRIVERS\intelppm.sys
F701B000 - \SystemRoot\system32\DRIVERS\ati2mtag.sys
F7007000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
F78B2000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
F6FE4000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F78BA000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F6FBD000 - \SystemRoot\system32\drivers\tifm21.sys
F6C7F000 - \SystemRoot\system32\DRIVERS\b57xp32.sys
F6C3B000 - \SystemRoot\system32\drivers\camchal.sys
F76B2000 - \SystemRoot\system32\drivers\camcaud.sys
F6C17000 - \SystemRoot\system32\drivers\portcls.sys
F76C2000 - \SystemRoot\system32\drivers\drmk.sys
F6BF4000 - \SystemRoot\system32\drivers\ks.sys
F6BC1000 - \SystemRoot\system32\DRIVERS\HSFHWICH.sys
F6AC3000 - \SystemRoot\system32\DRIVERS\HSF_DPV.sys
F6A17000 - \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
F78C2000 - \SystemRoot\System32\Drivers\Modem.SYS
F78CA000 - \SystemRoot\system32\DRIVERS\nscirda.sys
F7AAE000 - \SystemRoot\system32\DRIVERS\irenum.sys
F76D2000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F78D2000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
F69E9000 - \SystemRoot\system32\DRIVERS\SynTP.sys
F7B20000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F78DA000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F76E2000 - \SystemRoot\system32\DRIVERS\imapi.sys
F7AB6000 - \SystemRoot\System32\Drivers\UBHelper.SYS
F7ABA000 - \SystemRoot\system32\drivers\pfc.sys
F76F2000 - \SystemRoot\system32\DRIVERS\cdrom.sys
F7702000 - \SystemRoot\system32\DRIVERS\redbook.sys
F7B22000 - \SystemRoot\system32\DRIVERS\NTIDrvr.sys
F7AC2000 - \SystemRoot\system32\DRIVERS\CmBatt.sys
F716F000 - \SystemRoot\system32\DRIVERS\audstub.sys
F78E2000 - \SystemRoot\system32\DRIVERS\rasirda.sys
F78EA000 - \SystemRoot\system32\DRIVERS\TDI.SYS
F7712000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F7ACA000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
F69AA000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
F7722000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
F7732000 - \SystemRoot\system32\DRIVERS\raspptp.sys
F6999000 - \SystemRoot\system32\DRIVERS\psched.sys
F7742000 - \SystemRoot\system32\DRIVERS\msgpc.sys
F78F2000 - \SystemRoot\system32\DRIVERS\ptilink.sys
F78FA000 - \SystemRoot\system32\DRIVERS\raspti.sys
F7752000 - \SystemRoot\system32\DRIVERS\termdd.sys
F7B24000 - \SystemRoot\system32\DRIVERS\swenum.sys
F68A0000 - \SystemRoot\system32\DRIVERS\update.sys
F7AD6000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
F7762000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F7792000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F7B2E000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7138000 - \SystemRoot\System32\Drivers\Null.SYS
F7B30000 - \SystemRoot\System32\Drivers\Beep.SYS
F7137000 - \SystemRoot\System32\DRIVERS\AvgAsCln.sys
F7922000 - \SystemRoot\System32\drivers\vga.sys
F7B32000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7B34000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F792A000 - \SystemRoot\System32\Drivers\Msfs.SYS
F7932000 - \SystemRoot\System32\Drivers\Npfs.SYS
F7B06000 - \SystemRoot\system32\DRIVERS\rasacd.sys
EE825000 - \SystemRoot\system32\DRIVERS\ipsec.sys
EE7CD000 - \SystemRoot\system32\DRIVERS\tcpip.sys
EE7A5000 - \SystemRoot\system32\DRIVERS\netbt.sys
EE783000 - \SystemRoot\System32\drivers\afd.sys
F77C2000 - \SystemRoot\system32\DRIVERS\netbios.sys
EE758000 - \SystemRoot\system32\DRIVERS\rdbss.sys
EE6E9000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
F77D2000 - \SystemRoot\System32\Drivers\Fips.SYS
EE6C8000 - \SystemRoot\system32\DRIVERS\ipnat.sys
F77E2000 - \SystemRoot\system32\DRIVERS\wanarp.sys
F77F2000 - \SystemRoot\system32\DRIVERS\arp1394.sys
F712A000 - \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
F7812000 - \SystemRoot\System32\Drivers\Cdfs.SYS
EE5E8000 - \SystemRoot\System32\Drivers\dump_atapi.sys
F7B36000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F69E1000 - \SystemRoot\System32\drivers\Dxapi.sys
F793A000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F7256000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\ati2dvag.dll
BFA10000 - \SystemRoot\System32\ati2cqag.dll
BFA4D000 - \SystemRoot\System32\ati3duag.dll
BFC63000 - \SystemRoot\System32\ativvaxx.dll
B8EF4000 - \SystemRoot\system32\DRIVERS\AegisP.sys
B8E5A000 - \SystemRoot\system32\DRIVERS\irda.sys
B8EEC000 - \SystemRoot\system32\DRIVERS\s24trans.sys
B8EBC000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
B8B75000 - \SystemRoot\system32\drivers\wdmaud.sys
B8CEA000 - \SystemRoot\system32\drivers\sysaudio.sys
B893A000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
B8BFA000 - \??\C:\WINDOWS\system32\drivers\Haspnt.sys
B8987000 - \??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS
F7159000 - \??\C:\WINDOWS\system32\drivers\epm-psd.sys
B880E000 - \??\C:\WINDOWS\system32\drivers\epm-shd.sys
B8768000 - \??\C:\WINDOWS\system32\drivers\hardlock.sys
B8967000 - \SystemRoot\system32\DRIVERS\mdmxsdk.sys
B8936000 - \??\C:\Program Files\NavNT\NAVAPEL.SYS
B8676000 - \SystemRoot\system32\DRIVERS\srv.sys
F7B48000 - \??\C:\WINDOWS\system32\drivers\osaio.sys
F7116000 - \??\C:\WINDOWS\system32\drivers\osanbm.sys
B8596000 - \SystemRoot\system32\DRIVERS\secdrv.sys
B8045000 - \SystemRoot\System32\Drivers\HTTP.sys
B8ACF000 - \??\C:\Program Files\Symantec\SYMEVENT.SYS
B7CB3000 - \??\C:\Program Files\NavNT\NAVAP.sys
B7BE1000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20071010.023\NAVEX15.sys
B7BCE000 - \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20071010.023\NAVENG.sys
B78BB000 - \SystemRoot\system32\DRIVERS\w29n51.sys
B7890000 - \SystemRoot\system32\drivers\kmixer.sys
F715E000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 141
Liste des programmes installes
903SH_703SH USB-Handset Manager
Acer eManager for Notebook
Acer eManager for Notebook
Acer eNetManagement
Acer ePowerManagement
Acer GridVista
Adobe Download Manager 2.0 (Supprimer uniquement)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.7
Adobe® Photoshop® Album Starter Edition 3.0
Arcade 3.0
ArcSoft PhotoStudio 5.5
ATI - Utilitaire de désinstallation du logiciel
ATI Control Panel
ATI Display Driver
AutoUpdate
AVG Anti-Spyware 7.5
Canon MP150
Canon Utilities Easy-PhotoPrint
CCleaner (remove only)
Chessmaster 10ème Edition
Chessmaster 10ème Edition
Conexant AC-Link Audio
DivX
DivX Player
Easy-WebPrint
FastStone Capture 4.8
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Intel(R) PROSet/Wireless Software
Isitools 2.60
Jasc Paint Shop Pro 8
Java(TM) 6 Update 2
K-Lite Codec Pack 2.85 Full
Lecteur Windows Media 11
LiveUpdate 1.6 (Symantec Corporation)
LUMIX Simple Viewer
mCore
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Web Components
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)
mMHouse
mPfMgr
mProSafe
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
mWlsSafe
Nero Suite
Nikon FotoShare
Nikon Message Center
Norton AntiVirus Corporate Edition
NTI Backup NOW! 4
NTI Backup NOW! 4
NTI CD & DVD-Maker
NTI CD & DVD-Maker
OmniPage SE 2.0
PictureProject
PowerArchiver
PowerProducer
QuickTime
RealPlayer
SafeCast Shared Components
SHARP 3G/GSM USB Driver Ver3.0.0
SHARP 3G/GSM USB Driver Ver3.0.0
SoftV92 Data Fax Modem with SmartCP
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515 drivers.
TIxx21
Trust WB-3100P Portable Webcam
VideoLAN VLC media player 0.8.4a
Vilma Registry Explorer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
Yahoo! Toolbar avec bloqueur de fenêtres pop-up
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\Program Files
30/03/2005 23:29 <REP> .
30/03/2005 23:29 <REP> ..
16/10/2005 06:13 <REP> acer
30/03/2005 23:57 <REP> Acer Inc
30/03/2005 23:59 <REP> Adobe
16/12/2005 07:38 <REP> Ahead
31/03/2005 00:00 <REP> Arcade
05/04/2006 20:43 <REP> ArcSoft
16/10/2005 06:08 <REP> ATI Technologies
05/10/2007 01:37 <REP> BitTorrent
14/12/2005 00:04 <REP> BoontyGames
05/04/2006 20:38 <REP> Canon
11/10/2007 03:44 <REP> CCleaner
30/03/2005 23:35 <REP> ComPlus Applications
30/03/2005 23:52 <REP> CONEXANT
31/03/2005 00:01 <REP> CyberLink
24/10/2005 20:55 <REP> DivX
15/03/2006 19:50 <REP> EA GAMES
10/12/2005 08:59 <REP> EasyPHP1-8
04/12/2005 18:56 <REP> eMule
21/01/2007 11:37 <REP> FastStone Capture
30/03/2005 23:29 <REP> Fichiers communs
04/12/2005 18:43 <REP> FileZilla
20/05/2006 11:04 <REP> Google
11/10/2007 01:00 <REP> Grisoft
16/10/2005 22:48 <REP> HP
30/03/2005 23:45 <REP> Intel
30/03/2005 23:35 <REP> Internet Explorer
02/07/2006 21:42 <REP> Jasc Software Inc
03/09/2007 00:01 <REP> Java
09/03/2007 20:23 <REP> K-Lite Codec Pack
07/03/2006 23:02 <REP> Maxis
30/03/2005 23:34 <REP> Messenger
30/03/2005 23:38 <REP> microsoft frontpage
16/10/2005 22:31 <REP> Microsoft Office
08/12/2005 22:12 <REP> Microsoft Visual Studio
08/12/2005 22:12 <REP> Microsoft Works
16/10/2005 22:32 <REP> Microsoft.NET
04/02/2006 20:00 <REP> Mobile Action
30/03/2005 23:36 <REP> Movie Maker
30/03/2005 23:34 <REP> MSN
30/03/2005 23:34 <REP> MSN Gaming Zone
15/11/2006 12:27 <REP> MSXML 4.0
17/01/2006 21:11 <REP> NavNT
30/03/2005 23:36 <REP> NetMeeting
31/03/2005 00:06 <REP> NewTech Infosystems
19/06/2006 22:17 <REP> Nikon
30/03/2005 23:34 <REP> Online Services
30/03/2005 23:36 <REP> Outlook Express
26/01/2007 21:35 <REP> Panasonic
19/10/2005 15:26 <REP> PowerArchiver
19/06/2006 22:16 <REP> QuickTime
05/10/2007 00:07 <REP> Real
11/10/2007 03:40 <REP> RegCleaner
05/04/2006 20:44 <REP> ScanSoft
30/03/2005 23:36 <REP> Services en ligne
04/02/2006 19:53 <REP> SHARP 3G GSM USB Driver
17/01/2006 21:11 <REP> Symantec
30/03/2005 23:54 <REP> Synaptics
03/10/2007 14:40 <REP> Trend Micro
27/12/2005 18:46 <REP> Trust
16/12/2005 08:21 <REP> Ubisoft
13/03/2006 11:09 <REP> VideoLAN
03/10/2007 17:22 <REP> Vilma
19/04/2007 15:28 <REP> Windows Media Connect 2
30/03/2005 23:34 <REP> Windows Media Player
30/03/2005 23:34 <REP> Windows NT
16/10/2005 06:10 <REP> WinPCap
30/03/2005 23:38 <REP> xerox
16/10/2005 22:40 <REP> Yahoo!
0 fichier(s) 0 octets
70 Rép(s) 8 993 013 760 octets libres
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\Program Files\fichiers communs
30/03/2005 23:29 <REP> .
30/03/2005 23:29 <REP> ..
30/03/2005 23:29 <REP> Microsoft Shared
30/03/2005 23:29 <REP> SpeechEngines
30/03/2005 23:29 <REP> ODBC
30/03/2005 23:35 <REP> System
30/03/2005 23:36 <REP> MSSoap
30/03/2005 23:36 <REP> Services
30/03/2005 23:44 <REP> InstallShield
31/03/2005 00:06 <REP> NewTech Infosystems
31/03/2005 00:06 <REP> muvee Technologies
16/10/2005 22:31 <REP> DESIGNER
23/10/2005 23:11 <REP> Adobe
27/11/2005 14:08 <REP> PC SOFT
14/12/2005 00:04 <REP> Macrovision Shared
16/12/2005 07:38 <REP> Ahead
17/01/2006 21:11 <REP> Symantec Shared
05/04/2006 20:44 <REP> ScanSoft Shared
19/06/2006 22:16 <REP> Nikon
02/07/2006 21:41 <REP> SWF Studio
03/09/2007 00:00 <REP> Java
05/10/2007 00:07 <REP> Real
05/10/2007 00:07 <REP> xing shared
0 fichier(s) 0 octets
23 Rép(s) 8 993 013 760 octets libres
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
30/03/2005 23:44 <REP> .
30/03/2005 23:44 <REP> ..
07/03/2001 07:00 127 033 MSOWS40c.DLL
03/06/1999 12:09 122 937 MSOWS409.DLL
16/10/2005 22:31 <REP> 1036
15/07/2003 06:52 35 896 MSOSV.DLL
16/10/2005 22:31 <REP> 1033
11/07/2003 10:15 1 292 872 MSONSEXT.DLL
11/07/2003 02:25 80 448 PKMWS.DLL
5 fichier(s) 1 659 186 octets
4 Rép(s) 8 993 013 760 octets libres
c:\Documents and Settings\Thierry\Bureau\RHosts.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\catchme.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\cliptext.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\download.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\drivers.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\ERUNT.EXE
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\FixPath.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\ISADMIN.EXE
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\LS.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\MD5File.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\moveex.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\Process.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\procs.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\psservice.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\RegDACL.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\RestartIt!.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\sc.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\SF.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\shutdown.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\swreg.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\swsc.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\unzip.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\WINMSG.EXE
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\zip.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\Replace\W2K.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\apps\Replace\XP.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old2\attrib.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old2\find.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old2\findstr.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old2\regedit.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old1\attrib.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old1\find.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old1\findstr.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups_old1\regedit.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups\attrib.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups\find.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups\findstr.exe
c:\Documents and Settings\Thierry\Bureau\SDFIX\SDFix\backups\regedit.exe
c:\Documents and Settings\Thierry\Bureau\Clean\pskill.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\dumphive.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\exit.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\GenericRenosFix.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\HostsChk.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\Process.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\Reboot.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\restart.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\SmiUpdate.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\SrchSTS.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\swreg.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\swsc.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\swxcacls.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\unzip.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\VCCLSID.exe
c:\Documents and Settings\Thierry\Bureau\SmitfraudFix\WS2Fix.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\catchme.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\diff.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\dumphive.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\find2.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\Fport.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\grep.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\KProcCheck.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\LFiles.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\md5sums.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\pslist.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\streams.exe
c:\Documents and Settings\Thierry\Bureau\DiagHelp\swreg.exe
c:\Documents and Settings\Maryam\Local Settings\Temp\ycomp_setup.exe
c:\Documents and Settings\Maryam\Mes documents\psa30se_en_us.exe
c:\Documents and Settings\Maryam\Application Data\U3\temp\cleanup.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0409\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0409\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0409\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\040c\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\040c\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\040c\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0407\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0407\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0407\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0410\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0410\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0410\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0c0a\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0c0a\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0c0a\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0816\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0816\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0816\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0415\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0415\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0415\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0419\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0419\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0419\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0413\CNMlr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0413\CNMsr7K.dll
c:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP150 Series Printer\LanguageModules\0413\CNMur7K.dll
c:\Documents and Settings\All Users\Application Data\Grisoft\AVG Anti-Spyware 7.5\Downloads\help.dll
c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
****** Fin du rapport DiagHelp