Rouk76 Posté(e) le 2 février 2009 Partager Posté(e) le 2 février 2009 Désolé, je m'y suis surement mal pris alors >< Et bien j'ai installé Hijack sur mon PC et voici mon rapport. Serait-il possible de me dire les cases a cocher et a supprimer. Merci beaucoup. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 2 février 2009 Auteur Partager Posté(e) le 2 février 2009 Un souci particulier ? Lien vers le commentaire Partager sur d’autres sites More sharing options...
Rouk76 Posté(e) le 2 février 2009 Partager Posté(e) le 2 février 2009 Oui, le PC lag pas mal et sur le net j'ai des fenêtres de pub intempestive. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 2 février 2009 Auteur Partager Posté(e) le 2 février 2009 Coche et Fix checked toutes les lignes 04 avec Hijackthis . Redémarre le pc . Lance Clean v2.0 , procédure 1 ( vise ma signature ) Redémarre le pc . Lance MBAM et supprime tout ce qui est trouvé : http://www.malwarebytes.org/mbam.php Lance ComboFix , et poste le rapport créé : http://download.bleepingcomputer.com/sUBs/ComboFix.exe Lien vers le commentaire Partager sur d’autres sites More sharing options...
matt30-bis Posté(e) le 7 février 2009 Partager Posté(e) le 7 février 2009 Bonjour, Antivir me detecte le virus Tr/Agent.job. Jai beau lui dire de le déplacer en quarantaine ou de le supprimer, il revient à chaque fois, j'ai également fait un scan avec MAM. Il m'a trouvé la même chose, j'ai demandé à ce qui le supprime mais c'est toujours là. noisette m'a dit de poster mon rapport ici, ce que je fais. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:28:21, on 07/02/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe C:\Users\Mathias\AppData\Roaming\MICROS~1\logman.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\RocketDock\RocketDock.exe C:\Windows\ehome\ehtray.exe C:\Users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Users\Mathias\Desktop\HijackThis.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ig?hl=fr&source=iglk R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F3 - REG:win.ini: load=C:\Users\Mathias\AppData\Roaming\MICROS~1\logman.exe O1 - Hosts: ::1 localhost O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Google Update Service (gupdate1c987c7b322b263) (gupdate1c987c7b322b263) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- End of file - 5828 bytes Merci pour l'aide que tu pourras m'apporter. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 7 février 2009 Auteur Partager Posté(e) le 7 février 2009 Redémarre en mode sans échec et lance une analyse complète avec MBAM , supprime e qu'il troue . Indique dans ta réponse le chemin du trojan sur le disque . Lance à nouveau ComboFix et poste le rapport. Redémarre ensuite en mode normal. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 7 février 2009 Auteur Partager Posté(e) le 7 février 2009 Télécharge et lance Dr Web Cureit > ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe Après l'analyse rapide , sélectionne l'analyse complète . Poste le rapport créé. Fait ensuite ceci > http://www.malekal.com/Trojan_Agent_iob.php Lien vers le commentaire Partager sur d’autres sites More sharing options...
matt30-bis Posté(e) le 7 février 2009 Partager Posté(e) le 7 février 2009 MBAM n'a rien trouvé. Rapport ComboFix : ComboFix 09-02-06.02 - Mathias 2009-02-07 17:13:02.2 - NTFSx86 MINIMAL Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3326.2588 [GMT 1:00] Lancé depuis: c:\users\Mathias\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-07 au 2009-02-07 )))))))))))))))))))))))))))))))))))) . Pas de nouveau fichier créé dans ce laps de temps . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-07 09:58 --------- d-----w c:\users\Mathias\AppData\Roaming\uTorrent 2009-02-07 09:02 --------- d-----w c:\users\Mathias\AppData\Roaming\AIMP 2009-02-06 21:41 --------- d-----w c:\programdata\Electronic Arts 2009-02-06 21:23 --------- d-----w c:\programdata\Google Updater 2009-02-06 16:30 --------- d--h--w c:\program files\InstallShield Installation Information 2009-02-06 16:30 --------- d-----w c:\program files\Electronic Arts 2009-02-06 16:29 --------- d-----w c:\program files\Common Files\InstallShield 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\sessmgr.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\rsvp.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mstinit.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mqtgsvc.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\clipsrv.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\cisvc.exe 2009-02-05 19:27 --------- d-----w c:\program files\Google 2009-02-05 17:16 --------- d-----w c:\users\Mathias\AppData\Roaming\Convivea 2009-02-04 17:26 --------- d-----w c:\program files\PDFCreator 2009-02-03 11:49 410,984 ----a-w c:\windows\System32\deploytk.dll 2009-02-03 11:49 --------- d-----w c:\program files\Java 2009-02-01 15:43 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf 2009-02-01 14:16 --------- d-----w c:\program files\Remove Empty Directories 2009-02-01 13:59 319,488 ----a-w c:\windows\HideWin.exe 2009-02-01 13:59 319,456 ----a-w c:\windows\DIFxAPI.dll 2009-01-31 11:22 --------- d-----w c:\program files\JKDefrag v3.36 2009-01-29 19:12 --------- d-----w c:\program files\Opera 2009-01-26 18:17 --------- d-----w c:\program files\directx 2009-01-23 11:47 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Pro 2009-01-21 17:16 --------- d-----w c:\program files\AIMP2 2009-01-15 17:58 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-01-14 07:15 4,235,776 ----a-w c:\windows\system32\drivers\atikmdag.sys 2009-01-14 06:55 --------- d-----w c:\program files\Windows Mail 2009-01-14 05:03 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll 2009-01-14 05:02 159,744 ----a-w c:\windows\System32\atitmmxx.dll 2009-01-14 05:01 43,520 ----a-w c:\windows\System32\ati2edxx.dll 2009-01-14 05:01 348,160 ----a-w c:\windows\System32\atipdlxx.dll 2009-01-14 05:01 286,720 ----a-w c:\windows\System32\Ati2evxx.dll 2009-01-14 05:01 274,432 ----a-w c:\windows\System32\Oemdspif.dll 2009-01-14 04:59 729,088 ----a-w c:\windows\System32\Ati2evxx.exe 2009-01-14 04:50 2,345,472 ----a-w c:\windows\System32\atidxx32.dll 2009-01-14 04:44 3,963,392 ----a-w c:\windows\System32\atiumdag.dll 2009-01-14 04:22 4,765,696 ----a-w c:\windows\System32\atiumdva.dll 2009-01-14 04:08 50,688 ----a-w c:\windows\System32\amdpcom32.dll 2009-01-14 04:07 122,880 ----a-w c:\windows\System32\atiadlxx.dll 2009-01-14 03:59 11,247,616 ----a-w c:\windows\System32\atioglxx.dll 2009-01-14 03:50 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll 2009-01-14 02:54 57,344 ----a-w c:\windows\System32\amdcalrt.dll 2009-01-14 02:53 53,248 ----a-w c:\windows\System32\amdcalcl.dll 2009-01-14 02:51 3,239,936 ----a-w c:\windows\System32\amdcaldd.dll 2009-01-12 19:03 --------- d-----w c:\program files\SystemRequirementsLab 2009-01-10 17:59 --------- d-----w c:\programdata\Media Center Programs 2009-01-09 21:04 --------- d-----w c:\program files\ATI 2009-01-09 12:33 --------- d-----w c:\program files\Lavalys 2009-01-09 12:30 --------- d-----w c:\programdata\ATI 2009-01-09 12:26 --------- d-----w c:\program files\ATI Technologies 2009-01-04 13:04 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf 2009-01-03 12:37 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-01-02 17:13 --------- d-----w c:\program files\CCleaner 2009-01-02 17:09 --------- d-----w c:\program files\K-Lite Codec Pack 2009-01-02 13:12 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf 2009-01-02 13:11 --------- d-----w c:\program files\Microsoft Xbox 360 Accessories 2009-01-01 20:52 130,208 ------r c:\windows\bwUnin-8.1.1.87-8876480SL.exe 2009-01-01 11:51 127,034 ------r c:\windows\bwUnin-8.1.1.50-8876480SL.exe 2009-01-01 11:51 --------- d-----w c:\users\Mathias\AppData\Roaming\Logitech 2009-01-01 11:51 --------- d-----w c:\program files\Common Files\Logishrd 2009-01-01 11:50 --------- d-----w c:\program files\Logitech 2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-01-01 11:48 --------- d-----w c:\users\Mathias\AppData\Roaming\InstallShield 2009-01-01 11:48 --------- d-----w c:\programdata\Logitech 2009-01-01 11:47 --------- d-----w c:\programdata\LogiShrd 2009-01-01 11:45 --------- d-----w c:\program files\Common Files\Logitech 2008-12-31 18:50 1,700,352 ----a-w c:\windows\System32\gdiplus.dll 2008-12-31 18:50 1,060,864 ----a-w c:\windows\System32\mfc71.dll 2008-12-31 18:41 --------- d--h--r c:\users\Mathias\AppData\Roaming\SecuROM 2008-12-31 18:41 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE 2008-12-31 18:37 107,888 ----a-w c:\windows\System32\CmdLineExt.dll 2008-12-31 16:52 --------- d-----w c:\program files\RocketDock 2008-12-31 15:14 --------- d-----w c:\program files\Microsoft.NET 2008-12-31 15:11 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Lite 2008-12-30 22:55 --------- d-----w c:\program files\Quicksys 2008-12-30 22:52 --------- d-----w c:\users\Mathias\AppData\Roaming\SumatraPDF 2008-12-30 22:51 --------- d-----w c:\program files\SumatraPDF 2008-12-30 22:07 --------- d-----w c:\users\Mathias\AppData\Roaming\InfraRecorder 2008-12-30 22:07 --------- d-----w c:\program files\InfraRecorder 2008-12-30 21:53 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools 2008-12-30 21:52 --------- d-----w c:\programdata\DAEMON Tools Lite 2008-12-30 21:52 --------- d-----w c:\program files\DAEMON Tools Lite 2008-12-30 21:49 717,296 ----a-w c:\windows\system32\drivers\sptd.sys 2008-12-30 21:15 --------- d-----w c:\users\Mathias\AppData\Roaming\Malwarebytes 2008-12-30 21:15 --------- d-----w c:\programdata\Malwarebytes 2008-12-30 21:07 --------- d-----w c:\programdata\Avira 2008-12-30 21:07 --------- d-----w c:\program files\Avira 2008-12-30 21:00 --------- d-----w c:\program files\Media Player Classic 2008-12-30 20:59 --------- d-----w c:\users\Mathias\AppData\Roaming\Media Player Classic 2008-12-30 20:58 --------- d-----w c:\program files\IZArc 2008-12-30 20:31 --------- d-----w c:\program files\NETGEAR 2008-12-30 20:27 --------- d-----w c:\users\Mathias\AppData\Roaming\ATI 2008-12-30 20:25 --------- d-----w c:\program files\Common Files\ATI Technologies 2008-12-30 20:20 --------- d-----w c:\program files\Marvell . ((((((((((((((((((((((((((((( SnapShot@2009-02-07_15.38.43,19 ))))))))))))))))))))))))))))))))))))))))) . - 2009-02-07 14:28:23 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT + 2009-02-07 15:58:30 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT - 2009-02-07 14:38:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT + 2009-02-07 15:58:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT - 2009-02-07 14:32:14 101,052 ----a-w c:\windows\System32\perfc009.dat + 2009-02-07 15:51:56 100,640 ----a-w c:\windows\System32\perfc009.dat - 2009-02-07 14:32:15 123,350 ----a-w c:\windows\System32\perfc00C.dat + 2009-02-07 15:51:56 122,972 ----a-w c:\windows\System32\perfc00C.dat - 2009-02-07 14:32:14 586,980 ----a-w c:\windows\System32\perfh009.dat + 2009-02-07 15:51:56 586,568 ----a-w c:\windows\System32\perfh009.dat - 2009-02-07 14:32:15 669,328 ----a-w c:\windows\System32\perfh00C.dat + 2009-02-07 15:51:56 668,580 ----a-w c:\windows\System32\perfh00C.dat . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Google Update"="c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-01-31 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"="grpconv -o" [X] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-01-01 91440] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-02-01 809488] NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-09-14 1695744] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "TCP Query User{FE192C99-F762-4C67-A785-5F3A41D8DF62}d:\\téléchargement\\emule\\emule.exe"= UDP:d:\téléchargement\emule\emule.exe:eMule "UDP Query User{692464F3-7913-4E21-9CAF-3AB30118CAA5}d:\\téléchargement\\emule\\emule.exe"= TCP:d:\téléchargement\emule\emule.exe:eMule "{A0E7E796-1336-4536-A8D7-54B1C9BA7263}"= UDP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{4B9AB4D9-3443-4B49-965A-D4AB1DFF511E}"= TCP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{CCD649DA-2F00-4967-9AD1-46E7D3851D4C}"= UDP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "{2DEFF54C-ED98-4FBE-9319-C05EB6478BA2}"= TCP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "TCP Query User{B2158CE8-CE96-4310-9239-F66D838D77F2}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "UDP Query User{EE3280B1-D7AE-4203-A78A-9A3C3F5E0BA5}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "{EBF77E48-737F-45CE-BED0-231E1F279A32}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{984D7E41-3872-45CD-98F5-9BF642AF7676}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{DC96EF1A-9B8E-4A25-8058-2802DCEF1C3E}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{5D56120D-D172-4CEB-B342-4B7545CAC497}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{F1C33631-2EF5-4F42-825C-AAFE1430902D}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{B1AF75A4-161C-4522-A072-F85DDC9F0217}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "TCP Query User{583738C4-BC3C-4FB4-B68A-CE146F866456}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser "UDP Query User{FFBF7DB4-1604-4F83-9307-11D6E540DCF1}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser "{54E1C3CE-3BDB-4334-838C-05773BF8753F}"= UDP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (TCP-In) "{D684A30E-C1CB-4907-B0D3-26F8A29F4F8B}"= TCP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (UDP-In) "{06DB5605-32B3-4F20-B88E-1147F7D46722}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box "{199CB686-7667-48FC-9026-589C095A4210}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box "{95714B72-F3EE-473D-AB8E-16EB882F299B}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box "{154B4EBB-FDD7-4E54-BC9B-2D37B646DC4F}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box "{E0F3CC28-90B4-41F5-9AC4-D1594BC76BF6}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box "{E127B845-0CB9-497F-9E4B-5D0364DACA86}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box "TCP Query User{ED445966-C75A-4471-8064-7BA0EA651A49}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "UDP Query User{0A2E0582-ACBC-40A3-82F3-7EE3D6AA30D2}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager R0 mv61xx;mv61xx;c:\windows\System32\drivers\mv61xx.sys [2008-07-22 151592] S2 gupdate1c987c7b322b263;Google Update Service (gupdate1c987c7b322b263);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104] S3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [2008-12-31 48128] S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v3.sys [2008-12-30 227328] --- Autres Services/Pilotes en mémoire --- *NewlyCreated* - ECACHE *Deregistered* - sptd . Contenu du dossier 'Tâches planifiées' 2009-02-07 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 20:21] 2009-02-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 20:26] 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-192886970-665670061-1568562545-1000.job - c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-31 11:24] . - - - - ORPHELINS SUPPRIMES - - - - HKLM-RunOnce-<NO NAME> - (no file) . ------- Examen supplémentaire ------- . uStart Page = hxxp://www.google.fr/ig?hl=fr&source=iglk IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-07 17:14:42 Windows 6.0.6001 Service Pack 1 NTFS Recherche de processus cachés ... Recherche d'éléments en démarrage automatique cachés ... Recherche de fichiers cachés ... Scan terminé avec succès Fichiers cachés: 0 ************************************************************************** . --------------------- DLLs chargées dans les processus actifs --------------------- - - - - - - - > 'Explorer.exe'(632) c:\program files\Microsoft Office\OFFICE11\msohev.dll . Heure de fin: 2009-02-07 17:15:12 ComboFix-quarantined-files.txt 2009-02-07 16:15:10 ComboFix2.txt 2009-02-07 14:39:46 Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application. Après-CF: 111,402,901,504 octets libres 222 --- E O F --- 2009-02-02 11:24:42 ComboFix 09-02-06.02 - Mathias 2009-02-07 17:13:02.2 - NTFSx86 MINIMAL Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3326.2588 [GMT 1:00] Lancé depuis: c:\users\Mathias\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-07 au 2009-02-07 )))))))))))))))))))))))))))))))))))) . Pas de nouveau fichier créé dans ce laps de temps . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-07 09:58 --------- d-----w c:\users\Mathias\AppData\Roaming\uTorrent 2009-02-07 09:02 --------- d-----w c:\users\Mathias\AppData\Roaming\AIMP 2009-02-06 21:41 --------- d-----w c:\programdata\Electronic Arts 2009-02-06 21:23 --------- d-----w c:\programdata\Google Updater 2009-02-06 16:30 --------- d--h--w c:\program files\InstallShield Installation Information 2009-02-06 16:30 --------- d-----w c:\program files\Electronic Arts 2009-02-06 16:29 --------- d-----w c:\program files\Common Files\InstallShield 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\sessmgr.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\rsvp.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mstinit.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mqtgsvc.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\clipsrv.exe 2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\cisvc.exe 2009-02-05 19:27 --------- d-----w c:\program files\Google 2009-02-05 17:16 --------- d-----w c:\users\Mathias\AppData\Roaming\Convivea 2009-02-04 17:26 --------- d-----w c:\program files\PDFCreator 2009-02-03 11:49 410,984 ----a-w c:\windows\System32\deploytk.dll 2009-02-03 11:49 --------- d-----w c:\program files\Java 2009-02-01 15:43 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf 2009-02-01 14:16 --------- d-----w c:\program files\Remove Empty Directories 2009-02-01 13:59 319,488 ----a-w c:\windows\HideWin.exe 2009-02-01 13:59 319,456 ----a-w c:\windows\DIFxAPI.dll 2009-01-31 11:22 --------- d-----w c:\program files\JKDefrag v3.36 2009-01-29 19:12 --------- d-----w c:\program files\Opera 2009-01-26 18:17 --------- d-----w c:\program files\directx 2009-01-23 11:47 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Pro 2009-01-21 17:16 --------- d-----w c:\program files\AIMP2 2009-01-15 17:58 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-01-14 07:15 4,235,776 ----a-w c:\windows\system32\drivers\atikmdag.sys 2009-01-14 06:55 --------- d-----w c:\program files\Windows Mail 2009-01-14 05:03 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll 2009-01-14 05:02 159,744 ----a-w c:\windows\System32\atitmmxx.dll 2009-01-14 05:01 43,520 ----a-w c:\windows\System32\ati2edxx.dll 2009-01-14 05:01 348,160 ----a-w c:\windows\System32\atipdlxx.dll 2009-01-14 05:01 286,720 ----a-w c:\windows\System32\Ati2evxx.dll 2009-01-14 05:01 274,432 ----a-w c:\windows\System32\Oemdspif.dll 2009-01-14 04:59 729,088 ----a-w c:\windows\System32\Ati2evxx.exe 2009-01-14 04:50 2,345,472 ----a-w c:\windows\System32\atidxx32.dll 2009-01-14 04:44 3,963,392 ----a-w c:\windows\System32\atiumdag.dll 2009-01-14 04:22 4,765,696 ----a-w c:\windows\System32\atiumdva.dll 2009-01-14 04:08 50,688 ----a-w c:\windows\System32\amdpcom32.dll 2009-01-14 04:07 122,880 ----a-w c:\windows\System32\atiadlxx.dll 2009-01-14 03:59 11,247,616 ----a-w c:\windows\System32\atioglxx.dll 2009-01-14 03:50 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll 2009-01-14 02:54 57,344 ----a-w c:\windows\System32\amdcalrt.dll 2009-01-14 02:53 53,248 ----a-w c:\windows\System32\amdcalcl.dll 2009-01-14 02:51 3,239,936 ----a-w c:\windows\System32\amdcaldd.dll 2009-01-12 19:03 --------- d-----w c:\program files\SystemRequirementsLab 2009-01-10 17:59 --------- d-----w c:\programdata\Media Center Programs 2009-01-09 21:04 --------- d-----w c:\program files\ATI 2009-01-09 12:33 --------- d-----w c:\program files\Lavalys 2009-01-09 12:30 --------- d-----w c:\programdata\ATI 2009-01-09 12:26 --------- d-----w c:\program files\ATI Technologies 2009-01-04 13:04 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf 2009-01-03 12:37 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-01-02 17:13 --------- d-----w c:\program files\CCleaner 2009-01-02 17:09 --------- d-----w c:\program files\K-Lite Codec Pack 2009-01-02 13:12 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf 2009-01-02 13:11 --------- d-----w c:\program files\Microsoft Xbox 360 Accessories 2009-01-01 20:52 130,208 ------r c:\windows\bwUnin-8.1.1.87-8876480SL.exe 2009-01-01 11:51 127,034 ------r c:\windows\bwUnin-8.1.1.50-8876480SL.exe 2009-01-01 11:51 --------- d-----w c:\users\Mathias\AppData\Roaming\Logitech 2009-01-01 11:51 --------- d-----w c:\program files\Common Files\Logishrd 2009-01-01 11:50 --------- d-----w c:\program files\Logitech 2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-01-01 11:48 --------- d-----w c:\users\Mathias\AppData\Roaming\InstallShield 2009-01-01 11:48 --------- d-----w c:\programdata\Logitech 2009-01-01 11:47 --------- d-----w c:\programdata\LogiShrd 2009-01-01 11:45 --------- d-----w c:\program files\Common Files\Logitech 2008-12-31 18:50 1,700,352 ----a-w c:\windows\System32\gdiplus.dll 2008-12-31 18:50 1,060,864 ----a-w c:\windows\System32\mfc71.dll 2008-12-31 18:41 --------- d--h--r c:\users\Mathias\AppData\Roaming\SecuROM 2008-12-31 18:41 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE 2008-12-31 18:37 107,888 ----a-w c:\windows\System32\CmdLineExt.dll 2008-12-31 16:52 --------- d-----w c:\program files\RocketDock 2008-12-31 15:14 --------- d-----w c:\program files\Microsoft.NET 2008-12-31 15:11 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Lite 2008-12-30 22:55 --------- d-----w c:\program files\Quicksys 2008-12-30 22:52 --------- d-----w c:\users\Mathias\AppData\Roaming\SumatraPDF 2008-12-30 22:51 --------- d-----w c:\program files\SumatraPDF 2008-12-30 22:07 --------- d-----w c:\users\Mathias\AppData\Roaming\InfraRecorder 2008-12-30 22:07 --------- d-----w c:\program files\InfraRecorder 2008-12-30 21:53 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools 2008-12-30 21:52 --------- d-----w c:\programdata\DAEMON Tools Lite 2008-12-30 21:52 --------- d-----w c:\program files\DAEMON Tools Lite 2008-12-30 21:49 717,296 ----a-w c:\windows\system32\drivers\sptd.sys 2008-12-30 21:15 --------- d-----w c:\users\Mathias\AppData\Roaming\Malwarebytes 2008-12-30 21:15 --------- d-----w c:\programdata\Malwarebytes 2008-12-30 21:07 --------- d-----w c:\programdata\Avira 2008-12-30 21:07 --------- d-----w c:\program files\Avira 2008-12-30 21:00 --------- d-----w c:\program files\Media Player Classic 2008-12-30 20:59 --------- d-----w c:\users\Mathias\AppData\Roaming\Media Player Classic 2008-12-30 20:58 --------- d-----w c:\program files\IZArc 2008-12-30 20:31 --------- d-----w c:\program files\NETGEAR 2008-12-30 20:27 --------- d-----w c:\users\Mathias\AppData\Roaming\ATI 2008-12-30 20:25 --------- d-----w c:\program files\Common Files\ATI Technologies 2008-12-30 20:20 --------- d-----w c:\program files\Marvell . ((((((((((((((((((((((((((((( SnapShot@2009-02-07_15.38.43,19 ))))))))))))))))))))))))))))))))))))))))) . - 2009-02-07 14:28:23 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT + 2009-02-07 15:58:30 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT - 2009-02-07 14:38:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT + 2009-02-07 15:58:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT - 2009-02-07 14:32:14 101,052 ----a-w c:\windows\System32\perfc009.dat + 2009-02-07 15:51:56 100,640 ----a-w c:\windows\System32\perfc009.dat - 2009-02-07 14:32:15 123,350 ----a-w c:\windows\System32\perfc00C.dat + 2009-02-07 15:51:56 122,972 ----a-w c:\windows\System32\perfc00C.dat - 2009-02-07 14:32:14 586,980 ----a-w c:\windows\System32\perfh009.dat + 2009-02-07 15:51:56 586,568 ----a-w c:\windows\System32\perfh009.dat - 2009-02-07 14:32:15 669,328 ----a-w c:\windows\System32\perfh00C.dat + 2009-02-07 15:51:56 668,580 ----a-w c:\windows\System32\perfh00C.dat . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Google Update"="c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-01-31 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"="grpconv -o" [X] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-01-01 91440] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-02-01 809488] NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-09-14 1695744] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "TCP Query User{FE192C99-F762-4C67-A785-5F3A41D8DF62}d:\\téléchargement\\emule\\emule.exe"= UDP:d:\téléchargement\emule\emule.exe:eMule "UDP Query User{692464F3-7913-4E21-9CAF-3AB30118CAA5}d:\\téléchargement\\emule\\emule.exe"= TCP:d:\téléchargement\emule\emule.exe:eMule "{A0E7E796-1336-4536-A8D7-54B1C9BA7263}"= UDP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{4B9AB4D9-3443-4B49-965A-D4AB1DFF511E}"= TCP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{CCD649DA-2F00-4967-9AD1-46E7D3851D4C}"= UDP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "{2DEFF54C-ED98-4FBE-9319-C05EB6478BA2}"= TCP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "TCP Query User{B2158CE8-CE96-4310-9239-F66D838D77F2}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "UDP Query User{EE3280B1-D7AE-4203-A78A-9A3C3F5E0BA5}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "{EBF77E48-737F-45CE-BED0-231E1F279A32}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{984D7E41-3872-45CD-98F5-9BF642AF7676}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{DC96EF1A-9B8E-4A25-8058-2802DCEF1C3E}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{5D56120D-D172-4CEB-B342-4B7545CAC497}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{F1C33631-2EF5-4F42-825C-AAFE1430902D}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "{B1AF75A4-161C-4522-A072-F85DDC9F0217}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger "TCP Query User{583738C4-BC3C-4FB4-B68A-CE146F866456}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser "UDP Query User{FFBF7DB4-1604-4F83-9307-11D6E540DCF1}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser "{54E1C3CE-3BDB-4334-838C-05773BF8753F}"= UDP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (TCP-In) "{D684A30E-C1CB-4907-B0D3-26F8A29F4F8B}"= TCP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (UDP-In) "{06DB5605-32B3-4F20-B88E-1147F7D46722}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box "{199CB686-7667-48FC-9026-589C095A4210}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box "{95714B72-F3EE-473D-AB8E-16EB882F299B}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box "{154B4EBB-FDD7-4E54-BC9B-2D37B646DC4F}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box "{E0F3CC28-90B4-41F5-9AC4-D1594BC76BF6}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box "{E127B845-0CB9-497F-9E4B-5D0364DACA86}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box "TCP Query User{ED445966-C75A-4471-8064-7BA0EA651A49}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "UDP Query User{0A2E0582-ACBC-40A3-82F3-7EE3D6AA30D2}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager R0 mv61xx;mv61xx;c:\windows\System32\drivers\mv61xx.sys [2008-07-22 151592] S2 gupdate1c987c7b322b263;Google Update Service (gupdate1c987c7b322b263);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104] S3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [2008-12-31 48128] S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v3.sys [2008-12-30 227328] --- Autres Services/Pilotes en mémoire --- *NewlyCreated* - ECACHE *Deregistered* - sptd . Contenu du dossier 'Tâches planifiées' 2009-02-07 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 20:21] 2009-02-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 20:26] 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-192886970-665670061-1568562545-1000.job - c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-31 11:24] . - - - - ORPHELINS SUPPRIMES - - - - HKLM-RunOnce-<NO NAME> - (no file) . ------- Examen supplémentaire ------- . uStart Page = hxxp://www.google.fr/ig?hl=fr&source=iglk IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-07 17:14:42 Windows 6.0.6001 Service Pack 1 NTFS Recherche de processus cachés ... Recherche d'éléments en démarrage automatique cachés ... Recherche de fichiers cachés ... Scan terminé avec succès Fichiers cachés: 0 ************************************************************************** . --------------------- DLLs chargées dans les processus actifs --------------------- - - - - - - - > 'Explorer.exe'(632) c:\program files\Microsoft Office\OFFICE11\msohev.dll . Heure de fin: 2009-02-07 17:15:12 ComboFix-quarantined-files.txt 2009-02-07 16:15:10 ComboFix2.txt 2009-02-07 14:39:46 Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application. Après-CF: 111,402,901,504 octets libres 222 --- E O F --- 2009-02-02 11:24:42 Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 7 février 2009 Auteur Partager Posté(e) le 7 février 2009 Télécharge et lance Dr Web Cureit > ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe Après l'analyse rapide , sélectionne l'analyse complète . Poste le rapport créé. Fait ensuite ceci > http://www.malekal.com/Trojan_Agent_iob.php Lien vers le commentaire Partager sur d’autres sites More sharing options...
bob63 Posté(e) le 9 février 2009 Partager Posté(e) le 9 février 2009 Yop Un ami a moi n'arrive plus a ouvrir windows media player sauf clique droit ouvrir en tant qu'admin. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:03:32, on 09/02/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Lexmark 2500 Series\lxddamon.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\System32\rundll32.exe C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe C:\Users\Kheiz\AppData\Local\Google\Update\GoogleUpdate.exe C:\Users\Kheiz\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe C:\Users\Kheiz\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Windows\system32\wuauclt.exe C:\Users\Kheiz\Program Files\uTorrent\uTorrent.exe C:\Windows\system32\conime.exe C:\Program Files\TVersity\Media Server\web\admin\TVersity.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - C:\Program Files\BS.Player ControlBar\BSToolbar.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe" O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Users\Kheiz\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-21-3718856369-1133722837-3043362797-1011\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Mcx3') O4 - Startup: Outil de notification Live Search.lnk = Kheiz\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir au format PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file) O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file) O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm O13 - Gopher Prefix: O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.2.cab O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Installer) - http://t1.battlefield-heroes.com/patcher/westpatcher.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O22 - SharedTaskScheduler: Stardock Vista ControlPanel Extension - {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll O22 - SharedTaskScheduler: StardockDreamController - {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file) O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing) O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Cadence License Manager - Macrovision Corporation - C:\OrCAD\license_manager\lmgrd.exe O23 - Service: Eset Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (file missing) O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Windows Live Family Safety (fsssvc) - Unknown owner - C:\Program Files\Windows Live\Family Safety\fsssvc.exe (file missing) O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:\Windows\system32\HDDSvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe O23 - Service: lxdd_device - - C:\Windows\system32\lxddcoms.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe -- End of file - 14680 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
meuhkalisse Posté(e) le 11 février 2009 Partager Posté(e) le 11 février 2009 Alors salut a tous, j'ai un problem avec mon ordi depuis environ 3 semaines, j'ai fais des recherches. Voila, j'ai une application nommé system dans task manager et il prend environ 60 Mo d'utilisation de mémoire. Je ne suis pas capable de l'enlever ou de le stopper. J'ai intaller security task manager et j'ai découvert que c'étais le fichier dva.386 qui demarrer le fichier system au demarage. Mais je ne suis toujours pas capable de l'enlever. Alors si vous savez quoi je devrais faire pour m'en debarasser svp me répondre Merci ! Voila mon log HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:26:05, on 2009-02-10 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\UnivLaval\cvpnd.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Apoint2K\Apoint.exe C:\WINDOWS\system32\TPSMain.exe C:\Program Files\ltmoh\Ltmoh.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\RAMASST.exe C:\WINDOWS\system32\TPSBattM.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Yo\Mes documents\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800" O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226270831125 O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichier...ion_3_1_0_4.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\UnivLaval\cvpnd.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 9207 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 11 février 2009 Auteur Partager Posté(e) le 11 février 2009 @ meuhkalisse : Avec Hijackthis , coche et Fixchecked toutes les lignes 04 , sauf AVG8. Redémarre le pc . Le problème est-il toujours présent ? ______________________________________ @ bob63 : Avec Hijackthis , coche et Fixchecked toutes les lignes 04 , sauf Nod32. Désactive Windows Defender > http://infomars.fr/forum/index.php?showtopic=1244 Redémarre le pc . Lance ComboFix et poste le rapport créé > http://download.bleepingcomputer.com/sUBs/ComboFix.exe Lien vers le commentaire Partager sur d’autres sites More sharing options...
meuhkalisse Posté(e) le 11 février 2009 Partager Posté(e) le 11 février 2009 Salut Snooky! J'ai fais ce que tu m'as dis mais le programme system est toujours présent. Mon ordinateur est vraiment plus rapide au démarrage pcq plus rien ne démarre au démaragge. Alors, quoi faire maintenant. L'application system (image créer par dva.386) reste toujours insupprimable. Je fais également te parler de mes autres problèmes avec mon super portable que j'adore!!! 1. Lorsqu'il se met en veille, lorsque je veux le sortir de veille si je jpeux dire, l'écran n'apparait plus et je dois restarter mon ordinateur et si je veux que l'écran revienne au redemarrage, il faut que j'enleve le courant de mon ordi. 2. Certaine fois, apres que mon ordi s'aille mis en veille, mon son ne marche plus et je dois redemarrer. En plus, mon touchpad fais la meme affaire mais jamais en meme temps que le son. Soit l'un marche, ou soit l'autre. Alors dit moi ce que tu en pense... P.s. J'ai souvent envie de le jeter ce petit portable Merci d'avance Lien vers le commentaire Partager sur d’autres sites More sharing options...
meuhkalisse Posté(e) le 11 février 2009 Partager Posté(e) le 11 février 2009 Je t'envoi des informations sur le fichier system : Nom de l'image: System ; Nom de l'utilisateur : SYSTEM ; Habituellement, il y a 0 processeur utilisés ; et il prend 61 000 Ko d'utilisation de mémoire. Selon security task manager, c'est le fichier dva.386 qui est le problème. Ce fichier est-il vraiment important au fonctionnement du système ou bien je peux le supprimer ? Merci encore! Lien vers le commentaire Partager sur d’autres sites More sharing options...
meuhkalisse Posté(e) le 11 février 2009 Partager Posté(e) le 11 février 2009 Un peu de nouveau sur mon sujet, j'ai regardé sur plusieurs ordinateurs utilisant xp tout comme moi et le fichier dva.386 n'était sur aucun ordinateur. Le mien se situe dans C:/WINDOWS/system . L'idée de supprimer le fichier m'est venu et j'ai essayer mais le processus au nom de system est toujours la et il utilise encore 60 Mo de mémoire. Il passes fréquamment de 0 a 2 processeur utilisé. Je me demande maintenant si ce processus est normal ou non vu qu'il n'a vraisemblablement aucun moyen de l'enlever. Merci de me repondre! Gab Lien vers le commentaire Partager sur d’autres sites More sharing options...
2C.LiryC Posté(e) le 11 février 2009 Partager Posté(e) le 11 février 2009 ...Merci de me repondre! Gab Calmos . On est sur un forum, les gens viennent aider quand ils peuvent :8. C'est également pour cela, qu'on demande aussi aux gens de ne pas "remonter" leur sujet, plus d'une fois par jour. Ca ne sert à rien de s'impatienter, d'autant plus si ça fait depuis environ 3 semaines que tu as ce problème... Lien vers le commentaire Partager sur d’autres sites More sharing options...
bob63 Posté(e) le 12 février 2009 Partager Posté(e) le 12 février 2009 [ @ bob63 : Avec Hijackthis , coche et Fixchecked toutes les lignes 04 , sauf Nod32. Désactive Windows Defender > http://infomars.fr/forum/index.php?showtopic=1244 Redémarre le pc . Lance ComboFix et poste le rapport créé > http://download.bleepingcomputer.com/sUBs/ComboFix.exe Voila ComboFix 09-02-11.02 - Kheiz 2009-02-12 1:40:21.1 - NTFSx86 Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1273 [GMT 1:00] Lancé depuis: c:\users\Kheiz\Desktop\ComboFix.exe AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) FW: ESET Personal firewall *disabled* * Un nouveau point de restauration a été créé . ADS - system32: deleted 12 bytes in 1 streams. (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\config.ini . ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-12 au 2009-02-12 )))))))))))))))))))))))))))))))))))) . 2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Videos 2009-02-09 20:54 . 2006-11-02 11:23 <REP> d-------- c:\users\Mcx3\Saved Games 2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Pictures 2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Music 2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Links 2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Downloads 2009-02-09 20:54 . 2009-02-09 20:54 <REP> dr------- c:\users\Mcx3\Documents 2009-02-09 20:54 . 2009-02-09 20:55 <REP> d--h----- c:\users\Mcx3\AppData 2009-02-09 20:54 . 2009-02-09 20:54 <REP> d-------- c:\users\Mcx3 2009-01-30 20:54 . 2008-12-22 23:36 729,088 --a------ C:\JungleFlasher.exe 2009-01-30 20:54 . 2008-09-26 01:49 95,232 --a------ C:\PortIO32.exe 2009-01-30 20:50 . 2009-01-30 21:03 <REP> d-------- c:\windows\PortIO32 2009-01-30 11:07 . 2009-01-30 11:07 <REP> d-------- c:\program files\Prolific 2009-01-30 11:07 . 2007-07-31 18:45 76,800 --a------ c:\windows\System32\drivers\ser2pl.sys 2009-01-27 21:23 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys 2009-01-25 19:17 . 2009-01-25 19:17 <REP> d-------- c:\program files\llionsoft 2009-01-25 19:11 . 2009-01-25 19:14 <REP> d-------- c:\program files\PDF Blender 2009-01-19 19:28 . 2000-07-21 09:11 33,040 --a------ c:\windows\System32\DBNM606e.rra 2009-01-19 19:01 . 1999-03-08 20:28 309,760 --a------ c:\windows\System32\lmgr326b.dll 2009-01-19 16:22 . 2009-01-19 16:59 <REP> d-------- C:\calu 2009-01-18 17:58 . 2009-01-18 17:58 <REP> d-------- c:\users\Kheiz\AppData\Roaming\Red Kawa 2009-01-14 23:28 . 2009-01-22 21:12 <REP> d-------- c:\program files\RomStation 2009-01-14 16:27 . 2009-01-14 16:27 1,492 --a------ C:\ff8input.cfg 2009-01-14 15:32 . 2009-01-14 15:32 <REP> d-------- c:\program files\Creative Labs 2009-01-14 15:32 . 1999-07-06 14:13 40,960 --a------ c:\windows\System32\eax.dll 2009-01-14 15:31 . 2009-01-14 15:31 <REP> d-------- c:\program files\Eidos Interactive . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-11 22:26 --------- d-----w c:\users\Kheiz\AppData\Roaming\GrabIt 2009-02-11 18:15 --------- d-----w c:\program files\GrabIt 2009-02-10 22:50 --------- d-----w c:\program files\Messenger Plus! Live 2009-02-10 18:17 --------- d-----w c:\users\Kheiz\AppData\Roaming\uTorrent 2009-01-30 10:07 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-29 17:05 --------- d-----w c:\program files\Lx_cats 2009-01-27 20:26 --------- d-----w c:\programdata\Microsoft Help 2009-01-27 20:26 --------- d-----w c:\program files\Windows Mail 2009-01-27 11:21 --------- d-----w c:\program files\Cpukiller3 2009-01-20 18:57 --------- d-----w c:\users\Kheiz\AppData\Roaming\Thinstall 2009-01-17 20:50 --------- d-----w c:\programdata\Apple Computer 2009-01-11 16:05 --------- d-----w c:\program files\Sun 2009-01-11 13:07 --------- d-----w c:\programdata\Last.fm 2009-01-11 13:07 --------- d-----w c:\program files\Last.fm 2009-01-11 13:07 --------- d-----w c:\program files\iTunes 2009-01-11 11:32 --------- d-----w c:\users\Kheiz\AppData\Roaming\Download Manager 2009-01-09 16:27 --------- d-----w c:\program files\Mail Bomber 2009-01-06 17:52 --------- d-----w c:\program files\VirtualDub 2009-01-06 17:50 --------- d-----w c:\program files\RADVideo 2009-01-05 20:22 --------- d-----w c:\program files\Red Kawa 2009-01-05 19:30 --------- d-----w c:\program files\Common Files\Business Objects 2009-01-05 19:30 --------- d-----w c:\program files\Business Objects 2009-01-05 19:22 --------- d-----w c:\programdata\Macrovision 2009-01-05 19:16 --------- d-----w c:\program files\Ripp-it_AM 2009-01-05 19:13 --------- d-----w c:\program files\AviSynth 2.5 2008-12-30 20:55 --------- d-----w c:\program files\HighGrow 2008-12-30 17:11 --------- d-----w c:\program files\abgx360 2008-12-30 13:10 --------- d-----w c:\program files\Steam 2008-12-29 21:48 --------- d-----w c:\programdata\OrbNetworks 2008-12-29 13:15 --------- d-----w c:\programdata\Xfire 2008-12-29 13:15 --------- d-----w c:\program files\Xfire 2008-12-29 12:20 --------- d-----w c:\users\Kheiz\AppData\Roaming\Xfire 2008-12-28 17:26 --------- d-----w c:\program files\Virtual Earth 3D 2008-12-28 12:16 --------- d-----w c:\program files\DVD Decrypter 2008-12-27 20:07 --------- d-----w c:\program files\Orb Networks 2008-12-26 19:39 --------- d-----w c:\program files\Custom-Strike 2008-12-26 19:26 --------- d-----w c:\program files\SprayR 2008-12-26 14:44 --------- d-----w c:\program files\CCleaner 2008-12-26 14:40 --------- d-----w c:\program files\Common Files\Adobe 2008-12-26 14:38 --------- d-----w c:\users\Kheiz\AppData\Roaming\com.adobe.ExMan 2008-12-26 14:33 --------- d-----w c:\users\Kheiz\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2008-12-25 07:38 --------- d-----w c:\program files\DemoForge 2008-12-25 06:48 --------- d-----w c:\programdata\NVIDIA 2008-12-24 10:13 --------- d-----w c:\program files\Common Files\PX Storage Engine 2008-12-24 09:36 --------- d-----w c:\program files\Adobe Media Player 2008-12-24 09:35 --------- d-----w c:\program files\Common Files\Adobe AIR 2008-12-23 08:05 --------- d-----w c:\program files\RegCleaner 2008-12-22 21:23 --------- d-----w c:\program files\UDPixel 2008-12-22 18:35 --------- d-----w c:\program files\Common Files\Steam 2008-12-19 18:11 --------- d---a-w c:\programdata\TEMP 2008-12-19 13:09 --------- d-----w c:\users\Kheiz\AppData\Roaming\LimeWire 2008-12-18 12:31 --------- d-----w c:\users\Kheiz\AppData\Roaming\DiskAid 2008-12-18 12:26 --------- d-----w c:\program files\WinSCP 2008-12-18 11:18 --------- d-----w c:\program files\Microsoft Silverlight 2008-12-17 19:22 --------- d-----w c:\programdata\WLInstaller 2008-12-17 19:22 --------- d-----w c:\program files\Windows Live 2008-12-17 18:59 --------- d-----w c:\program files\Windows Live SkyDrive 2008-12-17 18:59 --------- d-----w c:\program files\Microsoft 2008-12-17 09:57 129,552 ----a-w c:\windows\System32\VBoxNetFltNotify.dll 2008-12-17 09:56 81,360 ----a-w c:\windows\system32\drivers\VBoxNetFlt.sys 2008-12-17 09:56 41,680 ----a-w c:\windows\system32\drivers\VBoxUSBMon.sys 2008-12-17 09:56 100,368 ----a-w c:\windows\system32\drivers\VBoxDrv.sys 2008-12-16 19:26 --------- d-----w c:\program files\DigiDNA 2008-12-16 12:52 --------- d-----w c:\users\Kheiz\AppData\Roaming\Apple Computer 2008-12-16 12:48 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2008-12-11 20:37 42,320 ----a-w c:\windows\System32\xfcodec.dll 2008-12-06 17:27 274,781 ----a-w c:\windows\Fast Video to GIF SWF Converter Uninstaller.exe 2008-12-02 21:37 49,480 ----a-w c:\windows\System32\sirenacm.dll 2008-07-27 20:21 174 --sha-w c:\program files\desktop.ini 2007-12-17 16:23 1,136,640 ----a-w c:\program files\Common Files\ewutils2.dll 2007-10-18 16:21 92,064 ----a-w c:\users\Kheiz\mqdmmdm.sys 2007-10-18 16:21 9,232 ----a-w c:\users\Kheiz\mqdmmdfl.sys 2007-10-18 16:21 79,328 ----a-w c:\users\Kheiz\mqdmserd.sys 2007-10-18 16:21 66,656 ----a-w c:\users\Kheiz\mqdmbus.sys 2007-10-18 16:21 6,208 ----a-w c:\users\Kheiz\mqdmcmnt.sys 2007-10-18 16:21 5,936 ----a-w c:\users\Kheiz\mqdmwhnt.sys 2007-10-18 16:21 4,048 ----a-w c:\users\Kheiz\mqdmcr.sys 2007-10-18 16:21 25,600 ----a-w c:\users\Kheiz\usbsermptxp.sys 2007-10-18 16:21 22,768 ----a-w c:\users\Kheiz\usbsermpt.sys 2008-01-03 18:48 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 2008-01-03 18:48 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 2008-02-22 10:32 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-03-02 949376] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.i420"= i263_32.drv "VIDC.X264"= x264vfw.dll "VIDC.XFR1"= xfcodec.dll "msacm.g723"= g723.acm "vidc.I263"= I263_32.drv [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer] --a------ 2007-05-04 07:40 312240 c:\program files\Lexmark Fax Solutions\fm3032.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon] --a------ 2007-03-05 08:40 20480 c:\program files\Lexmark 2500 Series\lxddamon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] --a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List] "c:\\Program Files\\FlashFXP\\FlashFXP.exe"= c:\program files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 "c:\\Program Files\\Lexmark 2500 Series\\app4r.exe"= c:\program files\Lexmark 2500 Series\app4r.exe:*:Enabled:Lexmark Imaging Studio [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{406EA5D1-EE2C-4FBF-AC1C-F6986F6ED448}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{CA255E8D-29F6-4998-A33B-C2AA93F5A415}"= UDP:3703:Adobe Version Cue CS3 Server "{1A9436AC-0028-4EDC-BBD8-C8D3142BCA8A}"= UDP:3704:Adobe Version Cue CS3 Server "{9C4FCA7F-10A2-4B48-ACF3-C1C5F137BD01}"= UDP:50900:Adobe Version Cue CS3 Server "{23B8FB25-0396-4186-8B0C-9B9DEA86E5FF}"= UDP:50901:Adobe Version Cue CS3 Server "{952D2727-8485-4719-84CD-BA9B6134B13F}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server "{C3AD499C-C59D-4308-AFD5-9AAC7F263A09}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server "{E99AA100-3AE7-4641-8933-0F470468F18C}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{C689CB64-C533-43B5-9E81-5077A119474F}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "TCP Query User{3DDD9BD4-0907-4AEC-9419-9078F4DFCE29}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet "UDP Query User{58481F26-BFBB-4FC7-9B6B-078A522A4368}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet "TCP Query User{F2A31159-75FA-44D6-843F-060920B0619E}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM "UDP Query User{9E2063B4-61EB-4E23-86F7-B392C7701D26}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM "TCP Query User{27560A2E-76C7-4698-A54E-BDA91B46DD2F}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{0AC2E0A9-3F3A-4B07-A4F3-344B79C274A6}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{1335C668-954D-4E3C-A2D3-F25014023163}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox "UDP Query User{39361653-6488-4AC9-8E97-CA3B1481FCC0}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox "TCP Query User{DCF3C640-0400-4156-879F-8D95F2DE48FA}c:\\program files\\flashfxp\\flashfxp.exe"= UDP:c:\program files\flashfxp\flashfxp.exe:FlashFXP "UDP Query User{CCB1B42A-35E7-4502-8747-B610B0C6D40C}c:\\program files\\flashfxp\\flashfxp.exe"= TCP:c:\program files\flashfxp\flashfxp.exe:FlashFXP "{C36F6FD2-B103-4E98-86BD-6C30A669540D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{78E80BC7-7CFD-40E1-B460-6AFB5F2AE5DA}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "TCP Query User{1D068E28-EF02-4D21-BD32-243AAEFAF98E}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC "UDP Query User{DF067CB3-45F9-4ED9-9587-D4A8C49736A8}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC "TCP Query User{9DDCE556-D48F-4FA4-84C9-3D7044944146}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus "UDP Query User{1E5D411C-293F-4A2A-A1A6-E516361B2835}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus "{94BDBE3B-75F6-43EC-A53F-AA8BDC2EAD98}"= UDP:13210:BitComet 13210 TCP "{E692FC4F-56AD-4160-BA8A-B353998A17F4}"= TCP:13210:BitComet 13210 UDP "TCP Query User{EB194772-EEDE-4E80-8B73-BA0006FAF16E}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{D7018494-B4DA-4E83-A80F-7D1E8994720B}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "TCP Query User{58D3A39D-4A4F-42C1-BE1F-5C43FA3894CE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent "UDP Query User{66964E55-0AED-49C8-8FCC-EFC1F906E5B6}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent "TCP Query User{B14AE775-A4E8-41B7-A42D-0FAF9A251115}c:\\users\\kheiz\\appdata\\local\\temp\\rar$ex00.740\\wlm lite 8.5.exe"= UDP:c:\users\kheiz\appdata\local\temp\rar$ex00.740\wlm lite 8.5.exe:wlm lite 8.5.exe "UDP Query User{3B4E1DB7-A4C3-45A0-8B1D-AFBBF00BED58}c:\\users\\kheiz\\appdata\\local\\temp\\rar$ex00.740\\wlm lite 8.5.exe"= TCP:c:\users\kheiz\appdata\local\temp\rar$ex00.740\wlm lite 8.5.exe:wlm lite 8.5.exe "TCP Query User{E33C9B30-CF2B-480C-AD86-3696FC7A0DDB}c:\\program files\\vidalia bundle\\tor\\tor.exe"= UDP:c:\program files\vidalia bundle\tor\tor.exe:tor "UDP Query User{1AAB29DE-97B0-49CD-A9DC-14AE61C0826B}c:\\program files\\vidalia bundle\\tor\\tor.exe"= TCP:c:\program files\vidalia bundle\tor\tor.exe:tor "TCP Query User{920805D1-8E53-4B76-80BD-0A26D7473B4F}c:\\users\\kheiz\\desktop\\wlm lite 8.5.exe"= UDP:c:\users\kheiz\desktop\wlm lite 8.5.exe:wlm lite 8.5.exe "UDP Query User{B5AFDE00-DA3A-41A5-80B6-12F61B39AE2A}c:\\users\\kheiz\\desktop\\wlm lite 8.5.exe"= TCP:c:\users\kheiz\desktop\wlm lite 8.5.exe:wlm lite 8.5.exe "{1FD3CA6D-2149-48CA-A36F-E0E379D97BBC}"= UDP:c:\program files\Microsoft Games\Viva Pinata\Viva Pinata.exe:Viva Piñata "{AF3D2819-2251-4C60-AB2E-19BAD7F57DA9}"= TCP:c:\program files\Microsoft Games\Viva Pinata\Viva Pinata.exe:Viva Piñata "TCP Query User{27A690DA-B5EF-4A92-804D-1BC28879BE05}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client "UDP Query User{E309E3EC-09CF-49A5-B7A3-3E5683A624CE}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client "TCP Query User{92E20042-F382-4016-8C19-A14C9E53271E}c:\\program files\\thq\\frontlines-fuel of war beta\\binaries\\ffow-beta.exe"= UDP:c:\program files\thq\frontlines-fuel of war beta\binaries\ffow-beta.exe:Frontlines Game "UDP Query User{C9B3E2CC-325D-4BBB-8F52-B1F079DAAD08}c:\\program files\\thq\\frontlines-fuel of war beta\\binaries\\ffow-beta.exe"= TCP:c:\program files\thq\frontlines-fuel of war beta\binaries\ffow-beta.exe:Frontlines Game "TCP Query User{FD3644B6-FAC3-4C94-898C-455B6896EC58}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire "UDP Query User{F664FDC4-1945-4EEB-8CE0-08729D1905D2}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire "{37BBC581-EE36-46D7-811C-2732232FC739}"= UDP:c:\program files\THQ\Frontlines-Fuel of War\Binaries\FFOW.exe:Frontlines Game "{35063291-5A40-4F8B-89BE-CBE7F2C728E6}"= TCP:c:\program files\THQ\Frontlines-Fuel of War\Binaries\FFOW.exe:Frontlines Game "TCP Query User{5614E7F9-39FE-4418-861A-C465392F3F26}c:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader "UDP Query User{36244725-E512-4E48-A1F3-FC18A2578B61}c:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader "TCP Query User{0BDE77AB-8E10-482F-9E10-94061EADCA83}c:\\program files\\free music zilla\\fmzilla.exe"= UDP:c:\program files\free music zilla\fmzilla.exe:FMZilla Module "UDP Query User{A49DAC03-63B6-4441-886D-4323BB902613}c:\\program files\\free music zilla\\fmzilla.exe"= TCP:c:\program files\free music zilla\fmzilla.exe:FMZilla Module "TCP Query User{F1B9967E-8DD3-45A7-9CD6-17538F8DE11D}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe "UDP Query User{BD7B4D2E-5318-42EB-B4EA-33C4711CAC09}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe "TCP Query User{B41A77FB-D66F-4B81-88C0-674361D98160}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player "UDP Query User{2CAB7BB5-7487-43C5-801A-D101F01BA7B0}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player "TCP Query User{E890D0D8-BE41-44C0-AF50-8D017576E3AD}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire "UDP Query User{D24171BD-341B-475B-8A96-663D2C835D16}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire "TCP Query User{8A482DDB-8CEB-4DCF-92BC-BE49A65DD452}c:\\program files\\xi\\netxfer\\nettransport.exe"= UDP:c:\program files\xi\netxfer\nettransport.exe:NetXfer Download Manager "UDP Query User{7133E79D-00B7-4E75-825D-538E97872EA8}c:\\program files\\xi\\netxfer\\nettransport.exe"= TCP:c:\program files\xi\netxfer\nettransport.exe:NetXfer Download Manager "TCP Query User{F504DDCF-BD45-4A00-B776-A13BCE294269}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= UDP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III "UDP Query User{F7AB187A-2DF3-48F7-8BE5-D16E23AC42C4}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= TCP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III "TCP Query User{CA383E5E-25C0-4B91-8963-8C73D82A7A42}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule "UDP Query User{0FFD6DC8-82FA-48BD-BE7B-5505DF184B01}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule "TCP Query User{1E1846AF-207A-4F46-B706-416F670646FE}c:\\program files\\transcode360\\transcode360tray.exe"= UDP:c:\program files\transcode360\transcode360tray.exe: "UDP Query User{4D79164D-3C04-4E1C-88A9-17C1B74B960A}c:\\program files\\transcode360\\transcode360tray.exe"= TCP:c:\program files\transcode360\transcode360tray.exe: "TCP Query User{12B5EF44-7FFE-4628-AB2D-7D5BB1EF8972}c:\\users\\kheiz\\desktop\\lhemule53\\lhemule53\\emule.exe"= UDP:c:\users\kheiz\desktop\lhemule53\lhemule53\emule.exe:emule.exe "UDP Query User{47545739-5B69-4AE4-8576-EEFD865947BD}c:\\users\\kheiz\\desktop\\lhemule53\\lhemule53\\emule.exe"= TCP:c:\users\kheiz\desktop\lhemule53\lhemule53\emule.exe:emule.exe "{73B4F511-2247-45E0-9894-597943CEB582}"= UDP:c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster "{99DABFDD-BCDA-4607-9A9C-8105FD0D0E0E}"= TCP:c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster "{5E9F2F92-302C-417E-AB31-6563754FF22B}"= UDP:c:\program files\FreeCall.com\FreeCall\FreeCall.exe:FreeCall "{86BD089C-09F4-4697-B955-888A04EB5922}"= TCP:c:\program files\FreeCall.com\FreeCall\FreeCall.exe:FreeCall "TCP Query User{5CEB96F9-9D01-4836-A0FF-0046BCA41DB5}c:\\users\\kheiz\\desktop\\bot\\spamer.exe"= UDP:c:\users\kheiz\desktop\bot\spamer.exe:spamer.exe "UDP Query User{DA6E3D28-1891-478F-84C7-620CEE3DE0F3}c:\\users\\kheiz\\desktop\\bot\\spamer.exe"= TCP:c:\users\kheiz\desktop\bot\spamer.exe:spamer.exe "TCP Query User{265CD8AE-0938-49C6-9FE9-D9BCB06A9D28}c:\\program files\\xbc\\nexbc.exe"= UDP:c:\program files\xbc\nexbc.exe:XBConnect "UDP Query User{8CA99E93-32A5-44D9-8027-274AEF462B44}c:\\program files\\xbc\\nexbc.exe"= TCP:c:\program files\xbc\nexbc.exe:XBConnect "{5F350EDB-42B3-42C2-8268-E5CCC76CF445}"= UDP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System "{46A61804-B698-47F3-9392-830FCC5310AB}"= TCP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System "{0A3FA6C7-5284-4895-909C-E911A046D6D0}"= UDP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor "{F514105E-AA7C-49E5-B958-D7063B014D49}"= TCP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor "{92DFF8ED-AD82-40DE-85DD-C4F979E1E839}"= UDP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio "{C4B7D5A9-5665-49E1-8E39-6FA748A3D3DD}"= TCP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio "{16A8BCA3-EF2B-45E0-9F32-8B066C5AA82D}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe: "{2FFBB25E-7616-422C-B956-6FD2979C9DDC}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe: "{86FD683A-8AE4-4F7B-A8A9-2286346D31A3}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe: "{06D5DD6A-BD46-44D4-AF2D-4FF8805B4772}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe: "TCP Query User{F5C205FD-2FC2-490C-8523-3983CE684BC5}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= UDP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe "UDP Query User{98924300-C71C-4F03-ACAA-3443333DE03B}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= TCP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe "{82F6F97F-658F-4316-9C3D-E744C5F8C548}"= UDP:c:\program files\Leaf Networks\Leaf\bin\Leaf.exe:Leaf "{376FDB3D-0447-4850-BDC5-F6F61CB6EE9E}"= TCP:c:\program files\Leaf Networks\Leaf\bin\Leaf.exe:Leaf "TCP Query User{3A360E7F-4140-4717-A473-59D54E7785D3}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe "UDP Query User{B43F923D-D1B4-4654-B516-CA35687DFFD7}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe "TCP Query User{70AFB64D-8838-4A8F-A4A9-0CA8A1B46B67}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= UDP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe "UDP Query User{D47393D0-7790-42C6-A0B6-5A4D549D5EED}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= TCP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe "TCP Query User{0801D3F9-1F29-4F3F-AD42-7D3A4BE958B7}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player "UDP Query User{EB8896BA-2254-4BE3-8F62-1FBA5448159D}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player "TCP Query User{32339FDA-6512-45DF-AB70-DC9E52BE7047}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet "UDP Query User{C1D3F69A-B74E-4190-A3EE-F6DB680D1690}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet "TCP Query User{6EDEEDD9-F9C4-4BD8-B17A-607F043158CC}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= UDP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III "UDP Query User{9BD03276-9794-4F5C-A2C8-0E190BF4E2F3}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= TCP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III "TCP Query User{E9848EB1-D159-4541-A9A5-DBCD5CFDB51F}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "UDP Query User{6CDFB351-990F-4458-A25F-1789BF673A40}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "TCP Query User{B89960F5-F9AF-44CA-9B91-7BBC896B3A8E}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application "UDP Query User{07FF5208-9FB5-4579-B1C7-68F3A3F1ECC0}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application "TCP Query User{989DA9A5-4F82-4E66-9E9E-C9109CD59A33}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "UDP Query User{061A6796-A2CE-4CAE-AC07-05B17742D5AB}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "TCP Query User{AA05F0DE-51D9-47B6-BDD0-42E06350963D}c:\\program files\\transcode360\\transcode360tray.exe"= UDP:c:\program files\transcode360\transcode360tray.exe: "UDP Query User{1A1686F6-DA31-451F-B84A-7C24CD6D42BA}c:\\program files\\transcode360\\transcode360tray.exe"= TCP:c:\program files\transcode360\transcode360tray.exe: "{70BF44B9-CBE5-4F21-95F3-B4D15BE77FEB}"= UDP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server "{B9018C9A-44CB-459A-BF49-1776660E9D27}"= TCP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server "{E5BC873E-F102-4AF4-9024-5FB92673E87A}"= UDP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{00571A5A-815A-46C8-B992-E7A8727E19E4}"= TCP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{8949DA0A-A4A3-4610-A94E-D2C0F9EBBD1A}"= UDP:c:\users\Kheiz\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{1E6BE95A-61E0-4DAD-9F18-F5C8773DC4D6}"= TCP:c:\users\Kheiz\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "TCP Query User{09B85EBD-E0B3-4683-A68D-19E82C2E0E95}c:\\users\\kheiz\\desktop\\wlm lite 8.5 finale fr [www.msncreative.net].exe"= UDP:c:\users\kheiz\desktop\wlm lite 8.5 finale fr [www.msncreative.net].exe:wlm lite 8.5 finale fr [www.msncreative.net].exe "UDP Query User{3D66E89F-753C-4FDC-B2C3-83C095E475D2}c:\\users\\kheiz\\desktop\\wlm lite 8.5 finale fr [www.msncreative.net].exe"= TCP:c:\users\kheiz\desktop\wlm lite 8.5 finale fr [www.msncreative.net].exe:wlm lite 8.5 finale fr [www.msncreative.net].exe "TCP Query User{C047936E-C49F-4101-94CC-3D6E319DDF12}c:\\users\\kheiz\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\kheiz\appdata\local\google\chrome\application\chrome.exe:chrome.exe "UDP Query User{AB8A863C-8D34-4242-89AB-1347C81B7487}c:\\users\\kheiz\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\kheiz\appdata\local\google\chrome\application\chrome.exe:chrome.exe "TCP Query User{A0AB5529-F427-489B-9D22-7D0B296650ED}c:\\program files\\xlink kai\\kaiengine.exe"= UDP:c:\program files\xlink kai\kaiengine.exe:XLink Kai Engine "UDP Query User{451F08CC-BF20-4814-8F87-C5A92C31D803}c:\\program files\\xlink kai\\kaiengine.exe"= TCP:c:\program files\xlink kai\kaiengine.exe:XLink Kai Engine "TCP Query User{E504981A-4E12-473F-B830-06A668A60CFE}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "UDP Query User{73665A52-1F17-4908-808C-170C672D6C34}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "TCP Query User{03F17295-0FFD-4E8F-9678-50BDC5996B01}c:\\windows\\system32\\javaw.exe"= UDP:c:\windows\system32\javaw.exe:Java Platform SE binary "UDP Query User{2989D968-BF26-4A24-9FE1-74FD7DF984DF}c:\\windows\\system32\\javaw.exe"= TCP:c:\windows\system32\javaw.exe:Java Platform SE binary "TCP Query User{33A5FA64-D65B-4C35-91C6-7C31D834DADC}c:\\program files\\messengerdiscovery\\messengerdiscovery.exe"= UDP:c:\program files\messengerdiscovery\messengerdiscovery.exe:MessengerDiscovery the Windows Live Messenger addon "UDP Query User{B283602A-BF5F-40A7-8ECC-5AC7AC85B576}c:\\program files\\messengerdiscovery\\messengerdiscovery.exe"= TCP:c:\program files\messengerdiscovery\messengerdiscovery.exe:MessengerDiscovery the Windows Live Messenger addon "TCP Query User{51426E82-F352-4611-9F1F-BB87EDC2189F}c:\\program files\\java\\jre1.6.0_07\\bin\\java.exe"= UDP:c:\program files\java\jre1.6.0_07\bin\java.exe:Java Platform SE binary "UDP Query User{0D7E6835-1219-4B51-8385-4EB790E347D1}c:\\program files\\java\\jre1.6.0_07\\bin\\java.exe"= TCP:c:\program files\java\jre1.6.0_07\bin\java.exe:Java Platform SE binary "TCP Query User{FFF01AFA-7158-4EF6-A11A-ABB8718890CC}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= UDP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3 "UDP Query User{736B622A-2DFB-40F3-9F4C-9F2CB703B5E5}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= TCP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3 "{252C80E8-BAB6-44E9-9DFC-580A81B6610E}"= UDP:c:\program files\Activision\Quantum of Solace\JB_LiveEngine_s.exe:Quantum of Solace "{85BF294C-9BDA-4C9D-A502-E9A0D8887835}"= TCP:c:\program files\Activision\Quantum of Solace\JB_LiveEngine_s.exe:Quantum of Solace "TCP Query User{7543F0A3-6396-4CA4-877F-FA4BA8C0CB44}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= UDP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3 "UDP Query User{5F3B1E9C-88EE-49C1-80C2-B7B7D90399B3}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= TCP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3 "{36A2B9B3-FBD3-4854-B124-FB2395D444D7}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{E1E9F492-3666-460E-952F-E170D7FD61FF}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{AEA7CB04-C34C-471C-B7B3-6C024E077D64}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{5E6DCAF1-948A-480D-89D8-988C1B053B02}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{F2283592-2607-4DC4-BB18-3EA442483BBB}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync "{0D5A8BE9-B71C-4161-AF5A-0C5EE192843D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{E47D0F58-1C64-4BFE-B906-937366C4A869}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\kpone44\counter-strike source\hl2.exe:hl2 "UDP Query User{F9BBAAEE-813B-40D4-BD1F-49517D9DCA39}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\kpone44\counter-strike source\hl2.exe:hl2 "TCP Query User{79AC4F81-35CD-4CF4-AF74-05DE9059E8E2}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike\\hl.exe"= UDP:c:\program files\steam\steamapps\kpone44\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{563076D1-4783-4F6A-BC95-414C6561641C}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike\\hl.exe"= TCP:c:\program files\steam\steamapps\kpone44\counter-strike\hl.exe:Half-Life Launcher "{3EA215EA-7CCE-44E5-8EBF-BEAB4DFDCFB2}"= UDP:5353:Adobe CSI CS4 "{51A9DC5A-274B-40D9-8E8D-F864A09F73E5}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4 "{16ECD65C-C153-42D6-8B53-59036A70418A}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4 "{D46ACE5A-5695-4618-A5D2-EF2A15941F50}"= UDP:3703:Adobe Version Cue CS4 Server "{5A5585A4-63CA-42CD-A893-C5092DE73019}"= UDP:3704:Adobe Version Cue CS4 Server "{26C35CB7-7FFC-461D-85D5-71EED92DFF86}"= UDP:51000:Adobe Version Cue CS4 Server "{50296605-E2C4-4D5B-8C1D-4813387BDFDB}"= UDP:51001:Adobe Version Cue CS4 Server "{AF13000E-9292-4A11-8564-D6EA8D6ADC30}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server "{5A031FE3-9318-446F-8374-5CC81B6A4822}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server "TCP Query User{0FEE8FE4-EBB2-422F-8AD6-6B6CDF26B4F9}c:\\program files\\tightvnc-jaadu\\winvnc.exe"= UDP:c:\program files\tightvnc-jaadu\winvnc.exe:TightVNC Win32 Server "UDP Query User{00245CF6-F54F-478C-9651-5708323F3954}c:\\program files\\tightvnc-jaadu\\winvnc.exe"= TCP:c:\program files\tightvnc-jaadu\winvnc.exe:TightVNC Win32 Server "{232AAFB0-5F1B-4EB0-B964-93758700DC27}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray "{9E301A18-A241-4D0B-AB29-7B9FD9BB7C85}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray "{16F4D94D-C5C6-4C57-9676-A8EB4F37F7BA}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client "{D3799AC8-9F32-4497-9CC5-974329954D39}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client "{9F7A294D-2ACE-49EB-9BD8-79C270A47A88}"= UDP:c:\program files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide "{A4156362-31C7-44D1-9268-333D8DC2BC70}"= TCP:c:\program files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide "{75B26C7C-7992-493A-A7BA-11DEBC2B4DB4}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan "{5FA71556-B578-41E9-8400-A26DB91DADED}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan "TCP Query User{D0295354-5E27-4E79-940E-E60BB190B0B6}c:\\program files\\orb networks\\orb\\bin\\orbtray.exe"= UDP:c:\program files\orb networks\orb\bin\orbtray.exe:Orb "UDP Query User{7274248B-9A87-4248-A68D-DD168CD4D2F2}c:\\program files\\orb networks\\orb\\bin\\orbtray.exe"= TCP:c:\program files\orb networks\orb\bin\orbtray.exe:Orb "{208FCDEF-D518-4638-B1E7-D4A79F7626D8}"= UDP:c:\program files\Orb Networks\Orb\bin\Orb.exe:Orb "{888BB3CB-9F9B-4A6E-87E3-783BCCF8E7AC}"= TCP:c:\program files\Orb Networks\Orb\bin\Orb.exe:Orb "{F7410519-9D92-446D-9B6A-F6DEDAB45262}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbIR.exe:OrbIR "{B01F0F99-D62E-463D-AE95-6699FD372EA7}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbIR.exe:OrbIR "TCP Query User{9A95F4BC-3B9C-455D-BFED-3A5D69105AF3}c:\\program files\\steam\\steamapps\\lordtiger18\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\lordtiger18\counter-strike source\hl2.exe:hl2 "UDP Query User{92352246-C778-4416-B06D-53D77A85C455}c:\\program files\\steam\\steamapps\\lordtiger18\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\lordtiger18\counter-strike source\hl2.exe:hl2 "TCP Query User{EA7E7C2A-13A2-448F-AE45-5FB553A0091A}c:\\program files\\sun\\xvm virtualbox\\virtualbox.exe"= UDP:c:\program files\sun\xvm virtualbox\virtualbox.exe:VirtualBox "UDP Query User{246874F5-C7BA-49A5-A272-E4AE72057172}c:\\program files\\sun\\xvm virtualbox\\virtualbox.exe"= TCP:c:\program files\sun\xvm virtualbox\virtualbox.exe:VirtualBox "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdnshelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdnshelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsinfo.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsinfo.exe:cdsinfo (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsinfo.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsinfo.exe:cdsinfo (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsmps.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsmps.exe:cdsmps (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsmps.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsmps.exe:cdsmps (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsMsgServer.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsMsgServer.exe:cdsMsgServer (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsMsgServer.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsMsgServer.exe:cdsMsgServer (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsNameServer.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsNameServer.exe:cdsNameServer (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsNameServer.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsNameServer.exe:cdsNameServer (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsOaPathUtil.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsOaPathUtil.exe:cdsOaPathUtil (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsOaPathUtil.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsOaPathUtil.exe:cdsOaPathUtil (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemote.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemote.exe:cdsRemote (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemote.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemote.exe:cdsRemote (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemshClient.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemshClient.exe:cdsRemshClient (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemshClient.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemshClient.exe:cdsRemshClient (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRunHidden.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsRunHidden.exe:cdsRunHidden (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRunHidden.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsRunHidden.exe:cdsRunHidden (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsServIpc.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsServIpc.exe:cdsServIpc (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsServIpc.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsServIpc.exe:cdsServIpc (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsUnzip.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsUnzip.exe:cdsUnzip (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsUnzip.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsUnzip.exe:cdsUnzip (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdswhich.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdswhich.exe:cdswhich (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdswhich.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdswhich.exe:cdswhich (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsZip.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsZip.exe:cdsZip (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsZip.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsZip.exe:cdsZip (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cds_root.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cds_root.exe:cds_root (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cds_root.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cds_root.exe:cds_root (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsAdminTool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\clsAdminTool.exe:clsAdminTool (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsAdminTool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\clsAdminTool.exe:clsAdminTool (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsbd.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\clsbd.exe:clsbd (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsbd.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\clsbd.exe:clsbd (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clu.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\clu.exe:clu (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clu.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\clu.exe:clu (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\dregprint.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\dregprint.exe:dregprint (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\dregprint.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\dregprint.exe:dregprint (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\emsMkError.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\emsMkError.exe:emsMkError (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\emsMkError.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\emsMkError.exe:emsMkError (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\mpsinfo.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\mpsinfo.exe:mpsinfo (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\mpsinfo.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\mpsinfo.exe:mpsinfo (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\msgHelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\msgHelp.exe:msgHelp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\msgHelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\msgHelp.exe:msgHelp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\nmp.exe:nmp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\nmp.exe:nmp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmppath.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\nmppath.exe:nmppath (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmppath.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\nmppath.exe:nmppath (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\switchversion.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\switchversion.exe:switchversion (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\switchversion.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\switchversion.exe:switchversion (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\van.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\van.exe:van (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\van.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\van.exe:van (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\versionviewer.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\versionviewer.exe:versionviewer (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\versionviewer.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\versionviewer.exe:versionviewer (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\capture.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\capture.exe:capture (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\capture.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\capture.exe:capture (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\comp16.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\comp16.exe:comp16 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\comp16.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\comp16.exe:comp16 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pcadi.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\pcadi.exe:pcadi (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pcadi.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\pcadi.exe:pcadi (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pspiceexplorersrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pspiceexplorersrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pstswp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\pstswp.exe:pstswp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pstswp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\pstswp.exe:pstswp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\regsvr32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\regsvr32.exe:regsvr32 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\regsvr32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\regsvr32.exe:regsvr32 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\sch2cap.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\sch2cap.exe:sch2cap (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\sch2cap.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\sch2cap.exe:sch2cap (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\tutorial\\CAPTUTOR.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\tutorial\CAPTUTOR.EXE:CAPTUTOR (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\tutorial\\CAPTUTOR.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\tutorial\CAPTUTOR.EXE:CAPTUTOR (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\cdnshelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\cdnshelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\topicgen.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\topicgen.exe:topicgen (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\topicgen.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\topicgen.exe:topicgen (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\_cdnshelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\_cdnshelp.exe:_cdnshelp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\_cdnshelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\_cdnshelp.exe:_cdnshelp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\mkdefcfg.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\fet\bin\mkdefcfg.exe:mkdefcfg (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\mkdefcfg.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\fet\bin\mkdefcfg.exe:mkdefcfg (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\versiontool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\fet\bin\versiontool.exe:versiontool (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\versiontool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\fet\bin\versiontool.exe:versiontool (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\fvupdateutil.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\fvupdateutil.exe:fvupdateutil (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\fvupdateutil.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\fvupdateutil.exe:fvupdateutil (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcad.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gcad.exe:gcad (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcad.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gcad.exe:gcad (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcam.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gcam.exe:gcam (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcam.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gcam.exe:gcam (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcdin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gcdin.exe:gcdin (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcdin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gcdin.exe:gcdin (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\idfin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\idfin.exe:idfin (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\idfin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\idfin.exe:idfin (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\ipc356.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\ipc356.exe:ipc356 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\ipc356.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\ipc356.exe:ipc356 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\layout.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\layout.exe:layout (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\layout.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\layout.exe:layout (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\libcat.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\libcat.exe:libcat (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\libcat.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\libcat.exe:libcat (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\lsession.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\lsession.exe:lsession (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\lsession.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\lsession.exe:lsession (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\max2hyp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\max2hyp.exe:max2hyp (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\max2hyp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\max2hyp.exe:max2hyp (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxascb.exe:maxascb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxascb.exe:maxascb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxascx.exe:maxascx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxascx.exe:maxascx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxdxf.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxdxf.exe:maxdxf (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxdxf.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxdxf.exe:maxdxf (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxeco.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxeco.exe:maxeco (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxeco.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxeco.exe:maxeco (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxfnetx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxfnetx.exe:maxfnetx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxfnetx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxfnetx.exe:maxfnetx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxminb.exe:maxminb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxminb.exe:maxminb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminw.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxminw.exe:maxminw (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminw.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxminw.exe:maxminw (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxminx.exe:maxminx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxminx.exe:maxminx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxorcad.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxorcad.exe:maxorcad (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxorcad.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxorcad.exe:maxorcad (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxp99x.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxp99x.exe:maxp99x (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxp99x.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxp99x.exe:maxp99x (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpadb.exe:maxpadb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpadb.exe:maxpadb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpadx.exe:maxpadx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpadx.exe:maxpadx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadb.exe:maxpcadb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadb.exe:maxpcadb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadx.exe:maxpcadx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadx.exe:maxpcadx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxprotb.exe:maxprotb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxprotb.exe:maxprotb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxprotx.exe:maxprotx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxprotx.exe:maxprotx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxstrb.exe:maxstrb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxstrb.exe:maxstrb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxstrx.exe:maxstrx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxstrx.exe:maxstrx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxtangb.exe:maxtangb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxtangb.exe:maxtangb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxtangx.exe:maxtangx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxtangx.exe:maxtangx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\mfceco.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\mfceco.exe:mfceco (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\mfceco.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\mfceco.exe:mfceco (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\orcadodb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\orcadodb.exe:orcadodb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\orcadodb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\orcadodb.exe:orcadodb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\padb.exe:padb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\padb.exe:padb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\padx.exe:padx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\padx.exe:padx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\pcadb.exe:pcadb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\pcadb.exe:pcadb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\pcadx.exe:pcadx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\pcadx.exe:pcadx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcb2max.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\pcb2max.exe:pcb2max (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcb2max.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\pcb2max.exe:pcb2max (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\prcat.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\prcat.exe:prcat (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\prcat.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\prcat.exe:prcat (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\protb.exe:protb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\protb.exe:protb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\protx.exe:protx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\protx.exe:protx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\searchTool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\searchTool.exe:searchTool (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\searchTool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\searchTool.exe:searchTool (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\setbrows.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\setbrows.exe:setbrows (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\setbrows.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\setbrows.exe:setbrows (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\specin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\specin.exe:specin (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\specin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\specin.exe:specin (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\strb.exe:strb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\strb.exe:strb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\strx.exe:strx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\strx.exe:strx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tangb.exe:tangb (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tangb.exe:tangb (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tangx.exe:tangx (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tangx.exe:tangx (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\to386.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\to386.exe:to386 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\to386.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\to386.exe:to386 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\toidf.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\toidf.exe:toidf (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\toidf.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\toidf.exe:toidf (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tomax.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tomax.exe:tomax (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tomax.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tomax.exe:tomax (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tospec.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tospec.exe:tospec (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tospec.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tospec.exe:tospec (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\update90.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\update90.exe:update90 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\update90.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\update90.exe:update90 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\F2G.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\F2G.EXE:F2G (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\F2G.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\F2G.EXE:F2G (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\G2F.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\G2F.EXE:G2F (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\G2F.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\G2F.EXE:G2F (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\custaped.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\custaped.exe:custaped (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\custaped.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\custaped.exe:custaped (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GERBLINE.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GERBLINE.EXE:GERBLINE (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GERBLINE.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GERBLINE.EXE:GERBLINE (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GerbTool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GerbTool.exe:GerbTool (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GerbTool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GerbTool.exe:GerbTool (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GT2VIEW.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GT2VIEW.EXE:GT2VIEW (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GT2VIEW.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GT2VIEW.EXE:GT2VIEW (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\gzip124.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\gzip124.exe:gzip124 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\gzip124.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\gzip124.exe:gzip124 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\System\\FixTbar.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\System\FixTbar.exe:FixTbar (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\System\\FixTbar.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\System\FixTbar.exe:FixTbar (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\samples\\demo\\reset.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\samples\demo\reset.exe:reset (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\samples\\demo\\reset.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\samples\demo\reset.exe:reset (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\batch32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\sroute\batch32.exe:batch32 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\batch32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\sroute\batch32.exe:batch32 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\sroute.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\sroute\sroute.exe:sroute (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\sroute.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\sroute\sroute.exe:sroute (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tutorial\\laytutor.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tutorial\laytutor.exe:laytutor (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tutorial\\laytutor.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tutorial\laytutor.exe:laytutor (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\vcadd\\vcadd32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\vcadd\vcadd32.exe:vcadd32 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\vcadd\\vcadd32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\vcadd\vcadd32.exe:vcadd32 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\appmgr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\appmgr.exe:appmgr (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\appmgr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\appmgr.exe:appmgr (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\IndiceFileGeneration.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\IndiceFileGeneration.exe:IndiceFileGeneration (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\IndiceFileGeneration.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\IndiceFileGeneration.exe:IndiceFileGeneration (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\lxcwin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\lxcwin.exe:lxcwin (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\lxcwin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\lxcwin.exe:lxcwin (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\Magneticdesigner.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\Magneticdesigner.exe:Magneticdesigner (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\Magneticdesigner.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\Magneticdesigner.exe:Magneticdesigner (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\modeled.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\modeled.exe:modeled (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\modeled.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\modeled.exe:modeled (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\MrkSrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\MrkSrvr.exe:MrkSrvr (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\MrkSrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\MrkSrvr.exe:MrkSrvr (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\msgview.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\msgview.exe:msgview (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\msgview.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\msgview.exe:msgview (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PDesign.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\PDesign.exe:PDesign (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PDesign.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\PDesign.exe:PDesign (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psched.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\psched.exe:psched (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psched.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\psched.exe:psched (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspice.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\pspice.exe:pspice (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspice.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\pspice.exe:pspice (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceaa.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceaa.exe:pspiceaa (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceaa.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceaa.exe:pspiceaa (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PSpiceEnc.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\PSpiceEnc.exe:PSpiceEnc (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PSpiceEnc.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\PSpiceEnc.exe:PSpiceEnc (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceexplorersrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceexplorersrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psp_cmd.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\psp_cmd.exe:psp_cmd (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psp_cmd.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\psp_cmd.exe:psp_cmd (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\regsvr32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\regsvr32.exe:regsvr32 (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\regsvr32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\regsvr32.exe:regsvr32 (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simmgr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\simmgr.exe:simmgr (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simmgr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\simmgr.exe:simmgr (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simsrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\simsrvr.exe:simsrvr (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simsrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\simsrvr.exe:simsrvr (Release OrCAD 16.0) "TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\stmed.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\stmed.exe:stmed (Release OrCAD 16.0) "UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\stmed.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\stmed.exe:stmed (Release OrCAD 16.0) "TCP Query User{D16E8910-4FC8-4E4C-B88A-0F7F2D20F891}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\4000001200003i\\cdsnameserver.exe"= UDP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\4000001200003i\cdsnameserver.exe:cdsnameserver.exe "UDP Query User{BAB2C790-CBF5-4626-85A2-9294EC6BABF2}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\4000001200003i\\cdsnameserver.exe"= TCP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\4000001200003i\cdsnameserver.exe:cdsnameserver.exe "TCP Query User{CDBF01DE-7DD4-4F0E-98CB-601D2B2C5A23}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\400000600003i\\cdsmsgserver.exe"= UDP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\400000600003i\cdsmsgserver.exe:cdsmsgserver.exe "UDP Query User{9BD86FA8-B281-4C67-A037-3E5ED65395DE}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\400000600003i\\cdsmsgserver.exe"= TCP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\400000600003i\cdsmsgserver.exe:cdsmsgserver.exe R1 nod32drv;nod32drv;c:\windows\System32\drivers\nod32drv.sys [2008-03-02 15424] R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [2009-01-11 100368] R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [2009-01-11 41680] R2 Cadence License Manager;Cadence License Manager;c:\orcad\license_manager\lmgrd.exe [2009-01-19 1327104] R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?] R2 TeamViewer;TeamViewer 3;c:\program files\TeamViewer3\TeamViewer_Host.exe [2008-05-05 181544] R3 dfmirage;dfmirage;c:\windows\System32\drivers\dfmirage.sys [2005-11-25 31896] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\System32\drivers\ManyCam.sys [2008-01-14 21632] R3 portio32;portio32;c:\windows\System32\drivers\portio32.sys [2008-11-30 2048] R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [2008-12-17 81360] S0 OemBiosDevice;Royalty OEM BIOS Extension;c:\windows\System32\drivers\royal.sys [2007-09-05 240128] S2 ekrn;Eset Service;"c:\program files\ESET\ESET Smart Security\ekrn.exe" --> c:\program files\ESET\ESET Smart Security\ekrn.exe [?] S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxddserv.exe [2007-04-26 99248] S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016] S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2008-10-11 56344] S3 fsssvc;Windows Live Family Safety;"c:\program files\Windows Live\Family Safety\fsssvc.exe" --> c:\program files\Windows Live\Family Safety\fsssvc.exe [?] S3 leafnets;Leaf Networks Adapter;c:\windows\System32\drivers\leafnets.sys [2007-05-03 55296] S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [2007-06-29 42512] S3 PsSdk41;PsSdk41;c:\windows\System32\drivers\pssdk41.sys [2008-09-16 36928] S3 PVUSB;CESG502 USB Driver;c:\windows\System32\drivers\CESG502.SYS [2008-01-18 40672] S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;c:\windows\System32\drivers\usb8023.sys [2008-07-27 15872] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f381f08-8701-11dd-970a-001638d7926d}] \shell\AutoRun\command - f:\autorun\SPLASH.EXE \shell\INSTALL\COMMAND - F:\SETUP.EXE . Contenu du dossier 'Tâches planifiées' 2009-02-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3718856369-1133722837-3043362797-1000.job - c:\users\Kheiz\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-09 18:47] 2009-02-12 c:\windows\Tasks\User_Feed_Synchronization-{3F0DB73F-2D2D-4456-9962-48954DA541BD}.job - c:\windows\system32\msfeedssync.exe [2008-01-18 22:33] . - - - - ORPHELINS SUPPRIMES - - - - WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) HKCU-Run-CubeDesktop - (no file) HKCU-Run-AdobeBridge - (no file) . ------- Examen supplémentaire ------- . uStart Page = hxxp://home.sweetim.com mStart Page = hxxp://home.sweetim.com uInternet Settings,ProxyOverride = local;*.local IE: &Tout télécharger avec FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm IE: Ajouter au fichier PDF existant - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir au format PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir la cible du lien en Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm IE: Tout télécharger avec NetXfer - c:\program files\Xi\NetXfer\NXAddList.html IE: Télécharger avec NetXfer - c:\program files\Xi\NetXfer\NXAddLink.html LSP: c:\windows\system32\imon.dll DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxp://t1.battlefield-heroes.com/patcher/westpatcher.cab FF - ProfilePath - c:\users\Kheiz\AppData\Roaming\Mozilla\Firefox\Profiles\gxmzppay.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q= 1 fichier(s) déplacé(s). FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll FF - plugin: c:\users\Kheiz\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll FF - plugin: c:\users\Kheiz\AppData\Roaming\Mozilla\Firefox\Profiles\gxmzppay.default\extensions\justintvpublisher@justin.tv\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-12 01:44:56 Windows 6.0.6001 Service Pack 1 NTFS Recherche de processus cachés ... Recherche d'éléments en démarrage automatique cachés ... Recherche de fichiers cachés ... Scan terminé avec succès Fichiers cachés: 0 ************************************************************************** . Heure de fin: 2009-02-12 1:47:35 ComboFix-quarantined-files.txt 2009-02-12 00:47:34 Avant-CF: 13 928 984 576 octets libres Après-CF: 13,886,480,384 octets libres 661 --- E O F --- 2009-01-27 20:26:47 Merci Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 12 février 2009 Auteur Partager Posté(e) le 12 février 2009 Lance Clean v2.0 by FRUiT , procédure 1. Lien vers le commentaire Partager sur d’autres sites More sharing options...
RDL_D4RkAgEnT Posté(e) le 13 février 2009 Partager Posté(e) le 13 février 2009 Bonjour, Mon PC est en ce moment incroyablement lent et a tendance à planter de plus en plus souvent. Voila mon log. Merci d'avance pour votre aide. D4RkAgEnT Logfile of HijackThis v1.99.1 Scan saved at 18:26:53, on 13/02/2009 Platform: Unknown Windows (WinNT 6.00.1905 SP1) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Users\D4RkAgEnT\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\conime.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\HIJACKTHIS VF\hijackthis vf.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bitcomet.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O1 - Hosts: ::1 localhost O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKCU\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\D4RkAgEnT\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Transfert par Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O13 - Gopher Prefix: O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{AD83399A-834A-4A76-962D-E24038866728}: NameServer = 192.168.0.1 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing) O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) Lien vers le commentaire Partager sur d’autres sites More sharing options...
meuhkalisse Posté(e) le 13 février 2009 Partager Posté(e) le 13 février 2009 Bonjours à tous! J'ai un problème avec l'ordinateur de ma mère et il est très lent au démarrage. Je sais que c'est les 04 dans hackjackthis qui gère les programme qui s'exécute au démarrage mais je ne sais pas lesquels sont essentiels. Alors si vous pourriez me dire quel 04 enlever. Je vous envoi le log de hackjackthis. Merci Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:21:40, on 2009-02-13 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\TOSHIBA\Utilities\KeNotify.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\ltmoh\ltmoh.exe C:\Program Files\Lexmark 2600 Series\lxdnmon.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe C:\Program Files\Apoint2K\ApMsgFwd.exe C:\Program Files\PDFCreator\PDFCreator.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Apoint2K\Apntex.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP O4 - HKLM\..\Run: [sVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe O4 - HKLM\..\Run: [smoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe" O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [skytel] Skytel.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (User 'Default user') O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O18 - Protocol: intu-ir2008 - {729D3592-92E7-4CBC-8E44-3C22B3F457B3} - C:\Program Files\ImpotRapide 2008\ic2008pp.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Universite Laval Cisco VPN Client VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\UnivLaval\VPN Client\cvpnd.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdnserv.exe O23 - Service: lxdn_device - - C:\Windows\system32\lxdncoms.exe O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- End of file - 10558 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 14 février 2009 Auteur Partager Posté(e) le 14 février 2009 msconfig à taper dans Exécuter > onglet Démarrage , décoche tout et redémarre le pc ... Lien vers le commentaire Partager sur d’autres sites More sharing options...
RDL_D4RkAgEnT Posté(e) le 14 février 2009 Partager Posté(e) le 14 février 2009 Bonjour, Je ne crois pas que tu aies vu mon log ^^ Merci d'avance pour ta réponse. D4RkAgEnT Lien vers le commentaire Partager sur d’autres sites More sharing options...
RDL_D4RkAgEnT Posté(e) le 16 février 2009 Partager Posté(e) le 16 février 2009 Je me permets de remonter le sujet. Bonne soirée. D4RkAgEnT Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 16 février 2009 Auteur Partager Posté(e) le 16 février 2009 Pareil en quittant Kaspersky en barre de tâches ? Lien vers le commentaire Partager sur d’autres sites More sharing options...
RDL_D4RkAgEnT Posté(e) le 17 février 2009 Partager Posté(e) le 17 février 2009 Ah là c'est plus rapide c'est sûr. Mais avant il était en barre des tâches et mon pc se comportait correctement. Lien vers le commentaire Partager sur d’autres sites More sharing options...
Messages recommandés
Archivé
Ce sujet est désormais archivé et ne peut plus recevoir de nouvelles réponses.