Et voilà le petit dernier :
¤¤¤¤¤¤¤¤¤¤ List’em by g3n-h@ckm@n 2.0.0.1 ¤¤¤¤¤¤¤¤¤¤
User : Sara (Administrateurs)
Update on 09/05/2010 by g3n-h@ckm@n ::::: 09.15
Start at: 12:50:06 | 13/05/2010
Genuine Intel® CPU T2300 @ 1.66GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 6.0.2900.5512
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1335 [VPS 100513-0] 4.8.1335 [ (!) Disabled | Updated ]
FW : Norton Internet Worm Protection[ (!) Disabled ]2006
C:\ -> Disque fixe local | 37,26 Go (5,14 Go free) [VAIO] | NTFS
D:\ -> Disque fixe local | 30,28 Go (4,38 Go free) [VAIO] | NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque CD-ROM
G:\ -> Disque amovible
I:\ -> Disque CD-ROM
J:\ -> Disque CD-ROM
K:\ -> Disque CD-ROM
L:\ -> Disque fixe local | 931,28 Go (374,03 Go free) [My Book] | FAT32
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\GigaTribe\gigatribe.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\List_Kill’em\List_Kill’em.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill’em\pv.exe
======================
Keys “Run”
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
WebCamRT.exe REG_SZ
updateMgr REG_SZ “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_8 -reboot 1
Skype REG_SZ “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
DAEMON Tools Lite REG_SZ “C:\Program Files\DAEMON Tools Lite\daemon.exe” -autorun
EA Core REG_SZ “C:\Program Files\Electronic Arts\EADM\Core.exe” -silent
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
ehTray REG_SZ C:\WINDOWS\ehome\ehtray.exe
VAIOCameraUtility REG_SZ “C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe”
SonyPowerCfg REG_SZ C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
VAIO Update 2 REG_SZ “C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe” /Stationary
PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
Acrobat Assistant 7.0 REG_SZ “C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe”
REG_SZ
LVCOMS REG_SZ C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
Omnipage REG_SZ C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
MimBoot REG_SZ C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
WD Button Manager REG_SZ WDBtnMgr.exe
LogitechGalleryRepair REG_SZ C:\Program Files\Logitech\ImageStudio\ISStart.exe
LogitechImageStudioTray REG_SZ C:\Program Files\Logitech\ImageStudio\LogiTray.exe
AdobeCS4ServiceManager REG_SZ “C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe” -launchedbylogin
AppleSyncNotifier REG_SZ C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
SunJavaUpdateSched REG_SZ “C:\Program Files\Java\jre6\bin\jusched.exe”
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
InstallVisualStyle REG_EXPAND_SZ C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
InstallTheme REG_EXPAND_SZ C:\WINDOWS\Resources\Themes\Royale.theme
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
NoDriveAutoRun REG_DWORD 255 (0xff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoCDBurning REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 255 (0xff)
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultUserName REG_SZ Sara
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL “sysdm.cpl”
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ Sara
AltDefaultDomainName REG_SZ YANKUMO
DefaultDomainName REG_SZ YANKUMO
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019
C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe REG_SZ C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe::Disabled:Adobe Photoshop Elements Media Server
C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe::Enabled:LimeWire
C:\Documents and Settings\Sara\LimeWire\LimeWire.exe REG_SZ C:\Documents and Settings\Sara\LimeWire\LimeWire.exe::Enabled:LimeWire
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe::Enabled:Windows Messenger
C:\Program Files\Ze leet Scraillpteu\mirc.exe REG_SZ C:\Program Files\Ze leet Scraillpteu\mirc.exe::Enabled:mIRC
C:\Program Files\uTorrent\utorrent.exe REG_SZ C:\Program Files\uTorrent\utorrent.exe::Enabled:µTorrent
C:\Program Files\ScanSoft\OmniPageSE\EregFre\NAVBrowser.exe REG_SZ C:\Program Files\ScanSoft\OmniPageSE\EregFre\NAVBrowser.exe::Enabled:NAVBrowser
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe REG_SZ C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe::Enabled:BlueSoleil
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000
C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe REG_SZ C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe::Enabled:Adobe CSI CS4
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe::Enabled:Windows Live Call
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe::Enabled:iTunes
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger
C:\Documents and Settings\Sara\Mes documents\Téléchargements\IM47892.JPG-www.myspace.com.exe REG_SZ C:\WINDOWS\infocard.exe::Enabled:Firewall Administrating
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe::Enabled:Windows Live FolderShare
C:\Program Files\GigaTribe\gigatribe.exe REG_SZ C:\Program Files\GigaTribe\gigatribe.exe::Enabled:GigaTribe
C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe::Enabled:Skype
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe::Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{5D6F45B3-9043-443D-A792-115447494D24}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{C3F79A2B-B9B4-4A66-B012-3EE46475B072}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units{D27CDB6E-AE6D-11CF-96B8-444553540000}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\KB910393]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{070D42DE-EB2C-95A1-F04C-C2F0AFF4BC84}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{0C24CCD8-B5DE-82B9-BBF5-CB551524A57F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{1BC46932-21B2-4130-86E0-B4EB4F7A7A7B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{233C1507-6A77-46A4-9443-F871F945D258}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{283807B5-2C60-11D0-A31D-00AA00B92C03}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{2A202491-F00D-11cf-87CC-0020AFEECF20}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{407408d4-94ed-4d86-ab69-a7f649d112ee}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{411EDCF7-755D-414E-A74B-3DCD6583F589}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{4278c270-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{4C886B6F-F34E-360C-AC6E-048EF1C98811}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{4f216970-c90c-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{5A8D6EE0-3E18-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{9A394342-4A68-4EBA-85A6-55B559F4E700}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{BDE0FA43-6952-4BA8-8C58-09AF690F88E1}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{CC2A9BA0-3BDD-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{E8EA5BD6-D931-4001-ABF6-81BAA500360A}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{EA29D410-CE41-4953-A862-2DE706A1DAD7}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{FDC11A6F-17D1-48f9-9EA3-9051954BAA24}]
==============
BHO :
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
===
DNS
================
Internet Explorer :
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://fr.msn.com/
Local Page REG_EXPAND_SZ %SystemRoot%\system32\blank.htm
Default_Search_URL REG_SZ http://www.google.com/ie
Default_Page_URL REG_SZ http://www.club-vaio.com/fr/
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Search Page REG_SZ http://www.google.com
========
Services
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x3 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
========
Safemode
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!
=========
Atapi.sys
C:\WINDOWS$NtServicePackUninstall$\atapi.sys :
MD5 :: [cdfe4411a69c224bd1d11b2da92dac51]
SHA256 :: [0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d]
C:\WINDOWS\ServicePackFiles\i386\atapi.sys :
MD5 :: [9f3a2f5aa6875c72bf062c712cfa2674]
SHA256 :: [b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9]
C:\WINDOWS\system32\drivers\atapi.sys :
MD5 :: [9f3a2f5aa6875c72bf062c712cfa2674]
SHA256 :: [b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9]
C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys :
MD5 :: [cdfe4411a69c224bd1d11b2da92dac51]
SHA256 :: [0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d]
C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys :
MD5 :: [cdfe4411a69c224bd1d11b2da92dac51]
SHA256 :: [0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d]
Référence :
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
D?fragmenteur de disque Windows
Copyright © 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d’analyse
37,26 Go total, 5,15 Go libre (13%), 36% fragment? (fragmentation du fichier 64%)
Vous devriez d?fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
Present !! : C:\Documents and Settings\All Users\Application Data\espionServerData
Present !! : C:\Program Files\DAEMON Tools Toolbar
Present !! : C:\Program Files\WindowsUpdate
Present !! : C:\WINDOWS\003042_.tmp
Present !! : C:\WINDOWS\DUMP396f.tmp
Present !! : C:\WINDOWS\DUMP4390.tmp
Present !! : C:\WINDOWS_delis32.ini
Present !! : C:\WINDOWS\kb913800.exe
Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : C:\WINDOWS\System32\pmsbfn32.dll
Present !! : C:\WINDOWS\Temp\JET1047.tmp
Present !! : C:\WINDOWS\Temp\JET1056.tmp
Present !! : C:\WINDOWS\Temp\JET13B2.tmp
Present !! : C:\WINDOWS\Temp\JET1529.tmp
Present !! : C:\WINDOWS\Temp\JET1874.tmp
Present !! : C:\WINDOWS\Temp\JET19CC.tmp
Present !! : C:\WINDOWS\Temp\JET1A3A.tmp
Present !! : C:\WINDOWS\Temp\JET1B43.tmp
Present !! : C:\WINDOWS\Temp\JET1C4D.tmp
Present !! : C:\WINDOWS\Temp\JET20F0.tmp
Present !! : C:\WINDOWS\Temp\JET2267.tmp
Present !! : C:\WINDOWS\Temp\JET22D5.tmp
Present !! : C:\WINDOWS\Temp\JET2507.tmp
Present !! : C:\WINDOWS\Temp\JET2536.tmp
Present !! : C:\WINDOWS\Temp\JET25AA.tmp
Present !! : C:\WINDOWS\Temp\JET26D7.tmp
Present !! : C:\WINDOWS\Temp\JET272A.tmp
Present !! : C:\WINDOWS\Temp\JET27B7.tmp
Present !! : C:\WINDOWS\Temp\JET27E6.tmp
Present !! : C:\WINDOWS\Temp\JET2814.tmp
Present !! : C:\WINDOWS\Temp\JET2815.tmp
Present !! : C:\WINDOWS\Temp\JET2863.tmp
Present !! : C:\WINDOWS\Temp\JET28E0.tmp
Present !! : C:\WINDOWS\Temp\JET2AC4.tmp
Present !! : C:\WINDOWS\Temp\JET2B3C.tmp
Present !! : C:\WINDOWS\Temp\JET2DE1.tmp
Present !! : C:\WINDOWS\Temp\JET2E4E.tmp
Present !! : C:\WINDOWS\Temp\JET3071.tmp
Present !! : C:\WINDOWS\Temp\JET3166.tmp
Present !! : C:\WINDOWS\Temp\JET31C9.tmp
Present !! : C:\WINDOWS\Temp\JET341B.tmp
Present !! : C:\WINDOWS\Temp\JET35EF.tmp
Present !! : C:\WINDOWS\Temp\JET360F.tmp
Present !! : C:\WINDOWS\Temp\JET3757.tmp
Present !! : C:\WINDOWS\Temp\JET382D.tmp
Present !! : C:\WINDOWS\Temp\JET3870.tmp
Present !! : C:\WINDOWS\Temp\JET391C.tmp
Present !! : C:\WINDOWS\Temp\JET3A35.tmp
Present !! : C:\WINDOWS\Temp\JET3AF1.tmp
Present !! : C:\WINDOWS\Temp\JET413A.tmp
Present !! : C:\WINDOWS\Temp\JET439B.tmp
Present !! : C:\WINDOWS\Temp\JET43AB.tmp
Present !! : C:\WINDOWS\Temp\JET4428.tmp
Present !! : C:\WINDOWS\Temp\JET44D4.tmp
Present !! : C:\WINDOWS\Temp\JET4503.tmp
Present !! : C:\WINDOWS\Temp\JET46C8.tmp
Present !! : C:\WINDOWS\Temp\JET49C5.tmp
Present !! : C:\WINDOWS\Temp\JET4A2E.tmp
Present !! : C:\WINDOWS\Temp\JET4A62.tmp
Present !! : C:\WINDOWS\Temp\JET4ADF.tmp
Present !! : C:\WINDOWS\Temp\JET4BB9.tmp
Present !! : C:\WINDOWS\Temp\JET4EB7.tmp
Present !! : C:\WINDOWS\Temp\JET4ED2.tmp
Present !! : C:\WINDOWS\Temp\JET504D.tmp
Present !! : C:\WINDOWS\Temp\JET586B.tmp
Present !! : C:\WINDOWS\Temp\JET5956.tmp
Present !! : C:\WINDOWS\Temp\JET5ACD.tmp
Present !! : C:\WINDOWS\Temp\JET5ADC.tmp
Present !! : C:\WINDOWS\Temp\JET5B79.tmp
Present !! : C:\WINDOWS\Temp\JET5C53.tmp
Present !! : C:\WINDOWS\Temp\JET5CC1.tmp
Present !! : C:\WINDOWS\Temp\JET5E67.tmp
Present !! : C:\WINDOWS\Temp\JET5F80.tmp
Present !! : C:\WINDOWS\Temp\JET6155.tmp
Present !! : C:\WINDOWS\Temp\JET61F1.tmp
Present !! : C:\WINDOWS\Temp\JET6378.tmp
Present !! : C:\WINDOWS\Temp\JET6869.tmp
Present !! : C:\WINDOWS\Temp\JET68D7.tmp
Present !! : C:\WINDOWS\Temp\JET6963.tmp
Present !! : C:\WINDOWS\Temp\JET6964.tmp
Present !! : C:\WINDOWS\Temp\JET6C03.tmp
Present !! : C:\WINDOWS\Temp\JET6C13.tmp
Present !! : C:\WINDOWS\Temp\JET7569.tmp
Present !! : C:\WINDOWS\Temp\JET7679.tmp
Present !! : C:\WINDOWS\Temp\JET7896.tmp
Present !! : C:\WINDOWS\Temp\JET78C.tmp
Present !! : C:\WINDOWS\Temp\JET7B26.tmp
Present !! : C:\WINDOWS\Temp\JET7D1A.tmp
Present !! : C:\WINDOWS\Temp\JET7FD9.tmp
Present !! : C:\WINDOWS\Temp\JET809.tmp
Present !! : C:\WINDOWS\Temp\JET8354.tmp
Present !! : C:\WINDOWS\Temp\JET853.tmp
Present !! : C:\WINDOWS\Temp\JET86DE.tmp
Present !! : C:\WINDOWS\Temp\JET876B.tmp
Present !! : C:\WINDOWS\Temp\JET8B82.tmp
Present !! : C:\WINDOWS\Temp\JET8B91.tmp
Present !! : C:\WINDOWS\Temp\JET8C1E.tmp
Present !! : C:\WINDOWS\Temp\JET8D47.tmp
Present !! : C:\WINDOWS\Temp\JET916D.tmp
Present !! : C:\WINDOWS\Temp\JET943C.tmp
Present !! : C:\WINDOWS\Temp\JET98DF.tmp
Present !! : C:\WINDOWS\Temp\JET98EF.tmp
Present !! : C:\WINDOWS\Temp\JET9B60.tmp
Present !! : C:\WINDOWS\Temp\JET9D35.tmp
Present !! : C:\WINDOWS\Temp\JET9DE1.tmp
Present !! : C:\WINDOWS\Temp\JET9EAC.tmp
Present !! : C:\WINDOWS\Temp\JET9EAD.tmp
Present !! : C:\WINDOWS\Temp\JETA61E.tmp
Present !! : C:\WINDOWS\Temp\JETAA16.tmp
Present !! : C:\WINDOWS\Temp\JETADDE.tmp
Present !! : C:\WINDOWS\Temp\JETAEB9.tmp
Present !! : C:\WINDOWS\Temp\JETAF94.tmp
Present !! : C:\WINDOWS\Temp\JETB292.tmp
Present !! : C:\WINDOWS\Temp\JETB706.tmp
Present !! : C:\WINDOWS\Temp\JETBC27.tmp
Present !! : C:\WINDOWS\Temp\JETBD01.tmp
Present !! : C:\WINDOWS\Temp\JETC186.tmp
Present !! : C:\WINDOWS\Temp\JETC34B.tmp
Present !! : C:\WINDOWS\Temp\JETC445.tmp
Present !! : C:\WINDOWS\Temp\JETCC92.tmp
Present !! : C:\WINDOWS\Temp\JETD159.tmp
Present !! : C:\WINDOWS\Temp\JETD64B.tmp
Present !! : C:\WINDOWS\Temp\JETD9A6.tmp
Present !! : C:\WINDOWS\Temp\JETDACF.tmp
Present !! : C:\WINDOWS\Temp\JETDBC9.tmp
Present !! : C:\WINDOWS\Temp\JETDD4B.tmp
Present !! : C:\WINDOWS\Temp\JETE213.tmp
Present !! : C:\WINDOWS\Temp\JETE37A.tmp
Present !! : C:\WINDOWS\Temp\JETE484.tmp
Present !! : C:\WINDOWS\Temp\JETE6C1.tmp
Present !! : C:\WINDOWS\Temp\JETE7CF.tmp
Present !! : C:\WINDOWS\Temp\JETEDF.tmp
Present !! : C:\WINDOWS\Temp\JETEF9F.tmp
Present !! : C:\WINDOWS\Temp\JETF0F7.tmp
Present !! : C:\WINDOWS\Temp\JETF30A.tmp
Present !! : C:\WINDOWS\Temp\JETF685.tmp
Present !! : C:\WINDOWS\Temp\JETF690.tmp
Present !! : C:\WINDOWS\Temp\JETF6F2.tmp
Present !! : C:\WINDOWS\Temp\JETF898.tmp
Present !! : C:\WINDOWS\Temp\JETF8F6.tmp
Present !! : C:\WINDOWS\Temp\JETFF4A.tmp
Present !! : C:\WINDOWS\Temp\SEP2.tmp
Present !! : C:\WINDOWS\Temp\SEPB9.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\3e.doc
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\4FE.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC1.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC2.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC3.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC4.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC5.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC6.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC7.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC8.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\AC9.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\ACA.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\ACB.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\ACC.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\ACD.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\ACE.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\ACF.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\afl.log
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\alm.log
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\amt.log
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\dw.log
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\gps.pdf
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\mac.txt
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\pp.doc
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\VP6.reg
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WT1.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WT2.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WT9.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WTA.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WTB.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WTC.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WTE.tmp
Present !! : C:\Documents and Settings\Sara\Local Settings\Temp\WTF.tmp
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\dotnetfx.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD10.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD11.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD12.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD13.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD14.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD15.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD16.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD17.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD18.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD19.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD1A.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD1B.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD1C.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD1D.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD1E.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD1F.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD20.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD21.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD22.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD23.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD24.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD25.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD26.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD27.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD28.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD29.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD2A.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD2B.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD2C.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD2D.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD2E.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD4.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD5.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD6.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD7.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD8.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EAD9.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EADA.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EADB.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EADC.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EADD.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EADE.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\EADF.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\eauninstall.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\First15.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\jre-6u13-windows-i586-p-iftw.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\jre-6u20-windows-i586-iftw-rv.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\setup_wm.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Sims2_uninst.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\VP6Install.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp_myclubvaio.exe
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_15c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_194.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_1ac.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_1e4.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_200.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_2c0.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_324.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_49c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_568.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_574.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_644.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_648.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_680.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_77c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_7ec.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_7f4.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_880.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_8f4.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_96c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_9cc.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_9fc.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_aac.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_abc.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_b14.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_bcc.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_be8.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_bf0.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_c1c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_c4.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_cd0.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_d58.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_d7c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_d98.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_de4.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_e50.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_e68.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_e90.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_ed4.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_f50.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_f58.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_f5c.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_f60.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_f84.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_f98.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\Perflib_Perfdata_fb8.dat
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\AutoRunGUI.dll
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\UninstallEADM.dll
Present !! : C:\Documents and Settings\Sara\LOCAL Settings\Temp\VP6VFW.dll
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar : {32099AAC-C132-4136-9E9A-4E364A424E17}
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe”
Present !! : HKCR\CLSID{0055c089-8582-441b-a0bf-17b458c2a3a8}
Present !! : HKLM\Software\Classes\Interface{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISRD
Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISRD
Present !! : HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_NDISRD
Present !! : HKLM\SYSTEM\ControlSet004\Enum\Root\LEGACY_NDISRD
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2010-05-13 13:03:30
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, www.gmer.net…
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spap.sys >>UNKNOWN [0x87586938]<<
kernel: MBR read successfully
user & kernel MBR OK
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
FirstRunDisabled REG_DWORD 1 (0x1)
UpdatesDisableNotify REG_DWORD 0 (0x0)
AntiVirusOverride REG_DWORD 0 (0x0)
FirewallOverride REG_DWORD 0 (0x0)
AntiVirusDisableNotify REG_DWORD 0 (0x0)
FirewallDisableNotify REG_DWORD 0 (0x0)
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 13:03:31,89
[quote="VIRUS_C_C"]
Salut
Merçi >> Senosen pour cette remarque ,d habitude je vérifie ,mais !! :super:
Rectifié !!!
brown_voodoook continue
[/quote]
Par rapport aux h manquants, je pense qu’il en manque dans chacun de tes liens rouges, je les avais rajoutés à chaque fois. Je pensais que c’était une précaution de ta part (ou quelque chose comme ça).
Je te préviens au cas où tu voudrais aider d’autres petits miséreux comme moi qui ne savent pas nettoyer leurs ordis!
Merci encore pour toutes tes précieuses indications!!!
Edité le 13/05/2010 à 13:33