St'em by g3n-h@ckm@n 1.0.5.2
Thx to Chiquitine29.....
User : fuselier (Administrateurs) # PC-DE-FUSELIER
Update on 07/11/2009 by g3n-h@ckm@n ::::: 20.00
Start at: 11:57:34 | 08/11/2009
Contact : g3n-h@ckm@n sur CCM
Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18828
Windows Firewall Status : Enabled
C:\ -> Disque fixe local | 141,59 Go (99,97 Go free) | NTFS
D:\ -> Disque fixe local | 7,45 Go (2,3 Go free) [HP_RECOVERY] | NTFS
E:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus en cours
C:\Windows\System32\smss.exe 476
C:\Windows\system32\csrss.exe 548
C:\Windows\system32\wininit.exe 600
C:\Windows\system32\csrss.exe 612
C:\Windows\system32\services.exe 648
C:\Windows\system32\lsass.exe 660
C:\Windows\system32\lsm.exe 668
C:\Windows\system32\svchost.exe 812
C:\Windows\system32\nvvsvc.exe 876
C:\Windows\system32\svchost.exe 904
C:\Windows\System32\svchost.exe 1004
C:\Windows\System32\svchost.exe 1032
C:\Windows\system32\svchost.exe 1044
C:\Windows\system32\svchost.exe 1144
C:\Windows\system32\SLsvc.exe 1160
C:\Windows\system32\svchost.exe 1204
C:\Windows\system32\winlogon.exe 1308
C:\Windows\system32\svchost.exe 1380
C:\Windows\System32\spoolsv.exe 1624
C:\Windows\system32\rundll32.exe 1648
C:\Program Files\Avira\AntiVir Desktop\sched.exe 1704
C:\Windows\system32\svchost.exe 1740
C:\Program Files\Avira\AntiVir Desktop\avguard.exe 2032
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 308
C:\Program Files\Bonjour\mDNSResponder.exe 368
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe 420
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 228
C:\Program Files\Common Files\LightScribe\LSSrvc.exe 760
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe 2064
C:\Windows\system32\svchost.exe 2080
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2104
C:\Windows\system32\svchost.exe 2144
C:\Windows\System32\svchost.exe 2232
C:\Windows\system32\SearchIndexer.exe 2268
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 2376
C:\Windows\system32\taskeng.exe 2700
C:\Windows\system32\Dwm.exe 2920
C:\Windows\system32\taskeng.exe 2984
C:\Windows\Explorer.EXE 3032
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe 2852
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3280
C:\Windows\RtHDVCpl.exe 3124
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 3136
C:\Program Files\HP\QuickPlay\QPService.exe 3112
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe 3232
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe 1632
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe 1528
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe 1496
C:\Program Files\iTunes\iTunesHelper.exe 1324
C:\Windows\System32\ServoApp.exe 3220
C:\Program Files\Java\jre6\bin\jusched.exe 1996
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 2908
C:\Windows\System32\rundll32.exe 2464
C:\Program Files\Windows Sidebar\sidebar.exe 2228
C:\Program Files\Windows Live\Messenger\msnmsgr.exe 1768
C:\Windows\ehome\ehtray.exe 3300
C:\Program Files\Skype\Phone\Skype.exe 2632
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEGE.EXE 1564
C:\Program Files\Electronic Arts\EADM\Core.exe 2916
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 3296
C:\Program Files\Logitech\SetPoint\SetPoint.exe 3416
C:\Program Files\OpenOffice.org 3\program\soffice.exe 3644
C:\Windows\system32\wbem\unsecapp.exe 340
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe 3668
C:\Windows\system32\wbem\wmiprvse.exe 3544
C:\Windows\ehome\ehmsas.exe 3760
C:\Program Files\OpenOffice.org 3\program\soffice.bin 592
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe 2608
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE 3900
C:\Program Files\iPod\bin\iPodService.exe 2176
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 4024
C:\Program Files\Internet Explorer\iexplore.exe 2360
C:\Program Files\Internet Explorer\iexplore.exe 1776
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe 4164
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe 4668
C:\Users\fuselier\Desktop\List_Killem.exe 4984
C:\Windows\system32\conime.exe 3924
C:\Windows\system32\cmd.exe 4816
C:\Windows\system32\wbem\wmiprvse.exe 4316
C:\Users\fuselier\AppData\Local\Temp\1F14.tmp\pv.exe 3508
======================
Cles de demarrage "Run"
======================
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
"msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe\" /background"
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"EPSON Stylus SX400 Series"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\E_FATIEGE.EXE /FU \"C:\\Users\\fuselier\\AppData\\Local\\Temp\\E_SAF61.tmp\" /EF \"HKCU\""
"EPSON Stylus SX400 Series (Copie 1)"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\E_FATIEGE.EXE /FU \"C:\\Windows\\TEMP\\E_SEB97.tmp\" /EF \"HKCU\""
"EA Core"="\"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe\" -silent"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"swg"="\"C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\""
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,4d,00,53,\
00,41,00,53,00,43,00,75,00,69,00,2e,00,65,00,78,00,65,00,20,00,2d,00,68,00,\
69,00,64,00,65,00,00,00
"SMSERIAL"="C:\\Program Files\\Motorola\\SMSERIAL\\sm56hlpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"RtHDVCpl"="RtHDVCpl.exe"
"IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe"
"QPService"="\"C:\\Program Files\\HP\\QuickPlay\\QPService.exe\""
"QlbCtrl"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,00,\
6c,00,65,00,73,00,25,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,00,74,00,2d,\
00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,48,00,50,00,20,00,51,00,\
75,00,69,00,63,00,6b,00,20,00,4c,00,61,00,75,00,6e,00,63,00,68,00,20,00,42,\
00,75,00,74,00,74,00,6f,00,6e,00,73,00,5c,00,51,00,6c,00,62,00,43,00,74,00,\
72,00,6c,00,2e,00,65,00,78,00,65,00,20,00,2f,00,53,00,74,00,61,00,72,00,74,\
00,00,00
"HP Health Check Scheduler"="C:\\Program Files\\Hewlett-Packard\\HP Health Check\\HPHC_Scheduler.exe"
"hpWirelessAssistant"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\
46,00,69,00,6c,00,65,00,73,00,25,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,\
00,74,00,2d,00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,48,00,50,00,\
20,00,57,00,69,00,72,00,65,00,6c,00,65,00,73,00,73,00,20,00,41,00,73,00,73,\
00,69,00,73,00,74,00,61,00,6e,00,74,00,5c,00,48,00,50,00,57,00,41,00,4d,00,\
61,00,69,00,6e,00,2e,00,65,00,78,00,65,00,00,00
"WAWifiMessage"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,\
69,00,6c,00,65,00,73,00,25,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,00,74,\
00,2d,00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,48,00,50,00,20,00,\
57,00,69,00,72,00,65,00,6c,00,65,00,73,00,73,00,20,00,41,00,73,00,73,00,69,\
00,73,00,74,00,61,00,6e,00,74,00,5c,00,57,00,69,00,46,00,69,00,4d,00,73,00,\
67,00,2e,00,65,00,78,00,65,00,00,00
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"AppleSyncNotifier"="C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleSyncNotifier.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Server Application"="C:\\Windows\\system32\\ServoApp.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\""
"Procaster"="\"C:\\Program Files\\Procaster\\Procaster.exe\" -autorun"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"avgnt"="\"C:\\Program Files\\Avira\\AntiVir Desktop\\avgnt.exe\" /min"
"Malwarebytes Anti-Malware (reboot)"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript"
"NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""
=====================
cles additionnelles
=====================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
===============
===============
===============
===============
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
======
BHO :
======
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
@=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
@="Search Helper"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
@="Google Dictionary Compression sdch"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
"NoExplorer"=dword:00000001
==========================
===============
Path : C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
===============
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
C:\Windows\system32\drivers\Sonyhcp.dll
C:\Users\fuselier\LOCAL Settings\Temp\wlsetup-cvr.exe
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
¤¤¤¤¤¤¤¤¤¤ C:\Windows\Prefetch :
ACRORD32.EXE-89736734.pf
AgAppLaunch.db
AgCx_Hibernate.snp.db
AgCx_SC1.db
AgCx_SC1.db.trx
AgCx_SC2.db
AgGlFaultHistory.db
AgGlFgAppHistory.db
AgGlGlobalHistory.db
AgGlUAD_P_S-1-5-21-3853129347-1298890495-163268213-1000.db
AgGlUAD_S-1-5-21-3853129347-1298890495-163268213-1000.db
AgRobust.db
ATTRIB.EXE-C481CEC1.pf
AVGNT.EXE-C4FB88B7.pf
AVNOTIFY.EXE-4291C867.pf
AVWSC.EXE-877F4F63.pf
CATCHME.EXE-B2576861.pf
CHCP.COM-950EAF32.pf
CMD.EXE-89305D47.pf
CONIME.EXE-B273009A.pf
CONSENT.EXE-65F6206D.pf
CONTROL.EXE-9459D5A0.pf
CSCRIPT.EXE-E4C98DEB.pf
DEFRAG.EXE-738093E8.pf
DFRGNTFS.EXE-4F838A89.pf
DLLHOST.EXE-6202E8F2.pf
DLLHOST.EXE-71214090.pf
DLLHOST.EXE-893DDF55.pf
EHMSAS.EXE-6BE9D904.pf
FIND.EXE-162DFE58.pf
FINDSTR.EXE-4176B665.pf
FIREFOX.EXE-E60C0AA7.pf
GOOGLETOOLBARUSER_32.EXE-6E5896AD.pf
GOOGLEUPDATE.EXE-8973CEDD.pf
GOOGLEUPDATERSERVICE.EXE-600E0B48.pf
HPHC_SERVICE.EXE-B8B935C8.pf
HPQTOASTER.EXE-3B718527.pf
IEXPLORE.EXE-1B894AFB.pf
IPODSERVICE.EXE-FE1A6FF7.pf
Layout.ini
LIST_KILLEM.EXE-6266EF32.pf
LOGONUI.EXE-1BEE4A84.pf
LOPSD.EXE-ADB8B447.pf
LOPSD[1].EXE-F0F99434.pf
LSTASKS.EXE-524D3AE1.pf
LULNCHR.EXE-8F9D089F.pf
MOBSYNC.EXE-D8BC6ED2.pf
MODE.COM-0F3F3F6D.pf
MSFEEDSSYNC.EXE-1F01ED17.pf
NOTEPAD.EXE-EB1B961A.pf
NTOSBOOT-B00DFAAD.pf
OSV.EXE-19F0ED90.pf
PfSvPerfStats.bin
PHOTOSCREENSAVER.SCR-F1874E40.pf
PV.EXE-397E0EFE.pf
PV.EXE-FCF36648.pf
ReadyBoot
REG.EXE-26976709.pf
REGEDIT.EXE-4748FE01.pf
RUNDLL32.EXE-905D47B9.pf
RUNDLL32.EXE-C681A23C.pf
RUNDLL32.EXE-CE557EE2.pf
RUNDLL32.EXE-F452D79D.pf
SCALC.EXE-EB3F5356.pf
SCHTASKS.EXE-2DE769BF.pf
SEARCHFILTERHOST.EXE-AA7A1FDD.pf
SEARCHPROTOCOLHOST.EXE-AFAD3EF9.pf
SED.EXE-35A5DBB4.pf
SETPATH.EXE-41103175.pf
SOFFICE.BIN-AB381126.pf
SOFFICE.EXE-B7A9F84B.pf
SSVAGENT.EXE-B025FA52.pf
SVCHOST.EXE-8FD92526.pf
SYNTPHELPER.EXE-4B6F43CF.pf
TASKENG.EXE-5BAF290C.pf
TRUSTEDINSTALLER.EXE-031B6478.pf
UNSECAPP.EXE-CD982D99.pf
VERCLSID.EXE-4D95F5A7.pf
VSSVC.EXE-04D079CC.pf
WERFAULT.EXE-B7E27BE5.pf
WERMGR.EXE-2A1BCBC7.pf
WINCAL.EXE-468711D0.pf
WINMAIL.EXE-D6E90604.pf
WMIADAP.EXE-369DF1CD.pf
WMIPRVSE.EXE-43972D0F.pf
WMPNSCFG.EXE-DF1DD51A.pf
WSCRIPT.EXE-65A9658F.pf
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤