Aller au contenu

[LOGICIEL] [Centralisation] .:::: Hijackthis ::::.


snooky

Messages recommandés

  • Réponses 8,5 k
  • Créé
  • Dernière réponse

Coche et Fix checked toutes les lignes 04 avec Hijackthis .

Redémarre le pc .

Lance Clean v2.0 , procédure 1 ( vise ma signature )

Redémarre le pc .

Lance MBAM et supprime tout ce qui est trouvé :

http://www.malwarebytes.org/mbam.php

Lance ComboFix , et poste le rapport créé :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Lien vers le commentaire
Partager sur d’autres sites

Bonjour, Antivir me detecte le virus Tr/Agent.job. Jai beau lui dire de le déplacer en quarantaine ou de le supprimer, il revient à chaque fois, j'ai également fait un scan avec MAM. Il m'a trouvé la même chose, j'ai demandé à ce qui le supprime mais c'est toujours là.

noisette m'a dit de poster mon rapport ici, ce que je fais.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:28:21, on 07/02/2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe

C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe

C:\Users\Mathias\AppData\Roaming\MICROS~1\logman.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files\RocketDock\RocketDock.exe

C:\Windows\ehome\ehtray.exe

C:\Users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\NETGEAR\WG111v3\WG111v3.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Users\Mathias\Desktop\HijackThis.exe

C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ig?hl=fr&source=iglk

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F3 - REG:win.ini: load=C:\Users\Mathias\AppData\Roaming\MICROS~1\logman.exe

O1 - Hosts: ::1 localhost

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [Google Update] "C:\Users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

O23 - Service: Google Update Service (gupdate1c987c7b322b263) (gupdate1c987c7b322b263) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

--

End of file - 5828 bytes

Merci pour l'aide que tu pourras m'apporter.

Lien vers le commentaire
Partager sur d’autres sites

MBAM n'a rien trouvé.

Rapport ComboFix :

ComboFix 09-02-06.02 - Mathias 2009-02-07 17:13:02.2 - NTFSx86 MINIMAL

Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3326.2588 [GMT 1:00]

Lancé depuis: c:\users\Mathias\Desktop\ComboFix.exe

.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-07 au 2009-02-07 ))))))))))))))))))))))))))))))))))))

.

Pas de nouveau fichier créé dans ce laps de temps

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-07 09:58 --------- d-----w c:\users\Mathias\AppData\Roaming\uTorrent

2009-02-07 09:02 --------- d-----w c:\users\Mathias\AppData\Roaming\AIMP

2009-02-06 21:41 --------- d-----w c:\programdata\Electronic Arts

2009-02-06 21:23 --------- d-----w c:\programdata\Google Updater

2009-02-06 16:30 --------- d--h--w c:\program files\InstallShield Installation Information

2009-02-06 16:30 --------- d-----w c:\program files\Electronic Arts

2009-02-06 16:29 --------- d-----w c:\program files\Common Files\InstallShield

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\sessmgr.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\rsvp.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mstinit.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mqtgsvc.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\clipsrv.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\cisvc.exe

2009-02-05 19:27 --------- d-----w c:\program files\Google

2009-02-05 17:16 --------- d-----w c:\users\Mathias\AppData\Roaming\Convivea

2009-02-04 17:26 --------- d-----w c:\program files\PDFCreator

2009-02-03 11:49 410,984 ----a-w c:\windows\System32\deploytk.dll

2009-02-03 11:49 --------- d-----w c:\program files\Java

2009-02-01 15:43 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf

2009-02-01 14:16 --------- d-----w c:\program files\Remove Empty Directories

2009-02-01 13:59 319,488 ----a-w c:\windows\HideWin.exe

2009-02-01 13:59 319,456 ----a-w c:\windows\DIFxAPI.dll

2009-01-31 11:22 --------- d-----w c:\program files\JKDefrag v3.36

2009-01-29 19:12 --------- d-----w c:\program files\Opera

2009-01-26 18:17 --------- d-----w c:\program files\directx

2009-01-23 11:47 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Pro

2009-01-21 17:16 --------- d-----w c:\program files\AIMP2

2009-01-15 17:58 --------- d-----w c:\program files\Malwarebytes' Anti-Malware

2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys

2009-01-14 07:15 4,235,776 ----a-w c:\windows\system32\drivers\atikmdag.sys

2009-01-14 06:55 --------- d-----w c:\program files\Windows Mail

2009-01-14 05:03 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll

2009-01-14 05:02 159,744 ----a-w c:\windows\System32\atitmmxx.dll

2009-01-14 05:01 43,520 ----a-w c:\windows\System32\ati2edxx.dll

2009-01-14 05:01 348,160 ----a-w c:\windows\System32\atipdlxx.dll

2009-01-14 05:01 286,720 ----a-w c:\windows\System32\Ati2evxx.dll

2009-01-14 05:01 274,432 ----a-w c:\windows\System32\Oemdspif.dll

2009-01-14 04:59 729,088 ----a-w c:\windows\System32\Ati2evxx.exe

2009-01-14 04:50 2,345,472 ----a-w c:\windows\System32\atidxx32.dll

2009-01-14 04:44 3,963,392 ----a-w c:\windows\System32\atiumdag.dll

2009-01-14 04:22 4,765,696 ----a-w c:\windows\System32\atiumdva.dll

2009-01-14 04:08 50,688 ----a-w c:\windows\System32\amdpcom32.dll

2009-01-14 04:07 122,880 ----a-w c:\windows\System32\atiadlxx.dll

2009-01-14 03:59 11,247,616 ----a-w c:\windows\System32\atioglxx.dll

2009-01-14 03:50 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll

2009-01-14 02:54 57,344 ----a-w c:\windows\System32\amdcalrt.dll

2009-01-14 02:53 53,248 ----a-w c:\windows\System32\amdcalcl.dll

2009-01-14 02:51 3,239,936 ----a-w c:\windows\System32\amdcaldd.dll

2009-01-12 19:03 --------- d-----w c:\program files\SystemRequirementsLab

2009-01-10 17:59 --------- d-----w c:\programdata\Media Center Programs

2009-01-09 21:04 --------- d-----w c:\program files\ATI

2009-01-09 12:33 --------- d-----w c:\program files\Lavalys

2009-01-09 12:30 --------- d-----w c:\programdata\ATI

2009-01-09 12:26 --------- d-----w c:\program files\ATI Technologies

2009-01-04 13:04 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf

2009-01-03 12:37 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2009-01-02 17:13 --------- d-----w c:\program files\CCleaner

2009-01-02 17:09 --------- d-----w c:\program files\K-Lite Codec Pack

2009-01-02 13:12 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf

2009-01-02 13:11 --------- d-----w c:\program files\Microsoft Xbox 360 Accessories

2009-01-01 20:52 130,208 ------r c:\windows\bwUnin-8.1.1.87-8876480SL.exe

2009-01-01 11:51 127,034 ------r c:\windows\bwUnin-8.1.1.50-8876480SL.exe

2009-01-01 11:51 --------- d-----w c:\users\Mathias\AppData\Roaming\Logitech

2009-01-01 11:51 --------- d-----w c:\program files\Common Files\Logishrd

2009-01-01 11:50 --------- d-----w c:\program files\Logitech

2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf

2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf

2009-01-01 11:48 --------- d-----w c:\users\Mathias\AppData\Roaming\InstallShield

2009-01-01 11:48 --------- d-----w c:\programdata\Logitech

2009-01-01 11:47 --------- d-----w c:\programdata\LogiShrd

2009-01-01 11:45 --------- d-----w c:\program files\Common Files\Logitech

2008-12-31 18:50 1,700,352 ----a-w c:\windows\System32\gdiplus.dll

2008-12-31 18:50 1,060,864 ----a-w c:\windows\System32\mfc71.dll

2008-12-31 18:41 --------- d--h--r c:\users\Mathias\AppData\Roaming\SecuROM

2008-12-31 18:41 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE

2008-12-31 18:37 107,888 ----a-w c:\windows\System32\CmdLineExt.dll

2008-12-31 16:52 --------- d-----w c:\program files\RocketDock

2008-12-31 15:14 --------- d-----w c:\program files\Microsoft.NET

2008-12-31 15:11 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Lite

2008-12-30 22:55 --------- d-----w c:\program files\Quicksys

2008-12-30 22:52 --------- d-----w c:\users\Mathias\AppData\Roaming\SumatraPDF

2008-12-30 22:51 --------- d-----w c:\program files\SumatraPDF

2008-12-30 22:07 --------- d-----w c:\users\Mathias\AppData\Roaming\InfraRecorder

2008-12-30 22:07 --------- d-----w c:\program files\InfraRecorder

2008-12-30 21:53 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools

2008-12-30 21:52 --------- d-----w c:\programdata\DAEMON Tools Lite

2008-12-30 21:52 --------- d-----w c:\program files\DAEMON Tools Lite

2008-12-30 21:49 717,296 ----a-w c:\windows\system32\drivers\sptd.sys

2008-12-30 21:15 --------- d-----w c:\users\Mathias\AppData\Roaming\Malwarebytes

2008-12-30 21:15 --------- d-----w c:\programdata\Malwarebytes

2008-12-30 21:07 --------- d-----w c:\programdata\Avira

2008-12-30 21:07 --------- d-----w c:\program files\Avira

2008-12-30 21:00 --------- d-----w c:\program files\Media Player Classic

2008-12-30 20:59 --------- d-----w c:\users\Mathias\AppData\Roaming\Media Player Classic

2008-12-30 20:58 --------- d-----w c:\program files\IZArc

2008-12-30 20:31 --------- d-----w c:\program files\NETGEAR

2008-12-30 20:27 --------- d-----w c:\users\Mathias\AppData\Roaming\ATI

2008-12-30 20:25 --------- d-----w c:\program files\Common Files\ATI Technologies

2008-12-30 20:20 --------- d-----w c:\program files\Marvell

.

((((((((((((((((((((((((((((( SnapShot@2009-02-07_15.38.43,19 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-02-07 14:28:23 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2009-02-07 15:58:30 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT

- 2009-02-07 14:38:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2009-02-07 15:58:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT

- 2009-02-07 14:32:14 101,052 ----a-w c:\windows\System32\perfc009.dat

+ 2009-02-07 15:51:56 100,640 ----a-w c:\windows\System32\perfc009.dat

- 2009-02-07 14:32:15 123,350 ----a-w c:\windows\System32\perfc00C.dat

+ 2009-02-07 15:51:56 122,972 ----a-w c:\windows\System32\perfc00C.dat

- 2009-02-07 14:32:14 586,980 ----a-w c:\windows\System32\perfh009.dat

+ 2009-02-07 15:51:56 586,568 ----a-w c:\windows\System32\perfh009.dat

- 2009-02-07 14:32:15 669,328 ----a-w c:\windows\System32\perfh00C.dat

+ 2009-02-07 15:51:56 668,580 ----a-w c:\windows\System32\perfh00C.dat

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

"Google Update"="c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-01-31 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400]

"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"GrpConv"="grpconv -o" [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-01-01 91440]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-02-01 809488]

NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-09-14 1695744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"TCP Query User{FE192C99-F762-4C67-A785-5F3A41D8DF62}d:\\téléchargement\\emule\\emule.exe"= UDP:d:\téléchargement\emule\emule.exe:eMule

"UDP Query User{692464F3-7913-4E21-9CAF-3AB30118CAA5}d:\\téléchargement\\emule\\emule.exe"= TCP:d:\téléchargement\emule\emule.exe:eMule

"{A0E7E796-1336-4536-A8D7-54B1C9BA7263}"= UDP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club

"{4B9AB4D9-3443-4B49-965A-D4AB1DFF511E}"= TCP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club

"{CCD649DA-2F00-4967-9AD1-46E7D3851D4C}"= UDP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV

"{2DEFF54C-ED98-4FBE-9319-C05EB6478BA2}"= TCP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV

"TCP Query User{B2158CE8-CE96-4310-9239-F66D838D77F2}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV

"UDP Query User{EE3280B1-D7AE-4203-A78A-9A3C3F5E0BA5}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV

"{EBF77E48-737F-45CE-BED0-231E1F279A32}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{984D7E41-3872-45CD-98F5-9BF642AF7676}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{DC96EF1A-9B8E-4A25-8058-2802DCEF1C3E}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{5D56120D-D172-4CEB-B342-4B7545CAC497}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{F1C33631-2EF5-4F42-825C-AAFE1430902D}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{B1AF75A4-161C-4522-A072-F85DDC9F0217}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"TCP Query User{583738C4-BC3C-4FB4-B68A-CE146F866456}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser

"UDP Query User{FFBF7DB4-1604-4F83-9307-11D6E540DCF1}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser

"{54E1C3CE-3BDB-4334-838C-05773BF8753F}"= UDP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (TCP-In)

"{D684A30E-C1CB-4907-B0D3-26F8A29F4F8B}"= TCP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (UDP-In)

"{06DB5605-32B3-4F20-B88E-1147F7D46722}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box

"{199CB686-7667-48FC-9026-589C095A4210}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box

"{95714B72-F3EE-473D-AB8E-16EB882F299B}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box

"{154B4EBB-FDD7-4E54-BC9B-2D37B646DC4F}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box

"{E0F3CC28-90B4-41F5-9AC4-D1594BC76BF6}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box

"{E127B845-0CB9-497F-9E4B-5D0364DACA86}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box

"TCP Query User{ED445966-C75A-4471-8064-7BA0EA651A49}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"UDP Query User{0A2E0582-ACBC-40A3-82F3-7EE3D6AA30D2}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

R0 mv61xx;mv61xx;c:\windows\System32\drivers\mv61xx.sys [2008-07-22 151592]

S2 gupdate1c987c7b322b263;Google Update Service (gupdate1c987c7b322b263);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104]

S3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [2008-12-31 48128]

S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v3.sys [2008-12-30 227328]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - ECACHE

*Deregistered* - sptd

.

Contenu du dossier 'Tâches planifiées'

2009-02-07 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 20:21]

2009-02-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 20:26]

2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-192886970-665670061-1568562545-1000.job

- c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-31 11:24]

.

- - - - ORPHELINS SUPPRIMES - - - -

HKLM-RunOnce-<NO NAME> - (no file)

.

------- Examen supplémentaire -------

.

uStart Page = hxxp://www.google.fr/ig?hl=fr&source=iglk

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-07 17:14:42

Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès

Fichiers cachés: 0

**************************************************************************

.

--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'Explorer.exe'(632)

c:\program files\Microsoft Office\OFFICE11\msohev.dll

.

Heure de fin: 2009-02-07 17:15:12

ComboFix-quarantined-files.txt 2009-02-07 16:15:10

ComboFix2.txt 2009-02-07 14:39:46

Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.

Après-CF: 111,402,901,504 octets libres

222 --- E O F --- 2009-02-02 11:24:42

ComboFix 09-02-06.02 - Mathias 2009-02-07 17:13:02.2 - NTFSx86 MINIMAL

Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3326.2588 [GMT 1:00]

Lancé depuis: c:\users\Mathias\Desktop\ComboFix.exe

.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-07 au 2009-02-07 ))))))))))))))))))))))))))))))))))))

.

Pas de nouveau fichier créé dans ce laps de temps

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-07 09:58 --------- d-----w c:\users\Mathias\AppData\Roaming\uTorrent

2009-02-07 09:02 --------- d-----w c:\users\Mathias\AppData\Roaming\AIMP

2009-02-06 21:41 --------- d-----w c:\programdata\Electronic Arts

2009-02-06 21:23 --------- d-----w c:\programdata\Google Updater

2009-02-06 16:30 --------- d--h--w c:\program files\InstallShield Installation Information

2009-02-06 16:30 --------- d-----w c:\program files\Electronic Arts

2009-02-06 16:29 --------- d-----w c:\program files\Common Files\InstallShield

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\sessmgr.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\rsvp.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mstinit.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\mqtgsvc.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\clipsrv.exe

2009-02-06 16:12 81,920 ----a-w c:\users\Mathias\AppData\Roaming\cisvc.exe

2009-02-05 19:27 --------- d-----w c:\program files\Google

2009-02-05 17:16 --------- d-----w c:\users\Mathias\AppData\Roaming\Convivea

2009-02-04 17:26 --------- d-----w c:\program files\PDFCreator

2009-02-03 11:49 410,984 ----a-w c:\windows\System32\deploytk.dll

2009-02-03 11:49 --------- d-----w c:\program files\Java

2009-02-01 15:43 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf

2009-02-01 14:16 --------- d-----w c:\program files\Remove Empty Directories

2009-02-01 13:59 319,488 ----a-w c:\windows\HideWin.exe

2009-02-01 13:59 319,456 ----a-w c:\windows\DIFxAPI.dll

2009-01-31 11:22 --------- d-----w c:\program files\JKDefrag v3.36

2009-01-29 19:12 --------- d-----w c:\program files\Opera

2009-01-26 18:17 --------- d-----w c:\program files\directx

2009-01-23 11:47 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Pro

2009-01-21 17:16 --------- d-----w c:\program files\AIMP2

2009-01-15 17:58 --------- d-----w c:\program files\Malwarebytes' Anti-Malware

2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys

2009-01-14 07:15 4,235,776 ----a-w c:\windows\system32\drivers\atikmdag.sys

2009-01-14 06:55 --------- d-----w c:\program files\Windows Mail

2009-01-14 05:03 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll

2009-01-14 05:02 159,744 ----a-w c:\windows\System32\atitmmxx.dll

2009-01-14 05:01 43,520 ----a-w c:\windows\System32\ati2edxx.dll

2009-01-14 05:01 348,160 ----a-w c:\windows\System32\atipdlxx.dll

2009-01-14 05:01 286,720 ----a-w c:\windows\System32\Ati2evxx.dll

2009-01-14 05:01 274,432 ----a-w c:\windows\System32\Oemdspif.dll

2009-01-14 04:59 729,088 ----a-w c:\windows\System32\Ati2evxx.exe

2009-01-14 04:50 2,345,472 ----a-w c:\windows\System32\atidxx32.dll

2009-01-14 04:44 3,963,392 ----a-w c:\windows\System32\atiumdag.dll

2009-01-14 04:22 4,765,696 ----a-w c:\windows\System32\atiumdva.dll

2009-01-14 04:08 50,688 ----a-w c:\windows\System32\amdpcom32.dll

2009-01-14 04:07 122,880 ----a-w c:\windows\System32\atiadlxx.dll

2009-01-14 03:59 11,247,616 ----a-w c:\windows\System32\atioglxx.dll

2009-01-14 03:50 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll

2009-01-14 02:54 57,344 ----a-w c:\windows\System32\amdcalrt.dll

2009-01-14 02:53 53,248 ----a-w c:\windows\System32\amdcalcl.dll

2009-01-14 02:51 3,239,936 ----a-w c:\windows\System32\amdcaldd.dll

2009-01-12 19:03 --------- d-----w c:\program files\SystemRequirementsLab

2009-01-10 17:59 --------- d-----w c:\programdata\Media Center Programs

2009-01-09 21:04 --------- d-----w c:\program files\ATI

2009-01-09 12:33 --------- d-----w c:\program files\Lavalys

2009-01-09 12:30 --------- d-----w c:\programdata\ATI

2009-01-09 12:26 --------- d-----w c:\program files\ATI Technologies

2009-01-04 13:04 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf

2009-01-03 12:37 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2009-01-02 17:13 --------- d-----w c:\program files\CCleaner

2009-01-02 17:09 --------- d-----w c:\program files\K-Lite Codec Pack

2009-01-02 13:12 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf

2009-01-02 13:11 --------- d-----w c:\program files\Microsoft Xbox 360 Accessories

2009-01-01 20:52 130,208 ------r c:\windows\bwUnin-8.1.1.87-8876480SL.exe

2009-01-01 11:51 127,034 ------r c:\windows\bwUnin-8.1.1.50-8876480SL.exe

2009-01-01 11:51 --------- d-----w c:\users\Mathias\AppData\Roaming\Logitech

2009-01-01 11:51 --------- d-----w c:\program files\Common Files\Logishrd

2009-01-01 11:50 --------- d-----w c:\program files\Logitech

2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf

2009-01-01 11:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf

2009-01-01 11:48 --------- d-----w c:\users\Mathias\AppData\Roaming\InstallShield

2009-01-01 11:48 --------- d-----w c:\programdata\Logitech

2009-01-01 11:47 --------- d-----w c:\programdata\LogiShrd

2009-01-01 11:45 --------- d-----w c:\program files\Common Files\Logitech

2008-12-31 18:50 1,700,352 ----a-w c:\windows\System32\gdiplus.dll

2008-12-31 18:50 1,060,864 ----a-w c:\windows\System32\mfc71.dll

2008-12-31 18:41 --------- d--h--r c:\users\Mathias\AppData\Roaming\SecuROM

2008-12-31 18:41 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE

2008-12-31 18:37 107,888 ----a-w c:\windows\System32\CmdLineExt.dll

2008-12-31 16:52 --------- d-----w c:\program files\RocketDock

2008-12-31 15:14 --------- d-----w c:\program files\Microsoft.NET

2008-12-31 15:11 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools Lite

2008-12-30 22:55 --------- d-----w c:\program files\Quicksys

2008-12-30 22:52 --------- d-----w c:\users\Mathias\AppData\Roaming\SumatraPDF

2008-12-30 22:51 --------- d-----w c:\program files\SumatraPDF

2008-12-30 22:07 --------- d-----w c:\users\Mathias\AppData\Roaming\InfraRecorder

2008-12-30 22:07 --------- d-----w c:\program files\InfraRecorder

2008-12-30 21:53 --------- d-----w c:\users\Mathias\AppData\Roaming\DAEMON Tools

2008-12-30 21:52 --------- d-----w c:\programdata\DAEMON Tools Lite

2008-12-30 21:52 --------- d-----w c:\program files\DAEMON Tools Lite

2008-12-30 21:49 717,296 ----a-w c:\windows\system32\drivers\sptd.sys

2008-12-30 21:15 --------- d-----w c:\users\Mathias\AppData\Roaming\Malwarebytes

2008-12-30 21:15 --------- d-----w c:\programdata\Malwarebytes

2008-12-30 21:07 --------- d-----w c:\programdata\Avira

2008-12-30 21:07 --------- d-----w c:\program files\Avira

2008-12-30 21:00 --------- d-----w c:\program files\Media Player Classic

2008-12-30 20:59 --------- d-----w c:\users\Mathias\AppData\Roaming\Media Player Classic

2008-12-30 20:58 --------- d-----w c:\program files\IZArc

2008-12-30 20:31 --------- d-----w c:\program files\NETGEAR

2008-12-30 20:27 --------- d-----w c:\users\Mathias\AppData\Roaming\ATI

2008-12-30 20:25 --------- d-----w c:\program files\Common Files\ATI Technologies

2008-12-30 20:20 --------- d-----w c:\program files\Marvell

.

((((((((((((((((((((((((((((( SnapShot@2009-02-07_15.38.43,19 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-02-07 14:28:23 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2009-02-07 15:58:30 151,552 ----a-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT

- 2009-02-07 14:38:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2009-02-07 15:58:25 151,552 ----a-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT

- 2009-02-07 14:32:14 101,052 ----a-w c:\windows\System32\perfc009.dat

+ 2009-02-07 15:51:56 100,640 ----a-w c:\windows\System32\perfc009.dat

- 2009-02-07 14:32:15 123,350 ----a-w c:\windows\System32\perfc00C.dat

+ 2009-02-07 15:51:56 122,972 ----a-w c:\windows\System32\perfc00C.dat

- 2009-02-07 14:32:14 586,980 ----a-w c:\windows\System32\perfh009.dat

+ 2009-02-07 15:51:56 586,568 ----a-w c:\windows\System32\perfh009.dat

- 2009-02-07 14:32:15 669,328 ----a-w c:\windows\System32\perfh00C.dat

+ 2009-02-07 15:51:56 668,580 ----a-w c:\windows\System32\perfh00C.dat

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

"Google Update"="c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-01-31 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400]

"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"GrpConv"="grpconv -o" [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-01-01 91440]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-02-01 809488]

NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-09-14 1695744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"TCP Query User{FE192C99-F762-4C67-A785-5F3A41D8DF62}d:\\téléchargement\\emule\\emule.exe"= UDP:d:\téléchargement\emule\emule.exe:eMule

"UDP Query User{692464F3-7913-4E21-9CAF-3AB30118CAA5}d:\\téléchargement\\emule\\emule.exe"= TCP:d:\téléchargement\emule\emule.exe:eMule

"{A0E7E796-1336-4536-A8D7-54B1C9BA7263}"= UDP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club

"{4B9AB4D9-3443-4B49-965A-D4AB1DFF511E}"= TCP:d:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club

"{CCD649DA-2F00-4967-9AD1-46E7D3851D4C}"= UDP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV

"{2DEFF54C-ED98-4FBE-9319-C05EB6478BA2}"= TCP:d:\jeux\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV

"TCP Query User{B2158CE8-CE96-4310-9239-F66D838D77F2}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV

"UDP Query User{EE3280B1-D7AE-4203-A78A-9A3C3F5E0BA5}d:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:d:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV

"{EBF77E48-737F-45CE-BED0-231E1F279A32}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{984D7E41-3872-45CD-98F5-9BF642AF7676}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{DC96EF1A-9B8E-4A25-8058-2802DCEF1C3E}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{5D56120D-D172-4CEB-B342-4B7545CAC497}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{F1C33631-2EF5-4F42-825C-AAFE1430902D}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{B1AF75A4-161C-4522-A072-F85DDC9F0217}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"TCP Query User{583738C4-BC3C-4FB4-B68A-CE146F866456}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser

"UDP Query User{FFBF7DB4-1604-4F83-9307-11D6E540DCF1}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser

"{54E1C3CE-3BDB-4334-838C-05773BF8753F}"= UDP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (TCP-In)

"{D684A30E-C1CB-4907-B0D3-26F8A29F4F8B}"= TCP:d:\téléchargement\µTorrent\uTorrent.exe:µTorrent (UDP-In)

"{06DB5605-32B3-4F20-B88E-1147F7D46722}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box

"{199CB686-7667-48FC-9026-589C095A4210}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout Paradise The Ultimate Box

"{95714B72-F3EE-473D-AB8E-16EB882F299B}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box

"{154B4EBB-FDD7-4E54-BC9B-2D37B646DC4F}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout Paradise The Ultimate Box

"{E0F3CC28-90B4-41F5-9AC4-D1594BC76BF6}"= UDP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box

"{E127B845-0CB9-497F-9E4B-5D0364DACA86}"= TCP:d:\jeux\Burnout Paradise The Ultimate Box\BurnoutParadise.exe:Burnout Paradise The Ultimate Box

"TCP Query User{ED445966-C75A-4471-8064-7BA0EA651A49}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"UDP Query User{0A2E0582-ACBC-40A3-82F3-7EE3D6AA30D2}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

R0 mv61xx;mv61xx;c:\windows\System32\drivers\mv61xx.sys [2008-07-22 151592]

S2 gupdate1c987c7b322b263;Google Update Service (gupdate1c987c7b322b263);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104]

S3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [2008-12-31 48128]

S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v3.sys [2008-12-30 227328]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - ECACHE

*Deregistered* - sptd

.

Contenu du dossier 'Tâches planifiées'

2009-02-07 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 20:21]

2009-02-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 20:26]

2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-192886970-665670061-1568562545-1000.job

- c:\users\Mathias\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-31 11:24]

.

- - - - ORPHELINS SUPPRIMES - - - -

HKLM-RunOnce-<NO NAME> - (no file)

.

------- Examen supplémentaire -------

.

uStart Page = hxxp://www.google.fr/ig?hl=fr&source=iglk

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-07 17:14:42

Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès

Fichiers cachés: 0

**************************************************************************

.

--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'Explorer.exe'(632)

c:\program files\Microsoft Office\OFFICE11\msohev.dll

.

Heure de fin: 2009-02-07 17:15:12

ComboFix-quarantined-files.txt 2009-02-07 16:15:10

ComboFix2.txt 2009-02-07 14:39:46

Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.

Après-CF: 111,402,901,504 octets libres

222 --- E O F --- 2009-02-02 11:24:42

Lien vers le commentaire
Partager sur d’autres sites

Yop ;)

Un ami a moi n'arrive plus a ouvrir windows media player sauf clique droit ouvrir en tant qu'admin.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:03:32, on 09/02/2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\Lexmark 2500 Series\lxddamon.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe

C:\Users\Kheiz\AppData\Local\Google\Update\GoogleUpdate.exe

C:\Users\Kheiz\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe

C:\Users\Kheiz\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

C:\Windows\system32\wuauclt.exe

C:\Users\Kheiz\Program Files\uTorrent\uTorrent.exe

C:\Windows\system32\conime.exe

C:\Program Files\TVersity\Media Server\web\admin\TVersity.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll

O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll

O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll

O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll

O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - C:\Program Files\BS.Player ControlBar\BSToolbar.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"

O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"

O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"

O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Users\Kheiz\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-21-3718856369-1133722837-3043362797-1011\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Mcx3')

O4 - Startup: Outil de notification Live Search.lnk = Kheiz\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe

O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm

O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir au format PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm

O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html

O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html

O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)

O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)

O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll

O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe

O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

O13 - Gopher Prefix:

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.2.cab

O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Installer) - http://t1.battlefield-heroes.com/patcher/westpatcher.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O22 - SharedTaskScheduler: Stardock Vista ControlPanel Extension - {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll

O22 - SharedTaskScheduler: StardockDreamController - {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll

O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)

O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing)

O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Cadence License Manager - Macrovision Corporation - C:\OrCAD\license_manager\lmgrd.exe

O23 - Service: Eset Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (file missing)

O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Windows Live Family Safety (fsssvc) - Unknown owner - C:\Program Files\Windows Live\Family Safety\fsssvc.exe (file missing)

O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:\Windows\system32\HDDSvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe

O23 - Service: lxdd_device - - C:\Windows\system32\lxddcoms.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe

O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe

--

End of file - 14680 bytes

Lien vers le commentaire
Partager sur d’autres sites

Alors salut a tous, j'ai un problem avec mon ordi depuis environ 3 semaines, j'ai fais des recherches. Voila, j'ai une application nommé system dans task manager et il prend environ 60 Mo d'utilisation de mémoire. Je ne suis pas capable de l'enlever ou de le stopper. J'ai intaller security task manager et j'ai découvert que c'étais le fichier dva.386 qui demarrer le fichier system au demarage. Mais je ne suis toujours pas capable de l'enlever. Alors si vous savez quoi je devrais faire pour m'en debarasser svp me répondre

Merci !

Voila mon log HijackThis

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:26:05, on 2009-02-10

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\UnivLaval\cvpnd.exe

C:\WINDOWS\system32\DVDRAMSV.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\WINDOWS\system32\TPSMain.exe

C:\Program Files\ltmoh\Ltmoh.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\RAMASST.exe

C:\WINDOWS\system32\TPSBattM.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Apoint2K\Apntex.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\MSN Messenger\usnsvc.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

C:\Documents and Settings\Yo\Mes documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [TPSMain] TPSMain.exe

O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"

O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe

O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226270831125

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichier...ion_3_1_0_4.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\UnivLaval\cvpnd.exe

O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe

O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--

End of file - 9207 bytes

Lien vers le commentaire
Partager sur d’autres sites

@ meuhkalisse :

Avec Hijackthis , coche et Fixchecked toutes les lignes 04 , sauf AVG8.

Redémarre le pc .

Le problème est-il toujours présent ?

______________________________________

@ bob63 :

Avec Hijackthis , coche et Fixchecked toutes les lignes 04 , sauf Nod32.

Désactive Windows Defender > http://infomars.fr/forum/index.php?showtopic=1244

Redémarre le pc .

Lance ComboFix et poste le rapport créé > http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Lien vers le commentaire
Partager sur d’autres sites

Salut Snooky!

J'ai fais ce que tu m'as dis mais le programme system est toujours présent. Mon ordinateur est vraiment plus rapide au démarrage pcq plus rien ne démarre au démaragge. Alors, quoi faire maintenant. L'application system (image créer par dva.386) reste toujours insupprimable.

Je fais également te parler de mes autres problèmes avec mon super portable que j'adore!!!

1. Lorsqu'il se met en veille, lorsque je veux le sortir de veille si je jpeux dire, l'écran n'apparait plus et je dois restarter mon ordinateur et si je veux que l'écran revienne au redemarrage, il faut que j'enleve le courant de mon ordi.

2. Certaine fois, apres que mon ordi s'aille mis en veille, mon son ne marche plus et je dois redemarrer. En plus, mon touchpad fais la meme affaire mais jamais en meme temps que le son. Soit l'un marche, ou soit l'autre.

Alors dit moi ce que tu en pense...

P.s. J'ai souvent envie de le jeter ce petit portable

Merci d'avance

Lien vers le commentaire
Partager sur d’autres sites

Je t'envoi des informations sur le fichier system : Nom de l'image: System ; Nom de l'utilisateur : SYSTEM ; Habituellement, il y a 0 processeur utilisés ; et il prend 61 000 Ko d'utilisation de mémoire. Selon security task manager, c'est le fichier dva.386 qui est le problème. Ce fichier est-il vraiment important au fonctionnement du système ou bien je peux le supprimer ? Merci encore!

Lien vers le commentaire
Partager sur d’autres sites

Un peu de nouveau sur mon sujet, j'ai regardé sur plusieurs ordinateurs utilisant xp tout comme moi et le fichier dva.386 n'était sur aucun ordinateur. Le mien se situe dans C:/WINDOWS/system . L'idée de supprimer le fichier m'est venu et j'ai essayer mais le processus au nom de system est toujours la et il utilise encore 60 Mo de mémoire. Il passes fréquamment de 0 a 2 processeur utilisé.

Je me demande maintenant si ce processus est normal ou non vu qu'il n'a vraisemblablement aucun moyen de l'enlever.

Merci de me repondre!

Gab

Lien vers le commentaire
Partager sur d’autres sites

...

Merci de me repondre!

Gab

Calmos :transpi: .

On est sur un forum, les gens viennent aider quand ils peuvent :8.

C'est également pour cela, qu'on demande aussi aux gens de ne pas "remonter" leur sujet, plus d'une fois par jour.

Ca ne sert à rien de s'impatienter, d'autant plus si ça fait depuis environ 3 semaines que tu as ce problème...

Lien vers le commentaire
Partager sur d’autres sites

[

@ bob63 :

Avec Hijackthis , coche et Fixchecked toutes les lignes 04 , sauf Nod32.

Désactive Windows Defender > http://infomars.fr/forum/index.php?showtopic=1244

Redémarre le pc .

Lance ComboFix et poste le rapport créé > http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Voila

ComboFix 09-02-11.02 - Kheiz 2009-02-12 1:40:21.1 - NTFSx86

Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1273 [GMT 1:00]

Lancé depuis: c:\users\Kheiz\Desktop\ComboFix.exe

AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)

FW: ESET Personal firewall *disabled*

* Un nouveau point de restauration a été créé

.

ADS - system32: deleted 12 bytes in 1 streams.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\config.ini

.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-12 au 2009-02-12 ))))))))))))))))))))))))))))))))))))

.

2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Videos

2009-02-09 20:54 . 2006-11-02 11:23 <REP> d-------- c:\users\Mcx3\Saved Games

2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Pictures

2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Music

2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Links

2009-02-09 20:54 . 2006-11-02 11:23 <REP> dr------- c:\users\Mcx3\Downloads

2009-02-09 20:54 . 2009-02-09 20:54 <REP> dr------- c:\users\Mcx3\Documents

2009-02-09 20:54 . 2009-02-09 20:55 <REP> d--h----- c:\users\Mcx3\AppData

2009-02-09 20:54 . 2009-02-09 20:54 <REP> d-------- c:\users\Mcx3

2009-01-30 20:54 . 2008-12-22 23:36 729,088 --a------ C:\JungleFlasher.exe

2009-01-30 20:54 . 2008-09-26 01:49 95,232 --a------ C:\PortIO32.exe

2009-01-30 20:50 . 2009-01-30 21:03 <REP> d-------- c:\windows\PortIO32

2009-01-30 11:07 . 2009-01-30 11:07 <REP> d-------- c:\program files\Prolific

2009-01-30 11:07 . 2007-07-31 18:45 76,800 --a------ c:\windows\System32\drivers\ser2pl.sys

2009-01-27 21:23 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys

2009-01-25 19:17 . 2009-01-25 19:17 <REP> d-------- c:\program files\llionsoft

2009-01-25 19:11 . 2009-01-25 19:14 <REP> d-------- c:\program files\PDF Blender

2009-01-19 19:28 . 2000-07-21 09:11 33,040 --a------ c:\windows\System32\DBNM606e.rra

2009-01-19 19:01 . 1999-03-08 20:28 309,760 --a------ c:\windows\System32\lmgr326b.dll

2009-01-19 16:22 . 2009-01-19 16:59 <REP> d-------- C:\calu

2009-01-18 17:58 . 2009-01-18 17:58 <REP> d-------- c:\users\Kheiz\AppData\Roaming\Red Kawa

2009-01-14 23:28 . 2009-01-22 21:12 <REP> d-------- c:\program files\RomStation

2009-01-14 16:27 . 2009-01-14 16:27 1,492 --a------ C:\ff8input.cfg

2009-01-14 15:32 . 2009-01-14 15:32 <REP> d-------- c:\program files\Creative Labs

2009-01-14 15:32 . 1999-07-06 14:13 40,960 --a------ c:\windows\System32\eax.dll

2009-01-14 15:31 . 2009-01-14 15:31 <REP> d-------- c:\program files\Eidos Interactive

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-11 22:26 --------- d-----w c:\users\Kheiz\AppData\Roaming\GrabIt

2009-02-11 18:15 --------- d-----w c:\program files\GrabIt

2009-02-10 22:50 --------- d-----w c:\program files\Messenger Plus! Live

2009-02-10 18:17 --------- d-----w c:\users\Kheiz\AppData\Roaming\uTorrent

2009-01-30 10:07 --------- d--h--w c:\program files\InstallShield Installation Information

2009-01-29 17:05 --------- d-----w c:\program files\Lx_cats

2009-01-27 20:26 --------- d-----w c:\programdata\Microsoft Help

2009-01-27 20:26 --------- d-----w c:\program files\Windows Mail

2009-01-27 11:21 --------- d-----w c:\program files\Cpukiller3

2009-01-20 18:57 --------- d-----w c:\users\Kheiz\AppData\Roaming\Thinstall

2009-01-17 20:50 --------- d-----w c:\programdata\Apple Computer

2009-01-11 16:05 --------- d-----w c:\program files\Sun

2009-01-11 13:07 --------- d-----w c:\programdata\Last.fm

2009-01-11 13:07 --------- d-----w c:\program files\Last.fm

2009-01-11 13:07 --------- d-----w c:\program files\iTunes

2009-01-11 11:32 --------- d-----w c:\users\Kheiz\AppData\Roaming\Download Manager

2009-01-09 16:27 --------- d-----w c:\program files\Mail Bomber

2009-01-06 17:52 --------- d-----w c:\program files\VirtualDub

2009-01-06 17:50 --------- d-----w c:\program files\RADVideo

2009-01-05 20:22 --------- d-----w c:\program files\Red Kawa

2009-01-05 19:30 --------- d-----w c:\program files\Common Files\Business Objects

2009-01-05 19:30 --------- d-----w c:\program files\Business Objects

2009-01-05 19:22 --------- d-----w c:\programdata\Macrovision

2009-01-05 19:16 --------- d-----w c:\program files\Ripp-it_AM

2009-01-05 19:13 --------- d-----w c:\program files\AviSynth 2.5

2008-12-30 20:55 --------- d-----w c:\program files\HighGrow

2008-12-30 17:11 --------- d-----w c:\program files\abgx360

2008-12-30 13:10 --------- d-----w c:\program files\Steam

2008-12-29 21:48 --------- d-----w c:\programdata\OrbNetworks

2008-12-29 13:15 --------- d-----w c:\programdata\Xfire

2008-12-29 13:15 --------- d-----w c:\program files\Xfire

2008-12-29 12:20 --------- d-----w c:\users\Kheiz\AppData\Roaming\Xfire

2008-12-28 17:26 --------- d-----w c:\program files\Virtual Earth 3D

2008-12-28 12:16 --------- d-----w c:\program files\DVD Decrypter

2008-12-27 20:07 --------- d-----w c:\program files\Orb Networks

2008-12-26 19:39 --------- d-----w c:\program files\Custom-Strike

2008-12-26 19:26 --------- d-----w c:\program files\SprayR

2008-12-26 14:44 --------- d-----w c:\program files\CCleaner

2008-12-26 14:40 --------- d-----w c:\program files\Common Files\Adobe

2008-12-26 14:38 --------- d-----w c:\users\Kheiz\AppData\Roaming\com.adobe.ExMan

2008-12-26 14:33 --------- d-----w c:\users\Kheiz\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

2008-12-25 07:38 --------- d-----w c:\program files\DemoForge

2008-12-25 06:48 --------- d-----w c:\programdata\NVIDIA

2008-12-24 10:13 --------- d-----w c:\program files\Common Files\PX Storage Engine

2008-12-24 09:36 --------- d-----w c:\program files\Adobe Media Player

2008-12-24 09:35 --------- d-----w c:\program files\Common Files\Adobe AIR

2008-12-23 08:05 --------- d-----w c:\program files\RegCleaner

2008-12-22 21:23 --------- d-----w c:\program files\UDPixel

2008-12-22 18:35 --------- d-----w c:\program files\Common Files\Steam

2008-12-19 18:11 --------- d---a-w c:\programdata\TEMP

2008-12-19 13:09 --------- d-----w c:\users\Kheiz\AppData\Roaming\LimeWire

2008-12-18 12:31 --------- d-----w c:\users\Kheiz\AppData\Roaming\DiskAid

2008-12-18 12:26 --------- d-----w c:\program files\WinSCP

2008-12-18 11:18 --------- d-----w c:\program files\Microsoft Silverlight

2008-12-17 19:22 --------- d-----w c:\programdata\WLInstaller

2008-12-17 19:22 --------- d-----w c:\program files\Windows Live

2008-12-17 18:59 --------- d-----w c:\program files\Windows Live SkyDrive

2008-12-17 18:59 --------- d-----w c:\program files\Microsoft

2008-12-17 09:57 129,552 ----a-w c:\windows\System32\VBoxNetFltNotify.dll

2008-12-17 09:56 81,360 ----a-w c:\windows\system32\drivers\VBoxNetFlt.sys

2008-12-17 09:56 41,680 ----a-w c:\windows\system32\drivers\VBoxUSBMon.sys

2008-12-17 09:56 100,368 ----a-w c:\windows\system32\drivers\VBoxDrv.sys

2008-12-16 19:26 --------- d-----w c:\program files\DigiDNA

2008-12-16 12:52 --------- d-----w c:\users\Kheiz\AppData\Roaming\Apple Computer

2008-12-16 12:48 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf

2008-12-11 20:37 42,320 ----a-w c:\windows\System32\xfcodec.dll

2008-12-06 17:27 274,781 ----a-w c:\windows\Fast Video to GIF SWF Converter Uninstaller.exe

2008-12-02 21:37 49,480 ----a-w c:\windows\System32\sirenacm.dll

2008-07-27 20:21 174 --sha-w c:\program files\desktop.ini

2007-12-17 16:23 1,136,640 ----a-w c:\program files\Common Files\ewutils2.dll

2007-10-18 16:21 92,064 ----a-w c:\users\Kheiz\mqdmmdm.sys

2007-10-18 16:21 9,232 ----a-w c:\users\Kheiz\mqdmmdfl.sys

2007-10-18 16:21 79,328 ----a-w c:\users\Kheiz\mqdmserd.sys

2007-10-18 16:21 66,656 ----a-w c:\users\Kheiz\mqdmbus.sys

2007-10-18 16:21 6,208 ----a-w c:\users\Kheiz\mqdmcmnt.sys

2007-10-18 16:21 5,936 ----a-w c:\users\Kheiz\mqdmwhnt.sys

2007-10-18 16:21 4,048 ----a-w c:\users\Kheiz\mqdmcr.sys

2007-10-18 16:21 25,600 ----a-w c:\users\Kheiz\usbsermptxp.sys

2007-10-18 16:21 22,768 ----a-w c:\users\Kheiz\usbsermpt.sys

2008-01-03 18:48 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

2008-01-03 18:48 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

2008-02-22 10:32 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-03-02 949376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.i420"= i263_32.drv

"VIDC.X264"= x264vfw.dll

"VIDC.XFR1"= xfcodec.dll

"msacm.g723"= g723.acm

"vidc.I263"= I263_32.drv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]

--a------ 2007-05-04 07:40 312240 c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]

--a------ 2007-03-05 08:40 20480 c:\program files\Lexmark 2500 Series\lxddamon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]

--a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]

"c:\\Program Files\\FlashFXP\\FlashFXP.exe"= c:\program files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3

"c:\\Program Files\\Lexmark 2500 Series\\app4r.exe"= c:\program files\Lexmark 2500 Series\app4r.exe:*:Enabled:Lexmark Imaging Studio

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{406EA5D1-EE2C-4FBF-AC1C-F6986F6ED448}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{CA255E8D-29F6-4998-A33B-C2AA93F5A415}"= UDP:3703:Adobe Version Cue CS3 Server

"{1A9436AC-0028-4EDC-BBD8-C8D3142BCA8A}"= UDP:3704:Adobe Version Cue CS3 Server

"{9C4FCA7F-10A2-4B48-ACF3-C1C5F137BD01}"= UDP:50900:Adobe Version Cue CS3 Server

"{23B8FB25-0396-4186-8B0C-9B9DEA86E5FF}"= UDP:50901:Adobe Version Cue CS3 Server

"{952D2727-8485-4719-84CD-BA9B6134B13F}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server

"{C3AD499C-C59D-4308-AFD5-9AAC7F263A09}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server

"{E99AA100-3AE7-4641-8933-0F470468F18C}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader

"{C689CB64-C533-43B5-9E81-5077A119474F}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader

"TCP Query User{3DDD9BD4-0907-4AEC-9419-9078F4DFCE29}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet

"UDP Query User{58481F26-BFBB-4FC7-9B6B-078A522A4368}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet

"TCP Query User{F2A31159-75FA-44D6-843F-060920B0619E}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM

"UDP Query User{9E2063B4-61EB-4E23-86F7-B392C7701D26}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM

"TCP Query User{27560A2E-76C7-4698-A54E-BDA91B46DD2F}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer

"UDP Query User{0AC2E0A9-3F3A-4B07-A4F3-344B79C274A6}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer

"TCP Query User{1335C668-954D-4E3C-A2D3-F25014023163}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox

"UDP Query User{39361653-6488-4AC9-8E97-CA3B1481FCC0}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox

"TCP Query User{DCF3C640-0400-4156-879F-8D95F2DE48FA}c:\\program files\\flashfxp\\flashfxp.exe"= UDP:c:\program files\flashfxp\flashfxp.exe:FlashFXP

"UDP Query User{CCB1B42A-35E7-4502-8747-B610B0C6D40C}c:\\program files\\flashfxp\\flashfxp.exe"= TCP:c:\program files\flashfxp\flashfxp.exe:FlashFXP

"{C36F6FD2-B103-4E98-86BD-6C30A669540D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

"{78E80BC7-7CFD-40E1-B460-6AFB5F2AE5DA}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

"TCP Query User{1D068E28-EF02-4D21-BD32-243AAEFAF98E}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC

"UDP Query User{DF067CB3-45F9-4ED9-9587-D4A8C49736A8}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC

"TCP Query User{9DDCE556-D48F-4FA4-84C9-3D7044944146}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus

"UDP Query User{1E5D411C-293F-4A2A-A1A6-E516361B2835}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus

"{94BDBE3B-75F6-43EC-A53F-AA8BDC2EAD98}"= UDP:13210:BitComet 13210 TCP

"{E692FC4F-56AD-4160-BA8A-B353998A17F4}"= TCP:13210:BitComet 13210 UDP

"TCP Query User{EB194772-EEDE-4E80-8B73-BA0006FAF16E}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client

"UDP Query User{D7018494-B4DA-4E83-A80F-7D1E8994720B}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client

"TCP Query User{58D3A39D-4A4F-42C1-BE1F-5C43FA3894CE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent

"UDP Query User{66964E55-0AED-49C8-8FCC-EFC1F906E5B6}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent

"TCP Query User{B14AE775-A4E8-41B7-A42D-0FAF9A251115}c:\\users\\kheiz\\appdata\\local\\temp\\rar$ex00.740\\wlm lite 8.5.exe"= UDP:c:\users\kheiz\appdata\local\temp\rar$ex00.740\wlm lite 8.5.exe:wlm lite 8.5.exe

"UDP Query User{3B4E1DB7-A4C3-45A0-8B1D-AFBBF00BED58}c:\\users\\kheiz\\appdata\\local\\temp\\rar$ex00.740\\wlm lite 8.5.exe"= TCP:c:\users\kheiz\appdata\local\temp\rar$ex00.740\wlm lite 8.5.exe:wlm lite 8.5.exe

"TCP Query User{E33C9B30-CF2B-480C-AD86-3696FC7A0DDB}c:\\program files\\vidalia bundle\\tor\\tor.exe"= UDP:c:\program files\vidalia bundle\tor\tor.exe:tor

"UDP Query User{1AAB29DE-97B0-49CD-A9DC-14AE61C0826B}c:\\program files\\vidalia bundle\\tor\\tor.exe"= TCP:c:\program files\vidalia bundle\tor\tor.exe:tor

"TCP Query User{920805D1-8E53-4B76-80BD-0A26D7473B4F}c:\\users\\kheiz\\desktop\\wlm lite 8.5.exe"= UDP:c:\users\kheiz\desktop\wlm lite 8.5.exe:wlm lite 8.5.exe

"UDP Query User{B5AFDE00-DA3A-41A5-80B6-12F61B39AE2A}c:\\users\\kheiz\\desktop\\wlm lite 8.5.exe"= TCP:c:\users\kheiz\desktop\wlm lite 8.5.exe:wlm lite 8.5.exe

"{1FD3CA6D-2149-48CA-A36F-E0E379D97BBC}"= UDP:c:\program files\Microsoft Games\Viva Pinata\Viva Pinata.exe:Viva Piñata

"{AF3D2819-2251-4C60-AB2E-19BAD7F57DA9}"= TCP:c:\program files\Microsoft Games\Viva Pinata\Viva Pinata.exe:Viva Piñata

"TCP Query User{27A690DA-B5EF-4A92-804D-1BC28879BE05}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client

"UDP Query User{E309E3EC-09CF-49A5-B7A3-3E5683A624CE}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client

"TCP Query User{92E20042-F382-4016-8C19-A14C9E53271E}c:\\program files\\thq\\frontlines-fuel of war beta\\binaries\\ffow-beta.exe"= UDP:c:\program files\thq\frontlines-fuel of war beta\binaries\ffow-beta.exe:Frontlines Game

"UDP Query User{C9B3E2CC-325D-4BBB-8F52-B1F079DAAD08}c:\\program files\\thq\\frontlines-fuel of war beta\\binaries\\ffow-beta.exe"= TCP:c:\program files\thq\frontlines-fuel of war beta\binaries\ffow-beta.exe:Frontlines Game

"TCP Query User{FD3644B6-FAC3-4C94-898C-455B6896EC58}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire

"UDP Query User{F664FDC4-1945-4EEB-8CE0-08729D1905D2}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire

"{37BBC581-EE36-46D7-811C-2732232FC739}"= UDP:c:\program files\THQ\Frontlines-Fuel of War\Binaries\FFOW.exe:Frontlines Game

"{35063291-5A40-4F8B-89BE-CBE7F2C728E6}"= TCP:c:\program files\THQ\Frontlines-Fuel of War\Binaries\FFOW.exe:Frontlines Game

"TCP Query User{5614E7F9-39FE-4418-861A-C465392F3F26}c:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader

"UDP Query User{36244725-E512-4E48-A1F3-FC18A2578B61}c:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader

"TCP Query User{0BDE77AB-8E10-482F-9E10-94061EADCA83}c:\\program files\\free music zilla\\fmzilla.exe"= UDP:c:\program files\free music zilla\fmzilla.exe:FMZilla Module

"UDP Query User{A49DAC03-63B6-4441-886D-4323BB902613}c:\\program files\\free music zilla\\fmzilla.exe"= TCP:c:\program files\free music zilla\fmzilla.exe:FMZilla Module

"TCP Query User{F1B9967E-8DD3-45A7-9CD6-17538F8DE11D}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe

"UDP Query User{BD7B4D2E-5318-42EB-B4EA-33C4711CAC09}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe

"TCP Query User{B41A77FB-D66F-4B81-88C0-674361D98160}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player

"UDP Query User{2CAB7BB5-7487-43C5-801A-D101F01BA7B0}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player

"TCP Query User{E890D0D8-BE41-44C0-AF50-8D017576E3AD}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire

"UDP Query User{D24171BD-341B-475B-8A96-663D2C835D16}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire

"TCP Query User{8A482DDB-8CEB-4DCF-92BC-BE49A65DD452}c:\\program files\\xi\\netxfer\\nettransport.exe"= UDP:c:\program files\xi\netxfer\nettransport.exe:NetXfer Download Manager

"UDP Query User{7133E79D-00B7-4E75-825D-538E97872EA8}c:\\program files\\xi\\netxfer\\nettransport.exe"= TCP:c:\program files\xi\netxfer\nettransport.exe:NetXfer Download Manager

"TCP Query User{F504DDCF-BD45-4A00-B776-A13BCE294269}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= UDP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III

"UDP Query User{F7AB187A-2DF3-48F7-8BE5-D16E23AC42C4}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= TCP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III

"TCP Query User{CA383E5E-25C0-4B91-8963-8C73D82A7A42}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule

"UDP Query User{0FFD6DC8-82FA-48BD-BE7B-5505DF184B01}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule

"TCP Query User{1E1846AF-207A-4F46-B706-416F670646FE}c:\\program files\\transcode360\\transcode360tray.exe"= UDP:c:\program files\transcode360\transcode360tray.exe:

"UDP Query User{4D79164D-3C04-4E1C-88A9-17C1B74B960A}c:\\program files\\transcode360\\transcode360tray.exe"= TCP:c:\program files\transcode360\transcode360tray.exe:

"TCP Query User{12B5EF44-7FFE-4628-AB2D-7D5BB1EF8972}c:\\users\\kheiz\\desktop\\lhemule53\\lhemule53\\emule.exe"= UDP:c:\users\kheiz\desktop\lhemule53\lhemule53\emule.exe:emule.exe

"UDP Query User{47545739-5B69-4AE4-8576-EEFD865947BD}c:\\users\\kheiz\\desktop\\lhemule53\\lhemule53\\emule.exe"= TCP:c:\users\kheiz\desktop\lhemule53\lhemule53\emule.exe:emule.exe

"{73B4F511-2247-45E0-9894-597943CEB582}"= UDP:c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{99DABFDD-BCDA-4607-9A9C-8105FD0D0E0E}"= TCP:c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{5E9F2F92-302C-417E-AB31-6563754FF22B}"= UDP:c:\program files\FreeCall.com\FreeCall\FreeCall.exe:FreeCall

"{86BD089C-09F4-4697-B955-888A04EB5922}"= TCP:c:\program files\FreeCall.com\FreeCall\FreeCall.exe:FreeCall

"TCP Query User{5CEB96F9-9D01-4836-A0FF-0046BCA41DB5}c:\\users\\kheiz\\desktop\\bot\\spamer.exe"= UDP:c:\users\kheiz\desktop\bot\spamer.exe:spamer.exe

"UDP Query User{DA6E3D28-1891-478F-84C7-620CEE3DE0F3}c:\\users\\kheiz\\desktop\\bot\\spamer.exe"= TCP:c:\users\kheiz\desktop\bot\spamer.exe:spamer.exe

"TCP Query User{265CD8AE-0938-49C6-9FE9-D9BCB06A9D28}c:\\program files\\xbc\\nexbc.exe"= UDP:c:\program files\xbc\nexbc.exe:XBConnect

"UDP Query User{8CA99E93-32A5-44D9-8027-274AEF462B44}c:\\program files\\xbc\\nexbc.exe"= TCP:c:\program files\xbc\nexbc.exe:XBConnect

"{5F350EDB-42B3-42C2-8268-E5CCC76CF445}"= UDP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System

"{46A61804-B698-47F3-9392-830FCC5310AB}"= TCP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System

"{0A3FA6C7-5284-4895-909C-E911A046D6D0}"= UDP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor

"{F514105E-AA7C-49E5-B958-D7063B014D49}"= TCP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor

"{92DFF8ED-AD82-40DE-85DD-C4F979E1E839}"= UDP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio

"{C4B7D5A9-5665-49E1-8E39-6FA748A3D3DD}"= TCP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio

"{16A8BCA3-EF2B-45E0-9F32-8B066C5AA82D}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe:

"{2FFBB25E-7616-422C-B956-6FD2979C9DDC}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe:

"{86FD683A-8AE4-4F7B-A8A9-2286346D31A3}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe:

"{06D5DD6A-BD46-44D4-AF2D-4FF8805B4772}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe:

"TCP Query User{F5C205FD-2FC2-490C-8523-3983CE684BC5}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= UDP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe

"UDP Query User{98924300-C71C-4F03-ACAA-3443333DE03B}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= TCP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe

"{82F6F97F-658F-4316-9C3D-E744C5F8C548}"= UDP:c:\program files\Leaf Networks\Leaf\bin\Leaf.exe:Leaf

"{376FDB3D-0447-4850-BDC5-F6F61CB6EE9E}"= TCP:c:\program files\Leaf Networks\Leaf\bin\Leaf.exe:Leaf

"TCP Query User{3A360E7F-4140-4717-A473-59D54E7785D3}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe

"UDP Query User{B43F923D-D1B4-4654-B516-CA35687DFFD7}c:\\users\\kheiz\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\kheiz\program files\utorrent\utorrent.exe:utorrent.exe

"TCP Query User{70AFB64D-8838-4A8F-A4A9-0CA8A1B46B67}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= UDP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe

"UDP Query User{D47393D0-7790-42C6-A0B6-5A4D549D5EED}c:\\users\\kheiz\\downloads\\ratiomaster_v1.7.5_-updated-\\ratiomaster 1.7.5 updated\\ratiomaster.exe"= TCP:c:\users\kheiz\downloads\ratiomaster_v1.7.5_-updated-\ratiomaster 1.7.5 updated\ratiomaster.exe:ratiomaster.exe

"TCP Query User{0801D3F9-1F29-4F3F-AD42-7D3A4BE958B7}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player

"UDP Query User{EB8896BA-2254-4BE3-8F62-1FBA5448159D}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player

"TCP Query User{32339FDA-6512-45DF-AB70-DC9E52BE7047}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet

"UDP Query User{C1D3F69A-B74E-4190-A3EE-F6DB680D1690}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet

"TCP Query User{6EDEEDD9-F9C4-4BD8-B17A-607F043158CC}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= UDP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III

"UDP Query User{9BD03276-9794-4F5C-A2C8-0E190BF4E2F3}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= TCP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III

"TCP Query User{E9848EB1-D159-4541-A9A5-DBCD5CFDB51F}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"UDP Query User{6CDFB351-990F-4458-A25F-1789BF673A40}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"TCP Query User{B89960F5-F9AF-44CA-9B91-7BBC896B3A8E}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application

"UDP Query User{07FF5208-9FB5-4579-B1C7-68F3A3F1ECC0}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application

"TCP Query User{989DA9A5-4F82-4E66-9E9E-C9109CD59A33}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver

"UDP Query User{061A6796-A2CE-4CAE-AC07-05B17742D5AB}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver

"TCP Query User{AA05F0DE-51D9-47B6-BDD0-42E06350963D}c:\\program files\\transcode360\\transcode360tray.exe"= UDP:c:\program files\transcode360\transcode360tray.exe:

"UDP Query User{1A1686F6-DA31-451F-B84A-7C24CD6D42BA}c:\\program files\\transcode360\\transcode360tray.exe"= TCP:c:\program files\transcode360\transcode360tray.exe:

"{70BF44B9-CBE5-4F21-95F3-B4D15BE77FEB}"= UDP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server

"{B9018C9A-44CB-459A-BF49-1776660E9D27}"= TCP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server

"{E5BC873E-F102-4AF4-9024-5FB92673E87A}"= UDP:c:\program files\Lexmark 2500 Series\lxddmon.exe:

"{00571A5A-815A-46C8-B992-E7A8727E19E4}"= TCP:c:\program files\Lexmark 2500 Series\lxddmon.exe:

"{8949DA0A-A4A3-4610-A94E-D2C0F9EBBD1A}"= UDP:c:\users\Kheiz\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)

"{1E6BE95A-61E0-4DAD-9F18-F5C8773DC4D6}"= TCP:c:\users\Kheiz\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

"TCP Query User{09B85EBD-E0B3-4683-A68D-19E82C2E0E95}c:\\users\\kheiz\\desktop\\wlm lite 8.5 finale fr [www.msncreative.net].exe"= UDP:c:\users\kheiz\desktop\wlm lite 8.5 finale fr [www.msncreative.net].exe:wlm lite 8.5 finale fr [www.msncreative.net].exe

"UDP Query User{3D66E89F-753C-4FDC-B2C3-83C095E475D2}c:\\users\\kheiz\\desktop\\wlm lite 8.5 finale fr [www.msncreative.net].exe"= TCP:c:\users\kheiz\desktop\wlm lite 8.5 finale fr [www.msncreative.net].exe:wlm lite 8.5 finale fr [www.msncreative.net].exe

"TCP Query User{C047936E-C49F-4101-94CC-3D6E319DDF12}c:\\users\\kheiz\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\kheiz\appdata\local\google\chrome\application\chrome.exe:chrome.exe

"UDP Query User{AB8A863C-8D34-4242-89AB-1347C81B7487}c:\\users\\kheiz\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\kheiz\appdata\local\google\chrome\application\chrome.exe:chrome.exe

"TCP Query User{A0AB5529-F427-489B-9D22-7D0B296650ED}c:\\program files\\xlink kai\\kaiengine.exe"= UDP:c:\program files\xlink kai\kaiengine.exe:XLink Kai Engine

"UDP Query User{451F08CC-BF20-4814-8F87-C5A92C31D803}c:\\program files\\xlink kai\\kaiengine.exe"= TCP:c:\program files\xlink kai\kaiengine.exe:XLink Kai Engine

"TCP Query User{E504981A-4E12-473F-B830-06A668A60CFE}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"UDP Query User{73665A52-1F17-4908-808C-170C672D6C34}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"TCP Query User{03F17295-0FFD-4E8F-9678-50BDC5996B01}c:\\windows\\system32\\javaw.exe"= UDP:c:\windows\system32\javaw.exe:Java Platform SE binary

"UDP Query User{2989D968-BF26-4A24-9FE1-74FD7DF984DF}c:\\windows\\system32\\javaw.exe"= TCP:c:\windows\system32\javaw.exe:Java Platform SE binary

"TCP Query User{33A5FA64-D65B-4C35-91C6-7C31D834DADC}c:\\program files\\messengerdiscovery\\messengerdiscovery.exe"= UDP:c:\program files\messengerdiscovery\messengerdiscovery.exe:MessengerDiscovery the Windows Live Messenger addon

"UDP Query User{B283602A-BF5F-40A7-8ECC-5AC7AC85B576}c:\\program files\\messengerdiscovery\\messengerdiscovery.exe"= TCP:c:\program files\messengerdiscovery\messengerdiscovery.exe:MessengerDiscovery the Windows Live Messenger addon

"TCP Query User{51426E82-F352-4611-9F1F-BB87EDC2189F}c:\\program files\\java\\jre1.6.0_07\\bin\\java.exe"= UDP:c:\program files\java\jre1.6.0_07\bin\java.exe:Java Platform SE binary

"UDP Query User{0D7E6835-1219-4B51-8385-4EB790E347D1}c:\\program files\\java\\jre1.6.0_07\\bin\\java.exe"= TCP:c:\program files\java\jre1.6.0_07\bin\java.exe:Java Platform SE binary

"TCP Query User{FFF01AFA-7158-4EF6-A11A-ABB8718890CC}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= UDP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3

"UDP Query User{736B622A-2DFB-40F3-9F4C-9F2CB703B5E5}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= TCP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3

"{252C80E8-BAB6-44E9-9DFC-580A81B6610E}"= UDP:c:\program files\Activision\Quantum of Solace\JB_LiveEngine_s.exe:Quantum of Solace

"{85BF294C-9BDA-4C9D-A502-E9A0D8887835}"= TCP:c:\program files\Activision\Quantum of Solace\JB_LiveEngine_s.exe:Quantum of Solace

"TCP Query User{7543F0A3-6396-4CA4-877F-FA4BA8C0CB44}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= UDP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3

"UDP Query User{5F3B1E9C-88EE-49C1-80C2-B7B7D90399B3}c:\\program files\\bethesda softworks\\fallout 3\\fallout3.exe"= TCP:c:\program files\bethesda softworks\fallout 3\fallout3.exe:Fallout3

"{36A2B9B3-FBD3-4854-B124-FB2395D444D7}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

"{E1E9F492-3666-460E-952F-E170D7FD61FF}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

"{AEA7CB04-C34C-471C-B7B3-6C024E077D64}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes

"{5E6DCAF1-948A-480D-89D8-988C1B053B02}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

"{F2283592-2607-4DC4-BB18-3EA442483BBB}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

"{0D5A8BE9-B71C-4161-AF5A-0C5EE192843D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"TCP Query User{E47D0F58-1C64-4BFE-B906-937366C4A869}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\kpone44\counter-strike source\hl2.exe:hl2

"UDP Query User{F9BBAAEE-813B-40D4-BD1F-49517D9DCA39}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\kpone44\counter-strike source\hl2.exe:hl2

"TCP Query User{79AC4F81-35CD-4CF4-AF74-05DE9059E8E2}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike\\hl.exe"= UDP:c:\program files\steam\steamapps\kpone44\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{563076D1-4783-4F6A-BC95-414C6561641C}c:\\program files\\steam\\steamapps\\kpone44\\counter-strike\\hl.exe"= TCP:c:\program files\steam\steamapps\kpone44\counter-strike\hl.exe:Half-Life Launcher

"{3EA215EA-7CCE-44E5-8EBF-BEAB4DFDCFB2}"= UDP:5353:Adobe CSI CS4

"{51A9DC5A-274B-40D9-8E8D-F864A09F73E5}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4

"{16ECD65C-C153-42D6-8B53-59036A70418A}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4

"{D46ACE5A-5695-4618-A5D2-EF2A15941F50}"= UDP:3703:Adobe Version Cue CS4 Server

"{5A5585A4-63CA-42CD-A893-C5092DE73019}"= UDP:3704:Adobe Version Cue CS4 Server

"{26C35CB7-7FFC-461D-85D5-71EED92DFF86}"= UDP:51000:Adobe Version Cue CS4 Server

"{50296605-E2C4-4D5B-8C1D-4813387BDFDB}"= UDP:51001:Adobe Version Cue CS4 Server

"{AF13000E-9292-4A11-8564-D6EA8D6ADC30}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server

"{5A031FE3-9318-446F-8374-5CC81B6A4822}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server

"TCP Query User{0FEE8FE4-EBB2-422F-8AD6-6B6CDF26B4F9}c:\\program files\\tightvnc-jaadu\\winvnc.exe"= UDP:c:\program files\tightvnc-jaadu\winvnc.exe:TightVNC Win32 Server

"UDP Query User{00245CF6-F54F-478C-9651-5708323F3954}c:\\program files\\tightvnc-jaadu\\winvnc.exe"= TCP:c:\program files\tightvnc-jaadu\winvnc.exe:TightVNC Win32 Server

"{232AAFB0-5F1B-4EB0-B964-93758700DC27}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray

"{9E301A18-A241-4D0B-AB29-7B9FD9BB7C85}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray

"{16F4D94D-C5C6-4C57-9676-A8EB4F37F7BA}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client

"{D3799AC8-9F32-4497-9CC5-974329954D39}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client

"{9F7A294D-2ACE-49EB-9BD8-79C270A47A88}"= UDP:c:\program files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide

"{A4156362-31C7-44D1-9268-333D8DC2BC70}"= TCP:c:\program files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide

"{75B26C7C-7992-493A-A7BA-11DEBC2B4DB4}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan

"{5FA71556-B578-41E9-8400-A26DB91DADED}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan

"TCP Query User{D0295354-5E27-4E79-940E-E60BB190B0B6}c:\\program files\\orb networks\\orb\\bin\\orbtray.exe"= UDP:c:\program files\orb networks\orb\bin\orbtray.exe:Orb

"UDP Query User{7274248B-9A87-4248-A68D-DD168CD4D2F2}c:\\program files\\orb networks\\orb\\bin\\orbtray.exe"= TCP:c:\program files\orb networks\orb\bin\orbtray.exe:Orb

"{208FCDEF-D518-4638-B1E7-D4A79F7626D8}"= UDP:c:\program files\Orb Networks\Orb\bin\Orb.exe:Orb

"{888BB3CB-9F9B-4A6E-87E3-783BCCF8E7AC}"= TCP:c:\program files\Orb Networks\Orb\bin\Orb.exe:Orb

"{F7410519-9D92-446D-9B6A-F6DEDAB45262}"= UDP:c:\program files\Orb Networks\Orb\bin\OrbIR.exe:OrbIR

"{B01F0F99-D62E-463D-AE95-6699FD372EA7}"= TCP:c:\program files\Orb Networks\Orb\bin\OrbIR.exe:OrbIR

"TCP Query User{9A95F4BC-3B9C-455D-BFED-3A5D69105AF3}c:\\program files\\steam\\steamapps\\lordtiger18\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\lordtiger18\counter-strike source\hl2.exe:hl2

"UDP Query User{92352246-C778-4416-B06D-53D77A85C455}c:\\program files\\steam\\steamapps\\lordtiger18\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\lordtiger18\counter-strike source\hl2.exe:hl2

"TCP Query User{EA7E7C2A-13A2-448F-AE45-5FB553A0091A}c:\\program files\\sun\\xvm virtualbox\\virtualbox.exe"= UDP:c:\program files\sun\xvm virtualbox\virtualbox.exe:VirtualBox

"UDP Query User{246874F5-C7BA-49A5-A272-E4AE72057172}c:\\program files\\sun\\xvm virtualbox\\virtualbox.exe"= TCP:c:\program files\sun\xvm virtualbox\virtualbox.exe:VirtualBox

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdnshelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdnshelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsinfo.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsinfo.exe:cdsinfo (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsinfo.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsinfo.exe:cdsinfo (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsmps.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsmps.exe:cdsmps (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsmps.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsmps.exe:cdsmps (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsMsgServer.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsMsgServer.exe:cdsMsgServer (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsMsgServer.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsMsgServer.exe:cdsMsgServer (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsNameServer.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsNameServer.exe:cdsNameServer (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsNameServer.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsNameServer.exe:cdsNameServer (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsOaPathUtil.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsOaPathUtil.exe:cdsOaPathUtil (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsOaPathUtil.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsOaPathUtil.exe:cdsOaPathUtil (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemote.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemote.exe:cdsRemote (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemote.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemote.exe:cdsRemote (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemshClient.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemshClient.exe:cdsRemshClient (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRemshClient.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsRemshClient.exe:cdsRemshClient (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRunHidden.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsRunHidden.exe:cdsRunHidden (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsRunHidden.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsRunHidden.exe:cdsRunHidden (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsServIpc.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsServIpc.exe:cdsServIpc (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsServIpc.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsServIpc.exe:cdsServIpc (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsUnzip.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsUnzip.exe:cdsUnzip (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsUnzip.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsUnzip.exe:cdsUnzip (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdswhich.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdswhich.exe:cdswhich (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdswhich.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdswhich.exe:cdswhich (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsZip.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cdsZip.exe:cdsZip (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cdsZip.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cdsZip.exe:cdsZip (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cds_root.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\cds_root.exe:cds_root (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\cds_root.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\cds_root.exe:cds_root (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsAdminTool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\clsAdminTool.exe:clsAdminTool (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsAdminTool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\clsAdminTool.exe:clsAdminTool (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsbd.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\clsbd.exe:clsbd (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clsbd.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\clsbd.exe:clsbd (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clu.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\clu.exe:clu (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\clu.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\clu.exe:clu (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\dregprint.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\dregprint.exe:dregprint (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\dregprint.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\dregprint.exe:dregprint (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\emsMkError.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\emsMkError.exe:emsMkError (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\emsMkError.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\emsMkError.exe:emsMkError (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\mpsinfo.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\mpsinfo.exe:mpsinfo (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\mpsinfo.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\mpsinfo.exe:mpsinfo (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\msgHelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\msgHelp.exe:msgHelp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\msgHelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\msgHelp.exe:msgHelp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\nmp.exe:nmp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\nmp.exe:nmp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmppath.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\nmppath.exe:nmppath (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\nmppath.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\nmppath.exe:nmppath (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\switchversion.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\switchversion.exe:switchversion (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\switchversion.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\switchversion.exe:switchversion (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\van.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\van.exe:van (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\van.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\van.exe:van (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\versionviewer.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\bin\versionviewer.exe:versionviewer (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\bin\\versionviewer.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\bin\versionviewer.exe:versionviewer (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\capture.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\capture.exe:capture (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\capture.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\capture.exe:capture (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\comp16.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\comp16.exe:comp16 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\comp16.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\comp16.exe:comp16 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pcadi.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\pcadi.exe:pcadi (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pcadi.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\pcadi.exe:pcadi (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pspiceexplorersrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pspiceexplorersrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pstswp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\pstswp.exe:pstswp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\pstswp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\pstswp.exe:pstswp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\regsvr32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\regsvr32.exe:regsvr32 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\regsvr32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\regsvr32.exe:regsvr32 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\sch2cap.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\sch2cap.exe:sch2cap (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\sch2cap.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\sch2cap.exe:sch2cap (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\tutorial\\CAPTUTOR.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\capture\tutorial\CAPTUTOR.EXE:CAPTUTOR (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\capture\\tutorial\\CAPTUTOR.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\capture\tutorial\CAPTUTOR.EXE:CAPTUTOR (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\cdnshelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\cdnshelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\cdnshelp.exe:cdnshelp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\topicgen.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\topicgen.exe:topicgen (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\topicgen.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\topicgen.exe:topicgen (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\_cdnshelp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\_cdnshelp.exe:_cdnshelp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\cdnshelp\\bin\\_cdnshelp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\cdnshelp\bin\_cdnshelp.exe:_cdnshelp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\mkdefcfg.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\fet\bin\mkdefcfg.exe:mkdefcfg (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\mkdefcfg.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\fet\bin\mkdefcfg.exe:mkdefcfg (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\versiontool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\fet\bin\versiontool.exe:versiontool (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\fet\\bin\\versiontool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\fet\bin\versiontool.exe:versiontool (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\fvupdateutil.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\fvupdateutil.exe:fvupdateutil (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\fvupdateutil.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\fvupdateutil.exe:fvupdateutil (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcad.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gcad.exe:gcad (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcad.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gcad.exe:gcad (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcam.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gcam.exe:gcam (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcam.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gcam.exe:gcam (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcdin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gcdin.exe:gcdin (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gcdin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gcdin.exe:gcdin (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\idfin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\idfin.exe:idfin (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\idfin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\idfin.exe:idfin (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\ipc356.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\ipc356.exe:ipc356 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\ipc356.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\ipc356.exe:ipc356 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\layout.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\layout.exe:layout (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\layout.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\layout.exe:layout (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\libcat.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\libcat.exe:libcat (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\libcat.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\libcat.exe:libcat (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\lsession.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\lsession.exe:lsession (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\lsession.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\lsession.exe:lsession (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\max2hyp.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\max2hyp.exe:max2hyp (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\max2hyp.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\max2hyp.exe:max2hyp (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxascb.exe:maxascb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxascb.exe:maxascb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxascx.exe:maxascx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxascx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxascx.exe:maxascx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxdxf.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxdxf.exe:maxdxf (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxdxf.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxdxf.exe:maxdxf (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxeco.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxeco.exe:maxeco (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxeco.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxeco.exe:maxeco (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxfnetx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxfnetx.exe:maxfnetx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxfnetx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxfnetx.exe:maxfnetx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxminb.exe:maxminb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxminb.exe:maxminb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminw.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxminw.exe:maxminw (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminw.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxminw.exe:maxminw (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxminx.exe:maxminx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxminx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxminx.exe:maxminx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxorcad.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxorcad.exe:maxorcad (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxorcad.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxorcad.exe:maxorcad (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxp99x.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxp99x.exe:maxp99x (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxp99x.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxp99x.exe:maxp99x (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpadb.exe:maxpadb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpadb.exe:maxpadb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpadx.exe:maxpadx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpadx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpadx.exe:maxpadx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadb.exe:maxpcadb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadb.exe:maxpcadb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadx.exe:maxpcadx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxpcadx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxpcadx.exe:maxpcadx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxprotb.exe:maxprotb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxprotb.exe:maxprotb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxprotx.exe:maxprotx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxprotx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxprotx.exe:maxprotx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxstrb.exe:maxstrb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxstrb.exe:maxstrb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxstrx.exe:maxstrx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxstrx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxstrx.exe:maxstrx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxtangb.exe:maxtangb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxtangb.exe:maxtangb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\maxtangx.exe:maxtangx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\maxtangx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\maxtangx.exe:maxtangx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\mfceco.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\mfceco.exe:mfceco (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\mfceco.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\mfceco.exe:mfceco (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\orcadodb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\orcadodb.exe:orcadodb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\orcadodb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\orcadodb.exe:orcadodb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\padb.exe:padb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\padb.exe:padb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\padx.exe:padx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\padx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\padx.exe:padx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\pcadb.exe:pcadb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\pcadb.exe:pcadb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\pcadx.exe:pcadx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcadx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\pcadx.exe:pcadx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcb2max.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\pcb2max.exe:pcb2max (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\pcb2max.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\pcb2max.exe:pcb2max (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\prcat.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\prcat.exe:prcat (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\prcat.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\prcat.exe:prcat (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\protb.exe:protb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\protb.exe:protb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\protx.exe:protx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\protx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\protx.exe:protx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\searchTool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\searchTool.exe:searchTool (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\searchTool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\searchTool.exe:searchTool (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\setbrows.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\setbrows.exe:setbrows (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\setbrows.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\setbrows.exe:setbrows (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\specin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\specin.exe:specin (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\specin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\specin.exe:specin (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\strb.exe:strb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\strb.exe:strb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\strx.exe:strx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\strx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\strx.exe:strx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangb.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tangb.exe:tangb (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangb.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tangb.exe:tangb (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangx.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tangx.exe:tangx (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tangx.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tangx.exe:tangx (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\to386.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\to386.exe:to386 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\to386.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\to386.exe:to386 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\toidf.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\toidf.exe:toidf (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\toidf.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\toidf.exe:toidf (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tomax.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tomax.exe:tomax (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tomax.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tomax.exe:tomax (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tospec.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tospec.exe:tospec (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tospec.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tospec.exe:tospec (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\update90.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\update90.exe:update90 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\update90.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\update90.exe:update90 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\F2G.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\F2G.EXE:F2G (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\F2G.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\F2G.EXE:F2G (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\G2F.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\G2F.EXE:G2F (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Fonts\\G2F.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Fonts\G2F.EXE:G2F (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\custaped.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\custaped.exe:custaped (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\custaped.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\custaped.exe:custaped (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GERBLINE.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GERBLINE.EXE:GERBLINE (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GERBLINE.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GERBLINE.EXE:GERBLINE (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GerbTool.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GerbTool.exe:GerbTool (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GerbTool.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GerbTool.exe:GerbTool (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GT2VIEW.EXE}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GT2VIEW.EXE:GT2VIEW (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\GT2VIEW.EXE}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\GT2VIEW.EXE:GT2VIEW (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\gzip124.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\gzip124.exe:gzip124 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\Program\\gzip124.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\Program\gzip124.exe:gzip124 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\System\\FixTbar.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\gtool\System\FixTbar.exe:FixTbar (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\gtool\\System\\FixTbar.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\gtool\System\FixTbar.exe:FixTbar (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\samples\\demo\\reset.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\samples\demo\reset.exe:reset (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\samples\\demo\\reset.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\samples\demo\reset.exe:reset (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\batch32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\sroute\batch32.exe:batch32 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\batch32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\sroute\batch32.exe:batch32 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\sroute.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\sroute\sroute.exe:sroute (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\sroute\\sroute.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\sroute\sroute.exe:sroute (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tutorial\\laytutor.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\tutorial\laytutor.exe:laytutor (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\tutorial\\laytutor.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\tutorial\laytutor.exe:laytutor (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\vcadd\\vcadd32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\layout\vcadd\vcadd32.exe:vcadd32 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\layout\\vcadd\\vcadd32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\layout\vcadd\vcadd32.exe:vcadd32 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\appmgr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\appmgr.exe:appmgr (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\appmgr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\appmgr.exe:appmgr (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\IndiceFileGeneration.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\IndiceFileGeneration.exe:IndiceFileGeneration (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\IndiceFileGeneration.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\IndiceFileGeneration.exe:IndiceFileGeneration (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\lxcwin.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\lxcwin.exe:lxcwin (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\lxcwin.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\lxcwin.exe:lxcwin (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\Magneticdesigner.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\Magneticdesigner.exe:Magneticdesigner (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\Magneticdesigner.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\Magneticdesigner.exe:Magneticdesigner (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\modeled.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\modeled.exe:modeled (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\modeled.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\modeled.exe:modeled (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\MrkSrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\MrkSrvr.exe:MrkSrvr (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\MrkSrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\MrkSrvr.exe:MrkSrvr (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\msgview.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\msgview.exe:msgview (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\msgview.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\msgview.exe:msgview (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PDesign.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\PDesign.exe:PDesign (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PDesign.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\PDesign.exe:PDesign (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psched.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\psched.exe:psched (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psched.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\psched.exe:psched (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspice.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\pspice.exe:pspice (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspice.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\pspice.exe:pspice (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceaa.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceaa.exe:pspiceaa (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceaa.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceaa.exe:pspiceaa (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PSpiceEnc.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\PSpiceEnc.exe:PSpiceEnc (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\PSpiceEnc.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\PSpiceEnc.exe:PSpiceEnc (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceexplorersrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\pspiceexplorersrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\pspiceexplorersrvr.exe:pspiceexplorersrvr (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psp_cmd.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\psp_cmd.exe:psp_cmd (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\psp_cmd.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\psp_cmd.exe:psp_cmd (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\regsvr32.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\regsvr32.exe:regsvr32 (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\regsvr32.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\regsvr32.exe:regsvr32 (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simmgr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\simmgr.exe:simmgr (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simmgr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\simmgr.exe:simmgr (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simsrvr.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\simsrvr.exe:simsrvr (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\simsrvr.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\simsrvr.exe:simsrvr (Release OrCAD 16.0)

"TCP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\stmed.exe}"= UDP:c:\orcad\OrCAD_16.0\tools\pspice\stmed.exe:stmed (Release OrCAD 16.0)

"UDP{c:\\OrCAD\\OrCAD_16.0\\tools\\pspice\\stmed.exe}"= TCP:c:\orcad\OrCAD_16.0\tools\pspice\stmed.exe:stmed (Release OrCAD 16.0)

"TCP Query User{D16E8910-4FC8-4E4C-B88A-0F7F2D20F891}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\4000001200003i\\cdsnameserver.exe"= UDP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\4000001200003i\cdsnameserver.exe:cdsnameserver.exe

"UDP Query User{BAB2C790-CBF5-4626-85A2-9294EC6BABF2}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\4000001200003i\\cdsnameserver.exe"= TCP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\4000001200003i\cdsnameserver.exe:cdsnameserver.exe

"TCP Query User{CDBF01DE-7DD4-4F0E-98CB-601D2B2C5A23}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\400000600003i\\cdsmsgserver.exe"= UDP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\400000600003i\cdsmsgserver.exe:cdsmsgserver.exe

"UDP Query User{9BD86FA8-B281-4C67-A037-3E5ED65395DE}c:\\users\\kheiz\\appdata\\roaming\\thinstall\\cadence orcad 10.5\\400000600003i\\cdsmsgserver.exe"= TCP:c:\users\kheiz\appdata\roaming\thinstall\cadence orcad 10.5\400000600003i\cdsmsgserver.exe:cdsmsgserver.exe

R1 nod32drv;nod32drv;c:\windows\System32\drivers\nod32drv.sys [2008-03-02 15424]

R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [2009-01-11 100368]

R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [2009-01-11 41680]

R2 Cadence License Manager;Cadence License Manager;c:\orcad\license_manager\lmgrd.exe [2009-01-19 1327104]

R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]

R2 TeamViewer;TeamViewer 3;c:\program files\TeamViewer3\TeamViewer_Host.exe [2008-05-05 181544]

R3 dfmirage;dfmirage;c:\windows\System32\drivers\dfmirage.sys [2005-11-25 31896]

R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\System32\drivers\ManyCam.sys [2008-01-14 21632]

R3 portio32;portio32;c:\windows\System32\drivers\portio32.sys [2008-11-30 2048]

R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [2008-12-17 81360]

S0 OemBiosDevice;Royalty OEM BIOS Extension;c:\windows\System32\drivers\royal.sys [2007-09-05 240128]

S2 ekrn;Eset Service;"c:\program files\ESET\ESET Smart Security\ekrn.exe" --> c:\program files\ESET\ESET Smart Security\ekrn.exe [?]

S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxddserv.exe [2007-04-26 99248]

S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]

S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2008-10-11 56344]

S3 fsssvc;Windows Live Family Safety;"c:\program files\Windows Live\Family Safety\fsssvc.exe" --> c:\program files\Windows Live\Family Safety\fsssvc.exe [?]

S3 leafnets;Leaf Networks Adapter;c:\windows\System32\drivers\leafnets.sys [2007-05-03 55296]

S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [2007-06-29 42512]

S3 PsSdk41;PsSdk41;c:\windows\System32\drivers\pssdk41.sys [2008-09-16 36928]

S3 PVUSB;CESG502 USB Driver;c:\windows\System32\drivers\CESG502.SYS [2008-01-18 40672]

S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;c:\windows\System32\drivers\usb8023.sys [2008-07-27 15872]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f381f08-8701-11dd-970a-001638d7926d}]

\shell\AutoRun\command - f:\autorun\SPLASH.EXE

\shell\INSTALL\COMMAND - F:\SETUP.EXE

.

Contenu du dossier 'Tâches planifiées'

2009-02-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3718856369-1133722837-3043362797-1000.job

- c:\users\Kheiz\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-09 18:47]

2009-02-12 c:\windows\Tasks\User_Feed_Synchronization-{3F0DB73F-2D2D-4456-9962-48954DA541BD}.job

- c:\windows\system32\msfeedssync.exe [2008-01-18 22:33]

.

- - - - ORPHELINS SUPPRIMES - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)

HKCU-Run-CubeDesktop - (no file)

HKCU-Run-AdobeBridge - (no file)

.

------- Examen supplémentaire -------

.

uStart Page = hxxp://home.sweetim.com

mStart Page = hxxp://home.sweetim.com

uInternet Settings,ProxyOverride = local;*.local

IE: &Tout télécharger avec FlashGet - c:\program files\FlashGet\jc_all.htm

IE: &Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm

IE: Ajouter au fichier PDF existant - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convertir au format PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: Convertir la cible du lien en Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm

IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

IE: Tout télécharger avec NetXfer - c:\program files\Xi\NetXfer\NXAddList.html

IE: Télécharger avec NetXfer - c:\program files\Xi\NetXfer\NXAddLink.html

LSP: c:\windows\system32\imon.dll

DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab

DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxp://t1.battlefield-heroes.com/patcher/westpatcher.cab

FF - ProfilePath - c:\users\Kheiz\AppData\Roaming\Mozilla\Firefox\Profiles\gxmzppay.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official

FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=

1 fichier(s) déplacé(s).

FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll

FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll

FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll

FF - plugin: c:\users\Kheiz\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll

FF - plugin: c:\users\Kheiz\AppData\Roaming\Mozilla\Firefox\Profiles\gxmzppay.default\extensions\justintvpublisher@justin.tv\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-12 01:44:56

Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès

Fichiers cachés: 0

**************************************************************************

.

Heure de fin: 2009-02-12 1:47:35

ComboFix-quarantined-files.txt 2009-02-12 00:47:34

Avant-CF: 13 928 984 576 octets libres

Après-CF: 13,886,480,384 octets libres

661 --- E O F --- 2009-01-27 20:26:47

Merci

Lien vers le commentaire
Partager sur d’autres sites

Bonjour,

Mon PC est en ce moment incroyablement lent et a tendance à planter de plus en plus souvent.

Voila mon log.

Merci d'avance pour votre aide.

D4RkAgEnT

Logfile of HijackThis v1.99.1

Scan saved at 18:26:53, on 13/02/2009

Platform: Unknown Windows (WinNT 6.00.1905 SP1)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Windows\RtHDVCpl.exe

C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Users\D4RkAgEnT\AppData\Local\Google\Update\GoogleUpdate.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Windows\system32\conime.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\HIJACKTHIS VF\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bitcomet.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O1 - Hosts: ::1 localhost

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon

O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKCU\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

O4 - HKCU\..\Run: [Google Update] "C:\Users\D4RkAgEnT\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Transfert par Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{AD83399A-834A-4A76-962D-E24038866728}: NameServer = 192.168.0.1

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll

O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe

O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe

O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe

O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe

O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Lien vers le commentaire
Partager sur d’autres sites

Bonjours à tous! J'ai un problème avec l'ordinateur de ma mère et il est très lent au démarrage. Je sais que c'est les 04 dans hackjackthis qui gère les programme qui s'exécute au démarrage mais je ne sais pas lesquels sont essentiels. Alors si vous pourriez me dire quel 04 enlever. Je vous envoi le log de hackjackthis. Merci

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:21:40, on 2009-02-13

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\TOSHIBA\Utilities\KeNotify.exe

C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe

C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe

C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe

C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\Program Files\ltmoh\ltmoh.exe

C:\Program Files\Lexmark 2600 Series\lxdnmon.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

C:\Program Files\Apoint2K\ApMsgFwd.exe

C:\Program Files\PDFCreator\PDFCreator.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Apoint2K\Apntex.exe

C:\Windows\System32\mobsync.exe

C:\Windows\system32\wuauclt.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\explorer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe

O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP

O4 - HKLM\..\Run: [sVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL

O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"

O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE

O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe

O4 - HKLM\..\Run: [smoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe

O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe

O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"

O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe"

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s

O4 - HKLM\..\Run: [skytel] Skytel.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (User 'Default user')

O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe

O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe

O4 - Global Startup: VPN Client.lnk = ?

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O18 - Protocol: intu-ir2008 - {729D3592-92E7-4CBC-8E44-3C22B3F457B3} - C:\Program Files\ImpotRapide 2008\ic2008pp.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: Universite Laval Cisco VPN Client VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\UnivLaval\VPN Client\cvpnd.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdnserv.exe

O23 - Service: lxdn_device - - C:\Windows\system32\lxdncoms.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--

End of file - 10558 bytes

Lien vers le commentaire
Partager sur d’autres sites

Archivé

Ce sujet est désormais archivé et ne peut plus recevoir de nouvelles réponses.


×
×
  • Créer...