S'abonner :  Newsletters    Magazines
Avis sur les produits Avis sur les logiciels Avis sur les jeux Actualités A propos de 01net
886 utilisateurs connectés

trojan win32:small-erh ?! aidez moi svp ( résolu )

manosaure le 04 avril 2007 à 21h51
bonsoir
lors d'un scan avast il m'a été trouvé le trojan win32:small-erh
je l'ai mis en quarantaine comme conseillé par avast: ma question est la suivante: c'est quoi?je m'en debarrasse comment sachant qu'il est dans le programme wanadoo et dans mes points de restauration ?
merci de votre aide

-->Message édité par manosaure le 30/04/2007 11:15:06<--
manosaure le 05 avril 2007 à 20h37
bonsoir
j'ai pas tout compris là! c'est mon sujet dont j'ai modifié le titre: explique moi ou est le probleme svp
merci
naheulbeuk le 05 avril 2007 à 20h38
bonjour, ce n'est pas à vous que je m'adressais, mais à la personne qui a exposé son pb alors que c'est un sujet qui est réservé à toi strictement et à ton pb ;)

bonne soirée, :)
-------
Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
Et son forum : http://www.site-naheulbeuk.com/forum/
manosaure le 05 avril 2007 à 22h29
bonsoir
ah ok!
merci ;)
Anthony10 le 06 avril 2007 à 22h29
Bonsoir manosaure,

  • Télécharge HijackThis que tu placeras dans un répertoire dédié tel C:\Program Files\HijackThis.

  • Double-clique sur HijackThis.exe pour lancer l'outil.
  • Ferme toutes les applications en cours sauf HijackThis.
  • Clique sur le bouton Do a system scan and save a logfile.
  • Un rapport sera généré puis le Bloc-notes l'affichera.
  • Dans le Bloc-notes, clique en haut sur le menu Edition puis choisis Sélectionner tout.
  • Dans le Bloc-notes, clique en haut sur le menu Edition puis choisis Copier.

  • Dans ta future réponse, colle le rapport de HijackThis.

  • A suivre,

    En cas de difficulté, voir le tutorial d'HijackThis sur le site de Malekal_Morte
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 07 avril 2007 à 22h13
    bonsoir anthony
    tout d'abord un grand merci pour ton aide d'autant plus que c'est la deuxième fois que tu sauves mon pc !! ;)
    voici le rapport
    Logfile of HijackThis v1.99.1
    Scan saved at 22:10:28, on 07/04/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\HP\KBD\KBD.EXE
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\windows\system\hpsysdrv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\PROGRA~1\Wanadoo\ComComp.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\PROGRA~1\Wanadoo\Toaster.exe
    C:\PROGRA~1\Wanadoo\Inactivity.exe
    C:\PROGRA~1\Wanadoo\PollingModule.exe
    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Inventel\Gateway\wlancfg.exe
    C:\Documents and Settings\Propriétaire\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qfr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qfr8.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qfr8.hpwis.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qfr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.symantec.com/techsupp/oem
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?e544cfe1fe7c4d42ac015410233531b9
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?e544cfe1fe7c4d42ac015410233531b9
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
    O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,911,0
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housec(...)
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

    bye et encore merci
    Anthony10 le 08 avril 2007 à 22h36
    Bonsoir manosaure,

  • Télécharge Silent Runners sur ton Bureau.

  • Double-clique sur SilentRunners.vbs pour lancer le script.
  • A la fenêtre de demande de recherches supplémentaires, clique sur Oui.
  • Un rapport sera généré sur ton Bureau nommé Startup Programs.txt
  • Dans ta future réponse, envoie ce rapport.

  • A suivre,
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 09 avril 2007 à 20h14
    bonsoir anthony
    quand je clique sur le lien que tu m'indiques , il ne se télécharge pas ; par contre s'ouvre la fenetre que voici:
    'Silent Runners.vbs -- find out what starts up with Windows!
    '(compatible with Windows 95/98/Millennium/NT 4.0/2000 Pro/XP Home & Pro/Vista RC1)
    '
    'DO NOT REMOVE THIS HEADER!
    '
    'Copyright Andrew ARONOFF 14 January 2007, http://www.silentrunners.org/
    'This script is provided without any warranty, either express or implied
    'It may not be copied or distributed without permission
    '
    '** YOU RUN THIS SCRIPT AT YOUR OWN RISK! ** (END OF HEADER)


    Option Explicit

    Dim strRevNo : strRevNo = "R50"

    Public flagTest : flagTest = False 'True if in testing mode
    'flagTest = True 'Uncomment to put in testing mode
    Public arSecTest : arSecTest = Array() 'array of section numbers to test

    Public intSection : intSection = 0 'section counter

    'This script is divided into 28 sections.

    'malware launch points:
    ' registry keys (1-12, 15)
    ' INI/INF-files (16-18)
    ' folders (19)
    ' enabled scheduled tasks (20)
    ' Winsock2 service provider DLLs (21)
    ' IE toolbars, explorer bars, extensions (22)
    ' started services (26)
    ' keyboard driver filters (27)
    ' printer monitors (28)

    'hijack points:
    ' System/Group Policies (14)
    ' prefixes for IE URLs (23)
    ' misc IE points (24)
    ' HOSTS file (25)

    'Output is suppressed if deemed normal unless the -all parameter is used
    'Section XVIII is skipped unless the -supp/-all parameters are used or
    'the first message box is answered "No" and the next message box "Yes"

    ' 1. HKCU/HKLM... Run/RunOnce/RunOnce\Setup/RunOnceEx
    ' HKLM... RunServices/RunServicesOnce
    ' HKCU/HKLM... Policies\Explorer\Run
    ' 2. HKLM... Active Setup\Installed Components\
    ' HKCU... Active Setup\Installed Components\
    ' (StubPath <> "" And HKLM version # > HKCU version #)
    ' 3. HKLM... Explorer\Browser Helper Objects\
    ' 4. HKLM... Shell Extensions\Approved\
    ' 5. HKLM... Explorer\SharedTaskScheduler/ShellExecuteHooks
    ' 6. HKCU/HKLM... ShellServiceObjectDelayLoad\
    ' 7. HKCU/HKLM... Command Processor\AutoRun
    ' HKCU... Policies\System\Shell (W2K/WXP/WVa only)
    ' HKCU... Windows\load & run
    ' HKLM... Windows\AppInit_DLLs
    ' HKCU/HKLM... Winlogon\Shell
    ' HKLM... Winlogon\Userinit, System, Ginadll, Taskman
    ' HKLM... Control\SafeBoot\Option\UseAlternateShell
    ' HKLM... Control\SecurityProviders\SecurityProviders
    ' HKLM... Control\Session Manager\BootExecute
    ' HKLM... Control\Session Manager\WOW\cmdline, wowcmdline
    ' 8. HKLM... Winlogon\Notify\ (subkey names/DLLName values <> O/S-specific dictionary data)
    ' 9. HKLM... Image File Execution Options ("Debugger" subkeys)
    '10. HKCU/HKLM... Policies... Startup/Shutdown, Logon/Logoff scripts (W2K/WXP/WVa)
    '11. HKCU/HKLM Protocols\Filter
    '12. Context menu shell extensions
    '13. HKCU/HKLM executable file type (bat/cmd/com/exe/hta/pif/scr)
    '14. System/Group Policies
    '15. Enabled Wallpaper & Screen Saver
    '16. WIN.INI (load/run <> ""), SYSTEM.INI (shell <> explorer.exe, scrnsave.exe), WINSTART.BAT
    '17. AUTORUN.INF in root directory of local fixed disks
    '18. DESKTOP.INI in any local fixed disk directory (section skipped by default)
    '19. %WINDIR%... Startup & All Users... Startup (W98/WMe) or
    ' %USERNAME%... Startup & All Users... Startup folder contents
    '20. Enabled Scheduled Tasks
    '21. Winsock2 Service Provider DLLs
    '22. Internet Explorer Toolbars, Explorer Bars, Extensions
    '23. Internet Explorer URL Prefixes
    '24. Misc. IE Hijack Points
    '25. HOSTS file
    '26. Started Services
    '27. Keyboard Driver Filters
    '28. Print Monitors

    Dim Wshso : Set Wshso = WScript.CreateObject("WScript.Shell")
    Dim WshoArgs : Set WshoArgs = WScript.Arguments
    Dim intErrNum, intMB, intMB1 'Err.Number, MsgBox return value x 2

    Dim strflagTest : strflagTest = ""
    If flagTest Then
    strflagTest = "TEST "
    Wshso.Popup "Silent Runners is in testing mode.",1, _
    "Testing, testing, 1-2-3...", vbOKOnly + vbExclamation
    End If

    'Configuration Detection Section

    ' FileSystemObject creation error (112)
    ' CScript/WScript (147)
    ' Dim (161)
    ' GetFileVersion(WinVer.exe) (VBScript 5.1) (182)
    ' OS version (223)
    ' WMI (279)
    ' Dim (364)
    ' command line arguments (440)
    ' supplementary search MsgBox (532)
    ' startup MsgBox (557)
    ' CreateTextFile error (583)
    ' output file header (625)
    ' WXP SP2 (629)

    On Error Resume Next
    Dim Fso : Set Fso = CreateObject("Scripting.FileSystemObject")
    intErrNum = Err.Number : Err.Clear
    On Error Goto 0

    If intErrNum <> 0 Then

    strURL = "http://tinyurl.com/7nn6"

    intMB = MsgBox (Chr(34) & "Silent Runners" & Chr(34) &_
    " cannot access file services critical to" & vbCRLF &_
    "proper script operation." & vbCRLF & vbCRLF &_
    "If you are running Windows XP, make sure that the" &_
    vbCRLF & Chr(34) & "Cryptographic Services" & Chr(34) &_
    " service is started." & vbCRLF & vbCRLF &_
    "You can also try reinstalling the latest version of the MS" &_
    vbCRLF & "Windows Script Host." & vbCRLF & vbCRLF &_
    "Press " & Chr(34) & "OK" & Chr(34) & " to direct your browser to " &_
    "the download site or" & vbCRLF & Space(10) & Chr(34) & "Cancel" &_
    Chr(34) & " to quit.", vbOKCancel + vbCritical, _
    "Can't access the FileSystemObject!")

    'if dl wanted now, send browser to dl site
    If intMB = 1 Then Wshso.Run strURL

    WScript.Quit

    End If

    Dim oNetwk : Set oNetwk = WScript.CreateObject("WScript.Network")

    Const HKLM = &H80000002, HKCU = &H80000001
    Const REG_SZ=1, REG_EXPAND_SZ=2, REG_BINARY=3, REG_DWORD=4, REG_MULTI_SZ=7
    Const REG_QWORD = 11
    Const MS = " [MS]"
    Const DQ = """", LBr = "{"
    Const IWarn = "<<!>> ", HWarn = "<<H>> "

    'determine whether output is via MsgBox/PopUp or Echo
    Dim flagOut
    If InStr(LCase(WScript.FullName),"wscript.exe") > 0 Then
    flagOut = "W" 'WScript
    ElseIf InStr(LCase(WScript.FullName),"cscript.exe") > 0 Then
    flagOut = "C" 'CScript
    Else 'echo and continue if it works
    flagOut = "C" 'assume CScript-compatible
    WScript.Echo "Neither " & Chr(34) & "WSCRIPT.EXE" & Chr(34) & " nor " &_
    Chr(34) & "CSCRIPT.EXE" & Chr(34) & " was detected as " &_
    "the script host." & vbCRLF & Chr(34) & "Silent Runners" & Chr(34) &_
    " will assume that the script host is CSCRIPT-compatible and will" & vbCRLF &_
    "use WScript.Echo for all messages."
    End If 'script host

    Const SysFolder = 1 : Const WinFolder = 0
    Dim strOS : strOS = "Unknown"
    Dim strOSLong : strOSLong = "Unknown"
    Dim strOSXP : strOSXP = "Windows XP Home" 'XP Home or Pro
    Public strFPSF : strFPSF = Fso.GetSpecialFolder(SysFolder).Path 'FullPathSystemFolder
    Public strFPWF : strFPWF = Fso.GetSpecialFolder(WinFolder).Path 'FullPathWindowsFolder
    Public strExeBareName 'bare file name w/o windows or system folder prefixes
    Dim strSysVer 'Winver.exe version number
    Dim intErrNum1, intErrNum2, intErrNum3, intErrNum4, intErrNum5, intErrNum6 'error number
    Dim intLenValue 'value length
    Dim strURL 'download URL
    'assume Group Policies cannot be set in the O/S
    Dim flagGP : flagGP = False
    'HKCU/HKLM CLSID Lower Limit, default is HKLM for O/S <= NT4
    Dim intCLL : intCLL = 1

    'Winver.exe is in \Windows under W98, but in \System32 for other O/S's
    'trap GetFileVersion error for VBScript version < 5.1
    On Error Resume Next
    If Fso.FileExists (strFPSF & "\Winver.exe") Then
    strSysVer = Fso.GetFileVersion(strFPSF & "\Winver.exe")
    Else
    strSysVer = Fso.GetFileVersion(strFPWF & "\Winver.exe")
    End If
    intErrNum = Err.Number : Err.Clear
    On Error Goto 0

    'if GetFileVersion returns error due to old WSH version
    If intErrNum <> 0 Then

    'store dl URL
    strURL = "http://tinyurl.com/7zh0"

    'if using WScript
    If flagOut = "W" Then

    'explain the problem
    intMB = MsgBox ("This script requires Windows Script Host (WSH) 5.1 " &_
    "or higher to run." & vbCRLF & vbCRLF & "Press " & Chr(34) & "OK" &_
    Chr(34) & " to direct your browser to the WSH download site or " &_
    Chr(34) & "Cancel" & Chr(34) & " to quit." & vbCRLF & vbCRLF &_
    "(WMI is also required. If it's missing, download instructions " &_
    "will appear later.)", vbOKCancel + vbExclamation, _
    "Unsupported Windows Script Host Version!")

    'if dl wanted now, send browser to dl site
    If intMB = 1 Then Wshso.Run strURL

    'if using CScript
    Else 'flagOut = "C"

    'explain the problem
    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " requires " &_
    "Windows Script Host 5.1 or higher to run." & vbCRLF & vbCRLF &_
    "It can be downloaded at: " & strURL

    End If 'WScript or CScript?

    'quit the script
    WScript.Quit

    End If 'VBScript version error encountered?

    'use WINVER.EXE file version to determine O/S
    If Instr(Left(strSysVer,3),"4.1") > 0 Then
    strOS = "W98" : strOSLong = "Windows 98"

    ElseIf Instr(Left(strSysVer,5),"4.0.1") > 0 Then
    strOS = "NT4" : strOSLong = "Windows NT 4.0"

    ElseIf Instr(Left(strSysVer,8),"4.0.0.95") > 0 Then
    strOS = "W98" : strOSLong = "Windows 95"

    ElseIf Instr(Left(strSysVer,8),"4.0.0.11") > 0 Then
    strOS = "W98" : strOSLong = "Windows 95 SR2 (OEM)"

    ElseIf Instr(Left(strSysVer,3),"5.0") > 0 Then
    strOS = "W2K" : strOSLong = "Windows 2000" : : intCLL = 0 : flagGP = True

    ElseIf Instr(Left(strSysVer,3),"5.1") > 0 Then
    'SP0 & SP1 = 5.1.2600.0, SP2 = 5.1.2600.2180
    strOS = "WXP" : strOSLong = "Windows XP" : intCLL = 0

    If Instr(strSysVer,".2180") > 0 Then strOSLong = "Windows XP SP2"

    ElseIf Instr(Left(strSysVer,3),"4.9") > 0 Then
    strOS = "WME" : strOSLong = "Windows Me (Millennium Edition)"

    ElseIf Instr(Left(strSysVer,3),"5.2") > 0 Then
    strOS = "WXP" : strOSLong = "Windows Server 2003 (interpreted as Windows XP)"
    flagGP = True : intCLL = 0

    ElseIf Instr(Left(strSysVer,3),"6.0") > 0 Then
    strOS = "WVA" : strOSLong = "Windows Vista RC1"
    flagGP = True : intCLL = 0

    Else 'unknown strSysVer

    If flagOut = "W" Then

    intMB = MsgBox ("The " & Chr(34) & "Silent Runners" & Chr(34) &_
    " script cannot determine the operating system." & vbCRLF & vbCRLF &_
    "Click " & Chr(34) & "OK" & Chr(34) & " to send an e-mail to the " &_
    "author, providing the following information:" & vbCRLF & vbCRLF &_
    "WINVER.EXE file version = " & strSysVer & vbCRLF & vbCRLF &_
    "or click " & Chr(34) & "Cancel" & Chr(34) & " to quit.", _
    49,"O/S Unknown!")

    If intMB = 1 Then Wshso.Run "mailto:Andrew%20Aronoff%20" &_
    "<%6F%73.%76%65%72.%65%72%72%6F%72@%73%69%6C%65%6E%74%72%75%6E%6E%65%72%73.%6F%72%67>?" &_
    "subject=Silent%20Runners%20OS%20Version%20Error&body=WINVER.EXE" &_
    "%20file%20version%20=%20" & strSysVer

    Else 'flagOut = "C"

    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " cannot " &_
    "determine the operating system." & vbCRLF & vbCRLF & "This script will exit."

    End If 'flagOut?

    WScript.Quit

    End If 'OS id'd from strSysVer?

    'use WMI to connect to the registry
    On Error Resume Next
    Dim oReg : Set oReg = GetObject("winmgmts:\root\default:StdRegProv")
    intErrNum = Err.Number : Err.Clear
    On Error Goto 0

    'detect WMI connection error
    If intErrNum <> 0 Then

    strURL = ""

    'for W98/NT4, assume WMI not installed and direct to d/l URL
    If strOS = "W98" Or strOS = "NT4" Then

    If strOS = "W98" Then strURL = "http://tinyurl.com/jbxe"
    If strOS = "NT4" Then strURL = "http://tinyurl.com/7wd7"

    'invite user to download WMI & quit
    If flagOut = "W" Then

    intMB = MsgBox ("This script requires " & Chr(34) & "WMI" &_
    Chr(34) & ", Windows Management Instrumentation, to run." &_
    vbCRLF & vbCRLF & "It can be downloaded at: " & strURL &_
    vbCRLF & vbCRLF & "Press " & Chr(34) & "OK" & Chr(34) &_
    " to direct your browser to the download site or " &_
    Chr(34) & "Cancel" & Chr(34) & " to quit.",_
    vbOKCancel + vbCritical,"WMI Not Installed!")

    If intMB = 1 Then Wshso.Run strURL

    'at command line, explain & quit
    Else 'flagOut = "C"

    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " requires " &_
    Chr(34) & "WMI" & Chr(34) & ", Windows Management Instrumentation, " &_
    "to run." & vbCRLF & vbCRLF & "It can be downloaded at: " & strURL

    End If

    'for W2K/WXP/WVa, explain how to start the WMI service
    ElseIf strOS = "W2K" Or strOS = "WXP" or strOS = "WVA" Then

    If strOS = "W2K" Then strLine = "Settings | Control Panel | "
    If strOS = "WXP" Then strLine = "Control Panel | "
    If strOS = "WVA" Then strLine = "Control Panel | Classic View | "

    'explain how to turn on WMI service
    If flagOut = "W" Then

    MsgBox "This script requires Windows Management Instrumentation" &_
    " to run." & vbCRLF & vbCRLF & "Click on Start | " & strLine &_
    "Administrative Tools | Services," & vbCRLF &_
    "and start the " & Chr(34) & "Windows Management Instrumentation" &_
    Chr(34) & " service.",vbOKOnly + vbCritical,"WMI Service not running!"

    'at command line, explain & quit
    Else 'flagOut = "C"

    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " requires " &_
    "Windows Management Instrumentation to run." & vbCRLF & vbCRLF &_
    "Click on Start | " & strLine & "Administrative " &_
    "Tools | Services" & vbCRLF & "and start the " & Chr(34) &_
    "Windows Management Instrumentation" & Chr(34) & " service."

    End If 'flagOut?

    Else 'WMe

    'say there's a WMI problem
    If flagOut = "W" Then

    MsgBox "This script requires WMI (Windows Management Instrumentation)" &_
    " to run," & vbCRLF & "but WMI is not running correctly.", _
    vbOKOnly + vbCritical,"WMI problem!"

    'at command line, explain & quit
    Else 'flagOut = "C"

    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " requires " &_
    "WMI (Windows Management Instrumentation) to run," & vbCRLF &_
    "but WMI is not running correctly."

    End If 'flagOut?

    End If 'which O/S?

    WScript.Quit

    End If 'WMI execution error

    'array of Run keys, counter x 5, hive member, startup folder file,
    'startup file shortcut, IERESET.INF file
    Dim arRunKeys, i, ii, j, k, l, oHiveElmt, oSUFi, oSUSC
    'dictionary, keys, items, hard disk collection
    Dim arSK, arSKk, arSKi, colDisks

    'arrays: Run key names, keys, sub-keys, value type, SecurityProviders,
    ' Protocol filters, values
    Dim arNames(), arKeys(), arSubKeys(), arType, arSP, arFilter(), arValues
    'Sub-Directory DeskTop.Ini array, Sub-Directory Error array, Error array
    'Recognized GP names, allowed GP names
    Public arSDDTI(), arSDErr(), arErr(), arRecNames(), arAllowedNames()

    'DeskTop.Ini counter, Error counter x 2, Classes data Hive counter
    Public ctrArDTI, ctrArErr, ctrErr, ctrCH
    Public ctrFo : ctrFo = 0 'folder counter

    'name member, key array member x 4, O/S, drive root directory, work file
    Dim oName, oKey, oKey2, strMemKey, strMemSubKey, oOS, oRoot, oFileWk
    'values x 7
    Dim strValue, strValue1, strValue2, strValue3, strValue4, strValue5, strValue6
    Dim strVal, intValue, strCmd
    'name, single character, startup folder name, startup folder, array member, temp var
    Dim strName, strChr, arSUFN, oSUF, strArMember, strTmp, strTmp2
    'output string x 3
    Public strOut, strOut1, strOut2

    'output file msg x 2, warning string, title line
    Dim strLine, strLine1, strLine2, strWarn, strTitleLine
    'infection/hijack warning detection flags -- add footer note if True
    Public flagIWarn : flagIWarn = False
    Public flagHWarn : flagHWarn = False
    Dim strKey, strKey1, strKey2, strKey3, strSubKey 'register key x 4, sub-key
    'output file name string (incl. path), file name (wo path),
    'PIF path string, single binary character
    Dim strFN, strFNNP, strPIFTgt, bin1C
    Public datLaunch : datLaunch = Now 'script launch time
    Public intCnt 'counter
    'ref time, time taken by 2 pop-up boxes
    Public datRef : datRef = 0
    Public datPUB1 : datPUB1 = 0 : Public datPUB2 : datPUB2 = 0

    'TRUE if show all output (default values not filtered)
    Public flagShowAll : flagShowAll = False
    Dim strRptOutput : strRptOutput = "Output limited to non-default values, " &_
    "except where indicated by " & Chr(34) & "{++}" & Chr(34) 'output file string
    Public strTitle : strTitle = ""
    Public strSubTitle : strSubTitle = ""
    Public strSubSubTitle : strSubSubTitle = ""
    Public flagNVP : flagNVP = False 'existence of name/value pairs in a key
    Public flagInfect : flagInfect = False 'flag infected condition
    Dim flagMatch 'flag matching keys
    Dim flagAllow 'flag key on approved list
    Dim flagFound 'flag key that exists in Registry
    Dim flagDirArg : flagDirArg = False 'presence of output directory argument
    Dim flagIsCLSID : flagIsCLSID = False 'true if argument in CLSID format
    Dim flagTitle 'True if title has already been written
    Dim flagAllArg : flagAllArg = False 'presence of all output argument
    Dim flagArray 'flag array containing elements
    Public flagSupp : flagSupp = False 'do *not* check for DESKTOP.INI in all
    'directories of local fixed disks
    Dim intLBSP 'Last BackSlash Position in path string
    Dim intSS 'lowest sort subscript
    Dim intType 'value type
    Dim strDLL, strCN 'DLL name, company name
    'string to signal all output by default
    Public strAllOutDefault : strAllOutDefault = ""

    Dim ScrPath : ScrPath = Fso.GetParentFolderName(WScript.ScriptFullName)
    If Right(ScrPath,1) <> "\" Then ScrPath = ScrPath & "\"
    'initialize Path of Output File Folder to script path
    Dim strPathOFFo : strPathOFFo = ScrPath

    'hive array
    Public arHives(1,1)
    arHives(0,0) = "HKCU" : arHives(1,0) = "HKLM"
    arHives(0,1) = &H80000001 : arHives(1,1) = &H80000002

    'set up argument usage message string

    Dim strLSp, strCSp 'Leading Spaces, Centering Spaces
    strLSp = Space(4) : strCSp = Space(33) 'WScript spacing
    If flagOut = "C" Then 'CScript spacing
    strLsp = Space(3) : strCSp = Space(28)
    End If

    Dim strMsg : strMsg = "Only two arguments are permitted:" &_
    vbCRLF & vbCRLF &_
    "1. the name of an existing directory for the output report" &_
    vbCRLF & strLSp & "(embed in quotes if it contains spaces)" &_
    vbCRLF & vbCRLF & strCSp & "AND:" & vbCRLF & vbCRLF &_
    "2. " & Chr(34) & "-supp" & Chr(34) & " to search " &_
    "all directories for DESKTOP.INI DLL" & vbCRLF &_
    strLSp & "launch points" &_
    vbCRLF & vbCRLF & strCSp & "-OR-" & vbCRLF & vbCRLF &_
    "3. " & Chr(34) & "-all" & Chr(34) & " to output all non-empty " &_
    "values and all launch" & vbCRLF & strLSp & "points checked"

    'check if output directory or "-all" or "-supp" was supplied as argument
    If WshoArgs.length > 0 And WshoArgs.length <= 2 Then

    For i = 0 To WshoArgs.length-1

    'if directory arg not already passed and arg directory exists
    If Not flagDirArg And Fso.FolderExists(WshoArgs(i)) Then

    'get the path & toggle the directory arg flag
    Dim oOFFo : Set oOFFo = Fso.GetFolder(WshoArgs(i))
    strPathOFFo = oOFFo.Path : flagDirArg = True
    If Right(strPathOFFo,1) <> "\" Then strPathOFFo = strPathOFFo & "\"
    Set oOFFo=Nothing

    'if -all arg not already passed and is this arg
    ElseIf Not flagAllArg And LCase(WshoArgs(i)) = "-all" Then

    'toggle ShowAll flag, toggle the all arg flag, fill report string
    flagShowAll = True : flagAllArg = True
    strRptOutput = "Output of all locations checked and all values found."

    'if -all arg not already passed and is this arg
    ElseIf Not flagAllArg And LCase(WshoArgs(i)) = "-supp" Then
    flagSupp = True : flagAllArg = True
    strRptOutput = "Search enabled of all directories on local fixed " &_
    "drives for DESKTOP.INI" & vbCRLF & " DLL launch points" &_
    vbCRLF & strRptOutput

    'argument can't be interpreted, so explain & quit
    Else

    If flagOut = "W" Then 'pop up a message window

    Wshso.Popup "The argument:" & vbCRLF &_
    Chr(34) & UCase(WshoArgs(i)) & Chr(34) & vbCRLF &_
    "... can't be interpreted." & vbCRLF & vbCRLF &_
    strMsg,10,"Bad Script Argument", vbOKOnly + vbExclamation

    Else 'flagOut = "C" 'write the message to the console

    WScript.Echo vbCRLF & "The argument: " &_
    Chr(34) & UCase(WshoArgs(i)) & Chr(34) &_
    " can't be interpreted." & vbCRLF & vbCRLF &_
    strMsg & vbCRLF

    End If 'WScript host?

    WScript.Quit

    End If 'argument can be interpreted?

    Next 'argument

    'too many args passed
    ElseIf WshoArgs.length > 2 Then

    'explain & quit
    If flagOut = "W" Then 'pop up a message window

    Wshso.Popup "Too many arguments (" & WshoArgs.length & ") were passed." &_
    vbCRLF & vbCRLF & strMsg,10,"Too Many Arguments",_
    vbOKOnly + vbCritical

    Else 'flagOut = "C" 'write the message to the console

    WScript.Echo "Too many arguments (" & WshoArgs.length & ") were passed." &_
    vbCRLF & vbCRLF & strMsg & vbCRLF

    End If 'WScript host?

    WScript.Quit

    End If 'directory arguments passed?

    Set WshoArgs=Nothing

    datRef = Now

    'if no cmd line argument for flagSupp and not testing, show popup
    If Not flagTest And Not flagShowAll And Not flagSupp And flagOut = "W" Then

    intMB = Wshso.Popup ("Do you want to skip the supplementary search?" &_
    vbCRLF & "(It typically takes several minutes.)" & vbCRLF & vbCRLF &_
    "Press " & Chr(34) & "Yes" & Chr(34) & Space(5) &_
    " to skip the supplementary search (default)" & vbCRLF & vbCRLF &_
    Space(10) & Chr(34) & "No" & Chr(34) & Space(6) &_
    " to perform it, or" & vbCRLF & vbCRLF &_
    Space(10) & Chr(34) & "Cancel" & Chr(34) &_
    " to get more information at the web site" & vbCRLF &_
    Space(25) & "and exit the script.",_
    15,"Skip supplementary search?",_
    vbYesNoCancel + vbQuestion + vbDefaultButton1 + vbSystemModal)

    If intMB = vbNo Then

    flagSupp = True

    intMB1 = MsgBox ("Are you SURE you want to run the supplementary " &_
    "search?" & vbCRLF & vbCRLF & "It's _rarely_ necessary " &_
    "and it takes a *long* time." & vbCRLF & vbCRLF & "Press " & DQ &_
    "Yes" & DQ & " to confirm running the supplementary search, " &_
    "or" & vbCRLF & Space(10) & DQ & "No" & DQ & " to run without it.", _
    vbYesNo + vbQuestion + vbDefaultButton2 + vbSystemModal,"Are you sure?")

    If intMB1 = vbNo Then flagSupp = False

    ElseIf intMB = vbCancel Then
    Wshso.Run "http://www.silentrunners.org/sr_thescript.html#supp"
    WScript.Quit
    End If

    End If

    datPUB1 = DateDiff("s",datRef,Now) : datRef = Now

    'inform user that script has started
    If Not flagTest Then
    If flagOut = "W" Then
    Wshso.PopUp Chr(34) & "Silent Runners" & Chr(34) & " has started." &_
    vbCRLF & vbCRLF & "A message box like this one will appear " &_
    "when it's done." & vbCRLF & vbCRLF & "Please be patient...",3,_
    "Silent Runners R" & strRevNo & " startup", _
    vbOKOnly + vbInformation + vbSystemModal
    Else
    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " has started." &_
    " Please be patient..."
    End If 'flagOut?
    End If 'flagTest?

    datPUB2 = DateDiff("s",datRef,Now)

    'create output file name with computer name & today's date
    'Startup Programs (pc_name_here) yyyy-mm-dd.txt

    strFNNP = "Startup Programs (" & oNetwk.ComputerName & ") " &_
    FmtDate(datLaunch) & " " & FmtHMS(datLaunch) & ".txt"
    strFN = strPathOFFo & strflagTest & strFNNP
    On Error Resume Next
    If Fso.FileExists(strFN) Then Fso.DeleteFile(strFN)
    Err.Clear
    Public oFN : Set oFN = Fso.CreateTextFile(strFN,True)
    intErrNum = Err.Number : Err.Clear
    On Error Goto 0

    'if can't create report file
    If intErrNum > 0 Then

    strURL = "http://www.silentrunners.org/Silent%20Runners%20RED.vbs"

    'invite user to run RED version & quit
    If flagOut = "W" Then

    intMB = MsgBox ("The script cannot create its report file. " &_
    "This is a known, intermittent" & vbCRLF & "problem under " &_
    strOSLong & "." & vbCRLF & vbCRLF &_
    "An alternative script version is available for download. " &_
    "After it runs, " & vbCRLF & "the script you're using now will " &_
    "run correctly." & vbCRLF & vbCRLF &_
    "Press " & Chr(34) & "OK" & Chr(34) & " to direct your browser " &_
    "to the alternate script location, or" & vbCRLF & Space(10) &_
    Chr(34) & "Cancel" & Chr(34) & " to quit.",49,"CreateTextFile Error!")

    'if alternative script wanted now, send browser to dl site
    If intMB = 1 Then Wshso.Run strURL

    'explain & quit
    Else 'flagOut = "C"

    WScript.Echo Chr(34) & "Silent Runners" & Chr(34) & " cannot " &_
    "create the report file." & vbCRLF & vbCRLF &_
    "An alternative script is available. Run it, then rerun this version." &_
    vbCRLF & "The alternative script can be downloaded at: " & vbCRLF &_
    vbCRLF & strURL

    End If

    WScript.Quit

    End If 'report file creation error?

    'add report header
    Set oNetwk=Nothing

    oFN.WriteLine Chr(34) & "Silent Runners.vbs" & Chr(34) &_
    ", revision " & strRevNo & ", http://www.silentrunners.org/" &_
    vbCRLF & "Operating System: " & strOSLong & vbCRLF & strRptOutput

    'test for WMI corruption and use WMI to differentiate between
    'WXP Home & WXP Pro

    'get the O/S collection
    Dim colOS : Set colOS = GetObject("winmgmts:\root\cimv2").ExecQuery _
    ("Select * from Win32_OperatingSystem")

    On Error Resume Next

    Err.Clear

    For Each oOS in colOS

    If strOS = "WXP" Then

    'modify strOSXP if O/S = Pro
    If InStr(1,LCase(oOS.Name),"professional",1) > 0 Then
    strOSXP = "Windows XP Professional"
    flagGP = True
    End If
    'modify strOSXP if SP2
    If Right(strOSLong,3) = "SP2" Then strOSXP = strOSXP & " SP2"

    End If 'WXP?

    Next 'oOS

    If Err.Number <> 0 Then

    strURL = "http://go.microsoft.com/fwlink/?LinkId=62562"

    oFN.WriteLine vbCRLF & "FATAL ERROR!" & vbCRLF & String(12,"-") &_
    vbCRLF & vbCRLF & DQ & "Silent Runners" & DQ &_
    " cannot use WMI to identify the operating system." &_
    vbCRLF & "This is caused by corruption of the WMI installation." &_
    vbCRLF & vbCRLF &_
    "WMI is complex and it is recommended that you use a Microsoft" &_
    vbCRLF & "tool, " & DQ & "WMIDiag.vbs," & DQ & " to diagnose WMI " &_
    "on your system." & vbCRLF & vbCRLF & "It can be downloaded here:" &_
    vbCRLF & vbCRLF & strURL

    intMB = MsgBox (DQ & "Silent Runners" & DQ & " cannot use WMI to " &_
    "identify the operating system." & vbCRLF & "This is caused by " &_
    "corruption of the WMI installation." &_
    vbCRLF & vbCRLF &_
    "WMI is complex and it is recommended that you use a Microsoft" &_
    vbCRLF & "tool, " & DQ & "WMIDiag.vbs," & DQ & " to diagnose WMI " &_
    "on your system." &_
    vbCRLF & vbCRLF &_
    "Press " & DQ & "OK" & DQ & " to direct your browser to the " &_
    "WMIDiag download site or" &_
    vbCRLF & Space(10) & DQ & "Cancel" & DQ & " to quit.",_
    vbOKCancel + vbCritical + + vbSystemModal + vbDefaultButton2,_
    "Can't iterate Win32_OperatingSystem!")

    'if dl wanted now, send browser to dl site
    If intMB = 1 Then Wshso.Run strURL

    WScript.Quit

    End If 'Err.Number<>0?

    On Error Goto 0

    Set colOS=Nothing




    '#1. HKCU/HKLM... Run/RunOnce/RunOnce\Setup/RunOnceEx
    ' HKLM... RunServices/RunServicesOnce
    ' HKCU/HKLM... Policies\Explorer\Run

    intSection = intSection + 1

    'execute section if not in testing mode or (in testing mode And this section selected for testing)
    If Not flagTest Or (flagTest And SecTest) Then

    'write registry header lines to file
    strTitle = "Startup items buried in registry:"
    TitleLineWrite

    'put keys in array (Key Index 0 - 6)
    arRunKeys = Array ("Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run", _
    "Software\Microsoft\Windows\CurrentVersion\Run", _
    "Software\Microsoft\Windows\CurrentVersion\RunOnce", _
    "Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup", _
    "Software\Microsoft\Windows\CurrentVersion\RunOnceEx", _
    "Software\Microsoft\Windows\CurrentVersion\RunServices", _
    "Software\Microsoft\Windows\CurrentVersion\RunServicesOnce")

    'Key Execution Flag/Subkey Recursion Flag array
    '
    'first number in the ordered pair in the array immediately below
    ' pertains to execution of the key:
    '0: not executed (ignore)
    '1: may be executed so display with EXECUTION UNLIKELY warning
    '2: executable
    '
    'second number in the ordered pair pertains to subkey recursion
    '0: subkeys not used
    '1: subkey recursion necessary

    '0 Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
    '1 Software\Microsoft\Windows\CurrentVersion\Run
    '2 Software\Microsoft\Windows\CurrentVersion\RunOnce
    '3 Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup
    '4 Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    '5 Software\Microsoft\Windows\CurrentVersion\RunServices
    '6 Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    'Hive HKCU - 0 HKLM - 1
    '
    'Key 0 1 2 3 4 5 6 0 1 2 3 4 5 6
    'Index

    'O/S:
    'W95 0,0 2,0 2,0 0,0 2,1 0,0 0,0 0,0 2,0 2,0 0,0 2,1 2,0 2,0
    'W98 0,0 2,0 2,0 0,0 2,1 0,0 0,0 0,0 2,0 2,0 2,0 2,1 2,0 2,0
    'WMe 2,1 2,1 2,0 2,0 2,1 0,0 0,0 2,1 2,1 2,0 2,0 2,1 2,0 2,0
    'NT4 0,0 2,0 2,0 0,0 2,1 0,0 0,0 0,0 2,0 2,0 0,0 2,1 0,0 0,0
    'W2K 2,1 2,1 2,1 0,0 2,1 0,0 0,0 2,1 2,1 2,1 0,0 2,1 0,0 0,0
    'WXP 2,0 2,0 2,0 0,0 2,1 0,0 0,0 2,0 2,0 2,0 0,0 2,1 0,0 0,0
    'WS2K3 ??? <-------------------- ??? --------------------> ???
    'WVa 2,0 2,0 2,0 0,0 2,1 0,0 0,0 2,0 2,0 2,0 0,0 2,1 0,0 0,0

    'arRegFlag(i,j,k): put flags in array by O/S:
    'hive = i (0 or 1), key_# = j (0-6),
    ' flags (key execution/subkey recursion) = k (0 or 1)
    ' k = 0 holds key execution value = 0/1/2
    ' 1 holds subkey recursion value = 0/1
    Dim arRegFlag()
    ReDim arRegFlag(1,6,1)

    'initialize entire array to zero
    For i = 0 To 1 : For j = 0 To 6 : For k = 0 To 1
    arRegFlag(i,j,k) = 0
    Next : Next : Next

    'add data to array for O/S that's running

    'W98
    If strOS = "W98" Then
    arRegFlag(0,1,0) = 2 'HKCU,Run = no-warn
    arRegFlag(0,2,0) = 2 'HKCU,RunOnce = no-warn
    arRegFlag(0,4,0) = 2 'HKCU,RunOnceEx = no-warn
    arRegFlag(0,4,1) = 1 'HKCU,RunOnceEx = sub-keys
    arRegFlag(1,1,0) = 2 'HKLM,Run = no-warn
    arRegFlag(1,2,0) = 2 'HKLM,RunOnce = no-warn
    'don't set HKLM,RunOnce\Setup for W95
    If strOSLong = "Windows 98" Then _
    arRegFlag(1,3,0) = 2 'HKLM,RunOnce\Setup = no-warn
    arRegFlag(1,4,0) = 2 'HKLM,RunOnceEx = no-warn
    arRegFlag(1,4,1) = 1 'HKLM,RunOnceEx = sub-keys
    arRegFlag(1,5,0) = 2 'HKLM,RunServices = no-warn
    arRegFlag(1,6,0) = 2 'HKLM,RunServicesOnce = no-warn
    End If

    If strOS = "WME" Then
    arRegFlag(0,0,0) = 2 'HKCU,Explorer\Run = no-warn
    arRegFlag(0,0,1) = 1 'HKCU,Explorer\Run = sub-keys
    arRegFlag(0,1,0) = 2 'HKCU,Run = no-warn
    arRegFlag(0,1,1) = 1 'HKCU,Run = sub-keys
    arRegFlag(0,2,0) = 2 'HKCU,RunOnce = no-warn
    arRegFlag(0,3,0) = 2 'HKCU,RunOnce\Setup = no-warn
    arRegFlag(0,4,0) = 2 'HKCU,RunOnceEx = no-warn
    arRegFlag(0,4,1) = 1 'HKCU,RunOnceEx = sub-keys
    arRegFlag(1,0,0) = 2 'HKLM,Explorer\Run = no-warn
    arRegFlag(1,0,1) = 1 'HKLM,Explorer\Run = sub-keys
    arRegFlag(1,1,0) = 2 'HKLM,Run = no-warn
    arRegFlag(1,1,1) = 1 'HKLM,Run = sub-keys
    arRegFlag(1,2,0) = 2 'HKLM,RunOnce = no-warn
    arRegFlag(1,3,0) = 2 'HKLM,RunOnce\Setup = no-warn
    arRegFlag(1,4,0) = 2 'HKLM,RunOnceEx = no-warn
    arRegFlag(1,4,1) = 1 'HKLM,RunOnceEx = sub-keys
    arRegFlag(1,5,0) = 2 'HKLM,RunServices = no-warn
    arRegFlag(1,6,0) = 2 'HKLM,RunServicesOnce = no-warn
    End If

    'NT4
    If strOS = "NT4" Then
    arRegFlag(0,1,0) = 2 'HKCU,Run = no-warn
    arRegFlag(0,2,0) = 2 'HKCU,RunOnce = no-warn
    arRegFlag(0,4,0) = 2 'HKCU,RunOnceEx = no-warn
    arRegFlag(0,4,1) = 1 'HKCU,RunOnceEx = sub-keys
    arRegFlag(1,1,0) = 2 'HKLM,Run = no-warn
    arRegFlag(1,2,0) = 2 'HKLM,RunOnce = no-warn
    arRegFlag(1,4,0) = 2 'HKLM,RunOnceEx = no-warn
    arRegFlag(1,4,1) = 1 'HKLM,RunOnceEx = sub-keys
    End If

    'W2K
    If strOs = "W2K" Then
    arRegFlag(0,0,0) = 2 'HKCU,Explorer\Run = no-warn
    arRegFlag(0,0,1) = 1 'HKCU,Explorer\Run = sub-keys
    arRegFlag(0,1,0) = 2 'HKCU,Run = no-warn
    arRegFlag(0,1,1) = 1 'HKCU,Run = sub-keys
    arRegFlag(0,2,0) = 2 'HKCU,RunOnce = no-warn
    arRegFlag(0,2,1) = 1 'HKCU,RunOnce = sub-keys (incl. Setup)
    arRegFlag(0,4,0) = 2 'HKCU,RunOnceEx = no-warn
    arRegFlag(0,4,1) = 1 'HKCU,RunOnceEx = sub-keys
    arRegFlag(1,0,0) = 2 'HKLM,Explorer\Run = no-warn
    arRegFlag(1,0,1) = 1 'HKLM,Explorer\Run = sub-keys
    arRegFlag(1,1,0) = 2 'HKLM,Run = no-warn
    arRegFlag(1,1,1) = 1 'HKLM,Run = sub-keys
    arRegFlag(1,2,0) = 2 'HKLM,RunOnce = no-warn
    arRegFlag(1,2,1) = 1 'HKLM,RunOnce = sub-keys (incl. Setup)
    arRegFlag(1,4,0) = 2 'HKLM,RunOnceEx = no-warn
    arRegFlag(1,4,1) = 1 'HKLM,RunOnceEx = sub-keys
    End If

    'WXP/WVa
    If strOs = "WXP" Or strOS = "WVA" Then
    arRegFlag(0,0,0) = 2 'HKCU,Explorer\Run = no-warn
    arRegFlag(0,1,0) = 2 'HKCU,Run = no-warn
    arRegFlag(0,2,0) = 2 'HKCU,RunOnce = no-warn
    arRegFlag(0,4,0) = 2 'HKLM,RunOnceEx = no-warn
    arRegFlag(0,4,1) = 1 'HKLM,RunOnceEx = sub-keys
    arRegFlag(1,0,0) = 2 'HKLM,Explorer\Run = no-warn
    arRegFlag(1,1,0) = 2 'HKLM,Run = no-warn
    arRegFlag(1,2,0) = 2 'HKLM,RunOnce = no-warn
    arRegFlag(1,4,0) = 2 'HKLM,RunOnceEx = no-warn
    arRegFlag(1,4,1) = 1 'HKLM,RunOnceEx = sub-keys
    End If

    'for each hive
    For i = 0 To 1

    'for each key
    For j = 0 To 6

    'if not ShowAll, show all output for Run keys
    If j = 1 And Not flagShowAll Then strAllOutDefault = " {++}"

    'if key is not ignored
    If arRegFlag(i,j,0) > 0 Then

    flagNVP = False

    'intialize string with warning if necessary
    strWarn = ""
    If arRegFlag(i,j,0) = 1 Then strWarn = "EXECUTION UNLIKELY: "

    'INFO
    'with no name/value pairs (sub-keys are identical)
    ' IsArray TypeName UBound
    'W98 True "Variant()" -1
    'WMe True "Variant()" -1
    'NT4 True "Variant()" -1
    'W2K False "Null" error (--)
    'WXP False "Null" error (--)
    'WS2K3 True "Variant()" error (--)
    'WVa False "Null" error (--)

    EnumNVP arHives(i,1), arRunKeys(j), arNames, arType

    If flagNVP Then 'name/value pairs exist

    'write the full key name
    oFN.WriteLine vbCRLF & arHives(i,0) & "\" & arRunKeys(j) & "\" & strAllOutDefault

    'for each data type in the names array
    For k = LBound(arNames) To UBound(arNames)

    'use the type to find the value
    strValue = RtnValue (arHives(i,1), arRunKeys(j), arNames(k), arType(k))
    'write the name & value
    WriteValueData arNames(k), strValue, arType(k), strWarn

    Next 'member of names array

    Else 'no name/value pairs

    If flagShowAll Then _
    oFN.WriteLine vbCRLF & arHives(i,0) & "\" & arRunKeys(j) & "\"

    End If 'flagNVP?

    'recurse subkeys if necessary
    If arRegFlag(i,j,1) = 1 Then

    'put all subkeys into array
    oReg.EnumKey arHives(i,1),arRunKeys(j),arKeys

    'excludes W2K/WXP/WVa with no sub-keys
    If IsArray(arKeys) Then

    'excludes W98/WMe/NT4/WS2K3 with no sub-keys
    For Each strMemKey in arKeys

    flagNVP = False
    strSubKey = arRunKeys(j) & "\" & strMemKey

    EnumNVP arHives(i,1), arRunKeys(j) & "\" & strMemKey,arNames,arType

    If flagNVP Then 'if name/value pairs exist

    'write the full key name
    oFN.WriteLine vbCRLF & arHives(i,0) & "\" & strSubKey &_
    "\" & strAllOutDefault

    'for each data type in the names array
    For k = LBound(arNames) To UBound(arNames)

    'use the type to find the value
    strValue = RtnValue (arHives(i,1), strSubKey, arNames(k), arType(k))
    'write the name & value
    WriteValueData arNames(k), strValue, arType(k), strWarn

    Next 'member of names array

    Else 'no name/value pairs

    If flagShowAll Then _
    oFN.WriteLine vbCRLF & arHives(i,0) & "\" & strSubKey & "\"

    End If 'flagNVP?

    Next 'sub-key

    End If 'sub-keys exist? W2K/WXP/WS2K3/WVa

    End If 'enum sub-keys?

    End If 'arRegFlag(i,j,0) > 0

    Next 'Run key

    Next 'Hive

    strAllOutDefault = "" : flagNVP = False

    'recover array memory
    ReDim arRunKeys(0)
    ReDim arKeys(0)
    ReDim arRegFlag(0)

    End If 'flagTest And SecTest?




    '#2. HKLM... Active Setup\Installed Components\
    ' HKCU... Active Setup\Installed Components\

    intSection = intSection + 1

    'execute section if not in testing mode or (in testing mode And this section selected for testing)
    If Not flagTest Or (flagTest And SecTest) Then

    'flags True if only numeric & comma chrs in Version values
    Dim flagHKLMVer, flagHKCUVer
    'StubPath Value string, HKLM Version value, HKCU Version value, HKLM program name
    Dim strSPV, strHKLMVer, strHKCUVer, strPgmName
    Dim arHKLMKeys, arHKCUKeys, strHKLMKey, strHKCUKey

    strKey = "Software\Microsoft\Active Setup\Installed Components"

    strSubTitle = "HKLM" & "\" & strKey & "\"

    'find all the subkeys
    oReg.EnumKey HKLM, strKey, arHKLMKeys 'HKLM
    oReg.EnumKey HKCU, strKey, arHKCUKeys 'HKCU

    'enumerate HKLM keys if present
    If IsArray(arHKLMKeys) Then

    'for each HKLM key
    For Each strHKLMKey In arHKLMKeys

    'INFO
    'Default Value not set:
    'W98/WMe: returns 0, strValue = ""
    'NT4/W2K/WXP/WVa: returns non-zero, strValue = Null

    'Non-Default name inexistent:
    'W98/WMe/NT4/W2K/WXP/WVa: returns non-zero, strValue = Null

    'Non-Default Value not set:
    'W2K: returns 0, strValue = unwritable string
    'W98/WMe/NT4/WXP/WVa: returns 0, strValue = ""

    'get the StubPath value
    intErrNum = oReg.GetStringValue (HKLM,strKey & "\" & strHKLMKey,"StubPath",strSPV)

    'if the StubPath name exists And value set (exc for W2K!)
    If intErrNum = 0 And strSPV <> "" Then

    flagMatch = False

    'if HKCU keys present
    If IsArray(arHKCUKeys) Then

    'for each HKCU key
    For Each strHKCUKey in arHKCUKeys

    'if identical HKLM key exists
    If LCase(strHKLMKey) = LCase(strHKCUKey) Then

    'assume Version fmts are OK
    flagHKLMVer = True : flagHKCUVer = True

    'get HKLM & HKCU Version values
    intErrNum1 = oReg.GetStringValue (HKLM,strKey & "\" & strHKLMKey, _
    "Version",strHKLMVer) 'HKLM Version #
    intErrNum2 = oReg.GetStringValue (HKCU,strKey & "\" & strHKCUKey, _
    "Version",strHKCUVer) 'HKCU Version #

    'if HKLM Version name exists And value set (exc for W2K!)
    If intErrNum1 = 0 And strHKLMVer <> "" Then

    'the next two loops check for allowed chars (numeric & comma)
    ' in returned Version values

    For i = 1 To Len(strHKLMVer)
    strChr = Mid(strHKLMVer,i,1)
    If Not IsNumeric(strChr) And strChr <> "," Then flagHKLMVer = False
    Next

    'if HKCU Version name exists And value set (exc for W2K!)
    If intErrNum2 = 0 And strHKCUVer <> "" Then

    'check that value consists only of numeric & comma chrs
    For i = 1 To Len(strHKCUVer)
    strChr = Mid(strHKCUVer,i,1)
    If Not IsNumeric(strChr) And strChr <> "," Then flagHKCUVer = False
    Next

    End If 'HKCU Version null or MT?

    'if HKLM Ver # has illegal fmt (i.e., is not assigned) or doesn't exist (is Null)
    ' or is empty, match = True
    'if HKCU/HKLM Ver # fmts OK And HKCU Ver # >= HKLM Ver #, match = True
    'if HKLM Ver # = "0,0" and HKCU Ver # = "", key will output
    ' but StubPath will not launch
    If Not flagHKLMVer Then flagMatch = True
    If flagHKLMVer And flagHKCUVer And strHKCUVer >= strHKLMVer Then flagMatch = True

    Else 'HKLM Version name doesn't exist Or value not set (exc for W2K!)

    flagMatch = True

    End If 'HKLM Version name exists And value set (exc for W2K!)?

    End If 'HKCU key=HKLM key?

    Next 'HKCU Installed Components key

    End If 'HKCU Installed Components subkeys exist?

    'if the StubPath will launch
    If Not flagMatch Then

    flagAllow = False 'assume StubPath DLL not on approved list
    strCN = CoName(IDExe(strSPV))

    'test for approved StubPath DLL
    If LCase(strHKLMKey) = ">{22d6f312-b0f6-11d0-94ab-0080c74c7e95}" And _
    (InStr(LCase(strSPV),"wmpocm.exe") > 0 Or _
    InStr(LCase(strSPV),"unregmp2.exe") > 0) And _
    strCN = MS And Not flagShowAll Then flagAllow = True

    'StubPath DLL not approved
    If Not flagAllow Then

    'get the default value (program name)
    intErrNum3 = oReg.GetStringValue (HKLM,strKey & "\" & strHKLMKey,"",strPgmName)
    'enclose pgm name in quotes if name exists and default value isn't empty
    If intErrNum3 = 0 And strPgmName <> "" Then
    strPgmName = Chr(34) & strPgmName & Chr(34)
    Else
    strPgmName = "(no title provided)"
    End If

    TitleLineWrite

    'output the CLSID & pgm name
    oFN.WriteLine strHKLMKey & "\(Default) = " & StringFilter(strPgmName,False)

    On Error Resume Next
    'output the StubPath value
    oFN.WriteLine Space(Len(strHKLMKey)+1) & "\StubPath = " &_
    Chr(34) & strSPV & Chr(34) & strCN
    'error check for W2K if StubPath value not set
    If Err.Number <> 0 Then oFN.WriteLine Space(Len(strHKLMKey)+1) & "\StubPath = " &_
    "(value not set)"
    Err.Clear
    On Error GoTo 0

    End If 'flagAllow false?

    End If 'flagMatch false?

    End If 'StubPath value exists?

    Next 'HKLM Installed Components subkey

    End If 'HKLM Installed Components subkeys exist?

    If flagShowAll Then TitleLineWrite

    'recover array memory
    ReDim arHKLMKeys(0)
    ReDim arHKCUKeys(0)

    strTitle = "" : strSubTitle = "" : strSubSubTitle = ""

    End If 'SecTest?




    '#3. HKLM... Explorer\Browser Helper Objects

    intSection = intSection + 1

    'execute section if not in testing mode or (in testing mode And this section selected for testing)
    If Not flagTest Or (flagTest And SecTest) Then

    strKey = "Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects"
    strSubTitle = "HKLM" & "\" & strKey & "\"

    'find all the subkeys
    oReg.EnumKey HKLM, strKey, arSubKeys

    'enumerate data if present
    If IsArray(arSubKeys) Then

    'for each key
    For Each strSubKey In arSubKeys

    flagTitle = False

    CLSIDLocTitle HKLM, strKey & "\" & strSubKey, "", strLocTitle

    For ctrCH = intCLL To 1

    ResolveCLSID strSubKey, arHives(ctrCH,1), strCLSIDTitle, strIPSDLL

    If strIPSDLL <> "" Then

    'output the title line if not already done
    TitleLineWrite

    If Not flagTitle Then

    'error check for W2K if value not set
    On Error Resume Next
    oFN.WriteLine strSubKey & "\(Default) = " & strLocTitle
    intErrNum = Err.Number : Err.Clear
    If intErrNum <> 0 Then oFN.WriteLine strSubKey &_
    "\(Default) = (no title provided)"
    flagTitle = True
    On Error GoTo 0

    End If

    'output CLSID title, InProcServer32 DLL & CoName
    oFN.WriteLine " -> {" & arHives(ctrCH,0) & "...CLSID} = " &_
    strCLSIDTitle & vbCRLF & Space(19) & "\InProcServer32\(Default) = " &_
    StringFilter(strIPSDLL,True) & CoName(IDExe(strIPSDLL))

    End If 'strIPSDLL exists?

    Next 'CLSID hive

    Next 'BHO subkey

    End If 'BHO subkeys exist?

    'if ShowAll, output the key name if not already done
    If flagShowAll Then TitleLineWrite
    strTitle = "" : strSubTitle = "" : strSubSubTitle = ""

    'recover array memory
    ReDim arSubKeys(0)

    End If 'SecTest?




    '#4. HKLM... Shell Extensions\Approved\

    intSection = intSection + 1

    'execute section if not in testing mode or (in testing mode And this section selected for testing)
    If Not flagTest Or (flagTest And SecTest) Then

    'CLSID value, InProcessServer32 DLL name & output file version,
    'CLSID Key Title display flag
    Dim strCLSID, strIPSDLL, strIPSDLLOut, strCLSIDTitle, strLocTitle

    'Shell Extension Approved array
    Dim arSEA()
    ReDim arSEA(388,1)
    'WXP
    arSEA(0,0) = "{00022613-0000-0000-C000-000000000046}" : arSEA(0,1) = "mmsys.cpl"
    arSEA(1,0) = "{176d6597-26d3-11d1-b350-080036a75b03}" : arSEA(1,1) = "icmui.dll"
    arSEA(2,0) = "{1F2E5C40-9550-11CE-99D2-00AA006E086C}" : arSEA(2,1) = "rshx32.dll"
    arSEA(3,0) = "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" : arSEA(3,1) = "docprop.dll"
    arSEA(4,0) = "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" : arSEA(4,1) = "ntshrui.dll"
    arSEA(5,0) = "{41E300E0-78B6-11ce-849B-444553540000}" : arSEA(5,1) = "themeui.dll"
    arSEA(6,0) = "{42071712-76d4-11d1-8b24-00a0c9068ff3}" : arSEA(6,1) = "deskadp.dll"
    arSEA(7,0) = "{42071713-76d4-11d1-8b24-00a0c9068ff3}" : arSEA(7,1) = "deskmon.dll"
    arSEA(8,0) = "{42071714-76d4-11d1-8b24-00a0c9068ff3}" : arSEA(8,1) = "deskpan.dll"
    arSEA(9,0) = "{4E40F770-369C-11d0-8922-00A024AB2DBB}" : arSEA(9,1) = "dssec.dll"
    arSEA(10,0) = "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" : arSEA(10,1) = "SlayerXP.dll"
    arSEA(11,0) = "{56117100-C0CD-101B-81E2-00AA004AE837}" : arSEA(11,1) = "shscrap.dll"
    arSEA(12,0) = "{59099400-57FF-11CE-BD94-0020AF85B590}" : arSEA(12,1) = "diskcopy.dll"
    arSEA(13,0) = "{59be4990-f85c-11ce-aff7-00aa003ca9f6}" : arSEA(13,1) = "ntlanui2.dll"
    arSEA(14,0) = "{5DB2625A-54DF-11D0-B6C4-0800091AA605}" : arSEA(14,1) = "icmui.dll"
    arSEA(15,0) = "{675F097E-4C4D-11D0-B6C1-0800091AA605}" : arSEA(15,1) = "icmui.dll"
    arSEA(16,0) = "{764BF0E1-F219-11ce-972D-00AA00A14F56}" : arSEA(16,1) = ""
    arSEA(17,0) = "{77597368-7b15-11d0-a0c2-080036af3f03}" : arSEA(17,1) = "printui.dll"
    arSEA(18,0) = "{7988B573-EC89-11cf-9C00-00AA00A14F56}" : arSEA(18,1) = "dskquoui.dll"
    arSEA(19,0) = "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}" : arSEA(19,1) = ""
    arSEA(20,0) = "{85BBD920-42A0-1069-A2E4-08002B30309D}" : arSEA(20,1) = "syncui.dll"
    arSEA(21,0) = "{88895560-9AA2-1069-930E-00AA0030EBC8}" : arSEA(21,1) = "hticons.dll"
    arSEA(22,0) = "{BD84B380-8CA2-1069-AB1D-08000948F534}" : arSEA(22,1) = "fontext.dll"
    arSEA(23,0) = "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" : arSEA(23,1) = "icmui.dll"
    arSEA(24,0) = "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" : arSEA(24,1) = "rshx32.dll"
    arSEA(25,0) = "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" : arSEA(25,1) = "ntshrui.dll"
    arSEA(26,0) = "{f92e8c40-3d33-11d2-b1aa-080036a75b03}" : arSEA(26,1) = "deskperf.dll"
    arSEA(27,0) = "{7444C717-39BF-11D1-8CD9-00C04FC29D45}" : arSEA(27,1) = "cryptext.dll"
    arSEA(28,0) = "{7444C719-39BF-11D1-8CD9-00C04FC29D45}" : arSEA(28,1) = "cryptext.dll"
    arSEA(29,0) = "{7007ACC7-3202-11D1-AAD2-00805FC1270E}" : arSEA(29,1) = "NETSHELL.dll"
    arSEA(30,0) = "{992CFFA0-F557-101A-88EC-00DD010CCC48}" : arSEA(30,1) = "NETSHELL.dll"
    arSEA(31,0) = "{E211B736-43FD-11D1-9EFB-0000F8757FCD}" : arSEA(31,1) = "wiashext.dll"
    arSEA(32,0) = "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}" : arSEA(32,1) = "wiashext.dll"
    arSEA(33,0) = "{905667aa-acd6-11d2-8080-00805f6596d2}" : arSEA(33,1) = "wiashext.dll"
    arSEA(34,0) = "{3F953603-1008-4f6e-A73A-04AAC7A992F1}" : arSEA(34,1) = "wiashext.dll"
    arSEA(35,0) = "{83bbcbf3-b28a-4919-a5aa-73027445d672}" : arSEA(35,1) = "wiashext.dll"
    arSEA(36,0) = "{F0152790-D56E-4445-850E-4F3117DB740C}" : arSEA(36,1) = "remotepg.dll"
    arSEA(37,0) = "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}" : arSEA(37,1) = "wuaucpl.cpl"
    arSEA(38,0) = "{60254CA5-953B-11CF-8C96-00AA00B8708C}" : arSEA(38,1) = "wshext.dll"
    arSEA(39,0) = "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}" : arSEA(39,1) = "oledb32.dll"
    arSEA(40,0) = "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}" : arSEA(40,1) = "mstask.dll"
    arSEA(41,0) = "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}" : arSEA(41,1) = "mstask.dll"
    arSEA(42,0) = "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}" : arSEA(42,1) = "mstask.dll"
    arSEA(43,0) = "{0DF44EAA-FF21-4412-828E-260A8728E7F1}" : arSEA(43,1) = ""
    arSEA(44,0) = "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(44,1) = "shdocvw.dll"
    arSEA(45,0) = "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(45,1) = "shdocvw.dll"
    arSEA(46,0) = "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(46,1) = "shdocvw.dll"
    arSEA(47,0) = "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(47,1) = "shdocvw.dll"
    arSEA(48,0) = "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(48,1) = "shdocvw.dll"
    arSEA(49,0) = "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(49,1) = "shdocvw.dll"
    arSEA(50,0) = "{D20EA4E1-3957-11d2-A40B-0C5020524152}" : arSEA(50,1) = "shdocvw.dll"
    arSEA(51,0) = "{D20EA4E1-3957-11d2-A40B-0C5020524153}" : arSEA(51,1) = "shdocvw.dll"
    arSEA(52,0) = "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}" : arSEA(52,1) = "shmedia.dll"
    arSEA(53,0) = "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}" : arSEA(53,1) = "shmedia.dll"
    arSEA(54,0) = "{E4B29F9D-D390-480b-92FD-7DDB47101D71}" : arSEA(54,1) = "shmedia.dll"
    arSEA(55,0) = "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}" : arSEA(55,1) = "shmedia.dll"
    arSEA(56,0) = "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}" : arSEA(56,1) = "shmedia.dll"
    arSEA(57,0) = "{c5a40261-cd64-4ccf-84cb-c394da41d590}" : arSEA(57,1) = "shmedia.dll"
    arSEA(58,0) = "{5E6AB780-7743-11CF-A12B-00AA004AE837}" : arSEA(58,1) = "browseui.dll"
    arSEA(59,0) = "{22BF0C20-6DA7-11D0-B373-00A0C9034938}" : arSEA(59,1) = "browseui.dll"
    arSEA(60,0) = "{91EA3F8B-C99B-11d0-9815-00C04FD91972}" : arSEA(60,1) = "browseui.dll"
    arSEA(61,0) = "{6413BA2C-B461-11d1-A18A-080036B11A03}" : arSEA(61,1) = "browseui.dll"
    arSEA(62,0) = "{F61FFEC1-754F-11d0-80CA-00AA005B4383}" : arSEA(62,1) = "browseui.dll"
    arSEA(63,0) = "{7BA4C742-9E81-11CF-99D3-00AA004AE837}" : arSEA(63,1) = "browseui.dll"
    arSEA(64,0) = "{30D02401-6A81-11d0-8274-00C04FD5AE38}" : arSEA(64,1) = "browseui.dll"
    arSEA(65,0) = "{32683183-48a0-441b-a342-7c2a440a9478}" : arSEA(65,1) = "browseui.dll"
    arSEA(66,0) = "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}" : arSEA(66,1) = "browseui.dll"
    arSEA(67,0) = "{07798131-AF23-11d1-9111-00A0C98BA67D}" : arSEA(67,1) = "browseui.dll"
    arSEA(68,0) = "{AF4F6510-F982-11d0-8595-00AA004CD6D8}" : arSEA(68,1) = "browseui.dll"
    arSEA(69,0) = "{01E04581-4EEE-11d0-BFE9-00AA005B4383}" : arSEA(69,1) = "browseui.dll"
    arSEA(70,0) = "{A08C11D2-A228-11d0-825B-00AA005B4383}" : arSEA(70,1) = "browseui.dll"
    arSEA(71,0) = "{00BB2763-6A77-11D0-A535-00C04FD7D062}" : arSEA(71,1) = "browseui.dll"
    arSEA(72,0) = "{7376D660-C583-11d0-A3A5-00C04FD706EC}" : arSEA(72,1) = "browseui.dll"
    arSEA(73,0) = "{6756A641-DE71-11d0-831B-00AA005B4383}" : arSEA(73,1) = "browseui.dll"
    arSEA(74,0) = "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}" : arSEA(74,1) = "browseui.dll"
    arSEA(75,0) = "{7e653215-fa25-46bd-a339-34a2790f3cb7}" : arSEA(75,1) = "browseui.dll"
    arSEA(76,0) = "{acf35015-526e-4230-9596-becbe19f0ac9}" : arSEA(76,1) = "browseui.dll"
    arSEA(77,0) = "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}" : arSEA(77,1) = "browseui.dll"
    arSEA(78,0) = "{00BB2764-6A77-11D0-A535-00C04FD7D062}" : arSEA(78,1) = "browseui.dll"
    arSEA(79,0) = "{03C036F1-A186-11D0-824A-00AA005B4383}" : arSEA(79,1) = "browseui.dll"
    arSEA(80,0) = "{00BB2765-6A77-11D0-A535-00C04FD7D062}" : arSEA(80,1) = "browseui.dll"
    arSEA(81,0) = "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}" : arSEA(81,1) = "browseui.dll"
    arSEA(82,0) = "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}" : arSEA(82,1) = "browseui.dll"
    arSEA(83,0) = "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}" : arSEA(83,1) = "browseui.dll"
    arSEA(84,0) = "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}" : arSEA(84,1) = "browseui.dll"
    arSEA(85,0) = "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}" : arSEA(85,1) = "browseui.dll"
    arSEA(86,0) = "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}" : arSEA(86,1) = "browseui.dll"
    arSEA(87,0) = "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}" : arSEA(87,1) = "shdocvw.dll"
    arSEA(88,0) = "{0A89A860-D7B1-11CE-8350-444553540000}" : arSEA(88,1) = "shdocvw.dll"
    arSEA(89,0) = "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}" : arSEA(89,1) = "shdocvw.dll"
    arSEA(90,0) = "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}" : arSEA(90,1) = "shdocvw.dll"
    arSEA(91,0) = "{FBF23B40-E3F0-101B-8488-00AA003E56F8}" : arSEA(91,1) = "shdocvw.dll"
    arSEA(92,0) = "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}" : arSEA(92,1) = "shdocvw.dll"
    arSEA(93,0) = "{FF393560-C2A7-11CF-BFF4-444553540000}" : arSEA(93,1) = "shdocvw.dll"
    arSEA(94,0) = "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}" : arSEA(94,1) = "shdocvw.dll"
    arSEA(95,0) = "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}" : arSEA(95,1) = "shdocvw.dll"
    arSEA(96,0) = "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" : arSEA(96,1) = "shdocvw.dll"
    arSEA(97,0) = "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}" : arSEA(97,1) = "shdocvw.dll"
    arSEA(98,0) = "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}" : arSEA(98,1) = "shdocvw.dll"
    arSEA(99,0) = "{131A6951-7F78-11D0-A979-00C04FD705A2}" : arSEA(99,1) = "shdocvw.dll"
    arSEA(100,0) = "{9461b922-3c5a-11d2-bf8b-00c04fb93661}" : arSEA(100,1) = "shdocvw.dll"
    arSEA(101,0) = "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}" : arSEA(101,1) = "shdocvw.dll"
    arSEA(102,0) = "{871C5380-42A0-1069-A2EA-08002B30309D}" : arSEA(102,1) = "shdocvw.dll"
    arSEA(103,0) = "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}" : arSEA(103,1) = "shdocvw.dll"
    arSEA(104,0) = "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" : arSEA(104,1) = "sendmail.dll"
    arSEA(105,0) = "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" : arSEA(105,1) = "sendmail.dll"
    arSEA(106,0) = "{88C6C381-2E85-11D0-94DE-444553540000}" : arSEA(106,1) = "occache.dll"
    arSEA(107,0) = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" : arSEA(107,1) = "webcheck.dll"
    arSEA(108,0) = "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}" : arSEA(108,1) = "webcheck.dll"
    arSEA(109,0) = "{F5175861-2688-11d0-9C5E-00AA00A45957}" : arSEA(109,1) = "webcheck.dll"
    arSEA(110,0) = "{08165EA0-E946-11CF-9C87-00AA005127ED}" : arSEA(110,1) = "webcheck.dll"
    arSEA(111,0) = "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}" : arSEA(111,1) = "webcheck.dll"
    arSEA(112,0) = "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}" : arSEA(112,1) = "webcheck.dll"
    arSEA(113,0) = "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}" : arSEA(113,1) = "webcheck.dll"
    arSEA(114,0) = "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}" : arSEA(114,1) = "webcheck.dll"
    arSEA(115,0) = "{D8BD2030-6FC9-11D0-864F-00AA006809D9}" : arSEA(115,1) = "webcheck.dll"
    arSEA(116,0) = "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}" : arSEA(116,1) = "webcheck.dll"
    arSEA(117,0) = "{352EC2B7-8B9A-11D1-B8AE-006008059382}" : arSEA(117,1) = "appwiz.cpl"
    arSEA(118,0) = "{0B124F8F-91F0-11D1-B8B5-006008059382}" : arSEA(118,1) = "appwiz.cpl"
    arSEA(119,0) = "{CFCCC7A0-A282-11D1-9082-006008059382}" : arSEA(119,1) = "appwiz.cpl"
    arSEA(120,0) = "{e84fda7c-1d6a-45f6-b725-cb260c236066}" : arSEA(120,1) = "shimgvw.dll"
    arSEA(121,0) = "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}" : arSEA(121,1) = "shimgvw.dll"
    arSEA(122,0) = "{3F30C968-480A-4C6C-862D-EFC0897BB84B}" : arSEA(122,1) = "shimgvw.dll"
    arSEA(123,0) = "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}" : arSEA(123,1) = "shimgvw.dll"
    arSEA(124,0) = "{EAB841A0-9550-11cf-8C16-00805F1408F3}" : arSEA(124,1) = "shimgvw.dll"
    arSEA(125,0) = "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}" : arSEA(125,1) = "shimgvw.dll"
    arSEA(126,0) = "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}" : arSEA(126,1) = "netplwiz.dll"
    arSEA(127,0) = "{add36aa8-751a-4579-a266-d66f5202ccbb}" : arSEA(127,1) = "netplwiz.dll"
    arSEA(128,0) = "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}" : arSEA(128,1) = "netplwiz.dll"
    arSEA(129,0) = "{58f1f272-9240-4f51-b6d4-fd63d1618591}" : arSEA(129,1) = "netplwiz.dll"
    arSEA(130,0) = "{7A9D77BD-5403-11d2-8785-2E0420524153}" : arSEA(130,1) = ""
    arSEA(131,0) = "{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}" : arSEA(131,1) = "zipfldr.dll"
    arSEA(132,0) = "{BD472F60-27FA-11cf-B8B4-444553540000}" : arSEA(132,1) = "zipfldr.dll"
    arSEA(133,0) = "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}" : arSEA(133,1) = "zipfldr.dll"
    arSEA(134,0) = "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}" : arSEA(134,1) = "cdfview.dll"
    arSEA(135,0) = "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}" : arSEA(135,1) = "cdfview.dll"
    arSEA(136,0) = "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}" : arSEA(136,1) = "cdfview.dll"
    arSEA(137,0) = "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}" : arSEA(137,1) = "cdfview.dll"
    arSEA(138,0) = "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}" : arSEA(138,1) = "cdfview.dll"
    arSEA(139,0) = "{63da6ec0-2e98-11cf-8d82-444553540000}" : arSEA(139,1) = "msieftp.dll"
    arSEA(140,0) = "{883373C3-BF89-11D1-BE35-080036B11A03}" : arSEA(140,1) = "docprop2.dll"
    arSEA(141,0) = "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}" : arSEA(141,1) = "docprop2.dll"
    arSEA(142,0) = "{8EE97210-FD1F-4B19-91DA-67914005F020}" : arSEA(142,1) = "docprop2.dll"
    arSEA(143,0) = "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}" : arSEA(143,1) = "docprop2.dll"
    arSEA(144,0) = "{6A205B57-2567-4A2C-B881-F787FAB579A3}" : arSEA(144,1) = "docprop2.dll"
    arSEA(145,0) = "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}" : arSEA(145,1) = "docprop2.dll"
    arSEA(146,0) = "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" : arSEA(146,1) = "dsquery.dll"
    arSEA(147,0) = "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" : arSEA(147,1) = "dsquery.dll"
    arSEA(148,0) = "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" : arSEA(148,1) = "dsquery.dll"
    arSEA(149,0) = "{F020E586-5264-11d1-A532-0000F8757D7E}" : arSEA(149,1) = "dsquery.dll"
    arSEA(150,0) = "{0D45D530-764B-11d0-A1CA-00AA00C16E65}" : arSEA(150,1) = "dsuiext.dll"
    arSEA(151,0) = "{62AE1F9A-126A-11D0-A14B-0800361B1103}" : arSEA(151,1) = "dsuiext.dll"
    arSEA(152,0) = "{ECF03A33-103D-11d2-854D-006008059367}" : arSEA(152,1) = "mydocs.dll"
    arSEA(153,0) = "{ECF03A32-103D-11d2-854D-006008059367}" : arSEA(153,1) = "mydocs.dll"
    arSEA(154,0) = "{4a7ded0a-ad25-11d0-98a8-0800361b1103}" : arSEA(154,1) = "mydocs.dll"
    arSEA(155,0) = "{750fdf0e-2a26-11d1-a3ea-080036587f03}" : arSEA(155,1) = "cscui.dll"
    arSEA(156,0) = "{10CFC467-4392-11d2-8DB4-00C04FA31A66}" : arSEA(156,1) = "cscui.dll"
    arSEA(157,0) = "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}" : arSEA(157,1) = "cscui.dll"
    arSEA(158,0) = "{143A62C8-C33B-11D1-84FE-00C04FA34A14}" : arSEA(158,1) = "agentpsh.dll"
    arSEA(159,0) = "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}" : arSEA(159,1) = "dfsshlex.dll"
    arSEA(160,0) = "{60fd46de-f830-4894-a628-6fa81bc0190d}" : arSEA(160,1) = "photowiz.dll"
    arSEA(161,0) = "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" : arSEA(161,1) = "mmcshext.dll"
    arSEA(162,0) = "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}" : arSEA(162,1) = "cabview.dll"
    arSEA(163,0) = "{32714800-2E5F-11d0-8B85-00AA0044F941}" : arSEA(163,1) = "wabfind.dll"
    arSEA(164,0) = "{8DD448E6-C188-4aed-AF92-44956194EB1F}" : arSEA(164,1) = "wmpshell.dll"
    arSEA(165,0) = "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}" : arSEA(165,1) = "wmpshell.dll"
    arSEA(166,0) = "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}" : arSEA(166,1) = "wmpshell.dll"
    'W2K
    arSEA(167,0) = "{41E300E0-78B6-11ce-849B-444553540000}" : arSEA(167,1) = "plustab.dll"
    arSEA(168,0) = "{1A9BA3A0-143A-11CF-8350-444553540000}" : arSEA(168,1) = "shell32.dll"
    arSEA(169,0) = "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" : arSEA(169,1) = "shell32.dll"
    arSEA(170,0) = "{86747AC0-42A0-1069-A2E6-08002B30309D}" : arSEA(170,1) = "shell32.dll"
    arSEA(171,0) = "{0AFACED1-E828-11D1-9187-B532F1E9575D}" : arSEA(171,1) = "shell32.dll"
    arSEA(172,0) = "{12518493-00B2-11d2-9FA5-9E3420524153}" : arSEA(172,1) = "shell32.dll"
    arSEA(173,0) = "{21B22460-3AEA-1069-A2DC-08002B30309D}" : arSEA(173,1) = "shell32.dll"
    arSEA(174,0) = "{B091E540-83E3-11CF-A713-0020AFD79762}" : arSEA(174,1) = "shell32.dll"
    arSEA(175,0) = "{FBF23B41-E3F0-101B-8488-00AA003E56F8}" : arSEA(175,1) = "shell32.dll"
    arSEA(176,0) = "{C2FBB630-2971-11d1-A18C-00C04FD75D13}" : arSEA(176,1) = "shell32.dll"
    arSEA(177,0) = "{C2FBB631-2971-11d1-A18C-00C04FD75D13}" : arSEA(177,1) = "shell32.dll"
    arSEA(178,0) = "{13709620-C279-11CE-A49E-444553540000}" : arSEA(178,1) = "shell32.dll"
    arSEA(179,0) = "{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}" : arSEA(179,1) = "shell32.dll"
    arSEA(180,0) = "{4622AD11-FF23-11d0-8D34-00A0C90F2719}" : arSEA(180,1) = "shell32.dll"
    arSEA(181,0) = "{7BA4C740-9E81-11CF-99D3-00AA004AE837}" : arSEA(181,1) = "shell32.dll"
    arSEA(182,0) = "{D969A300-E7FF-11d0-A93B-00A0C90F2719}" : arSEA(182,1) = "shell32.dll"
    arSEA(183,0) = "{09799AFB-AD67-11d1-ABCD-00C04FC30936}" : arSEA(183,1) = "shell32.dll"
    arSEA(184,0) = "{3FC0B520-68A9-11D0-8D77-00C04FD70822}" : arSEA(184,1) = "shell32.dll"
    arSEA(185,0) = "{75048700-EF1F-11D0-9888-006097DEACF9}" : arSEA(185,1) = "shell32.dll"
    arSEA(186,0) = "{6D5313C0-8C62-11D1-B2CD-006097DF8C11}" : arSEA(186,1) = "shell32.dll"
    arSEA(187,0) = "{57651662-CE3E-11D0-8D77-00C04FC99D61}" : arSEA(187,1) = "shell32.dll"
    arSEA(188,0) = "{4657278A-411B-11d2-839A-00C04FD918D0}" : arSEA(188,1) = "shell32.dll"
    arSEA(189,0) = "{A470F8CF-A1E8-4f65-8335-227475AA5C46}" : arSEA(189,1) = "shell32.dll"
    arSEA(190,0) = "{568804CA-CBD7-11d0-9816-00C04FD91972}" : arSEA(190,1) = "browseui.dll"
    arSEA(191,0) = "{5b4dae26-b807-11d0-9815-00c04fd91972}" : arSEA(191,1) = "browseui.dll"
    arSEA(192,0) = "{8278F931-2A3E-11d2-838F-00C04FD918D0}" : arSEA(192,1) = "browseui.dll"
    arSEA(193,0) = "{E13EF4E4-D2F2-11d0-9816-00C04FD91972}" : arSEA(193,1) = "browseui.dll"
    arSEA(194,0) = "{ECD4FC4F-521C-11D0-B792-00A0C90312E1}" : arSEA(194,1) = "browseui.dll"
    arSEA(195,0) = "{D82BE2B0-5764-11D0-A96E-00C04FD705A2}" : arSEA(195,1) = "browseui.dll"
    arSEA(196,0) = "{0E5CBF21-D15F-11d0-8301-00AA005B4383}" : arSEA(196,1) = "browseui.dll"
    arSEA(197,0) = "{7487cd30-f71a-11d0-9ea7-00805f714772}" : arSEA(197,1) = "browseui.dll"
    arSEA(198,0) = "{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}" : arSEA(198,1) = "thumbvw.dll"
    arSEA(199,0) = "{EAB841A0-9550-11CF-8C16-00805F1408F3}" : arSEA(199,1) = "thumbvw.dll"
    arSEA(200,0) = "{1AEB1360-5AFC-11D0-B806-00C04FD706EC}" : arSEA(200,1) = "thumbvw.dll"
    arSEA(201,0) = "{9DBD2C50-62AD-11D0-B806-00C04FD706EC}" : arSEA(201,1) = "thumbvw.dll"
    arSEA(202,0) = "{500202A0-731E-11D0-B829-00C04FD706EC}" : arSEA(202,1) = "thumbvw.dll"
    arSEA(203,0) = "{0B124F8C-91F0-11D1-B8B5-006008059382}" : arSEA(203,1) = "appwiz.cpl"
    arSEA(204,0) = "{fe1290f0-cfbd-11cf-a330-00aa00c16e65}" : arSEA(204,1) = "dsfolder.dll"
    arSEA(205,0) = "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" : arSEA(205,1) = "dsfolder.dll"
    arSEA(206,0) = "{450D8FBA-AD25-11D0-98A8-0800361B1103}" : arSEA(206,1) = "mydocs.dll"
    'WXP SP2
    arSEA(207,0) = "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}" : arSEA(207,1) = "shdocvw.dll"
    arSEA(208,0) = "{596AB062-B4D2-4215-9F74-E9109B0A8153}" : arSEA(208,1) = "twext.dll"
    arSEA(209,0) = "{9DB7A13C-F208-4981-8353-73CC61AE2783}" : arSEA(209,1) = "twext.dll"
    arSEA(210,0) = "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}" : arSEA(210,1) = "extmgr.dll"
    'NT4
    arSEA(211,0) = "{764BF0E1-F219-11ce-972D-00AA00A14F56}" : arSEA(211,1) = "shcompui.dll"
    arSEA(212,0) = "{8DE56A0D-E58B-41FE-9F80-3563CDCB2C22}" : arSEA(212,1) = "thumbvw.dll"
    arSEA(213,0) = "{13709620-C279-11CE-A49E-444553540000}" : arSEA(213,1) = "SHDOC401.DLL"
    arSEA(214,0) = "{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}" : arSEA(214,1) = "SHDOC401.DLL"
    arSEA(215,0) = "{7BA4C740-9E81-11CF-99D3-00AA004AE837}" : arSEA(215,1) = "SHDOC401.DLL"
    arSEA(216,0) = "{D969A300-E7FF-11d0-A93B-00A0C90F2719}" : arSEA(216,1) = "SHDOC401.DLL"
    arSEA(217,0) = "{4622AD11-FF23-11d0-8D34-00A0C90F2719}" : arSEA(217,1) = "SHDOC401.DLL"
    arSEA(218,0) = "{3AD1E410-AAB9-11d0-89D7-00C04FC9E26E}" : arSEA(218,1) = "SHDOCVW.DLL"
    arSEA(219,0) = "{57651662-CE3E-11D0-8D77-00C04FC99D61}" : arSEA(219,1) = "SHDOC401.DLL"
    arSEA(220,0) = "{B091E540-83E3-11CF-A713-0020AFD79762}" : arSEA(220,1) = "SHDOC401.DLL"
    arSEA(221,0) = "{3FC0B520-68A9-11D0-8D77-00C04FD70822}" : arSEA(221,1) = "SHDOC401.DLL"
    arSEA(222,0) = "{7D688A77-C613-11D0-999B-00C04FD655E1}" : arSEA(222,1) = "SHELL32.dll"
    arSEA(223,0) = "{BDEADF00-C265-11d0-BCED-00A0C90AB50F}" : arSEA(223,1) = "MSONSEXT.DLL"
    arSEA(224,0) = "{C2FBB630-2971-11d1-A18C-00C04FD75D13}" : arSEA(224,1) = "SHDOC401.DLL"
    arSEA(225,0) = "{C2FBB631-2971-11d1-A18C-00C04FD75D13}" : arSEA(225,1) = "SHDOC401.DLL"
    arSEA(226,0) = "{75048700-EF1F-11D0-9888-006097DEACF9}" : arSEA(226,1) = "SHDOC401.DLL"
    arSEA(227,0) = "{6D5313C0-8C62-11D1-B2CD-006097DF8C11}" : arSEA(227,1) = "SHDOC401.DLL"
    arSEA(228,0) = "{FBF23B41-E3F0-101B-8488-00AA003E56F8}" : arSEA(228,1) = "SHDOC401.DLL"
    arSEA(229,0) = "{5a61f7a0-cde1-11cf-9113-00aa00425c62}" : arSEA(229,1) = "w3ext.dll"
    'WMe
    arSEA(230,0) = "{3F30C968-480A-4C6C-862D-EFC0897BB84B}" : arSEA(230,1) = "THUMBVW.DLL" 'see (122)
    arSEA(231,0) = "{53C74826-AB99-4d33-ACA4-3117F51D3788}" : arSEA(231,1) = "SHELL32.DLL"
    arSEA(232,0) = "{992CFFA0-F557-101A-88EC-00DD010CCC48}" : arSEA(232,1) = "rnaui.dll" 'see (30)
    arSEA(233,0) = "{FEF10FA2-355E-4e06-9381-9B24D7F7CC88}" : arSEA(233,1) = "SHELL32.DLL"
    'MS PowerToys
    arSEA(234,0) = "{AA7C7080-860A-11CE-8424-08002B2CFF76}" : arSEA(234,1) = "SENDTOX.DLL"
    arSEA(235,0) = "{7BB70120-6C78-11CF-BFC7-444553540000}" : arSEA(235,1) = "SENDTOX.DLL"
    arSEA(236,0) = "{7BB70122-6C78-11CF-BFC7-444553540000}" : arSEA(236,1) = "SENDTOX.DLL"
    arSEA(237,0) = "{7BB70121-6C78-11CF-BFC7-444553540000}" : arSEA(237,1) = "SENDTOX.DLL"
    arSEA(238,0) = "{7BB70123-6C78-11CF-BFC7-444553540000}" : arSEA(238,1) = "SENDTOX.DLL"
    arSEA(239,0) = "{9E56BE62-C50F-11CF-9A2C-00A0C90A90CE}" : arSEA(239,1) = "SENDTOX.DLL"
    arSEA(240,0) = "{90A756E0-AFCF-11CE-927B-0800095AE340}" : arSEA(240,1) = "target.dll"
    arSEA(241,0) = "{afc638f0-e8a4-11ce-9ade-00aa00a42d2e}" : ar
    Anthony10 le 10 avril 2007 à 01h26
    Bonjour,

    Clique droit sur le lien suivant puis clique sur "Enregistrer sous" ou "Enregistrer la cible sous" :
    http://www.silentrunners.org/Silent%20Runners.vbs

    Lance-le et envoie le résultat.

    Anthony.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 10 avril 2007 à 08h54
    bonjour
    cette fois ci cela a marché; voici le résultat:
    "Silent Runners.vbs", revision R50, http://www.silentrunners.org/
    Operating System: Windows XP SP2
    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:
    ---------------------------------

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "WOOKIT" = "C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe" ["France Télécom R&D"]
    "msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
    "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" ["Google Inc."]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "WOOWATCH" = "C:\PROGRA~1\Wanadoo\Watch.exe" ["France Télécom R&D"]
    "WOOTASKBARICON" = "C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe" ["France Télécom R&D"]
    "StorageGuard" = ""C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r" ["Sonic Solutions"]
    "snpstd" = "C:\WINDOWS\vsnpstd.exe" [file not found]
    "Recguard" = "C:\WINDOWS\SMINST\RECGUARD.EXE" [empty string]
    "PS2" = "C:\WINDOWS\system32\ps2.exe" ["Hewlett-Packard Company"]
    "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
    "NWEReboot" = "(empty string)" [file not found]
    "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
    "KBD" = "C:\HP\KBD\KBD.EXE" ["Hewlett-Packard Company"]
    "hpsysdrv" = "c:\windows\system\hpsysdrv.exe" ["Hewlett-Packard Company"]
    "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
    "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]
    "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
    "AlcxMonitor" = "ALCXMNTR.EXE" ["Realtek Semiconductor Corp."]
    "NeroFilterCheck" = "C:\WINDOWS\System32\NeroCheck.exe" ["Ahead Software Gmbh"]
    "RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
    "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
    "Lexmark X1100 Series" = ""C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"" ["Lexmark International, Inc."]
    "DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
    "CloneCDTray" = ""C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s" ["SlySoft, Inc."]
    "NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "AcroIEHlprObj Class"
    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]
    {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Windows Live Sign-in Helper"
    \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
    {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Google Toolbar Helper"
    \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
    {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Windows Live Toolbar Helper"
    \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
    "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
    -> {HKLM...CLSID} = "Desktop Explorer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
    "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
    "{7F67036B-66F1-411A-AD85-759FB9C5B0DB}" = "SampleView"
    -> {HKLM...CLSID} = "SampleView"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\ShellvRTF.dll" ["XSS"]
    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
    -> {HKLM...CLSID} = "WinRAR"
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
    "{46E22146-59C0-4136-9233-52E412E2B428}" = "EzCddax extension"
    -> {HKLM...CLSID} = "EzCddax Class"
    \InProcServer32\(Default) = "C:\Program Files\Easy CD-DA Extractor 8\ezcddax8.dll" [null data]
    "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
    -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
    \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
    "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
    -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
    \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
    "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.5 Context Menu Shell Extension"
    -> {HKLM...CLSID} = "WinAceContext Menu Extension"
    \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
    "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.5 DragDrop Shell Extension"
    -> {HKLM...CLSID} = "WinAceDrag-Drop Extension"
    \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
    "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.5 Context Menu Shell Extension"
    -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
    \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
    "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.5 Property Sheet Shell Extension"
    -> {HKLM...CLSID} = "WinAceProperty Sheet Extension"
    \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
    "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
    -> {HKLM...CLSID} = "avast"
    \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
    "{9999A076-A9E2-4C99-8A2B-632FC9429223}" = "Bonjour"
    -> {HKLM...CLSID} = "Bonjour"
    \InProcServer32\(Default) = "C:\Program Files\Bonjour\ExplorerPlugin.dll" ["Apple Computer, Inc."]
    "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
    -> {HKLM...CLSID} = "DesktopContext Class"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
    "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
    -> {HKLM...CLSID} = "NVIDIA CPL Extension"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
    "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
    -> {HKLM...CLSID} = "nView Desktop Context Menu"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
    "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
    -> {HKLM...CLSID} = "Mes dossiers de partage"
    \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
    "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
    -> {HKLM...CLSID} = "WPDShServiceObj Class"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
    <<!>> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]

    HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
    {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
    -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
    \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]

    HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
    avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
    -> {HKLM...CLSID} = "avast"
    \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
    EzCddax\(Default) = "{46E22146-59C0-4136-9233-52E412E2B428}"
    -> {HKLM...CLSID} = "EzCddax Class"
    \InProcServer32\(Default) = "C:\Program Files\Easy CD-DA Extractor 8\ezcddax8.dll" [null data]
    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
    -> {HKLM...CLSID} = "WinRAR"
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
    ZFAdd\(Default) = "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"
    -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
    \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

    HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
    -> {HKLM...CLSID} = "WinRAR"
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
    ZFAdd\(Default) = "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"
    -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
    \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

    HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
    avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
    -> {HKLM...CLSID} = "avast"
    \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
    -> {HKLM...CLSID} = "WinRAR"
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    Group Policies {policy setting}:
    --------------------------------

    Note: detected settings may not have any effect.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
    {Prevent access to registry editing tools}

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Shutdown: Allow system to be shut down without having to log on}

    "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop may be disabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    HKCU\Control Panel\Desktop\
    "Wallpaper" = "C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Fond d'écran.bmp"


    Enabled Screen Saver:
    ---------------------

    HKCU\Control Panel\Desktop\
    "SCRNSAVE.EXE" = "C:\WINDOWS\System32\AVASTSS.scr" ["ALWIL Software"]


    Startup items in "Propriétaire" & "All Users" startup folders:
    --------------------------------------------------------------

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    "Kodak software updater" -> shortcut to: "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" [null data]
    "Logiciel Kodak EasyShare" -> shortcut to: "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe -hx" [null data]
    "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]


    Enabled Scheduled Tasks:
    ------------------------

    "Nettoyage de disque" -> launches: "C:\WINDOWS\system32\cleanmgr.exe" [MS]
    "Vérifier les mises à jour de Windows Live Toolbar" -> launches: "C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE" [MS]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Computer, Inc."]

    Transport Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
    %SystemRoot%\system32\mswsock.dll [MS], 1 - 3


    Toolbars, Explorer Bars, Extensions:
    ------------------------------------

    Toolbars

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
    -> {HKLM...CLSID} = "&Google"
    \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
    "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
    -> {HKLM...CLSID} = "Windows Live Toolbar"
    \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

    HKLM\Software\Microsoft\Internet Explorer\Toolbar\
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
    -> {HKLM...CLSID} = "&Google"
    \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
    "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = (no title provided)
    -> {HKLM...CLSID} = "Windows Live Toolbar"
    \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

    Explorer Bars

    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

    HKLM\Software\Classes\CLSID\{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}\(Default) = "Volet Wanadoo"
    Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
    InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string]

    HKLM\Software\Classes\CLSID\{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}\(Default) = "ToolBand Class"
    Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
    InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string]

    HKLM\Software\Classes\CLSID\{5BF498C0-931E-4A4F-B33F-456D07137EAA}\(Default) = "Volet Wanadoo"
    Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
    InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string]

    HKLM\Software\Classes\CLSID\{9999A076-A9E2-4C99-8A2B-632FC9429223}\(Default) = "Bonjour"
    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    InProcServer32\(Default) = "C:\Program Files\Bonjour\ExplorerPlugin.dll" ["Apple Computer, Inc."]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKCU\Software\Microsoft\Internet Explorer\Extensions\
    {1462651F-F4BA-4C76-A001-C4284D0FE16E}\
    "ButtonText" = "Wanadoo"
    "Exec" = "http://www.wanadoo.fr" [file not found]

    HKLM\Software\Microsoft\Internet Explorer\Extensions\
    {7F9DB11C-E358-4CA6-A83D-ACC663939424}\
    "ButtonText" = "Bonjour"

    {E2E2DD38-D088-4134-82B7-F2BA38496583}\
    "MenuText" = "@xpsp3res.dll,-20001"
    "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]

    {FB5F1910-F110-11D2-BB9E-00C04F795683}\
    "ButtonText" = "Messager Wanadoo"
    "MenuText" = "Messager Wanadoo"
    "Exec" = "C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe" ["France Telecom"]


    Miscellaneous IE Hijack Points
    ------------------------------

    C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

    Added lines (compared with English-language version):
    [Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    [Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/"

    Missing lines (compared with English-language version):
    [Strings]: 2 lines

    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
    <<H>> "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)
    -> {HKLM...CLSID} = "Search Class"
    \InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\SEARCH~1.DLL" [empty string]


    Running Services (Display Name, Service Name, Path {Service DLL}):
    ------------------------------------------------------------------

    avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]
    avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]
    avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
    avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
    France Telecom Routing Table Service, FTRTSVC, "C:\WINDOWS\System32\FTRTSVC.exe" ["France Telecom"]
    LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
    Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
    NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]
    Service Bonjour, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Computer, Inc."]
    Service de lancement de WlanCfg, Wlancfg, "C:\Program Files\Inventel\Gateway\wlancfg.exe SVC" ["Inventel"]
    Service Messenger Sharing Folders USN Journal Reader, usnjsvc, ""C:\Program Files\MSN Messenger\usnsvc.exe"" [MS]


    Print Monitors:
    ---------------

    HKLM\System\CurrentControlSet\Control\Print\Monitors\
    Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
    Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]


    ----------
    <<!>>: Suspicious data at a malware launch point.
    <<H>>: Suspicious data at a browser hijack point.

    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + To search all directories of local fixed drives for DESKTOP.INI
    DLL launch points, use the -supp parameter or answer "No" at the
    first message box and "Yes" at the second message box.
    ---------- (total run time: 92 seconds, including 16 seconds for message boxes)
    bye
    Anthony10 le 11 avril 2007 à 01h22
    Bonsoir manosaure,

  • Fais un scan en ligne Kaspersky avec Internet Explorer :
  • Dans la nouvelle fenêtre, clique sur J'accepte.
  • Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
  • Patiente pendant l'installation des Mises à jour.
  • Choisis par la suite l'analyse du Poste de travail
  • Sauvegarde puis colle le rapport généré en fin d'analyse.

  • AIDE : Configurer le contrôle des ActiveX

    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 11 avril 2007 à 11h48
    bonjour
    voici le rapport de kapersky:
    KASPERSKY ON-LINE SCANNER REPORT
    Wednesday, April 11, 2007 11:47:35 AM
    Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky On-line Scanner version : 5.0.83.0
    Dernière mise à jour de la base antivirus Kaspersky : 11/04/2007
    Enregistrements dans la base antivirus Kaspersky : 277613
    Paramètres d'analyse
    Analyser avec la base antivirus suivante standard
    Analyser les archives vrai
    Analyser les bases de messagerie vrai
    Cible de l'analyse Poste de travail
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    Statistiques de l'analyse
    Total d'objets analysés 80951
    Nombre de virus trouvés 0
    Nombre d'objets infectés 0 / 0
    Nombre d'objets suspects 0
    Durée de l'analyse 02:28:35

    Nom de l'objet infecté Nom du virus Dernière action
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\Desktop.ini L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Blonds On Fire.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Dangerous Tides.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\L'affaire Katsumi.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\melanie.sex.model.(melanie.coste).avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Sex Commandos - Stacy Valentine.asf L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Thumbs.db L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\XXX - Lingerie (Laura Angel, Nikki Anderson).avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\brooke_richards_002.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\CELEB Catherine Bell Playboy Nude.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\fond0405_cal_1024.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_037.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_044.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_045.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_047.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_055.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\sopWallpaper01.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tabatha_cash_001.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\Thumbs.db L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tiffany_taylor_002.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tiffany_taylor_008.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\cert8.db L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\history.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\key3.db L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\parent.lock L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\search.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\urlclassifier2.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Messenger\lesbiscous@hotmail.fr\SharingMetadata\Logs\Dfsr00005.log L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Messenger\lesbiscous@hotmail.fr\SharingMetadata\pending.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Messenger\lesbiscous@hotmail.fr\SharingMetadata\Working\database_B86C_685E_6C68_1980\dfsr.db L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Messenger\lesbiscous@hotmail.fr\SharingMetadata\Working\database_B86C_685E_6C68_1980\fsr.log L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Messenger\lesbiscous@hotmail.fr\SharingMetadata\Working\database_B86C_685E_6C68_1980\fsrtmp.log L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Messenger\lesbiscous@hotmail.fr\SharingMetadata\Working\database_B86C_685E_6C68_1980\tmp.edb L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows Live Contacts\lesbiscous@hotmail.fr\real\members.stg L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows Live Contacts\lesbiscous@hotmail.fr\shadow\members.stg L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Mozilla\Firefox\Profiles\p1bupekc.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\MSHist012007041120070412\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF54D6.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF552F.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFD0D6.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFD159.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\ntuser.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\Propriétaire\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\BWKDLogs\BWTargetInf.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\agent.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\busyprs.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\BWLocalWebListener.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\D0000000.FCS L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\FileDL.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\inuse.txt L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\L0000006.FCS L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\main.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.idx L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\RG.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\scheddbg.log L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.dat L'objet est verrouillé ignoré
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.idx L'objet est verrouillé ignoré
    C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
    C:\System Volume Information\_restore{855E1445-C257-4E62-98F7-CCA06E6C4C35}\RP28\change.log L'objet est verrouillé ignoré
    C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\fwdbglog.txt L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\fwpktlog.txt L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\IAMDB.RDB L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\NOM-K5WGBUATAIQ.ldb L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\tvDebug.log L'objet est verrouillé ignoré
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
    C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
    C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
    C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\Temp\Perflib_Perfdata_20c.dat L'objet est verrouillé ignoré
    C:\WINDOWS\Temp\ZLT0496f.TMP L'objet est verrouillé ignoré
    C:\WINDOWS\Temp\ZLT0497c.TMP L'objet est verrouillé ignoré
    C:\WINDOWS\Temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré
    C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
    C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
    C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
    F:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
    Analyse terminée.
    bye
    Anthony10 le 12 avril 2007 à 01h26
    Bonsoir manosaure,

    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Blonds On Fire.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Dangerous Tides.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\L'affaire Katsumi.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\melanie.sex.model.(melanie.coste).avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Sex Commandos - Stacy Valentine.asf L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Thumbs.db L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\XXX - Lingerie (Laura Angel, Nikki Anderson).avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\brooke_richards_002.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\CELEB Catherine Bell Playboy Nude.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\fond0405_cal_1024.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_037.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_044.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_045.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_047.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_055.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\sopWallpaper01.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tabatha_cash_001.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\Thumbs.db L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tiffany_taylor_002.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tiffany_taylor_008.jpg L'objet est verrouillé ignoré


    Sans commentaire...

    Le rapport du scan en lige est "propre".
    Rencontres-tu encore des problèmes ?

    Anthony.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 12 avril 2007 à 08h58
    bonjour
    le seul probleme que j'ai maintenant c'est que l'espace wanadoo ne se lance plus ( même par le menu demarrer et apres avoir reinstallé le cd) . Par contre crois tu que je puisse vider ma quarantaine d'avast sans probleme?
    merci anthony :jap: :hello:
    manosaure le 12 avril 2007 à 09h15
    bonjour
    une petite précision anthony: le "sans commentaire" m'a laissé sans voix étant donné que j'ignorais son existence !! ( dossier de mon ex ) :??: :/
    on m'aide sur le forum pour le supprimer !
    bye ;)
    Anthony10 le 13 avril 2007 à 02h03
    Bonsoir manosaure,

    Depuis quand rencontres-tu le problème avec l'Espace Orange ?
    Qui t'aides à supprimer le dossier ?

    Anthony.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 13 avril 2007 à 08h46
    bonjour anthony
    j'ai eu le probleme avec l'espace wanadoo quelque temps avant d'avoir le trojan; du coup je passe par firefox pour aller sur internet et orange :D
    pour le dossier c'est wxc59 dans la section windows qui m'aide (il m'a conseillé unlocker mais pour l'instant ça marche pas ja vais essayer en mode sans echec comme il me l'a dit après )
    sinon tu crois que je peux vider ma quarantaine( sachant qu'il y a d'autres trojans dedans )?
    merci et bye :hello:
    Anthony10 le 14 avril 2007 à 01h57
    Bonsoir manosaure,

    Quel est le problème exact avec l'Espace Wanadoo/Orange ?
    Vide ta Quarantaine.

    Anthony.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 14 avril 2007 à 13h10
    bonjour :)
    je vide ma quarantaine !
    quant à l'espace wanadoo ca me dit qu'il est impossible de lancer car 1 ou plusieurs fichiers sont endommagés ou manquants ;mais passant par mozilla pour aller sur orange (mis en favoris) je ne m'en suis pas trop préoccupée.
    bye
    Anthony10 le 15 avril 2007 à 12h48
    Bonjour manosaure,

    Si tu disposes du CD d'installation de l'Espace Wanadoo/Orange, réinstalle-le.
    As-tu encore des problèmes ?

    Anthony.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 16 avril 2007 à 12h49
    bonjour anthony
    pour orange je vais faire ce que tu m'as dit, par contre dans la section windows pour mon problème de dossier confidentiel vérouillé impossible à désinstaller ( même avec unlocker ) francoisdo m'a dit de m'adresser a la section virus. As tu une idée ou faut il que je crée un nouveau sujet ?
    merci et bye :hello:
    Anthony10 le 16 avril 2007 à 20h59
    Bonsoir manosaure,

    Quels dossiers veux-tu supprimer ?

    Anthony.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 17 avril 2007 à 12h40
    bonjour anthony
    le fameux dossier que tu as annoté "sans commentaire "; il se trouve dans les documents accesssibles par le poste de travail, là il y a un dossier christophe à l'intérieur duquel se trouve un dossier confidentiel. Lorsque je passe le curseur de la souris dessus ça me dit qu'il est vide et unlocker me dit pareil mais dans les scans de kapersky et d'avast ça dit le contraire ; en plus impossible de le supprimer ! :??:
    merci et bye
    -->Message édité par manosaure le 17/04/2007 12:44:25<--
    Anthony10 le 18 avril 2007 à 21h52
    Bonjour,

  • Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.

  • Double-clique sur OTMoveIt.exe pour le lancer.
  • Copie/colle les fichiers/dossiers suivants dans le cadre de gauche nommé Paste List of Files/Folders to be moved.

  • C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel

  • Clique sur MoveIt! pour lancer la suppression.
  • Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.

  • Dans ta future réponse, envoie le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles.

  • A suivre,
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 18 avril 2007 à 23h04
    bonsoir anthony
    ce dossier va me rendre folle
    impossible de faire un copier coller ou autre, ça me dit" acces refusé verifiez que le dossier n'est pas plein ou protégé en écriture" !!
    je sais plus quoi faire.
    As tu une autre idée?
    bye
    Anthony10 le 19 avril 2007 à 22h26
    Bonsoir,


  • Télécharge DiagHelp.zip (de Malekal) sur ton Bureau.

  • Dézippe-le entièrement sur ton Bureau.
  • Double-clique sur go.cmd, une fenêtre de commande s'ouvrira.
  • Choisis l'option 1 en tapant 1 puis presse la touche Entr du clavier.
  • Un rapport sera généré sous le nom de resultat.txt.

  • --------

    Menu Démarrer / executer et tape : cmd puis clic sur OK.
    Tape chacune de ces communes en appuyant sur la touche entrée à chaque fois pour valider la commande :

    gmer -del folder "C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel"

    L'ordinateur va redémarrer et envoie le rapport de DiagHelp.
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 20 avril 2007 à 22h48
    bonsoir anthony
    voici le rapport:
    C:\WINDOWS\System32/drivers\aswmon.sys -->18/04/2007 18:12:31
    C:\WINDOWS\System32/drivers\aswmon2.sys -->18/04/2007 18:12:12
    C:\WINDOWS\System32/drivers\aswRdr.sys -->18/04/2007 18:10:01
    C:\WINDOWS\System32/drivers\aswTdi.sys -->18/04/2007 18:09:10
    C:\WINDOWS\System32/drivers\aavmker4.sys -->18/04/2007 18:07:49
    C:\WINDOWS\System32/drivers\hamachi.sys -->17/03/2007 10:09:36
    C:\WINDOWS\System32/drivers\nv4_mini.sys -->22/10/2006 13:22:00

    C:\WINDOWS\System32\QuickTime.qtp -->20/04/2007 17:55:46
    C:\WINDOWS\System32\nvapps.xml -->20/04/2007 09:59:51
    C:\WINDOWS\System32\vsconfig.xml -->20/04/2007 09:58:01
    C:\WINDOWS\System32\CONFIG.NT -->20/04/2007 09:52:34
    C:\WINDOWS\System32\aswBoot.exe -->18/04/2007 18:16:59
    C:\WINDOWS\System32\AVASTSS.scr -->18/04/2007 18:06:59
    C:\WINDOWS\System32\FNTCACHE.DAT -->10/04/2007 18:17:22
    C:\WINDOWS\System32\zllictbl.dat -->10/04/2007 09:33:20
    C:\WINDOWS\System32\MRT.exe -->03/04/2007 22:48:52
    C:\WINDOWS\System32\x_dtrace_log -->03/04/2007 22:08:40
    C:\WINDOWS\System32\00B73160_kds.xml -->03/04/2007 22:07:18
    C:\WINDOWS\System32\wpa.dbl -->03/04/2007 09:22:03
    C:\WINDOWS\System32\perfh00C.dat -->25/03/2007 18:39:51
    C:\WINDOWS\System32\perfh009.dat -->25/03/2007 18:39:50
    C:\WINDOWS\System32\perfc00C.dat -->25/03/2007 18:39:50
    C:\WINDOWS\System32\perfc009.dat -->25/03/2007 18:39:49
    C:\WINDOWS\System32\PerfStringBackup.INI -->25/03/2007 18:39:44
    C:\WINDOWS\System32\wuaueng.dll -->22/03/2007 23:08:24
    C:\WINDOWS\System32\wuapi.dll -->22/03/2007 23:08:20
    C:\WINDOWS\System32\wucltui.dll -->22/03/2007 23:08:18
    C:\WINDOWS\System32\wuweb.dll -->22/03/2007 23:08:14
    C:\WINDOWS\System32\wuaucpl.cpl -->22/03/2007 23:08:14
    C:\WINDOWS\System32\cdm.dll -->22/03/2007 23:08:06
    C:\WINDOWS\System32\wuauclt.exe -->22/03/2007 23:08:04
    C:\WINDOWS\System32\wups2.dll -->22/03/2007 23:08:00

    C:\WINDOWS\WindowsUpdate.log -->20/04/2007 20:48:21
    C:\WINDOWS\setupapi.log -->20/04/2007 20:45:42
    C:\WINDOWS\wiadebug.log -->20/04/2007 20:45:16
    C:\WINDOWS\wiaservc.log -->20/04/2007 20:45:14
    C:\WINDOWS\TLCAPPS.INI -->20/04/2007 20:43:20
    C:\WINDOWS\QTFont.qfn -->20/04/2007 17:55:22
    C:\WINDOWS\QTFont.for -->20/04/2007 17:55:22
    C:\WINDOWS\5-wlancfg.log -->20/04/2007 09:59:18
    C:\WINDOWS\bootstat.dat -->20/04/2007 09:55:24
    C:\WINDOWS\4-wlancfg.log -->19/04/2007 22:26:08
    C:\WINDOWS\3-wlancfg.log -->18/04/2007 23:08:10
    C:\WINDOWS\2-wlancfg.log -->17/04/2007 23:27:30
    C:\WINDOWS\NeroDigital.ini -->16/04/2007 21:33:39
    C:\WINDOWS\setuperr.log -->16/04/2007 07:05:22
    C:\WINDOWS\setupact.log -->16/04/2007 07:05:22

    C:\WINDOWS\ALCXMNTR.EXE |02/01/2003 14:19:41
    C:\WINDOWS\Crsaver.exe |22/01/2006 18:12:32
    C:\WINDOWS\GPInstall.exe |27/09/2006 22:57:37
    C:\WINDOWS\IsUn040c.exe |02/01/2003 13:48:30
    C:\WINDOWS\IsUninst.exe |02/01/2003 14:38:51
    C:\WINDOWS\PATCH.EXE |27/10/2006 22:08:03
    C:\WINDOWS\runtsckl.exe |02/11/2005 18:07:12
    C:\WINDOWS\slrundll.exe |19/02/2006 19:02:29
    C:\WINDOWS\tsc.exe |27/10/2006 22:12:23
    C:\WINDOWS\twunk_16.exe |01/01/2003 19:26:40
    C:\WINDOWS\twunk_32.exe |01/01/2003 19:26:40
    C:\WINDOWS\UnGins.exe |06/02/2006 13:31:52
    C:\WINDOWS\unin040c.exe |28/12/2004 16:58:19
    C:\WINDOWS\uninst.exe |13/06/2006 15:16:26
    C:\WINDOWS\unvise32.exe |21/10/2004 18:40:33
    C:\WINDOWS\unvise32qt.exe |19/12/2004 11:04:58
    C:\WINDOWS\zllsputility.exe |10/04/2007 09:30:44
    C:\WINDOWS\AuHCcup1.dll |23/07/1999 10:53:20
    C:\WINDOWS\BPMNT.dll |27/10/2006 22:12:22
    C:\WINDOWS\daemon.dll |22/08/2004 18:04:56
    C:\WINDOWS\hcextoutput.dll |27/10/2006 22:12:23
    C:\WINDOWS\loadhttp.dll |15/10/2002 14:29:40
    C:\WINDOWS\mickey32.dll |22/01/2006 18:12:32
    C:\WINDOWS\patchw32.dll |14/12/2001 13:34:46
    C:\WINDOWS\POCE98.DLL |23/09/1998 22:10:16
    C:\WINDOWS\POCELANG.DLL |23/02/1999 15:12:18
    C:\WINDOWS\TMUPDATE.DLL |27/10/2006 22:08:04
    C:\WINDOWS\twain.dll |01/01/2003 19:26:40
    C:\WINDOWS\twain_32.dll |01/01/2003 19:26:40
    C:\WINDOWS\UNZIP.DLL |27/10/2006 22:08:04
    C:\WINDOWS\vsapi32.dll |27/10/2006 22:12:22
    C:\WINDOWS\zllsputility_loc040c.dll |10/04/2007 09:30:54
    C:\WINDOWS\system32\append.exe |01/01/2003 19:50:49
    C:\WINDOWS\system32\aswBoot.exe |09/04/2006 18:25:12
    C:\WINDOWS\system32\ati2evxx.exe |02/01/2003 14:18:41
    C:\WINDOWS\system32\Ati2mdxx.exe |02/01/2003 14:18:41
    C:\WINDOWS\system32\debug.exe |01/01/2003 19:51:07
    C:\WINDOWS\system32\dns-sd.exe |28/11/2005 12:10:30
    C:\WINDOWS\system32\dosx.exe |01/01/2003 19:51:09
    C:\WINDOWS\system32\dvdplay.exe |24/08/2001 09:47:34
    C:\WINDOWS\system32\edlin.exe |01/01/2003 19:51:13
    C:\WINDOWS\system32\exe2bin.exe |01/01/2003 19:51:14
    C:\WINDOWS\system32\fastopen.exe |01/01/2003 19:51:15
    C:\WINDOWS\system32\FTRTSVC.exe |01/12/2005 11:31:30
    C:\WINDOWS\system32\GkSui20.EXE |22/06/2006 12:25:34
    C:\WINDOWS\system32\hkcmd.exe |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxcfg.exe |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxdiag.exe |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxext.exe |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxtray.exe |02/01/2003 14:13:36
    C:\WINDOWS\system32\java.exe |01/12/2005 11:31:10
    C:\WINDOWS\system32\javaw.exe |01/12/2005 11:31:10
    C:\WINDOWS\system32\keystone.exe |15/07/2004 11:42:00
    C:\WINDOWS\system32\LEXBCES.EXE |28/12/2004 16:59:17
    C:\WINDOWS\system32\LEXPPS.EXE |28/12/2004 16:59:19
    C:\WINDOWS\system32\mem.exe |01/01/2003 19:51:36
    C:\WINDOWS\system32\mscdexnt.exe |01/01/2003 19:24:25
    C:\WINDOWS\system32\NeroCheck.exe |09/07/2001 12:50:42
    C:\WINDOWS\system32\nlsfunc.exe |01/01/2003 19:24:40
    C:\WINDOWS\system32\nvappbar.exe |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvcolor.exe |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvcplui.exe |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvdspsch.exe |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvsvc32.exe |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvudisp.exe |21/10/2004 19:09:50
    C:\WINDOWS\system32\NVUNINST.EXE |12/02/2007 12:51:04
    C:\WINDOWS\system32\nwiz.exe |02/01/2003 14:16:48
    C:\WINDOWS\system32\ps2.EXE |02/01/2003 14:29:40
    C:\WINDOWS\system32\redir.exe |01/01/2003 19:25:05
    C:\WINDOWS\system32\S3uninst.exe |02/01/2003 14:11:07
    C:\WINDOWS\system32\ScsiAccess.EXE |04/02/2003 09:22:30
    C:\WINDOWS\system32\setver.exe |01/01/2003 19:25:10
    C:\WINDOWS\system32\share.exe |01/01/2003 19:25:10
    C:\WINDOWS\system32\slrundll.exe |19/02/2006 19:02:33
    C:\WINDOWS\system32\slserv.exe |19/02/2006 19:02:33
    C:\WINDOWS\system32\Uninstall_UV_DirectShow_Pack.exe |21/10/2004 18:39:47
    C:\WINDOWS\system32\unwlsdrv.exe |06/01/2005 16:04:00
    C:\WINDOWS\system32\usrmlnka.exe |24/08/2001 09:47:48
    C:\WINDOWS\system32\usrprbda.exe |24/08/2001 09:47:48
    C:\WINDOWS\system32\usrshuta.exe |24/08/2001 09:47:48
    C:\WINDOWS\system32\3DViewer.dll |14/04/2004 09:06:42
    C:\WINDOWS\system32\a3d.dll |02/01/2003 14:19:41
    C:\WINDOWS\system32\ActPanel.dll |01/12/2005 11:31:03
    C:\WINDOWS\system32\amstream.dll |12/12/2002 15:14:32
    C:\WINDOWS\system32\ati2cqag.dll |19/02/2006 19:02:45
    C:\WINDOWS\system32\ati2dvaa.dll |19/02/2006 19:02:45
    C:\WINDOWS\system32\ati2dvag.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\ati3d1ag.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\ati3d2ag.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\ati3duag.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\ATIDDC.DLL |02/01/2003 14:18:41
    C:\WINDOWS\system32\atiiiexx.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\atioglxx.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\atipdlxx.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\atitvo32.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\ativcoxx.dll |02/01/2003 14:18:41
    C:\WINDOWS\system32\ativtmxx.dll |19/02/2006 19:02:44
    C:\WINDOWS\system32\ativvaxx.dll |19/02/2006 19:02:44
    C:\WINDOWS\system32\atmfd.dll |01/01/2003 19:50:52
    C:\WINDOWS\system32\atmlib.dll |01/01/2003 19:50:52
    C:\WINDOWS\system32\atrc.dll |30/01/2004 15:48:19
    C:\WINDOWS\system32\Audio3D.dll |02/01/2003 14:19:41
    C:\WINDOWS\system32\BASSMOD.dll |19/11/2005 17:14:32
    C:\WINDOWS\system32\bcbmm.dll |02/01/2003 13:54:56
    C:\WINDOWS\system32\borlndmm.dll |02/01/2003 13:54:56
    C:\WINDOWS\system32\cc3250.dll |02/01/2003 13:54:56
    C:\WINDOWS\system32\cc3250mt.dll |02/01/2003 13:54:56
    C:\WINDOWS\system32\CmdLineExt.dll |27/10/2006 21:21:35
    C:\WINDOWS\system32\CmdLineExt03.dll |17/03/2007 17:46:00
    C:\WINDOWS\system32\compatui.dll |01/01/2003 19:51:00
    C:\WINDOWS\system32\cook.dll |30/01/2004 15:32:42
    C:\WINDOWS\system32\delphimm.dll |02/01/2003 13:54:56
    C:\WINDOWS\system32\dgrpsetu.dll |01/01/2003 19:51:07
    C:\WINDOWS\system32\dgsetup.dll |01/01/2003 19:51:07
    C:\WINDOWS\system32\DivX.dll |09/04/2003 14:23:50
    C:\WINDOWS\system32\DivXc32.dll |11/12/2001 14:17:12
    C:\WINDOWS\system32\DivXc32f.dll |27/11/2001 02:19:54
    C:\WINDOWS\system32\dnssd.dll |28/11/2005 12:10:18
    C:\WINDOWS\system32\drv1.dll |30/01/2004 15:48:20
    C:\WINDOWS\system32\drv2.dll |30/01/2004 15:48:20
    C:\WINDOWS\system32\drvc.dll |07/05/2004 18:40:16
    C:\WINDOWS\system32\dunzip32.dll |18/12/2006 15:10:38
    C:\WINDOWS\system32\dzip32.dll |18/12/2006 15:10:38
    C:\WINDOWS\system32\ElbyCDIO.dll |19/10/2003 00:33:55
    C:\WINDOWS\system32\encdec.dll |01/01/2003 19:51:13
    C:\WINDOWS\system32\EqnClass.Dll |01/01/2003 19:51:13
    C:\WINDOWS\system32\ffJmpWeb.dll |01/12/2005 11:30:37
    C:\WINDOWS\system32\fsuz.dll |22/06/2006 12:25:34
    C:\WINDOWS\system32\hccutils.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\hpreg.dll |02/01/2003 14:44:14
    C:\WINDOWS\system32\HSFCI005.dll |02/01/2003 14:22:16
    C:\WINDOWS\system32\hsfcisp2.dll |19/02/2006 19:02:41
    C:\WINDOWS\system32\hticons.dll |01/01/2003 19:51:23
    C:\WINDOWS\system32\HUFFYUV.DLL |08/12/2001 22:20:20
    C:\WINDOWS\system32\hxltcolor.dll |30/01/2004 15:48:20
    C:\WINDOWS\system32\hypertrm.dll |17/11/2004 19:57:39
    C:\WINDOWS\system32\iAlmcoin.dll |01/01/2003 18:56:25
    C:\WINDOWS\system32\iAlmCoIn_v13.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmdd5.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmdev5.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmdnt5.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmgdev.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmgicd.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmrem.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\ialmrnt5.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\iccvid.dll |01/01/2003 19:51:24
    C:\WINDOWS\system32\ieencode.dll |19/02/2006 19:02:40
    C:\WINDOWS\system32\IfHelper.dll |01/12/2005 11:31:31
    C:\WINDOWS\system32\igfxdev.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxdgps.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxdo.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxeud.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxexps.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxhk.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxpph.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxres.dll |02/01/2003 02:28:36
    C:\WINDOWS\system32\igfxress.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\igfxsrvc.dll |02/01/2003 14:13:36
    C:\WINDOWS\system32\Ijl11.dll |06/02/2006 13:30:44
    C:\WINDOWS\system32\imagX7.dll |26/07/2004 18:16:10
    C:\WINDOWS\system32\imagXpr7.dll |26/07/2004 18:16:10
    C:\WINDOWS\system32\imagXR7.dll |26/07/2004 18:16:10
    C:\WINDOWS\system32\imagXRA7.dll |26/07/2004 18:16:10
    C:\WINDOWS\system32\imsinstall_loc040c.dll |10/04/2007 09:30:53
    C:\WINDOWS\system32\imslsp_install_loc040c.dll |10/04/2007 09:30:53
    C:\WINDOWS\system32\instFunc.dll |02/01/2003 14:15:22
    C:\WINDOWS\system32\ir32_32.dll |01/01/2003 19:51:28
    C:\WINDOWS\system32\ir41_qc.dll |14/11/2002 12:59:36
    C:\WINDOWS\system32\ir41_qcx.dll |14/11/2002 12:59:36
    C:\WINDOWS\system32\ir50_32.dll |14/11/2002 12:59:38
    C:\WINDOWS\system32\ir50_qc.dll |14/11/2002 12:59:38
    C:\WINDOWS\system32\ir50_qcx.dll |14/11/2002 12:59:40
    C:\WINDOWS\system32\isrdbg32.dll |01/01/2003 19:51:28
    C:\WINDOWS\system32\jdns_sd.dll |28/11/2005 12:10:28
    C:\WINDOWS\system32\jgaw400.dll |01/01/2003 19:51:29
    C:\WINDOWS\system32\jgdw400.dll |01/01/2003 19:51:29
    C:\WINDOWS\system32\jgmd400.dll |01/01/2003 19:51:29
    C:\WINDOWS\system32\jgpl400.dll |01/01/2003 19:51:29
    C:\WINDOWS\system32\jgsd400.dll |01/01/2003 19:51:29
    C:\WINDOWS\system32\jgsh400.dll |01/01/2003 19:51:29
    C:\WINDOWS\system32\kcm2sp.dll |14/04/2000 15:23:52
    C:\WINDOWS\system32\KodakCoI.dll |07/10/2003 18:29:16
    C:\WINDOWS\system32\KodakOneTouch.dll |08/09/2000 18:53:50
    C:\WINDOWS\system32\kpcp32.dll |14/04/2000 15:23:56
    C:\WINDOWS\system32\KPDPM.dll |17/06/2006 21:50:17
    C:\WINDOWS\system32\KPDPMUI.dll |17/06/2006 21:50:17
    C:\WINDOWS\system32\kpsys32.dll |14/04/2000 15:23:56
    C:\WINDOWS\system32\LEX2KUSB.DLL |28/12/2004 16:59:17
    C:\WINDOWS\system32\LEXBCE.DLL |28/12/2004 16:59:17
    C:\WINDOWS\system32\LEXLMPM.DLL |28/12/2004 16:59:10
    C:\WINDOWS\system32\LEXP2P32.DLL |28/12/2004 16:59:18
    C:\WINDOWS\system32\lfbmp11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfbmp13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\LFCMP11n.DLL |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfcmp13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\lfeps11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lffax11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfgif11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfgif13n.dll |29/01/2006 14:04:11
    C:\WINDOWS\system32\lfpcd11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfpcx11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\Lfpng11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfpsd11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lftga11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lftif11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\lfwmf11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\libeay32_0.9.6l.dll |10/04/2007 09:30:19
    C:\WINDOWS\system32\LTDIS11n.dll |07/06/2002 04:02:00
    C:\WINDOWS\system32\ltdis13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\ltefx13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\ltfil11n.DLL |07/06/2002 04:02:00
    C:\WINDOWS\system32\ltfil13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\ltimg11n.dll |07/06/2002 04:02:02
    C:\WINDOWS\system32\ltimg13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\ltkrn11n.dll |07/06/2002 04:02:02
    C:\WINDOWS\system32\ltkrn13n.dll |29/01/2006 14:04:10
    C:\WINDOWS\system32\Ltwvc11n.dll |07/06/2002 04:02:02
    C:\WINDOWS\system32\mdmxsdk.dll |02/01/2003 14:22:16
    C:\WINDOWS\system32\mdwmdmsp.dll |24/08/2001 09:47:06
    C:\WINDOWS\system32\msdmo.dll |12/12/2002 15:14:32
    C:\WINDOWS\system32\msencode.dll |01/01/2003 19:24:26
    C:\WINDOWS\system32\MSRTEDIT.DLL |22/01/1999 20:46:58
    C:\WINDOWS\system32\mtxparhd.dll |19/02/2006 19:02:36
    C:\WINDOWS\system32\nbicdnt.dll |02/01/2003 14:11:07
    C:\WINDOWS\system32\NeroCo.dll |16/02/2005 16:18:04
    C:\WINDOWS\system32\nv4_disp.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvapi.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvcod.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvcodins.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvcpl.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvcpluir.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvdisps.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvdispsr.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvexpbar.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvgames.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvgamesr.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvhwvid.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nview.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvmccs.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvmccsrs.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvmccss.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvmccssr.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvmctray.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvmobls.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvmoblsr.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvnt4cpl.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvoglnt.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrsar.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrscs.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrsda.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrsde.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrsel.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrseng.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrses.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrsesm.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrsfi.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrsfr.dll |02/01/2003 14:16:45
    C:\WINDOWS\system32\nvrshe.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrshu.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrsit.dll |02/01/2003 14:16:46
    C:\WINDOWS\system32\nvrsja.dll |02/01/2003 14:16:46
    C:\WINDOWS\system32\nvrsko.dll |02/01/2003 14:16:46
    C:\WINDOWS\system32\nvrsnl.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvrsno.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvrspl.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrspt.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvrsptb.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvrsru.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrssk.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrssl.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrssv.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvrstr.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvrszhc.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvrszht.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvshell.dll |02/01/2003 14:16:47
    C:\WINDOWS\system32\nvvitvs.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvvitvsr.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvwddi.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwdmcpl.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwimg.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrsar.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrscs.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrsda.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsde.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsel.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrseng.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrses.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsesm.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrsfi.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsfr.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrshe.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrshu.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrsit.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsja.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsko.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsnl.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsno.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrspl.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrspt.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsptb.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrsru.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrssk.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrssl.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrssv.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrstr.dll |15/07/2004 11:42:00
    C:\WINDOWS\system32\nvwrszhc.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwrszht.dll |02/01/2003 14:16:48
    C:\WINDOWS\system32\nvwss.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\nvwssr.dll |22/10/2006 13:22:00
    C:\WINDOWS\system32\OemInfo.dll |02/01/2003 13:54:56
    C:\WINDOWS\system32\omano.dll |02/01/2003 14:44:29
    C:\WINDOWS\system32\OptimFROG.dll |21/04/2004 00:00:00
    C:\WINDOWS\system32\paqsp.dll |24/08/2001 09:47:16
    C:\WINDOWS\system32\PCDLIB32.DLL |09/12/1998 10:53:58
    C:\WINDOWS\system32\PrintAPI.dll |18/07/2001 17:25:46
    C:\WINDOWS\system32\psisdecd.dll |19/11/2005 18:27:12
    C:\WINDOWS\system32\PTPITCP.dll |17/06/2006 21:50:17
    C:\WINDOWS\system32\Px.dll |06/02/2006 11:37:22
    C:\WINDOWS\system32\pxdrv.dll |26/01/2006 02:01:00
    C:\WINDOWS\system32\PxMas.dll |06/02/2006 11:36:18
    C:\WINDOWS\system32\PxSFS.DLL |06/02/2006 11:40:44
    C:\WINDOWS\system32\PxWave.dll |06/02/2006 11:35:46
    C:\WINDOWS\system32\pxwma.dll |06/02/2006 11:38:22
    C:\WINDOWS\system32\python22.dll |02/01/2003 13:54:58
    C:\WINDOWS\system32\PythonCOM22.dll |02/01/2003 13:55:12
    C:\WINDOWS\system32\PyWinTypes22.dll |02/01/2003 13:55:12
    C:\WINDOWS\system32\qd3d.dll |14/04/2004 09:06:42
    C:\WINDOWS\system32\qedwipes.dll |12/12/2002 15:14:32
    C:\WINDOWS\system32\rave.dll |14/04/2004 09:06:44
    C:\WINDOWS\system32\RDBios32.dll |09/04/2003 07:40:14
    C:\WINDOWS\system32\ROBOEX32.DLL |07/11/2000 18:36:14
    C:\WINDOWS\system32\rsnpstd.dll |01/04/2007 11:07:56
    C:\WINDOWS\system32\rv10.dll |30/01/2004 15:48:20
    C:\WINDOWS\system32\rv20.dll |30/01/2004 15:48:20
    C:\WINDOWS\system32\rv30.dll |30/01/2004 15:48:20
    C:\WINDOWS\system32\rv40.dll |14/02/2004 15:49:52
    C:\WINDOWS\system32\S3Disply.dll |02/01/2003 14:11:07
    C:\WINDOWS\system32\S3Gamma2.dll |02/01/2003 14:11:07
    C:\WINDOWS\system32\s3gnb.dll |02/01/2003 14:11:07
    C:\WINDOWS\system32\S3Info2.dll |02/01/2003 14:11:07
    C:\WINDOWS\system32\S3Ovrlay.dll |02/01/2003 14:11:07
    C:\WINDOWS\system32\sbe.dll |01/01/2003 19:25:08
    C:\WINDOWS\system32\ShellvRTF.dll |02/01/2003 14:38:53
    C:\WINDOWS\system32\SierraNW.dll |21/10/2004 19:22:08
    C:\WINDOWS\system32\sipr.dll |30/01/2004 15:48:19
    C:\WINDOWS\system32\SiSApCom.dll |02/01/2003 14:15:22
    C:\WINDOWS\system32\sisgl.dll |02/01/2003 14:15:22
    C:\WINDOWS\system32\sisgrv.dll |02/01/2003 14:15:22
    C:\WINDOWS\system32\SiSInst.dll |02/01/2003 14:15:22
    C:\WINDOWS\system32\SiSParse.dll |02/01/2003 14:15:22
    C:\WINDOWS\system32\slbcsp.dll |01/01/2003 19:25:13
    C:\WINDOWS\system32\slbiop.dll |01/01/2003 19:25:13
    C:\WINDOWS\system32\slbrccsp.dll |01/01/2003 19:25:13
    C:\WINDOWS\system32\slcoinst.dll |19/02/2006 19:02:33
    C:\WINDOWS\system32\slextspk.dll |19/02/2006 19:02:33
    C:\WINDOWS\system32\slgen.dll |19/02/2006 19:02:33
    C:\WINDOWS\system32\SNWValid.dll |21/10/2004 19:22:07
    C:\WINDOWS\system32\spnike.dll |24/08/2001 09:47:18
    C:\WINDOWS\system32\sprio600.dll |24/08/2001 09:47:18
    C:\WINDOWS\system32\sprio800.dll |24/08/2001 09:47:18
    C:\WINDOWS\system32\sprof32.dll |14/04/2000 15:24:56
    C:\WINDOWS\system32\spxcoins.dll |01/01/2003 19:25:19
    C:\WINDOWS\system32\syscontr.dll |02/01/2003 14:44:14
    C:\WINDOWS\system32\tsd32.dll |01/01/2003 19:26:40
    C:\WINDOWS\system32\TwnLib4.dll |09/07/2004 10:43:56
    C:\WINDOWS\system32\umloader.dll |13/02/2003 16:01:00
    C:\WINDOWS\system32\usrcntra.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrcoina.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrdpa.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrdtea.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrfaxa.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrlbva.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrrtosa.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrsdpia.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrsvpia.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrv42a.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrv80a.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrvoica.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\usrvpa.dll |24/08/2001 09:47:20
    C:\WINDOWS\system32\vidx16.dll |22/03/1998 14:50:02
    C:\WINDOWS\system32\vp31vfw.dll |05/05/2003 22:02:50
    C:\WINDOWS\system32\vsdata.dll |04/11/2006 19:57:16
    C:\WINDOWS\system32\VSFilter.dll |08/03/2004 01:07:06
    C:\WINDOWS\system32\vsinit.dll |10/04/2007 09:28:48
    C:\WINDOWS\system32\vsmonapi.dll |10/04/2007 09:29:58
    C:\WINDOWS\system32\vspubapi.dll |10/04/2007 09:29:59
    C:\WINDOWS\system32\vsregexp.dll |10/04/2007 09:30:18
    C:\WINDOWS\system32\vsutil.dll |10/04/2007 09:28:47
    C:\WINDOWS\system32\vsutil_loc040c.dll |10/04/2007 09:30:52
    C:\WINDOWS\system32\vswmi.dll |10/04/2007 09:30:02
    C:\WINDOWS\system32\vsxml.dll |10/04/2007 09:30:00
    C:\WINDOWS\system32\VXBLOCK.dll |22/12/2005 02:00:00
    C:\WINDOWS\system32\W32N50.dll |11/06/2006 10:21:23
    C:\WINDOWS\system32\WBDBT32I.DLL |02/01/2003 13:54:56
    C:\WINDOWS\system32\WBDBV32I.DLL |02/01/2003 13:54:56
    C:\WINDOWS\system32\win87em.dll |01/01/2003 19:26:50
    C:\WINDOWS\system32\WnAspiNT.DLL |04/02/2003 09:24:08
    C:\WINDOWS\system32\WooDial2000.dll |14/05/2005 18:44:42
    C:\WINDOWS\system32\xvid.dll |24/06/2003 16:14:07
    C:\WINDOWS\system32\zlcomm.dll |10/04/2007 09:30:11
    C:\WINDOWS\system32\zlcommdb.dll |10/04/2007 09:30:11
    C:\WINDOWS\system32\zlib.dll |22/06/2006 12:25:38
    C:\WINDOWS\system32\zpeng24.dll |10/04/2007 09:30:01

    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\WINDOWS\system

    08/05/1998 00:04 52 736 hpsysdrv.exe
    1 fichier(s) 52 736 octets
    0 Rép(s) 10 713 632 768 octets libres
    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\WINDOWS\system32

    19/08/2004 17:09 6 144 csrss.exe
    1 fichier(s) 6 144 octets
    0 Rép(s) 10 713 628 672 octets libres

    Contenu de Downloaded Program Files
    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\WINDOWS\Downloaded Program Files

    11/04/2007 09:09 <REP> .
    11/04/2007 09:09 <REP> ..
    24/08/2006 09:28 141 424 asinst.dll
    22/08/2006 10:06 537 asinst.inf
    02/01/2003 13:43 65 desktop.ini
    15/10/1997 09:52 697 DirectAnimation Java Classes.osd
    11/12/2006 17:44 367 LegitCheckControl.inf
    20/01/2000 16:25 1 162 Microsoft XML Parser for Java.osd
    14/10/2005 12:02 372 736 MsnPUpld.dll
    14/10/2005 13:49 587 MSNPupld.inf
    19/06/2002 15:11 117 088 PURen-us.dll
    31/05/2002 10:20 117 328 purfr-fr.dll
    09/11/2006 15:36 5 019 swflash.inf
    02/11/2005 18:01 1 777 xscan.inf
    02/11/2005 18:07 435 712 xscan53.ocx
    13 fichier(s) 1 194 499 octets

    Total des fichiers listés :
    13 fichier(s) 1 194 499 octets
    2 Rép(s) 10 713 628 672 octets libres

    Recherche de rootkit! (Merci S!Ri)

    Recherche d'infections connues



    catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
    http://www.gmer.net

    scanning hidden processes ...

    scanning hidden services ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    Liste des programmes installes

    802.11 USB Wireless LAN Adapter
    AC3Filter (remove only)
    Adobe Acrobat 5.0
    Adobe Flash Player 9 ActiveX
    Adobe Reader 8 - Français
    Adobe® Photoshop® Album Edition Découverte 3.0
    Archiveur WinRAR
    ATI Display Driver
    avast! Antivirus
    Barre d'outils Outlook de Windows Live (Windows Live Toolbar)
    Bloqueur de fenêtres pop-up (Windows Live Toolbar)
    Bonjour
    Bonjour
    Budget Familial
    CCleaner (remove only)
    CCScore
    CloneCD
    Connexion facile à Internet
    Connexion facile à Internet
    Correctif pour Windows XP (KB914440)
    Correctif Windows XP - KB873339
    Correctif Windows XP - KB885250
    Correctif Windows XP - KB885835
    Correctif Windows XP - KB885836
    Correctif Windows XP - KB885884
    Correctif Windows XP - KB886185
    Correctif Windows XP - KB887472
    Correctif Windows XP - KB887742
    Correctif Windows XP - KB888113
    Correctif Windows XP - KB888302
    Correctif Windows XP - KB890859
    Correctif Windows XP - KB891781
    DAEMON Tools
    DivX Codec 3.1alpha release
    DivX Pro Codec
    Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)
    Easy CD-DA Extractor 8.2.1
    EasyCleaner
    Empire Earth II
    ESSBrwr
    ESSCDBK
    ESScore
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTOOLS
    essvatgt
    essvcpt
    EVEREST Home Edition v1.10
    Extension de Windows Live Toolbar (Windows Live Toolbar)
    FaxTools
    Hamachi 1.0.1.5
    HLPPDOCK
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB926239)
    HpSdpAppCoreApp
    Intel(R) Extreme Graphics Driver
    InterVideo WinDVD Player
    Java 2 Runtime Environment, SE v1.4.0_03
    KBD
    kgcbase
    KSU
    Lecteur Windows Media 11
    LiveReg (Symantec Corporation)
    Logiciel Kodak EasyShare
    Ludiclub.com
    Media Library Management Wizard
    Menus intelligents (Windows Live Toolbar)
    Messenger Plus! Live
    Microsoft .NET Framework (French)
    Microsoft .NET Framework (French) v1.0.3705
    Microsoft .NET Framework 1.0 Hotfix (KB886906)
    Microsoft .NET Framework 2.0
    Microsoft .NET Framework 2.0
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Word 2002
    Microsoft Works 7.0
    Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
    Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)
    Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)
    Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
    Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)
    Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)
    Mise à jour de sécurité pour Windows XP (KB890046)
    Mise à jour de sécurité pour Windows XP (KB893756)
    Mise à jour de sécurité pour Windows XP (KB896358)
    Mise à jour de sécurité pour Windows XP (KB896422)
    Mise à jour de sécurité pour Windows XP (KB896423)
    Mise à jour de sécurité pour Windows XP (KB896424)
    Mise à jour de sécurité pour Windows XP (KB896428)
    Mise à jour de sécurité pour Windows XP (KB899587)
    Mise à jour de sécurité pour Windows XP (KB899591)
    Mise à jour de sécurité pour Windows XP (KB900725)
    Mise à jour de sécurité pour Windows XP (KB901017)
    Mise à jour de sécurité pour Windows XP (KB901214)
    Mise à jour de sécurité pour Windows XP (KB902400)
    Mise à jour de sécurité pour Windows XP (KB904706)
    Mise à jour de sécurité pour Windows XP (KB905414)
    Mise à jour de sécurité pour Windows XP (KB905749)
    Mise à jour de sécurité pour Windows XP (KB905915)
    Mise à jour de sécurité pour Windows XP (KB908519)
    Mise à jour de sécurité pour Windows XP (KB908531)
    Mise à jour de sécurité pour Windows XP (KB911562)
    Mise à jour de sécurité pour Windows XP (KB911567)
    Mise à jour de sécurité pour Windows XP (KB911927)
    Mise à jour de sécurité pour Windows XP (KB912812)
    Mise à jour de sécurité pour Windows XP (KB912919)
    Mise à jour de sécurité pour Windows XP (KB913446)
    Mise à jour de sécurité pour Windows XP (KB913580)
    Mise à jour de sécurité pour Windows XP (KB914388)
    Mise à jour de sécurité pour Windows XP (KB914389)
    Mise à jour de sécurité pour Windows XP (KB916281)
    Mise à jour de sécurité pour Windows XP (KB917159)
    Mise à jour de sécurité pour Windows XP (KB917344)
    Mise à jour de sécurité pour Windows XP (KB917422)
    Mise à jour de sécurité pour Windows XP (KB917953)
    Mise à jour de sécurité pour Windows XP (KB918118)
    Mise à jour de sécurité pour Windows XP (KB918439)
    Mise à jour de sécurité pour Windows XP (KB918899)
    Mise à jour de sécurité pour Windows XP (KB919007)
    Mise à jour de sécurité pour Windows XP (KB920213)
    Mise à jour de sécurité pour Windows XP (KB920214)
    Mise à jour de sécurité pour Windows XP (KB920670)
    Mise à jour de sécurité pour Windows XP (KB920683)
    Mise à jour de sécurité pour Windows XP (KB920685)
    Mise à jour de sécurité pour Windows XP (KB921398)
    Mise à jour de sécurité pour Windows XP (KB921883)
    Mise à jour de sécurité pour Windows XP (KB922616)
    Mise à jour de sécurité pour Windows XP (KB922760)
    Mise à jour de sécurité pour Windows XP (KB922819)
    Mise à jour de sécurité pour Windows XP (KB923191)
    Mise à jour de sécurité pour Windows XP (KB923414)
    Mise à jour de sécurité pour Windows XP (KB923689)
    Mise à jour de sécurité pour Windows XP (KB923694)
    Mise à jour de sécurité pour Windows XP (KB923980)
    Mise à jour de sécurité pour Windows XP (KB924191)
    Mise à jour de sécurité pour Windows XP (KB924270)
    Mise à jour de sécurité pour Windows XP (KB924496)
    Mise à jour de sécurité pour Windows XP (KB924667)
    Mise à jour de sécurité pour Windows XP (KB925454)
    Mise à jour de sécurité pour Windows XP (KB925486)
    Mise à jour de sécurité pour Windows XP (KB925902)
    Mise à jour de sécurité pour Windows XP (KB926255)
    Mise à jour de sécurité pour Windows XP (KB926436)
    Mise à jour de sécurité pour Windows XP (KB927779)
    Mise à jour de sécurité pour Windows XP (KB927802)
    Mise à jour de sécurité pour Windows XP (KB928090)
    Mise à jour de sécurité pour Windows XP (KB928255)
    Mise à jour de sécurité pour Windows XP (KB928843)
    Mise à jour de sécurité pour Windows XP (KB929969)
    Mise à jour de sécurité pour Windows XP (KB930178)
    Mise à jour de sécurité pour Windows XP (KB931261)
    Mise à jour de sécurité pour Windows XP (KB931784)
    Mise à jour de sécurité pour Windows XP (KB932168)
    Mise à jour pour Windows XP (KB898461)
    Mise à jour pour Windows XP (KB900485)
    Mise à jour pour Windows XP (KB904942)
    Mise à jour pour Windows XP (KB910437)
    Mise à jour pour Windows XP (KB911280)
    Mise à jour pour Windows XP (KB916595)
    Mise à jour pour Windows XP (KB920872)
    Mise à jour pour Windows XP (KB922582)
    Mise à jour pour Windows XP (KB929338)
    Mise à jour pour Windows XP (KB931836)
    Movie Maker Background Music Files
    Movie Maker Sound Effects
    Movie Maker Title Images
    Mozilla Firefox (2.0.0.2)
    Mozilla Firefox (2.0.0.3)
    MSXML 4.0 SP2 (KB927978)
    Navigateur Wanadoo
    Navigation par onglets (Windows Live Toolbar)
    Nero 7 Premium
    Notifier
    NVIDIA Drivers
    OfotoXMI
    OneCare Advisor (Windows Live Toolbar)
    OTtBP
    OTtBPSDK
    Outil de connexion Wanadoo
    Personal License Update Wizard for Windows Media Player
    Plus! MP3 Audio Converter LE
    PowerDVD
    PS2
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QuickTime
    S3Display
    S3Gamma2
    S3Info2
    S3Overlay
    Satsuki Decoder Pack
    SecondLife (remove only)
    Security Update for Microsoft .NET Framework 2.0 (KB922770)
    Security Update pour Microsoft .NET Framework 2.0 (KB917283)
    SFR
    SHASTA
    Shockwave
    Simple Installer - Multilanguage Version
    SKIN0001
    SKINXSDK
    Sonic Update Manager
    Spybot - Search & Destroy 1.4
    staticcr
    Unlocker 1.8.5
    VideoCAM Eye
    VPRINTOL
    Wanadoo Messager
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage v1.3.0254.0
    Windows Installer 3.1 (KB893803)
    Windows Live Favorites pour Windows Live Toolbar
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Toolbar
    Windows Live Toolbar
    Windows Media Bonus Pack for Windows XP
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Format SDK Hotfix - KB891122
    Windows Media Player 11
    Windows Media Player Playlist Import to Excel Wizard
    Windows Media Player Skin Importer
    Windows Media Player Tray Control
    Windows XP Service Pack 2
    WIRELESS
    XviD Video Codec 24062003-1 (Koepi's developer build)
    ZoneAlarm



    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\Program Files

    20/04/2007 20:41 <REP> .
    20/04/2007 20:41 <REP> ..
    20/04/2007 20:44 <REP> ABBYY FineReader 5.0 Sprint
    28/12/2004 17:05 <REP> ABBYY FineReader 6.0
    21/10/2004 19:07 <REP> AC3Filter
    10/04/2007 18:17 <REP> Adobe
    09/04/2006 18:25 <REP> Alwil Software
    19/12/2006 23:01 <REP> Bonjour
    13/04/2007 10:26 <REP> CCleaner
    16/10/2006 14:21 76 800 CUISINON.EXE
    16/11/2005 13:08 <REP> CyberLink
    04/12/2005 19:55 <REP> directx
    16/10/2006 14:22 <REP> DivX
    16/11/2005 13:49 <REP> D-Tools
    19/11/2005 17:32 <REP> Easy CD-DA Extractor 8
    25/11/2005 22:52 <REP> Easy Internet signup
    06/11/2005 16:48 <REP> FaxTools
    21/10/2004 19:08 <REP> ffdshow
    03/04/2007 21:52 <REP> Fichiers communs
    12/11/2006 23:10 5 711 904 Firefox Setup 2.0.exe
    17/04/2007 17:23 <REP> Google
    17/03/2007 10:10 <REP> Hamachi
    17/02/2007 15:03 <REP> Internet Explorer
    11/06/2006 10:25 <REP> Inventel
    01/12/2005 11:31 <REP> Java
    17/06/2006 22:15 <REP> Kodak
    29/01/2006 12:24 <REP> Lavalys
    20/04/2007 20:45 <REP> Lexmark X1100 Series
    22/06/2006 12:25 <REP> Ludiclub
    08/04/2007 08:55 <REP> Messenger Plus! Live
    02/01/2003 13:45 <REP> microsoft frontpage
    01/01/2003 19:20 <REP> Microsoft Office
    01/01/2003 19:21 <REP> Microsoft Visual Studio
    01/01/2003 19:24 <REP> Microsoft Works
    19/02/2006 19:02 <REP> Movie Maker
    16/04/2007 17:12 <REP> Mozilla Firefox
    02/01/2003 13:41 <REP> MSN Gaming Zone
    08/04/2007 08:55 <REP> MSN Messenger
    19/11/2005 18:29 <REP> Nero
    19/02/2006 18:58 <REP> NetMeeting
    15/12/2006 15:01 <REP> Outlook Express
    23/02/2006 14:35 <REP> QuickTime
    21/10/2004 19:08 <REP> Satsuki Decodeur Pack
    11/04/2007 22:35 <REP> SecondLife
    11/06/2006 10:21 <REP> Securitoo
    17/03/2007 17:35 <REP> Sierra
    19/11/2005 17:30 <REP> SlySoft
    24/10/2004 20:47 <REP> Snapshot Viewer
    31/03/2007 21:09 <REP> Spybot - Search & Destroy
    09/04/2006 18:24 <REP> Symantec
    01/04/2007 12:03 <REP> TLC-Edusoft
    23/10/2006 18:31 <REP> ToniArts
    13/11/2005 18:43 <REP> Uninstall Information
    13/04/2007 09:50 <REP> Unlocker
    01/04/2007 11:08 <REP> VideoCAM Eye
    20/04/2007 10:00 <REP> Wanadoo
    01/12/2005 11:30 <REP> Wanadoo Messager
    21/10/2004 19:49 <REP> WinAce
    09/03/2007 11:05 <REP> Windows Live Favorites
    20/04/2007 20:47 <REP> Windows Live Toolbar
    18/12/2006 15:10 <REP> Windows Media Bonus Pack for Windows XP
    18/12/2006 14:56 <REP> Windows Media Connect 2
    18/12/2006 14:56 <REP> Windows Media Player
    19/02/2006 18:58 <REP> Windows NT
    19/11/2005 17:10 <REP> WinRAR
    02/01/2003 13:45 <REP> xerox
    21/10/2004 19:07 <REP> XviD
    17/04/2007 17:37 <REP> Yahoo!
    10/04/2007 09:29 <REP> Zone Labs
    2 fichier(s) 5 788 704 octets
    67 Rép(s) 10 712 141 824 octets libres
    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\Program Files\fichiers communs

    03/04/2007 21:52 <REP> .
    03/04/2007 21:52 <REP> ..
    10/04/2007 17:55 <REP> Adobe
    19/11/2005 18:29 <REP> Ahead
    01/01/2003 19:21 <REP> Designer
    11/06/2006 10:26 278 528 FDEUnInstaller.exe
    19/11/2005 18:53 <REP> InstallShield
    17/06/2006 21:49 <REP> Kodak
    19/03/2007 00:33 <REP> Microsoft Shared
    02/01/2003 13:42 <REP> MSSoap
    02/01/2003 13:38 <REP> ODBC
    12/11/2006 23:30 <REP> Real
    26/10/2005 19:44 <REP> Services
    04/04/2007 17:35 <REP> Softwin
    02/01/2003 14:36 <REP> Sonic
    02/01/2003 13:38 <REP> SpeechEngines
    09/04/2006 18:24 <REP> Symantec Shared
    15/12/2006 15:01 <REP> System
    01/04/2007 11:07 <REP> VCAMEye
    1 fichier(s) 278 528 octets
    18 Rép(s) 10 712 141 824 octets libres
    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders

    19/03/2007 00:33 <REP> .
    19/03/2007 00:33 <REP> ..
    01/01/2003 19:21 <REP> 1033
    19/03/2007 00:33 <REP> 1036
    29/01/2004 16:08 1 277 952 MSONSEXT.DLL
    13/02/2001 16:23 58 784 MSOSV.DLL
    04/06/1999 05:09 122 937 MSOWS409.DLL
    08/03/2001 00:00 127 033 MSOWS40c.DLL
    06/08/2000 17:04 401 462 MSVCP60.DLL
    29/01/2004 16:08 69 632 PKMAXCTL.DLL
    29/01/2004 16:08 868 352 PKMCDO.DLL
    29/01/2004 16:08 53 248 PKMCORE.DLL
    29/01/2004 16:08 102 400 PKMFORMS.DLL
    29/01/2004 16:38 634 880 PKMRES.DLL
    29/01/2004 16:08 28 672 PKMSSTLB.DLL
    22/01/2001 11:25 40 960 PKMTEMPL.DLL
    29/01/2004 16:08 24 576 PKMTRACE.DLL
    29/01/2004 16:08 86 016 PKMWS.DLL
    29/01/2004 16:08 237 568 PROMDEMO.DLL
    18/03/1999 06:37 593 977 RAGENT.DLL
    29/01/2004 16:08 184 320 SECMGR.DLL
    29/01/2004 16:08 315 392 VAIDDMGR.DLL
    29/01/2004 16:08 32 768 VAIMEM.DLL
    19 fichier(s) 5 260 929 octets
    4 Rép(s) 10 712 137 728 octets libres
    Le volume dans le lecteur C s'appelle windows
    Le numéro de série du volume est 6C68-1980

    Répertoire de C:\

    11/11/2001 00:00 68 096 diff.exe
    27/08/2006 14:10 103 424 grep.exe
    2 fichier(s) 171 520 octets
    0 Rép(s) 10 712 137 728 octets libres
    c:\Documents and Settings\Administrateur\Local Settings\Temp\ac3filter_0_69b.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\DivXPro505GAINBundle.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\ffdshow-20030523.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\rtdrvmon.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\war3_Install.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\XviD-24062003-1.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\daemon\install.exe
    c:\Documents and Settings\Administrateur\Local Settings\Temp\daemon\setup.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_1e0010_e3e8b\Setup.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_3d001c_46195\Setup.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\bonjour\BonjourSetup.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\CCS\ccsstop.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\ESS\bindbins\bindbins.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\Ksu\KSUStop.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\QUICK\QuickTimeInstaller.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\wtf\finish.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\wtf\start.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\ac3filter_0_69b.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\DivXPro505GAINBundle.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\ffdshow-20030523.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\rtdrvmon.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\war3_Install.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\XviD-24062003-1.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\daemon\install.exe
    c:\Documents and Settings\Default User\Local Settings\Temp\daemon\setup.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\catchme.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\diff.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\dumphive.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\FilesInfoCmd.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\Fport.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\grep.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\LFiles.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\LISTDLLS.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\pslist.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\streams.exe
    c:\Documents and Settings\Propriétaire\Bureau\DiagHelp\swreg.exe
    c:\Documents and Settings\Propriétaire\Bureau\recettes cuisine\CUISINON.EXE
    c:\Documents and Settings\Propriétaire\Bureau\windows\IE6.0sp1-KB905915-Windows-2000-XP-x86-FRA.exe
    c:\Documents and Settings\Propriétaire\Bureau\windows\Windows-KB890830-V1.12-FRA.exe
    c:\Documents and Settings\Propriétaire\Local Settings\Temp\rtdrvmon.exe
    c:\Documents and Settings\Propriétaire\Local Settings\Temp\~nsu.tmp\Au_.exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\ccsetup138.exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\Hamachi 1.0.1.5 [Par Ratiatum.com].exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\MsgPlusLive-411.exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\Second Life 1-14-0-1 Setup.exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\unlocker1.8.5.exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\uTorrent-1.6.1-install.exe
    c:\Documents and Settings\Propriétaire\Mes documents\Mes fichiers reçus\zlsSetup_70_337_000_fr.exe
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_1e0010_e3e8b\EasyShrx.Dll
    c:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_3d001c_46195\EasyShrx.Dll
    c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
    c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
    c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
    c:\Documents and Settings\Propriétaire\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll

    par contre pour le reste j'ai pas trop compris : il fallait que je tape ce que tu m'as demandé? dans le doute je l'ai fait et ça a repondu : chemin d'acces specifié introuvable
    bye
    Anthony10 le 22 avril 2007 à 18h22
    Bonjour,

  • Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.

  • Double-clique sur OTMoveIt.exe pour le lancer.
  • Copie/colle les fichiers/dossiers suivants dans le cadre de gauche nommé Paste List of Files/Folders to be moved.

  • C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel


  • Clique sur MoveIt! pour lancer la suppression.
  • Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.

  • Dans ta future réponse, envoie le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles.

  • A suivre,
    -------
    Mon forum (avec Bruce Lee):
    http://cybersecurite.xooit.com/index.php
    manosaure le 28 avril 2007 à 14h31
    salut anthony
    voici le résultat :
    Folder move failed. C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel scheduled to be moved on reboot.

    Created on 04/28/2007 14:11:11
    bye
    naheulbeuk le 28 avril 2007 à 14h57
    bonjour, Anthony10 étant indisponible, je vais prendre la suite ;)

    tu as essayé de vider le contenu de ton dossier "confidentiel" ?
    -------
    Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
    Et son forum : http://www.site-naheulbeuk.com/forum/
    manosaure le 28 avril 2007 à 16h25
    salut naheulbeuk :hello:
    j'ai tout essayé: le vider le supprimer etc rien a faire ca me dit que le dossier est vide et qu'il est protégé donc impossible de faire quoi que ce soit (les scan le trouve rempli par contre) je t'invite a lire ce que j'ai expliqué a anthony 10 car c'est assez folklo: bon courage ;)
    bye
    naheulbeuk le 28 avril 2007 à 16h36
  • Télécharge Brute Force Uninstaller sur ton Bureau.

  • Crée un nouveau dossier BFU à la racine de C (c:\BFU)
  • Dézippe-le entièrement sur dans le dossier crée.

  • Copie la totalité de la citation dans ton Bloc-Notes.

  • FolderDelete C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel

    SystemEmptyTempFolder
    SystemEmptyRecycleBin
    SystemEmptyInternetCache


  • Enregistre-le sous le nom de aftermath.bfu, dans le dossier C:\BFU

  • Redémarre en mode sans échec.

  • Ouvre le dossier BFU
  • Double-clique sur BFU.exe pour lancer Brute Force Uninstaller.
  • Coche la case pour obtenir un rapport
  • A côté de la case scriptline to execute, clique sur l'icône < inclued picture > et choisis aftermath.bfu
  • Clique sur Execute afin de le lancer.
  • Une fois fini, clique sur Exit pour fermer le programme.

  • Redémarre normalement.
  • Post moi le rapport du Brute Force Uninstaller ;)

  • bonne aprèsm :p
    -------
    Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
    Et son forum : http://www.site-naheulbeuk.com/forum/
    manosaure le 28 avril 2007 à 16h55
    une question idiote mais: a la racine de C c'est a dire ?? je vais dans lecteur C puis dans programme file et la je cree ce que tu m'as dit ?
    merci de m'aider
    bye
    naheulbeuk le 28 avril 2007 à 17h45
    "à la racine du C:" ca veut dire que tu vas dans C et tu crée directement le dossier que je t'ai dit dans le lecteur C ;)
    -------
    Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
    Et son forum : http://www.site-naheulbeuk.com/forum/
    manosaure le 29 avril 2007 à 13h00
    bonjour naheulbeuk
    voici ce que tu m'as demandé:
    BFU v1.00.9
    Windows XP SP2 (WinNT 5.01.2600 SP2)
    Script started at 12:49:16, on 29/04/2007

    Failed: FolderDelete C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel (operation failed)
    Failed: FileDelete C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DF58A3.tmp (operation failed)
    Script completed.

    merci et bon dimanche
    bye :)
    naheulbeuk le 29 avril 2007 à 13h24
    re, c'est vraiment bizarre, ton dossier semble insupprimable !!! :??:

    cela te pose un réel problème si on le supprime pas (je vois vraiment pas comment faire désolé) ? :/
    -------
    Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
    Et son forum : http://www.site-naheulbeuk.com/forum/
    manosaure le 29 avril 2007 à 19h06
    bonsoir
    tant pis !!! :( ce qui me gêne c'est qu'il est plein de films x et autres merveilles du genre !lors que je poste des rapports de problemes ca fait mauvais genre :/ ;)
    merci d'avoir essayé :super:
    bye
    naheulbeuk le 29 avril 2007 à 19h31
    tu peux pas non plus vider son contenu ?
    -------
    Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
    Et son forum : http://www.site-naheulbeuk.com/forum/
    manosaure le 29 avril 2007 à 21h48
    bonsoir
    le probleme c'est que je ne peux pas car ça me dit qu'il est protégé( vérouillé) et qu'en plus il est vide alors que lors des scans il apparaît ça :
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Blonds On Fire.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Dangerous Tides.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\L'affaire Katsumi.avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\melanie.sex.model.(melanie.coste).avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Sex Commandos - Stacy Valentine.asf L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\Thumbs.db L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\films x\XXX - Lingerie (Laura Angel, Nikki Anderson).avi L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\brooke_richards_002.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\CELEB Catherine Bell Playboy Nude.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\fond0405_cal_1024.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_037.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_044.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_045.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_047.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\pamela_anderson_055.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\sopWallpaper01.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tabatha_cash_001.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\Thumbs.db L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tiffany_taylor_002.jpg L'objet est verrouillé ignoré
    C:\Documents and Settings\CHRISTOPHE\Mes documents\confidentiel\sexy wall papers\tiffany_taylor_008.jpg L'objet est verrouillé ignoré


    Tcomprends ma surprise et ma colère en voyant ça dans mon pc et qu'en plus je peux pas m'en débarasser :fou: !!!
    enfin si même sur le forum vous ne pouvez rien pour moi je vais me resigner a garder ça :sweat:
    merci et bye :)
    naheulbeuk le 29 avril 2007 à 22h02
    désolé pour toi :/

    bonne soirée ;)
    -------
    Visitez mon site sur la sécurité informatique : http://www.site-naheulbeuk.com
    Et son forum : http://www.site-naheulbeuk.com/forum/


    PRODUITS

    TÉLÉCHARGER - LOGICIELS

    JEUX VIDÉOS

    LOISIRS

    01NET PRO

    AVIS ET COMMENTAIRES

    A PROPOS DE 01NET

    publicité
    > Nouveauté :CIEL
    Auto-entrepreneur Facile
    La gestion de vos outils de facturation et de devis.

    Service 01net
    Newsletters 01net
    abonnez vous gratuitement !
      
    01Informatique
    01 INFORMATIQUE
    L'hebdo de référence des décideurs informatiques.
    Micro Hebdo
    MICRO HEBDO
    L'hebdo qui vous simplifie la micro
    et Internet.
    L'Ordinateur Individuel
    L'ORDINATEUR INDIVIDUEL
    Le mensuel informatique qui vous informe et vous conseille.
    Tous droits réservés © 1999 - 2009 Internext - 01net.