Voici le fichier log du RSIT
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrateur at 2009-04-20 18:34:30
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 25 GB (64%) free of 38 GB
Total RAM: 1023 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:35:28, on 20/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE
O:\RSIT.exe
C:\DOCUME~1\ADMINI~1.D7F\LOCALS~1\Temp\Rar$EX00.609\Administrateur.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.net-studio.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = google.net-studio.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = google.net-studio.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: ;Tag&rename
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [L08FXLRD_7488265] "C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" -m
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
End of file - 3976 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-10-04 8491008]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-10-04 81920]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2007-12-20 7225344]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"=C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe [2006-08-05 136704]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-08-24 15360]
"L08FXLRD_7488265"=C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE [2007-06-12 351000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-24 200064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-08-24 133632]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoSMHelp"=1
"NoRun"=0
"NoFind"=0
"NoLogOff"=0
"NoSetFolders"=0
"DisallowRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\Device Manager\dpinst.exe"="C:\Program Files\Windows Live\Messenger\Device Manager\dpinst.exe:*:Enabled:ipsec"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Fichiers communs\Nero\Nero Web\SetupX.exe"="C:\Program Files\Fichiers communs\Nero\Nero Web\SetupX.exe:*:Enabled:ipsec"
"C:\Program Files\FileZilla FTP Client\fzsftp.exe"="C:\Program Files\FileZilla FTP Client\fzsftp.exe:*:Enabled:ipsec"
"C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe:*:Enabled:ipsec"
"C:\Program Files\Fichiers communs\InstallShield\Driver\7\Intel 32\IDriver.exe"="C:\Program Files\Fichiers communs\InstallShield\Driver\7\Intel 32\IDriver.exe:*:Enabled:ipsec"
"C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe"="C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe:*:Enabled:ipsec"
"C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe"="C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe:*:Enabled:ipsec"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\WINDOWS\system32\nwiz.exe"="C:\WINDOWS\system32\nwiz.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\restore\rstrui.exe"="C:\WINDOWS\system32\restore\rstrui.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\RUNDLL32.EXE"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:ipsec"
"C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe"="C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe:*:Enabled:ipsec"
"C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE"="C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
======List of files/folders created in the last 1 months======
2009-04-20 18:23:32 ----D---- C:\rsit
2009-04-20 18:23:32 ----D---- C:\Program Files\trend micro
2009-04-18 12:13:39 ----D---- C:\Program Files\VirtualDJ
2009-04-18 12:01:17 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\DFX
2009-04-18 12:01:13 ----D---- C:\Program Files\DFX
2009-04-18 10:23:01 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\dvdcss
2009-04-17 19:46:36 ----RASHD---- C:\autorun.inf
2009-04-17 19:46:09 ----A---- C:\UsbFix.txt
2009-04-17 12:59:59 ----D---- C:\Program Files\Microsoft Etudes
2009-04-17 12:59:51 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-04-17 12:59:44 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-04-17 12:59:44 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-04-17 12:59:44 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-04-17 12:59:44 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-04-17 12:59:44 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-04-17 12:59:44 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-04-17 12:59:43 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-04-17 12:59:42 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-04-16 22:16:28 ----D---- C:\Program Files\Microsoft Works
2009-04-16 22:15:06 ----SHD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-04-16 22:11:40 ----A---- C:\WINDOWS\system32\h323log.txt
2009-04-16 22:09:56 ----A---- C:\WINDOWS\system32\usbui.dll
2009-04-16 22:07:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-16 22:07:57 ----A---- C:\WINDOWS\ODBCINST.INI
2009-04-16 22:07:53 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-04-16 22:07:53 ----A---- C:\WINDOWS\system32\irclass.dll
2009-04-16 22:07:53 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-04-16 22:07:53 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-04-16 22:07:53 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-04-16 22:07:52 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-04-16 22:07:51 ----A---- C:\WINDOWS\system32\storprop.dll
2009-04-16 22:07:51 ----A---- C:\WINDOWS\system32\batt.dll
2009-04-16 22:07:51 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-04-16 22:07:42 ----ASH---- C:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
2009-04-16 22:07:27 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2009-04-16 22:07:09 ----A---- C:\WINDOWS\setuplog.txt
2009-04-16 21:58:25 ----D---- C:\Program Files\Microsoft Office
2009-04-16 21:58:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-04-16 21:56:03 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\vlc
2009-04-16 21:55:22 ----D---- C:\Program Files\VideoLAN
2009-04-16 21:50:21 ----A---- C:\WINDOWS\system32\TUProgSt.exe
2009-04-16 21:50:20 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2009-04-16 21:50:19 ----A---- C:\WINDOWS\system32\TuneUpDefragService.exe
2009-04-16 21:50:18 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\TuneUp Software
2009-04-16 21:50:03 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-04-16 21:50:03 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
2009-04-16 21:46:47 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-04-16 21:46:29 ----N---- C:\WINDOWS\system32\difxapi.dll
2009-04-16 21:43:22 ----R---- C:\WINDOWS\alcwzrd.exe
2009-04-16 21:43:22 ----R---- C:\WINDOWS\Alcmtr.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\system32\ChCfg.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\SoundMan.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\SkyTel.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\RtlUpd.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\RTLCPL.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\RTHDCPL.exe
2009-04-16 21:43:20 ----R---- C:\WINDOWS\MicCal.exe
2009-04-16 21:43:06 ----D---- C:\Program Files\Realtek
2009-04-16 21:43:02 ----R---- C:\WINDOWS\RtlExUpd.dll
2009-04-16 21:43:02 ----A---- C:\WINDOWS\HideWin.exe
2009-04-16 21:37:11 ----RA---- C:\WINDOWS\system32\fdco1.dll
2009-04-16 21:37:10 ----A---- C:\WINDOWS\system32\nvunrm.exe
2009-04-16 21:36:39 ----RA---- C:\WINDOWS\system32\nvconrm.dll
2009-04-16 21:36:39 ----RA---- C:\WINDOWS\system32\bdco1.dll
2009-04-16 21:30:45 ----D---- C:\WINDOWS\NV13721376.TMP
2009-04-16 21:30:45 ----A---- C:\WINDOWS\system32\nvudisp.exe
2009-04-16 21:28:25 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2009-04-16 21:21:19 ----RA---- C:\WINDOWS\system32\fdco1ins.dll
2009-04-16 21:20:46 ----RA---- C:\WINDOWS\system32\bdco1ins.dll
2009-04-16 21:18:30 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-04-16 21:18:27 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\InstallShield
2009-04-16 21:14:27 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\WinRAR
2009-04-16 20:28:49 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\Auslogics
2009-04-16 20:26:18 ----D---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\Identities
2009-04-16 20:25:40 ----SD---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\Microsoft
2009-04-16 20:25:40 ----ASH---- C:\Documents and Settings\Administrateur.D7FB462C37C9481\Application Data\desktop.ini
2009-04-16 20:25:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-16 20:20:15 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2009-04-16 20:19:37 ----D---- C:\Program Files\TaskSwitchXP
2009-04-16 20:18:48 ----A---- C:\WINDOWS\setdebug.exe
2009-04-16 20:18:47 ----A---- C:\WINDOWS\system32\jit.dll
2009-04-16 20:18:47 ----A---- C:\WINDOWS\system32\javaee.dll
2009-04-16 20:18:47 ----A---- C:\WINDOWS\system32\dx3j.dll
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\wjview.exe
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\vmhelper.dll
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\msjdbc10.dll
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\msjava.dll
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\msawt.dll
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\jview.exe
2009-04-16 20:18:44 ----A---- C:\WINDOWS\system32\jdbgmgr.exe
2009-04-16 20:18:43 ----A---- C:\WINDOWS\system32\javart.dll
2009-04-16 20:18:43 ----A---- C:\WINDOWS\system32\javaprxy.dll
2009-04-16 20:18:43 ----A---- C:\WINDOWS\system32\javacypt.dll
2009-04-16 20:18:43 ----A---- C:\WINDOWS\system32\clspack.exe
2009-04-16 20:15:41 ----A---- C:\WINDOWS\control.ini
2009-04-16 20:15:26 ----A---- C:\WINDOWS\OEWABLog.txt
2009-04-16 20:15:19 ----D---- C:\WINDOWS\system32\dllcache
2009-04-16 20:15:19 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-04-16 20:14:45 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-04-16 20:14:43 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-04-16 20:14:19 ----A---- C:\WINDOWS\system32\acctres.dll
2009-04-16 20:14:12 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wups.dll
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-04-16 20:14:11 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-04-16 20:14:10 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-04-16 20:14:09 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-04-16 20:14:09 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-04-16 20:14:09 ----A---- C:\WINDOWS\system32\srclient.dll
2009-04-16 20:14:09 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-04-16 20:14:09 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-04-16 20:14:08 ----A---- C:\WINDOWS\system32\inetres.dll
2009-04-16 20:14:08 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-04-16 20:14:07 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-04-16 20:14:07 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-04-16 20:14:07 ----A---- C:\WINDOWS\system32\mstask.dll
2009-04-16 20:13:16 ----A---- C:\WINDOWS\vbaddin.ini
2009-04-16 20:13:16 ----A---- C:\WINDOWS\vb.ini
2009-04-16 20:12:47 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-04-16 20:12:45 ----A---- C:\WINDOWS\system32\getuname.dll
2009-04-16 20:12:45 ----A---- C:\WINDOWS\system32\charmap.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\winmine.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\tskill.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\tscon.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\sol.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\shadow.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\reset.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\regini.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\msg.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\freecell.exe
2009-04-16 20:12:44 ----A---- C:\WINDOWS\system32\calc.exe
2009-04-16 20:12:43 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-04-16 20:12:43 ----A---- C:\WINDOWS\system32\logoff.exe
2009-04-16 20:12:43 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-04-16 20:12:41 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-04-16 20:12:40 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-04-16 20:12:40 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-04-16 20:12:40 ----A---- C:\WINDOWS\system32\spider.exe
2009-04-16 20:12:40 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-04-16 20:12:40 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-04-16 20:12:39 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-04-16 20:12:39 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-04-16 20:12:39 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-04-16 20:12:39 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-04-16 20:12:39 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-04-16 20:12:39 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-04-16 20:12:38 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\stclient.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-04-16 20:12:37 ----A---- C:\WINDOWS\system32\colbact.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\comuid.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-04-16 20:12:36 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-04-16 20:12:32 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-04-16 20:12:31 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-04-16 20:12:31 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-04-16 20:12:31 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-04-15 19:53:29 ----D---- C:\Program Files\Yahoo!
2009-04-09 00:18:23 ----D---- C:\WINDOWS\NV18441848.TMP
2009-04-09 00:03:53 ----D---- C:\WINDOWS\NV788792.TMP
2009-04-08 23:55:53 ----D---- C:\WINDOWS\NV380384.TMP
2009-04-07 22:43:31 ----D---- C:\Config.Msi
======List of files/folders modified in the last 1 months======
2009-04-20 18:34:05 ----D---- C:\WINDOWS\system32\drivers
2009-04-20 18:34:02 ----D---- C:\WINDOWS\Temp
2009-04-20 18:23:32 ----D---- C:\Program Files
2009-04-20 18:21:30 ----D---- C:\WINDOWS\pss
2009-04-20 18:18:34 ----D---- C:\WINDOWS\system32
2009-04-18 12:13:46 ----RSD---- C:\WINDOWS\Fonts
2009-04-18 12:01:17 ----SHD---- C:\WINDOWS\Installer
2009-04-17 21:13:18 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-17 19:44:26 ----D---- C:\WINDOWS
2009-04-17 12:59:51 ----RSD---- C:\WINDOWS\assembly
2009-04-17 12:59:51 ----HD---- C:\WINDOWS\inf
2009-04-17 12:59:51 ----D---- C:\WINDOWS\system32\DirectX
2009-04-17 10:54:01 ----D---- C:\WINDOWS\Prefetch
2009-04-16 22:35:44 ----D---- C:\WINDOWS\Microsoft.NET
2009-04-16 22:18:00 ----D---- C:\WINDOWS\system32\Restore
2009-04-16 22:07:53 ----D---- C:\WINDOWS\system
2009-04-16 22:06:55 ----D---- C:\WINDOWS\WBEM
2009-04-16 22:06:55 ----D---- C:\WINDOWS\system32\fr
2009-04-16 22:06:55 ----D---- C:\WINDOWS\Network Diagnostic
2009-04-16 22:06:55 ----D---- C:\WINDOWS\L2Schemas
2009-04-16 22:05:08 ----D---- C:\WINDOWS\AppPatch
2009-04-16 22:04:58 ----D---- C:\WINDOWS\system32\Setup
2009-04-16 22:04:57 ----RD---- C:\WINDOWS\Web
2009-04-16 22:04:17 ----RD---- C:\WINDOWS\Offline Web Pages
2009-04-16 22:04:14 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-16 22:04:09 ----D---- C:\WINDOWS\twain_32
2009-04-16 22:04:08 ----D---- C:\WINDOWS\system32\ras
2009-04-16 22:04:06 ----D---- C:\WINDOWS\system32\icsxml
2009-04-16 22:03:53 ----D---- C:\WINDOWS\system32\1036
2009-04-16 21:58:52 ----D---- C:\WINDOWS\SHELLNEW
2009-04-16 21:58:45 ----A---- C:\WINDOWS\win.ini
2009-04-16 21:50:22 ----SD---- C:\WINDOWS\Tasks
2009-04-16 21:47:06 ----D---- C:\Program Files\VIA
2009-04-16 21:43:20 ----D---- C:\WINDOWS\system32\RTCOM
2009-04-16 21:34:24 ----D---- C:\WINDOWS\nview
2009-04-16 21:31:06 ----D---- C:\WINDOWS\Help
2009-04-16 21:30:03 ----D---- C:\WINDOWS\system32\CatRoot
2009-04-16 21:26:05 ----D---- C:\Documents and Settings
2009-04-16 21:11:44 ----D---- C:\WINDOWS\system32\config
2009-04-16 21:11:32 ----D---- C:\WINDOWS\system32\wbem
2009-04-16 21:11:31 ----D---- C:\WINDOWS\Registration
2009-04-16 20:28:16 ----SHD---- C:\RECYCLER
2009-04-16 20:26:22 ----D---- C:\WINDOWS\SoftwareDistribution
2009-04-16 20:25:55 ----D---- C:\WINDOWS\system32\MsDtc
2009-04-16 20:25:55 ----D---- C:\WINDOWS\security
2009-04-16 20:25:55 ----D---- C:\WINDOWS\repair
2009-04-16 20:25:52 ----D---- C:\WINDOWS\Debug
2009-04-16 20:25:36 ----SHD---- C:\System Volume Information
2009-04-16 20:22:40 ----AD---- C:\WINDOWS\i386
2009-04-16 20:20:40 ----D---- C:\Program Files\WinRAR
2009-04-16 20:20:34 ----D---- C:\Program Files\Nero
2009-04-16 20:19:56 ----D---- C:\Program Files\Mozilla Thunderbird
2009-04-16 20:19:47 ----D---- C:\Program Files\Mozilla Firefox
2009-04-16 20:19:30 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-04-16 20:19:30 ----A---- C:\WINDOWS\system.ini
2009-04-16 20:17:34 ----D---- C:\WINDOWS\WinSxS
2009-04-16 20:16:18 ----D---- C:\WINDOWS\system32\URTTemp
2009-04-16 20:15:08 ----D---- C:\WINDOWS\system32\ias
2009-04-16 20:14:23 ----D---- C:\WINDOWS\srchasst
2009-04-16 20:14:19 ----D---- C:\Program Files\Windows Media Player
2009-04-16 20:14:19 ----D---- C:\Program Files\Fichiers communs\Services
2009-04-16 20:14:18 ----D---- C:\Program Files\Outlook Express
2009-04-16 20:14:16 ----D---- C:\Program Files\Internet Explorer
2009-04-16 20:14:09 ----D---- C:\Program Files\Fichiers communs\System
2009-04-16 20:13:29 ----D---- C:\WINDOWS\system32\Com
2009-04-16 20:12:52 ----D---- C:\Program Files\Windows Media Connect 2
2009-04-16 20:12:40 ----D---- C:\WINDOWS\system32\fr-fr
2009-04-16 20:11:42 ----SH---- C:\boot.ini
2009-04-07 22:40:57 ----D---- C:\WINDOWS\NV18721876.TMP
2009-04-07 20:59:06 ----D---- C:\Program Files\Fichiers communs\Nero
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R3 dac970nt;dac970nt; \??\C:\WINDOWS\system32\drivers\qgohnn.sys []
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-08-24 144384]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-10-04 6854464]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-09-20 53632]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-09-20 22016]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-08-24 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-08-24 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-08-24 17152]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-08-24 26368]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\WINDOWS\system32\drivers\viahduaa.sys [2007-12-12 212992]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-08-24 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-08-24 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-10-04 155716]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-04-16 603904]
R2 UxTuneUp;TuneUp Extension de thème; C:\WINDOWS\System32\svchost.exe [2008-08-24 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-07-16 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-07-16 68952]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 514864]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 218912]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-04-16 362240]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 167960]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 995840]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-08-24 14336]
-----------------EOF-----------------