Rechercher : dans
Par :

Svp analyse scan hijackthis de antivirus 360

Dernière réponse le 22 dc 2008 à 17:29:59 caroline2, le 16 dc 2008 à 00:25:10 
 Signaler ce message aux modérateurs

Bonjour,
voil deux jours que j'ai des pages internet explorer qui s'ouvrent m'indiquant que mon ordinateur est infect et qu'il faut tlcharger antivirus 360 et je fermer toujours ces fentres mais a persiste bien que je n'ai pas tlcharg cet antivirus. J'ai fait le scan avec HijackThis et svp si vous pouver m'aider analyser o est le problme je vous serais reconnaissnate
Merci
------------------------------------------------------------­--------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:58:28, on 15/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [27656107949475256988225418229111] C:\Program Files\Antivirus 2009\av2009.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Slection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrle d'AcDcToday) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcDcToday.ocx
O16 - DPF: {AE563727-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Gestion d'AcPreview) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcPreview.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\d3dx9_2532.dll
O20 - Winlogon Notify: 78377e2a511 - C:\WINDOWS\System32\d3dx9_2532.dll
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: BrlAPI - Unknown owner - D:\UdeM\cygwin\bin\cygrunsrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
----------------------------------------------------------
Meric bcp !

Configuration: Windows XP
Internet Explorer 6.0

Meilleures réponses pour « Svp analyse scan hijackthis de antivirus 360 » dans :
Comment analyser un rapport HijackThis VoirCet article est destin aux utilisateurs dsirant apprendre mieux connaitre cet outil, encore ce jour incontournable pour tablir un premier diagnostic sur un PC infect. Il n'a pas pour vocation d'tre purement technique, mais vous propose...
Télécharger Vista Dual Scan VoirScanner votre PC contre les virus et contre les spyware en mme temps ! Vista Dual Scan est un scanner antivirus et antispyware gratuit. Le scanner dtecte et supprime les virus, les vers, les trojans et les spywares. Vista Dual Scan est optimis...

1

Cesel45, le 16 dc 2008 à 00:39:03

Bonjour

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [htp://safesearch.cyberdefender.com/smallsearch.html]

O4 - HKCU\..\Run: [27656107949475256988225418229111] C:\Program Files\Antivirus 2009\av2009.exe

O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

J'ai trouv trois lignes fixer.

Répondre à Cesel45

2

jorginho67, le 16 dc 2008 à 00:39:34
  • +1

Salut !

Tlcharge SmitfraudFix
Utilitaire de S!Ri: Moe et balltrap34

Installe le la racine de C : tuto d'utilisation

Double clique sur l'exe pour le dcompresser et lancer le fix.

Utilisation option 1 Recherche :

Double clique sur smitfraudfix.cmd
Slectionne 1 pour crer un rapport des fichiers responsables de l'infection.

Ne fais rien d'autre sans notre avis

Copie/colle le RAPPORT sur ta prochaine rponse sur ce post stp.

Process.exe est dtect par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme tant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destin mettre fin des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrter des logiciels de scurit (Antivirus, Firewall...) d'o l'alerte mise par ces antivirus.


Tutoriel d'aide @+

Hohoho...asentNol;-))

Répondre à jorginho67

3

caroline2, le 16 dc 2008 à 01:03:05

Salut jorginho67,
merci pour la rapidit de ta rponse. En installant SmitfraudFix il y a mon symantec qui m'avertit du risque d'tre infect par IEDefender est-ce normal ? voici donc le rapport de SmitfraudFix
------------
SmitFraudFix v2.386

Rapport fait 18:54:57,53, 15/12/2008
Execut partir de C:\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du systme de fichiers est NTFS
Fix execut en mode normal

Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

hosts

Fichier hosts corrompu !

127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info

C:\


C:\WINDOWS


C:\WINDOWS\system


C:\WINDOWS\Web


C:\WINDOWS\system32


C:\WINDOWS\system32\LogFiles


C:\Documents and Settings\TAHAR


C:\DOCUME~1\TAHAR\LOCALS~1\Temp


C:\Documents and Settings\TAHAR\Application Data


Menu Dmarrer


C:\DOCUME~1\LOCALS~1\Favoris


Bureau


C:\Program Files


Cls corrompues


Elments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"


o4Patch
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri



IEDFix
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



Agent.OMZ.Fix
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


VACFix
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


404Fix
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


Sharedtaskscheduler
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


AppInit_DLLs
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\WINDOWS\\System32\\d3dx9_2532.dll"


Winlogon
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""


RK



DNS

Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.2.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{86E28817-2EA3-4AB9-8831-89F4F2BD9C29}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{86E28817-2EA3-4AB9-8831-89F4F2BD9C29}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{2ABDBB89-CA82-4F98-8173-FF0896DF4FE5}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1


Recherche infection wininet.dll


Fin
----------------------

Merci encore !!

Répondre à caroline2

4

jorginho67, le 16 dc 2008 à 01:08:31

Arffff tu n'as pas tout lu... ;-p

Process.exe est dtect par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme tant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destin mettre fin des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrter des logiciels de scurit (Antivirus, Firewall...) d'o l'alerte mise par ces antivirus.


On continue !

Tlcharge HostsXpert sur ton Bureau :
http://www.funkytoad.com/download/HostsXpert.zip

Dcompresse-le (Clic droit >> Extraire ici)

Double-clique sur HostsXpert pour le lancer

clique sur le bouton "Restore MS Hosts File" puis ferme le programme

/!\ Avant de cliquer sur le bouton "Restore MS Hosts File", vrifie que le cadenas en haut gauche est ouvert sinon tu vas avoir un message d'erreur /!\.


Ensuite :

Option 2

Redmarre en mode sans chec

Pour cela, tapotes la touche F8 (Si F8 ne marche pas utilise la touche F5) ds le dbut de lallumage du pc sans tarrter.
Une fentre va souvrir, tu te dplaces avec les flches du clavier sur dmarrer en mode sans chec puis tape [Entre].
Une fois sur le bureau sil ny a pas toutes les couleurs et autres cest normal !

comment demarrer en mode sans echec en images

-------------------------------------------------------------------------------
Double clique sur smitfraudfix.cmd
Cette fois choisit loption 2 !!
rpond Oui (o) tout

Une fois le nettoyage termin, SmitFraudfix ouvre le rapport de nettoyage sur le bloc-note.

Redmarre l'ordinateur en mode normal (comme d'habitude),
Sur le bureau doit se trouver le rapport enregistr (sinon il est sur le Poste de Travail / Disque C / rapport.txt)

Refais un log Hitjackthis et poste les <gras>deux rapports s'il te plait !</gras>

@+

Hohoho...asentNol;-))

Répondre à jorginho67

5

caroline2, le 16 dc 2008 à 01:55:51

Salut,
une fentre internet explorer vient de s'ouvrir et l c'est le soit disant le rapid antivirus qui fait le scan !! je suis perdue !!
voici les deux rapports :

---------------Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:47, on 15/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vVX3000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [27656107949475256988225418229111] C:\Program Files\Antivirus 2009\av2009.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Slection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrle d'AcDcToday) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcDcToday.ocx
O16 - DPF: {AE563727-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Gestion d'AcPreview) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcPreview.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\d3dx9_2532.dll
O20 - Winlogon Notify: 78377e2a511 - C:\WINDOWS\System32\d3dx9_2532.dll
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: BrlAPI - Unknown owner - D:\UdeM\cygwin\bin\cygrunsrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
------------------------------

SmitFraudFix v2.386

Rapport fait 19:31:03,40, 15/12/2008
Execut partir de C:\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du systme de fichiers est NTFS
Fix execut en mode sans echec

SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

Arret des processus


hosts

127.0.0.1 localhost

VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.
Generic Renos Fix

GenericRenosFix by S!Ri


Suppression des fichiers infects


IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



Agent.OMZ.Fix

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


RK


DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{86E28817-2EA3-4AB9-8831-89F4F2BD9C29}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{86E28817-2EA3-4AB9-8831-89F4F2BD9C29}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{2ABDBB89-CA82-4F98-8173-FF0896DF4FE5}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1


Suppression Fichiers Temporaires


Winlogon.System
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


Nettoyage du registre

Nettoyage termin.

SharedTaskScheduler Aprs SmitFraudFix
!!!Attention, les cls qui suivent ne sont pas forcment infectes!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


Fin

Merci :)

Répondre à caroline2

6

caroline2, le 17 dc 2008 à 21:03:40

Relance de la discussion...

Bonjour,
je n'arrive pas toujours me dbarasser de ce rapidantivirus, j'ai fait un SDfix, actuellement j'ai lanc malwarebyte et j'attends le rapport, y a t il quelqu'un qui peut m'aider svp
Merci !

Répondre à caroline2

7

Cesel45, le 17 dc 2008 à 21:12:39

Malwarebyte devrait lui faire sa fte.

Répondre à Cesel45

9

caroline2, le 17 dc 2008 à 21:25:25

J'espre Cesel45 :)

Répondre à caroline2

8

jorginho67, le 17 dc 2008 à 21:14:11

Bon, tu me posteras le rapport de MBAM qui se trouve sous l'onglet Log/rapport @+

Hohoho...asentNol;-))

Répondre à jorginho67

10

caroline2, le 17 dc 2008 à 21:27:47

Merci jorginho67 le rapport sera prt d'ici une heure je pense
@+

Répondre à caroline2

11

caroline2, le 17 dc 2008 à 23:06:37

Voici le rapport (il a dtect& Torjan.zlob, Torjan.Vundo et Rogue Adware Alert) mais j'ai toujours ces pages internet explorer qui s'ouvrent avec rapidantivirus :
Malwarebytes' Anti-Malware 1.31
Version de la base de donnes: 1507
Windows 5.1.2600 Service Pack 3

17/12/2008 16:39:15
mbam-log-2008-12-17 (16-39-07).txt

Type de recherche: Examen complet (C:\|D:\|)
Elments examins: 349191
Temps coul: 2 hour(s), 35 minute(s), 22 second(s)

Processus mmoire infect(s): 0
Module(s) mmoire infect(s): 1
Cl(s) du Registre infecte(s): 1
Valeur(s) du Registre infecte(s): 1
Elment(s) de donnes du Registre infect(s): 0
Dossier(s) infect(s): 0
Fichier(s) infect(s): 1

Processus mmoire infect(s):
(Aucun lment nuisible dtect)

Module(s) mmoire infect(s):
C:\WINDOWS\system32\__c007215C.dat (Trojan.Zlob) -> No action taken.

Cl(s) du Registre infecte(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c007215c (Trojan.Vundo) -> No action taken.

Valeur(s) du Registre infecte(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AdwareAlert (Rogue.AdwareAlert) -> No action taken.

Elment(s) de donnes du Registre infect(s):
(Aucun lment nuisible dtect)

Dossier(s) infect(s):
(Aucun lment nuisible dtect)

Fichier(s) infect(s):
C:\WINDOWS\system32\__c007215C.dat (Trojan.Vundo) -> No action taken.

Répondre à caroline2

12

caroline2, le 17 dc 2008 à 23:25:02

Excusez moi voici le rapport gnr :

Malwarebytes' Anti-Malware 1.31
Version de la base de donnes: 1507
Windows 5.1.2600 Service Pack 3

17/12/2008 16:40:36
mbam-log-2008-12-17 (16-40-36).txt

Type de recherche: Examen complet (C:\|D:\|)
Elments examins: 349191
Temps coul: 2 hour(s), 35 minute(s), 22 second(s)

Processus mmoire infect(s): 0
Module(s) mmoire infect(s): 1
Cl(s) du Registre infecte(s): 1
Valeur(s) du Registre infecte(s): 1
Elment(s) de donnes du Registre infect(s): 0
Dossier(s) infect(s): 0
Fichier(s) infect(s): 1

Processus mmoire infect(s):
(Aucun lment nuisible dtect)

Module(s) mmoire infect(s):
C:\WINDOWS\system32\__c007215C.dat (Trojan.Zlob) -> Delete on reboot.

Cl(s) du Registre infecte(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c007215c (Trojan.Vundo) -> Delete on reboot.

Valeur(s) du Registre infecte(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

Elment(s) de donnes du Registre infect(s):
(Aucun lment nuisible dtect)

Dossier(s) infect(s):
(Aucun lment nuisible dtect)

Fichier(s) infect(s):
C:\WINDOWS\system32\__c007215C.dat (Trojan.Vundo) -> Delete on reboot.

Répondre à caroline2

13

jorginho67, le 18 dc 2008 à 00:18:25

Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
Choisis l'option "Do a system scan and save a log file"
Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
Clique sur "Edition" ->> "Slectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport ici
@+

Hohoho...asentNol;-))

Répondre à jorginho67

14

caroline2, le 18 dc 2008 à 00:44:59

J'ai fait passer spyDoctor et il m'a trouv ces infections,Torjan FakeAlert, AdwareBHO.GEN, Adwareadvertising et Backdoor.VB.GEN qui est d'un risque trs lv mais bon j'ai la version d'valuation et non la version complte et donc je ne peux pas les rparer. Voici le rapport de HijackThis :
-------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:40:42, on 17/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vVX3000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Slection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrle d'AcDcToday) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcDcToday.ocx
O16 - DPF: {AE563727-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Gestion d'AcPreview) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcPreview.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\d3dx9_2532.dll
O20 - Winlogon Notify: 78377e2a511 - C:\WINDOWS\System32\d3dx9_2532.dll
O20 - Winlogon Notify: __c007215C - C:\WINDOWS\
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: BrlAPI - Unknown owner - D:\UdeM\cygwin\bin\cygrunsrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
End of file - 13433 bytes

Répondre à caroline2

15

jorginho67, le 18 dc 2008 à 00:58:50

1) Tlcharge OTMoveIt3 de OldTimer
http://oldtimer.geekstogo.com/OTMoveIt3.exe

* Enregistre-le sur ton bureau. Ne le lances pas pour l'instant.

2) Sauvegarde ces instructions car il faudra fermer toutes les fentres et applications lors de l'installation et de l'analyse.

Clic droit sur le bureau => nouveau => document texte => double clique dessus et copi/colle ces instructions que tu pourras consulter pour faire la manip' correctement !

Ferme toutes les autres fentres, tous les autres programmes. Pas de connections Internet.


3) Relance HijackThis, choisis "do a scan only"
coche la case devant les lignes ci-dessous et clic en bas sur "fix checked", puis clique sur OK.


O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


Comment fixer les lignes et Gnrer un rapport
(merci balltrap34)

Ferme HijackThis.

4) Double-clique sur OTMoveIt3.exe pour le lancer (l'extension peut ne pas apparatre)
* Copie-colle l'ensemble des lignes en gras ci dessous dans la partie "Paste Instructions for Items to be Moved" (en-dessous de la barre jaune) :

:files
c:\program files\cyberdefender\antispyware\issintro.exe
c:\program files\adwarealert\adwarealert.exe
:commands
[emptytemp]
[Reboot]


* Clique sur le bouton rouge Moveit! pour lancer le nettoyage
* Copie-colle dans ta prochaine rponse tout ce qui se trouve dans la fentre Results (en vert droite)

==> Un rapport sera gnr dans le dossier C:\ _OTMoveIt\MovedFiles avec la date et l'heure du passage de l'outil (mmddyyyy_hhmmss.log)

* Ferme OTMoveIt3 (en cliquant sur Exit)


Note : Si un fichier ou un dossier ne sait tre supprim directement, l'outil peut demander un redmarrage pour terminer le processus.
Clique alors sur "Yes" pour accepter...



5) Fais redmarrer ton PC et poste un nouveau rapport HijackThis @+

Hohoho...asentNol;-))

Répondre à jorginho67

16

caroline2, le 18 dc 2008 à 01:33:39

Voici les deux rapports :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:27:36, on 17/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Slection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrle d'AcDcToday) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcDcToday.ocx
O16 - DPF: {AE563727-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Gestion d'AcPreview) - file://C:\Program Files\Autodesk Architectural Desktop 3 Fra\AcPreview.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\d3dx9_2532.dll
O20 - Winlogon Notify: 78377e2a511 - C:\WINDOWS\System32\d3dx9_2532.dll
O20 - Winlogon Notify: __c007215C - C:\WINDOWS\
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: BrlAPI - Unknown owner - D:\UdeM\cygwin\bin\cygrunsrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
End of file - 11787 bytes
------------------------

========== FILES ==========
File/Folder c:\program files\cyberdefender\antispyware\issintro.exe not found.
File/Folder c:\program files\adwarealert\adwarealert.exe not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12172008_191329

Répondre à caroline2

17

jorginho67, le 18 dc 2008 à 07:53:57

C'est toi qui a install ceci ? => AdwareAlert @+

Hohoho...asentNol;-))

Répondre à jorginho67

18

caroline2, le 18 dc 2008 à 19:55:50

Non je n'ai rien install part ce que tu m'a demand d'installer et en plus il y a quelqu'un qui pirate ma connexion car j'ai une surconsommation de UPLOAD de 5Go ces deux derniers jours et comme j'ai dpass la limite fixe par fournisseur d'accs internet (10Go) je dois payer 50 $ je ne sais plus quoi faire :((((( aidez-moi stp

Répondre à caroline2

21

caroline2, le 18 dc 2008 à 22:30:58

J'ai tlcharg Zone alarm et un autre programme pour savoir le UPLOAD et le DOWNLOAD et je vois que pour ce qui est au niveau du SENT j'atteint les 850 ko est-ce normal ? et Zone ALarm m'alerte de beaucoup de programmes qu'il bloquent est-ce que je dois faire un autre rapport de Hijack

Merci !!

Répondre à caroline2

19

jorginho67, le 18 dc 2008 à 20:13:59

Tu sembles ne pas avoir de parefeu contrlant les connexions sortantes, ce qui est un risque de scurit.
Tu DOIS ABSOLUMENT installer un vrai FIREWALL ( pare feu autre que celui de Windows qui est une vrai passoire ) .
Tu as le choix entre ces possibilits :

========== /!\ Bien lire les Tutos pour un parametrage optimal /!\ ==========

* ComodoFirewallPro 2.4 En Franais et simple aussi.

Tlchargement
tutorial d'instalation => clique sur "Comodo au plus simple (pour les dbutants)" .

Attention la 3.0 est en anglais uniquement et est plus difficile a paramtrer
* Tuto de config'
---------------------------------------------------------------------------------------
* Kerio Efficace mais un poil plus compliqu.

* Tuto et lien de tlchargement
autre lien
---------------------------------------------------------------------------------------
* Zone Alarm En Franais et le plus simple d'utilisation.

* Tuto et lien de tlchargement



@+

Hohoho...asentNol;-))

Répondre à jorginho67

20

caroline2, le 18 dc 2008 à 20:21:09

Salut jorginho67,
connais-tu un logiciel gratuit qui me permet de suivre mes dowonload et mes upload
merci

Répondre à caroline2

22

jorginho67, le 18 dc 2008 à 22:52:17

et Zone ALarm m'alerte de beaucoup de programmes qu'il bloquent

REGARDE LE TUTORIEL...

Il faut crer des rgles.


Plus tu le feras au dbut, moins d'alertes tu auras par la suite. @+

Hohoho...asentNol;-))

Répondre à jorginho67

23

caroline2, le 18 dc 2008 à 23:01:17

J'arrive pas savoir comment faire pour bloquer celui qui utilise ma connexion pour faire des upload il a dj fait plus de 120Mo aujourd'hui, est-il possible de crer une rgle pour bloquer tout UPLOAD depuis mon laptop je ne cesse d'avoir de upload de plus de 800ko cet instant et ces deux derniers jours j'ai eu 10 Go de UPLOAD !!! comment faire stp !

Répondre à caroline2

24

jorginho67, le 18 dc 2008 à 23:11:19

UPLOAD...

tu veux dire que quelqu'un envoie des fichiers quelque part depuis TON pc ?

Upload de quoi ?

J'avoue ne pas saisir ce que tu veux dire.

Si tu as mis le pare feu, celui ci bloque les ports, et les odnnes sortantes. @+

Hohoho...asentNol;-))

Répondre à jorginho67

25

caroline2, le 18 dc 2008 à 23:21:27

Le upload a veut dire que quelqu'un est entrain d'envoyer de fichiers d'autres personnes partir de ma connexion internet ce n'est pas compt sur sa connexion par exemple moi j'ai avec mon founisseur d'accs internet droit 10Go en upload (des fichiers que je peux partager avec d'autres) et 20Go en dowload par mois et si je dpasse chaque 1Go me coute dans les 8$ et donc une personne utilise ;q connexion pour partager des fichiers avec d'autres personnes et l actuellement j'ai en upload chaque seconde pratiquement entre 800 et 900 kbps en upload et en download uniauement peu prs 120 kbps et j'ai un gros problme avec le upload car en voyant le rapport d'un logiciel que je viens de tlcharger et qui me calcule le traffic plus de 204Mo en upload et si a continue je dois me dconnecter car d'ici ce soit j'aurais plus de 1Go en upload et je ne comprends pas pourquoi. Je ne sais pas quoi faire et en plus ces pages internet n'arretent pas toujours de s'ouvrir et l j'ai le spyware guard 2008 qui soit disant veut faire son scan... je suis dsespre :((((((((((((

Répondre à caroline2

26

Lyonnais92, le 19 dc 2008 à 00:07:37
  • +1

Re,

On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de tlchargement, ainsi que des instructions pour excuter l'outil:

http://www.bleepingcomputer.com/combofix/fr/comment-utiliser­-combofix


* Vrifie que tu as ferm/dsactiv tous les programmes anti-virus, anti-malware ou anti-spyware afin qu'ils n'interfrent pas avec le travail de ComboFix.

Envoie le contenu de C:\ComboFix.txt dans ta prochaine rponse afin que on l'examine.
@+
Faitescequel'onvousdemande,niplus,nimoins.
Necrezpasdedoublons,nisurCCMnisurunautresite.M­erci

Répondre à Lyonnais92

27

jorginho67, le 19 dc 2008 à 13:28:18

Merci Lyonnais ;-)

Caroline, tu peux lui faire confiance, je lui est demand un coup de main ;-) @+

Hohoho...asentNol;-))

Répondre à jorginho67

33

jorginho67, le 19 dc 2008 à 15:57:31

Juste une question ;

Quel est ton FAI ( Fournisseur Accs Internet ) et ta box ?? @+

Hohoho...asentNol;-))

Répondre à jorginho67

34

caroline2, le 19 dc 2008 à 16:03:31

Je suis montral et j'ai comme fournisseur d'accs internet Videotron avec leur module Arris tu penses que a peut tre un problme de leur rseau ce UPLOAD car je ne comprends plus rien ?? et j'ai vraiment galr pour ajouter ces deux messages a me dit que a c'est ajout alors que non j'ai d faire plusieurs tentatives

Répondre à caroline2

35

jorginho67, le 19 dc 2008 à 16:17:08

Non, ce ne doit pas tre un soucis de leur part, mais surement de quelqu'un qui s'est " grff " sur ta connexion.

En attendant, fais ce que t'a demand Lyonnais plus haut, poste le rapport ds que possible. @+

Hohoho...asentNol;-))

Répondre à jorginho67

37

caroline2, le 19 dc 2008 à 16:24:04

Salut,
je l'ai post plusieurs fois et je n'arrive pas savoir pourquoi il ne veut pas me l'ajouter, je fais un autre essai :

ComboFix 08-12-18.01 - TAHAR 2008-12-19 9:10:17.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.3.1252.1.1036.18.446.85 [GMT -4:00]
Lanc depuis: c:\documents and settings\TAHAR\Bureau\ComboFix.exe
Commutateurs utiliss :: c:\documents and settings\TAHAR\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-F­RA.exe
* Un nouveau point de restauration a t cr
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrateur\Application Data\[u]0/u20000009085d1fe511C.manifest
c:\documents and settings\Administrateur\Application Data\[u]0/u20000009085d1fe511O.manifest
c:\documents and settings\Administrateur\Application Data\[u]0/u20000009085d1fe511P.manifest
c:\documents and settings\Administrateur\Application Data\[u]0/u20000009085d1fe511S.manifest
c:\documents and settings\BOUFADEN\Application Data\[u]0/u20000009085d1fe511C.manifest
c:\documents and settings\BOUFADEN\Application Data\[u]0/u20000009085d1fe511O.manifest
c:\documents and settings\BOUFADEN\Application Data\[u]0/u20000009085d1fe511P.manifest
c:\documents and settings\BOUFADEN\Application Data\[u]0/u20000009085d1fe511S.manifest
c:\documents and settings\TAHAR\Application Data\[u]0/u20000009085d1fe511C.manifest
c:\documents and settings\TAHAR\Application Data\[u]0/u20000009085d1fe511O.manifest
c:\documents and settings\TAHAR\Application Data\[u]0/u20000009085d1fe511P.manifest
c:\documents and settings\TAHAR\Application Data\[u]0/u20000009085d1fe511S.manifest
c:\windows\GnuHashes.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\GroupPolicyManifest
c:\windows\system32\GroupPolicyManifest\1.music.mp3
c:\windows\system32\GroupPolicyManifest\1.music.mp3.kwd
c:\windows\system32\GroupPolicyManifest\10.setup.zip
c:\windows\system32\GroupPolicyManifest\10.setup.zip.kwd
c:\windows\system32\GroupPolicyManifest\11.unpack.zip
c:\windows\system32\GroupPolicyManifest\11.unpack.zip.kwd
c:\windows\system32\GroupPolicyManifest\12.limepro.zip
c:\windows\system32\GroupPolicyManifest\12.limepro.zip.kwd
c:\windows\system32\GroupPolicyManifest\13.keygen.zip
c:\windows\system32\GroupPolicyManifest\13.keygen.zip.kwd
c:\windows\system32\GroupPolicyManifest\13.tmp
c:\windows\system32\GroupPolicyManifest\2.crack.zip
c:\windows\system32\GroupPolicyManifest\2.crack.zip.kwd
c:\windows\system32\GroupPolicyManifest\8.mpgvideo.mpg
c:\windows\system32\GroupPolicyManifest\8.mpgvideo.mpg.kwd
c:\windows\system32\GroupPolicyManifest\9.remix.mp3
c:\windows\system32\GroupPolicyManifest\9.remix.mp3.kwd
c:\windows\system32\tmp.reg
C:\xcrashdump.dat

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Legacy_NPF
-------\Service_Boonty Games


((((((((((((((((((((((((((((( Fichiers crs du 2008-11-19 au 2008-12-19 ))))))))))))))))))))))))))))))))))))
.

2008-12-19 08:48 . <REP> c:\windows\LastGood.Tmp
2008-12-19 00:14 . 2008-12-19 00:14 <REP> d-------- c:\documents and settings\TAHAR\Application Data\HPAppData
2008-12-19 00:14 . 2008-12-19 00:14 <REP> d-------- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2008-12-19 00:06 . 2008-12-19 00:06 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-18 23:53 . 2008-12-19 08:55 167,256 --a------ c:\windows\hpoins21.dat
2008-12-18 23:53 . 2007-09-05 14:31 8,138 --------- c:\windows\hpomdl21.dat
2008-12-18 16:04 . 2008-12-19 09:19 608,288 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-18 16:04 . 2008-12-19 09:19 9,176 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-18 15:58 . 2008-12-18 15:58 <REP> d-------- c:\documents and settings\All Users\Application Data\MailFrontier
2008-12-18 15:58 . 2008-07-09 09:05 75,248 --a------ c:\windows\zllsputility.exe
2008-12-18 15:58 . 2008-07-09 09:05 54,672 --a------ c:\windows\system32\vsutil_loc040c.dll
2008-12-18 15:58 . 2008-07-09 09:05 42,384 --a------ c:\windows\zllsputility_loc040c.dll
2008-12-18 15:58 . 2008-07-09 09:05 21,904 --a------ c:\windows\system32\imsinstall_loc040c.dll
2008-12-18 15:58 . 2008-07-09 09:05 17,808 --a------ c:\windows\system32\imslsp_install_loc040c.dll
2008-12-18 15:58 . 2004-04-27 04:40 11,264 --a------ c:\windows\system32\SpOrder.dll
2008-12-18 15:58 . 2008-12-18 16:01 4,212 ---h----- c:\windows\system32\zllictbl.dat
2008-12-18 15:48 . 2008-12-18 15:48 <REP> d-------- c:\program files\DU Meter
2008-12-18 15:48 . 2008-12-18 15:48 <REP> d-------- c:\documents and settings\All Users\Application Data\Hagel Technologies
2008-12-18 14:31 . 2008-12-18 14:31 <REP> d-------- c:\documents and settings\TAHAR\Application Data\Comodo
2008-12-18 14:31 . 2008-12-18 14:31 <REP> d-------- c:\documents and settings\All Users\Application Data\Comodo
2008-12-18 14:20 . 2008-12-18 14:20 216 --a------ C:\boot.ini.comodofirewall
2008-12-18 14:19 . 2008-12-18 15:36 <REP> d-------- c:\program files\Comodo
2008-12-18 13:47 . 2008-12-18 13:47 373,760 --ahs---- c:\windows\system32\15E5.tmp
2008-12-18 10:53 . 2008-12-18 10:53 373,760 --ahs---- c:\windows\system32\12.tmp
2008-12-17 19:13 . 2008-12-17 19:13 <REP> d-------- C:\_OTMoveIt
2008-12-16 19:38 . 2008-12-16 19:38 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-16 19:32 . 2008-12-16 19:33 <REP> d-------- c:\windows\ERUNT
2008-12-16 19:15 . 2008-11-06 02:03 <REP> d-------- C:\SDFix
2008-12-16 13:15 . 2008-12-16 13:15 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-16 13:15 . 2008-12-16 13:15 <REP> d-------- c:\documents and settings\TAHAR\Application Data\Malwarebytes
2008-12-16 13:15 . 2008-12-16 13:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-16 13:15 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-16 13:15 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-16 12:12 . 2008-12-16 12:13 <REP> d-------- c:\program files\CCleaner
2008-12-15 19:29 . 2006-08-01 00:01 <REP> d-------- c:\documents and settings\Administrateur\WINDOWS
2008-12-15 19:29 . 2006-07-31 16:16 <REP> d-------- c:\documents and settings\Administrateur\Voisinage rseau
2008-12-15 19:29 . 2006-02-14 03:31 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-12-15 19:29 . 2006-08-01 00:01 <REP> d--h----- c:\documents and settings\Administrateur\Modles
2008-12-15 19:29 . 2006-08-01 00:01 <REP> dr------- c:\documents and settings\Administrateur\Mes documents
2008-12-15 19:29 . 2006-08-01 00:01 <REP> dr------- c:\documents and settings\Administrateur\Menu Dmarrer
2008-12-15 19:29 . 2006-08-01 00:01 <REP> dr------- c:\documents and settings\Administrateur\Favoris
2008-12-15 19:29 . 2006-02-14 03:31 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-12-15 19:29 . 2006-08-01 00:01 <REP> d-------- c:\documents and settings\Administrateur\Application Data\toshiba
2008-12-15 19:29 . 2006-08-01 00:01 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Sonic
2008-12-15 19:29 . 2008-12-15 19:29 <REP> d-------- c:\documents and settings\Administrateur
2008-12-15 18:43 . 2008-12-18 11:55 <REP> d-------- C:\SmitfraudFix
2008-12-15 18:42 . 2008-12-15 18:47 1,660,481 --a------ C:\SmitfraudFix.exe
2008-12-14 14:40 . 2008-12-14 14:41 373,760 --ahs---- c:\windows\system32\A7.tmp
2008-12-13 20:47 . 2008-12-13 22:34 <REP> d-------- c:\documents and settings\All Users\Application Data\WildTangent
2008-12-13 09:39 . 2008-12-13 09:39 373,760 --ahs---- c:\windows\system32\75F.tmp
2008-12-13 09:39 . 2008-12-13 09:39 135,168 --a------ c:\windows\system32\d3dx9_2532.dll
2008-12-11 20:46 . 2008-12-11 20:47 <REP> d-------- c:\program files\Microsoft LifeCam
2008-12-08 20:21 . 2008-12-11 16:42 921,624 --a------ C:\img2-001.raw
2008-12-08 20:10 . 2008-04-13 20:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2008-12-08 20:10 . 2008-04-13 20:45 60,032 --a--c--- c:\windows\system32\dllcache\usbaudio.sys
2008-12-08 20:08 . 2007-04-10 17:46 1,966,696 --a------ c:\windows\system32\drivers\VX3000.sys
2008-12-08 20:08 . 2007-04-10 17:46 709,992 --a------ c:\windows\vVX3000.exe
2008-12-08 20:08 . 2007-04-10 17:46 476,520 --a------ c:\windows\vVX3000.dll
2008-12-08 20:08 . 2007-04-10 17:46 202,088 --a------ c:\windows\system32\LCCoin14.dll
2008-12-08 20:08 . 2007-04-10 17:46 185,704 --a------ c:\windows\system32\cVX3000.dll
2008-12-08 20:08 . 2007-04-10 17:46 116,072 --a------ c:\windows\VX3000.dll
2008-12-08 20:08 . 2007-04-10 17:46 15,498 --a------ c:\windows\VX3000.ini
2008-12-08 20:08 . 2007-04-10 17:46 13,023 --a------ c:\windows\VX3000.src
2008-12-08 19:22 . 2008-12-08 19:22 <REP> d-------- c:\windows\system32\drivers\umdf
2008-12-02 21:43 . 2008-12-02 21:44 <REP> d-------- c:\program files\QuickTime
2008-11-25 16:36 . 2008-11-25 17:07 <REP> d-------- c:\documents and settings\TAHAR\Application Data\SSH
2008-11-25 16:34 . 2008-11-25 16:34 <REP> d-------- c:\program files\SSH Communications Security

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-19 13:27 --------- d-----w c:\documents and settings\TAHAR\Application Data\Skype
2008-12-19 13:18 --------- d-----w c:\program files\Symantec AntiVirus
2008-12-19 12:19 --------- d-----w c:\documents and settings\TAHAR\Application Data\skypePM
2008-12-19 04:14 --------- d-----w c:\program files\HP
2008-12-19 04:14 --------- d-----w c:\program files\Hewlett-Packard
2008-12-19 04:06 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-12-18 23:43 --------- d-----w c:\program files\eMule
2008-12-18 18:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-18 18:30 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-18 14:23 --------- d-----w c:\program files\Spyware Doctor
2008-12-13 21:49 --------- d-----w c:\documents and settings\TAHAR\Application Data\LimeWire
2008-12-08 23:15 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-08 23:15 --------- d-----w c:\program files\Creative
2008-12-03 01:43 --------- d-----w c:\program files\Fichiers communs\Apple
2008-11-30 23:10 --------- d-----w c:\documents and settings\TAHAR\Application Data\dvdcss
2008-11-25 00:44 --------- d-----w c:\documents and settings\TAHAR\Application Data\WinEdt
2008-11-07 15:19 286,720 ------w c:\windows\Setup1.exe
2008-11-07 15:18 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-11-03 21:19 --------- d-----w c:\documents and settings\TAHAR\Application Data\PC Tools
2008-10-26 23:21 237,568 ----a-w c:\windows\system32\rmc_rtspdl.dll
2008-10-26 23:21 156,672 ----a-w c:\windows\system32\rmc_fixasf.exe
2008-10-26 23:19 323,584 ----a-w c:\windows\system32\AUDIOGENIE2.DLL
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-21 21:38 --------- d-----w c:\program files\NCH Software
2008-10-16 18:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 18:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 18:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 18:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 18:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 18:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 18:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 18:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 18:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 18:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 01:01 670,208 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 20:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2007-01-20 13:32 36,808,256 ----a-w c:\program files\iTunesSetup.exe
2005-05-13 15:12 217,073 --sha-r c:\windows\meta4.exe
2005-10-24 09:13 66,560 --sha-r c:\windows\MOTA113.exe
2005-10-13 19:27 422,400 --sha-r c:\windows\x2.64.exe
2005-10-07 17:14 308,224 --sha-r c:\windows\system32\avisynth.dll
2005-07-14 10:31 27,648 --sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 13:32 616,448 --sha-r c:\windows\system32\cygwin1.dll
2005-06-21 20:37 45,568 --sha-r c:\windows\system32\cygz.dll
2004-01-24 22:00 70,656 --sha-r c:\windows\system32\i420vfw.dll
1997-07-21 18:30 1,045,776 --sha-w c:\windows\system32\Msjet35.dll
1997-06-23 02:00 123,664 --sha-w c:\windows\system32\Msjint35.dll
1997-06-23 11:06 24,848 --sha-w c:\windows\system32\Msjter35.dll
1997-06-23 11:06 252,176 --sha-w c:\windows\system32\Msrd2x35.dll
1997-06-23 11:06 287,504 --sha-w c:\windows\system32\Msxbse35.dll
2006-04-27 08:24 2,945,024 --sha-r c:\windows\system32\Smab.dll
2005-02-28 11:16 240,128 --sha-r c:\windows\system32\x.264.exe
2004-01-24 22:00 70,656 --sha-r c:\windows\system32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les lments vides & les lments initiaux lgitimes ne sont pas lists
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2008-06-09 2645528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-11 344064]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2006-01-28 1589248]
"SmoothView"="c:\program files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-10 69632]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-03-07 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-03-31 125072]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"TPSMain"="TPSMain.exe" [2005-08-03 c:\windows\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"AdslTaskBar"="stmctrl.dll" [2004-08-31 c:\windows\system32\stmctrl.dll]
"CFSServ.exe"="CFSServ.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-05-25 171448]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

c:\documents and settings\BOUFADEN\Menu Dmarrer\Programmes\Dmarrage\
Lancement rapide de Microsoft Office OneNote 2003.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]

c:\documents and settings\All Users\Menu Dmarrer\Programmes\Dmarrage\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-06-26 323646]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\78377e2a511]
2008-12-13 09:39 135168 c:\windows\system32\d3dx9_2532.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\d3dx9_2532.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Dmarrer^Programmes^Dmarrage^officejet 6100.lnk]
path=c:\documents and settings\All Users\Menu Dmarrer\Programmes\Dmarrage\officejet 6100.lnk
backup=c:\windows\pss\officejet 6100.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^TAHAR^Menu Dmarrer^Programmes^Dmarrage^Adobe Gamma.lnk]
path=c:\documents and settings\TAHAR\Menu Dmarrer\Programmes\Dmarrage\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 22:34 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\setup\\HPZNUI01.EXE"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService [2008-12-18 1386008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-04 99376]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2006-02-14 225792]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\DRIVERS\stmatm.sys [2006-08-28 60255]
S3 BrlAPI;BrlAPI;d:\udem\cygwin\bin\cygrunsrv.exe [2008-10-09 68096]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2006-03-31 118928]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-11-03 356920]
S3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\DRIVERS\torususb.sys [2006-08-28 542991]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01e24a49-c437-11dc-ad4f-0016363d8257}]
\Shell\AutoRun\command - 83fgj.com
\Shell\explore\Command - 83fgj.com
\Shell\open\Command - 83fgj.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0328699a-be2a-11dc-ad4a-0016363d8257}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL antihost.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ecd81cf-7075-11dd-ada5-0016363d8257}]
\Shell\AutoRun\command - F:\83fgj.com
\Shell\explore\Command - F:\83fgj.com
\Shell\open\Command - F:\83fgj.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ecd81d2-7075-11dd-ada5-0016363d8257}]
\Shell\AutoRun\command - 83fgj.com
\Shell\explore\Command - 83fgj.com
\Shell\open\Command - 83fgj.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ecd81da-7075-11dd-ada5-0016363d8257}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ecd81db-7075-11dd-ada5-0016363d8257}]
\Shell\AutoRun\command - H:\83fgj.com
\Shell\explore\Command - H:\83fgj.com
\Shell\open\Command - H:\83fgj.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{340b1b7e-4544-11dd-ad83-0016363d8257}]
\Shell\AutoRun\command - F:\oufddh.exe
\Shell\explore\Command - F:\oufddh.exe
\Shell\open\Command - F:\oufddh.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e7dffc0-4f2d-11db-ac19-0016363d8257}]
\Shell\AutoRun\command - RavMon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6cf3daf3-6090-11dc-ad11-0016363d8257}]
\Shell\AutoRun\command - F:\oufddh.exe
\Shell\explore\Command - F:\oufddh.exe
\Shell\open\Command - F:\oufddh.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b01f798-6fb8-11dd-ada3-0016363d8257}]
\Shell\AutoRun\command - F:\83fgj.com
\Shell\explore\Command - F:\83fgj.com
\Shell\open\Command - F:\83fgj.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b01f79b-6fb8-11dd-ada3-0016363d8257}]
\Shell\AutoRun\command - F:\83fgj.com
\Shell\explore\Command - F:\83fgj.com
\Shell\open\Command - F:\83fgj.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7db4d2b2-6df1-11dd-ad9f-0016363d8257}]
\Shell\AutoRun\command - F:\c9hehpa.bat
\Shell\explore\Command - F:\c9hehpa.bat
\Shell\open\Command - F:\c9hehpa.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a8c8e0e-6b7f-11dd-ad9a-0016363d8257}]
\Shell\AutoRun\command - F:\oufddh.exe
\Shell\explore\Command - F:\oufddh.exe
\Shell\open\Command - F:\oufddh.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9332580d-12e5-11dd-ad72-0016363d8257}]
\Shell\AutoRun\command - oufddh.exe
\Shell\explore\Command - oufddh.exe
\Shell\open\Command - oufddh.exe
.
Contenu du dossier 'Tches planifies'

2008-11-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2007-02-10 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1158325142.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-06-26 19:46]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKCU-Run-AdwareAlert - c:\program files\AdwareAlert\AdwareAlert.exe
HKLM-Run-CyberDefender Early Detection Center - c:\program files\CyberDefender\AntiSpyware\ISSIntro.exe
Notify-__c007215C - (no file)


.
------- Examen supplmentaire -------
.
uStart Page = hxxp://www.yahoo.fr/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

c:\windows\Downloaded Program Files\InstFred.ocx - O16 -: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1}
file://c:\program files\Autodesk Architectural Desktop 3 Fra\InstFred.ocx

c:\windows\Downloaded Program Files\InstBanr.ocx - O16 -: {AE563727-B4F5-11D4-A415-00108302FDFD}
file://c:\program files\Autodesk Architectural Desktop 3 Fra\InstBanr.ocx
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-19 09:21:08
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachs ...

Recherche d'lments en dmarrage automatique cachs ...

Recherche de fichiers cachs ...

Scan termin avec succs
Fichiers cachs: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- DLLs charges dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(552)
c:\windows\System32\d3dx9_2532.dll
c:\windows\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\windows\system32\acs.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\drivers\CDANTSRV.EXE
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\DU Meter\DUMeterSvc.exe
c:\program files\Synaptics\SynTP\Toshiba.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\ConfigFree\CFSServ.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\windows\system32\fxssvc.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\windows\system32\TPSBattM.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: 2008-12-19 9:33:39 - La machine a redmarr
ComboFix-quarantined-files.txt 2008-12-19 13:33:29

Avant-CF: 9357570048 octets libres
Aprs-CF: 9,913,978,880 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

398 --- E O F --- 2008-12-18 14:20:00

Répondre à caroline2

39

caroline2, le 19 dc 2008 à 16:40:06

Merci pour votre aide et je me demandais s'il n' y a pas moyen de savoir quel processus est entrain de s'excuter plus que les autres car j'ai toujours peu prs entre 800 et 900kbps de UPLOAD et les pages internet explorer qui s'ouvrent encore avec cette fois le REGISTER DEFENDER qui veut faire le scan... je suis fatigue mais je tiens bon en esprant que a se rgle sinon je ne sais pas si mon laptop s'en sortira :((

Répondre à caroline2

40

Lyonnais92, le 19 dc 2008 à 16:46:31
  • +1

Re,

beaucoup d'infections par les supports amovibles.

--> Tlcharge UsbFix (de Chiquitine29) sur ton Bureau :
http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

--> Lance l'installation avec les paramtres par dfaut.

--> Branche tes sources de donnes externes ton PC (cl USB, disque dur externe, etc...) sans les ouvrir.

--> Double-clique sur le raccourci UsbFix sur ton Bureau.

--> Le PC va redmarrer.

--> Aprs redmarrage, poste le rapport UsbFix.txt

Note : le rapport UsbFix.txt est sauvegard la racine du disque.

(Si le Bureau ne rapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tche", tape explorer.exe et valide)

=====================

Ouvre l'explorateur windows (clic droit sur dmarrer et explorer)

Cherche C:\SmitfraudFix fais un clic droit et Supprimer.

(on va utiliser la dernire version)

Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
et tlcharge SmitfraudFix.exe.

Regarde le tuto
Excute le en choisissant loption 1, il va gnrer un rapport
Copie/colle le sur le poste stp.

=======================

Tu continues surveiller les uploads et downloads ?
@+
Faitescequel'onvousdemande,niplus,nimoins.
Necrezpasdedoublons,nisurCCMnisurunautresite.Merci

Répondre à Lyonnais92

41

caroline2, le 19 dc 2008 à 16:52:21

Salut Lyonnais,
merci je fais a tout de suite et je surveille toujours mes uploads et doxnloads et le problme c'est le upload toujours entre 800 et 900 kbps et dj hier j'ai eu 1.3 Go de upload !!! c'est beaucoup d'habitude je ne dpasse pas les 80 Mo par jour


@+

Répondre à caroline2

42

caroline2, le 19 dc 2008 à 17:23:07

C'est vrai qu'en y pensant parfois quand je dmarre mon laptop parfois j'ai l'assistant d'un ajout de nouveau matriel qui s'ouvre come si j'ai connect un matriel mon port Usb alors que ce n'est pas le cas. Voici les deux rapports :


-------------- UsbFix V2.413.5 ---------------

* User : TAHAR - ASMA
* Outils mis a jours le 17/12/2008 par Chiquitine29 et Chimay8
* Recherche effectue 11:01:06 le 19/12/2008
* Windows Xp - Internet Explorer 6.0.2900.5512


--------------- [ Processus actifs ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\DOCUME~1\TAHAR\LOCALS~1\Temp\1.tmp\b2e.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--------------- [ Informations lecteurs ] ----------------

C: - Lecteur fixe D: - Lecteur fixe E: - Lecteur de CD-ROM H: - Lecteur amovible
+- Contenu de l'autorun : E:\autorun.inf

[autorun]
open=setup.exe
icon=setup.exe,0
[Version]
CDGuid={D64BC2CF-0F12-47d7-B412-B4F3FD684253}
SoftwareGuid=
InfrastructureDatabaseList=hpomdl21.dat
LanguagesInthisCD=enu,ell,plk,rus,trk,chs,cht,csy,dan,deu,es­n,fin,fra,hun,ita,jpn,kor,nld,nob,ptb,sve,heb,ara
DefaultLanguageInThisRelease=enu
DIVISION=hpo
ICE_REV=21
FIRST_IO_REVISION=09
LAST_IO_REVISION=09
VCD_FILEVER=0
Manufacturer=HP
RegistryManufacturer=Hewlett-Packard
ProductSeries=Photosmart All-In-One Series
Pre-Install=%ProgramFilesx86%%Manufacturer%
SilentInstall=No
InvalidPathCharacters=#$&,%
ConnectivityPlugin=%sourcepath%setup\hpzdui%ICE_SUFFIX%.exe
PreloadICEEngineToGUIDFolder=%sourcepath%hpzprl01.dat
PreloadRecoveryMechanism=%sourcepath%hpzprl02.dat
PreloadRestingPad=%sourcepath%hpzprl03.dat
UI_03=No
UI_20=Yes
UI_21=No
UI_25=No
UI_30=Yes
UI_50=No
UI_80=swreinstall&NoDeviceConnected&NoDeviceDiscovery
UI_250=Yes
UI_260=Yes
UI_40=Yes
UI_60=Yes
UI_70=Yes
UI_110=Yes
UI_100=Yes
RegistryRebootLocation=DigitalImaging\Install
autorunid=PS_AIO_02_Network_UOW_DVD
ConnectivityStopAndRestart=%InstallMainBin%hpqtra08.exe
driverver=09/06/2007, 090.000.261.000
first_ca_revision=0
CPENetworkSupport=Yes
IEFIX=NoFix
last_ca_revision=0
log=1
maxinstalldirlength=64
maxinstalltime=35
maxpathforcd=100
mininstalltime=15
networkinstall=%sourcepath%setup\hpznui%ICE_SUFFIX%.exe
preloadiceexes=hpoprl10.dat
preloadlpmsis=hpoprl08.dat
preloadproductcontext=hpoprl09.dat
preloadproductmsis=hpoprl07.dat
preloadreadme=hpoprl06.dat
productfinishevent=somestring
provider=HP
setupfinishevent=somestring
shortcut=Yes
shortcutcheckbox=Yes
startup=Yes
UI_261=TimeoutIfSWFirst
DirectConnectSuccessTimeout=5
usingdevicediscovery=Yes
DeviceDiscoveryBucket=DeviceManagement_AIO
%DeviceManagementGUID%={3D47716D-05A9-4538-982E-5D83873A16FD}
[Strings]
_TargetDatFile=autorun,scr
%Preload%=%InstallDirx86%Digital Imaging\%CDGuid%\
%ICETemp%=%ProgramFilesx86%%ICETempInPF%\
%ICETempInPF%=%Manufacturer%\Temp\%CDGuid%
%Recovery%=%ICETemp%
%RecoveryInPF%=%ICETempInPF%
%Preloadx86%=%InstallDirx86%Digital Imaging\%CDGuid%\
%InstallMain%=%InstallDirx86%Digital Imaging\
%ProductScrubberDatfile%=hposcr21.dat
%autorunlocation%=.
%setupName%=hpzsetup.exe
%setupStubName%=hpzstub.exe
%MSIRollbackDatFile%=hpzmsirb.dat
%DeviceInstanceRollbackFile%=hpzdirb.dat
%CUEVersion%=9.0
%CUEDivision%=hpq
%WebPrintVersion%=2.0
%DTSSVersion%=8.0
%SoftwareUpdateVersion%=8.0
%PhotosmartEssentialVersion%=2.01
%bounty_id%=D10
%DeviceManagementGUID%={5DD44B11-5236-4e00-BBCC-F30D94AA8741}
%DeviceManagement_ICE_REV%=01
%DeviceManagementDisplayName%=HP Imaging Device Functions
%DeviceManagementUninstallKey%=HP Imaging Device Functions
%eSupportGUID%={EFD54B7D-744F-4730-8F9C-AAF80E6028BA}
%eSupport_ICE_REV%=05
%eSupportDisplayName%=HP Solution Center
%eSupportUninstallKey%=HP Solution Center & Imaging Support Tools
%CustomerExperienceGUID%={BBE9EEF0-BBAC-4871-90DC-4CE0EC02D00B}
%CustomerExperience_ICE_REV%=06
%CustomerExperienceDisplayName%=HP Customer Participation Program
%CustomerExperienceUninstallKey%=HPExtendedCapabilities
%SoftwareUpdate_ICE_REV%=07
%SoftwareUpdateDisplayName%=HP Update
%SoftwareUpdateUninstallKey%={AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
%OCRGUID%={E379D32C-7B7A-48ad-9166-732A48B5A435}
%OCR_ICE_REV%=11
%OCRDisplayName%=HP OCR Software
%OCRUninstallKey%=HPOCR
%WebPrintGUID%={2D1F2124-29E6-460A-B140-E9DF3BC594CE}
%WebPrint_ICE_REV%=15
%WebPrintDisplayName%=HP Smart Web Printing
%WebPrintUninstallKey%={820F9BE6-0998-4187-BE0C-8192BDDC2FEF}
%DTSSGUID%={3D74A00B-BBFC-4834-A728-0633F0D91840}
%DTSS_ICE_REV%=16
%DTSSDisplayName%=Shop for HP Supplies
%DTSSUninstallKey%={7902E313-FF0F-4493-ACB1-A8147B78DCD0}
%DTSSUpgradeCode%={FE9B929E-3BAF-40B1-BFFC-3A078ABAA0C8}
%PhotosmartEssentialGUID%={7FB920E4-5D4E-4e0f-BB7D-C178E5A11A51}
%PhotosmartEssential_ICE_REV%=13
%PhotosmartEssentialDisplayName%=HP Photosmart Essential %PhotosmartEssentialVersion%
%PhotosmartEssentialUninstallKey%=HP Photosmart Essential
%PhotosmartEssentialBASEGUID%={E4E30953-546D-477b-9C50-5B3E07A0A58E}
%PhotosmartEssentialTATTOOGUID%={EAF69D39-7A09-434e-B743-C2CDA5800D75}
%PhotosmartEssentialNOPODGUID%={3C2E7DE1-4FE5-475e-89D7-BA64C1C7B059}
%pcihelp%=%sourcepath%Setup\ps_aio_02_help\
%pcipath%=%InstallDirx86%Digital Imaging\%CDGuid%\Product\
%pcitour%=%sourcepath%Setup\Tour\
%prlhelp%=%InstallDirx86%Digital Imaging\%CDGuid%\Setup\ps_aio_02_help\
%prltour%=%InstallDirx86%Digital Imaging\%CDGuid%\Setup\Tour\
%InstallMainBin%=%InstallDirx86%Digital Imaging\bin\
[MSI]
InstallDir=%ProgramFilesx86%%Manufacturer%\
_TargetDatFile=autorun,scr
Launchbase=msiexec.exe
commandline=ICE_SUFFIX=%ICE_SUFFIX%
[SUI.OPTIN]
Qualifier=%LangQualifier%
LaunchBase=%sourcepath%setup\
1=hpzgat01.exe -on -gate MARS -f %datfile%
[SUI.OPTOUT]
Qualifier=%LangQualifier%
LaunchBase=%sourcepath%setup\
1=hpzgat01.exe -off -gate MARS -f %datfile%
[SUI]
Opt-In_Default=ON
[LanguageMap]
_TargetDatFile=autorun,scr
0x0409=enu
0x0404=cht
0x0804=chs
0x0405=csy
0x0406=dan
0x0407=deu
0x0408=ell
0x040a=esn
0x040b=fin
0x040c=fra
0x040e=hun
0x0410=ita
0x0411=jpn
0x0412=kor
0x0413=nld
0x0414=nob
0x0415=plk
0x0416=ptb
0x0419=rus
0x041d=sve
0x041f=trk
0x0c04=cht
0x1004=chs
0x1404=cht
0x0813=nld
0x0809=enu
0x0c09=enu
0x1009=enu
0x1409=enu
0x1809=enu
0x1c09=enu
0x2009=enu
0x2409=enu
0x2809=enu
0x2c09=enu
0x080c=fra
0x0c0c=fra
0x100c=fra
0x140c=fra
0x180c=fra
0x0456=esn
0x0807=deu
0x0c07=deu
0x1007=deu
0x1407=deu
0x0810=ita
0x0812=kor
0x0c0a=esn
0x080a=esn
0x100a=esn
0x140a=esn
0x180a=esn
0x1c0a=esn
0x200a=esn
0x240a=esn
0x280a=esn
0x2c0a=esn
0x300a=esn
0x340a=esn
0x380a=esn
0x3c0a=esn
0x400a=esn
0x440a=esn
0x480a=esn
0x4c0a=esn
0x500a=esn
0x042d=esn
0x0403=esn
0x081d=sve
0x0422=rus
0x0816=ptb
0x040d=heb
0x041e=xxx
0x0401=ara
0x0801=ara
0x0c01=ara
0x1001=ara
0x1401=ara
0x1801=ara
0x1c01=ara
0x2001=ara
0x2401=ara
0x2801=ara
0x2c01=ara
0x3001=ara
0x3401=ara
0x3801=ara
0x3c01=ara
0x4001=ara
[TwoLetterLanguageMap]
_TargetDatFile=autorun,scr
ara=ar
cht=zh
chs=zh
csy=cs
dan=da
deu=de
ell=el
enu=en
esn=es
fin=fi
fra=fr
heb=he
hun=hu
ita=it
jpn=ja
kor=ko
nld=nl
nob=no
plk=pl
ptb=pt
rus=ru
sve=sv
trk=tr
[PreInstalls]
1=Kahuna1
2=Kahuna2
3=Kahuna3
4=Kahuna4
5=Kahuna5
6=Kahuna6
7=Kahuna7
[PreInstalls.Kahuna1]
CDGUID={5D22B85D-6503-4c4d-8BE1-D5CD9E0F5181}
1={7AB63E68-A8E2-49EF-A575-CCEC39F66312}
2={45B6180B-DCAB-4093-8EE8-6164457517F0}
[PreInstalls.Kahuna2]
CDGUID={5D32B85D-6503-4c4d-8BE1-D5CD9E0F5181}
1={45B6180B-DCAB-4093-8EE8-6164457517F0}
2={19E1E220-E757-43bd-AC1A-EC095CB8A667}
3={F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}
[PreInstalls.Kahuna3]
CDGUID={C6C44651-7C66-4b11-92E8-17565D3D22DD}
1={45B6180B-DCAB-4093-8EE8-6164457517F0}
2={15B9DC72-73F9-4d99-9E28-848D66DA8D99}
3={F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}
4={0FABD3D7-3036-4e78-B29D-58957ADB0A12}
[PreInstalls.Kahuna4]
CDGUID={5E1494D4-3562-4FFB-B35C-600F80F6934C}
1={45B6180B-DCAB-4093-8EE8-6164457517F0}
2={15B9DC72-73F9-4d99-9E28-848D66DA8D99}
3={A1062847-0846-427A-92A1-BB8251A91E91}
[PreInstalls.Kahuna5]
CDGUID={0D182A5E-AEE0-42ca-BD1D-4EEB2FFA256D}
1={A1062847-0846-427A-92A1-BB8251A91E91}
2={4C04DF1B-6A39-4299-9DD1-1FA60000266E}
3={AAC4FC36-8F89-4587-8DD3-EBC57C83374D}
[PreInstalls.Kahuna6]
CDGUID={D0420D64-8D33-4374-A2B2-9225C7925CA6}
1={A1062847-0846-427A-92A1-BB8251A91E91}
2={4C04DF1B-6A39-4299-9DD1-1FA60000266E}
3={AAC4FC36-8F89-4587-8DD3-EBC57C83374D}
[PreInstalls.Kahuna7]
CDGUID={32498B7B-E1F3-4ad5-A23B-F26414E94BE0}
1={342C7C88-D335-4bc2-8CF1-281857629CE2}
2={ABA2B37F-AB88-486e-870A-52454A23FEE0}
3={BA2D9411-DBB4-43e4-9421-780413650A67}
[SystemRequirements]
AdminRightRequired=1
RunIfFailureAsynch=
RunIfFailureSynch=
RunIfFailureSynchTimeout=
RunIfWarningAsynch=
RunIfWarningSynch=
RunIfWarningSynchTimeout=
checkspooler=No
installspace=916
maxos=
mincolors=16
mincputext=Pentium II, K6, Transmeta 5400
mindisk=372
mindisplay=800x600
minie=6.00.2600.0000
minmhz=233
minram=56
minsysdisk=250
oslist=500,501,501_64,600,600_64
reccolors=16
reccputext=Pentium II, K6, Transmeta 5400
recdisk=372
recdisplay=800x600
recie=6.00.2600.0000
recmhz=233
recram=56
recsysdisk=250
sectionlist=Buckets
warnproducttypelist=3
blockproducttypelist=3
[SystemRequirements.600]
MinBuildNumber=6000
RecBuildNumber=6000
checkspooler=No
installspace=916
maxos=
mincolors=16
mincputext=Pentium II, K6, Transmeta 5400
mindisk=930
mindisplay=800x600
minie=6.00.2600.0000
minmhz=233
minram=56
minsysdisk=160
oslist=500,501,501_64,600,600_64
reccolors=16
reccputext=Pentium II, K6, Transmeta 5400
recdisk=930
recdisplay=800x600
recie=6.00.2600.0000
recmhz=233
recram=56
recsysdisk=160
sectionlist=Buckets
warnproducttypelist=3
blockproducttypelist=3
[SystemRequirements.Min]
SysReqPlugIn=%sourcepath%setup\hpzchk01.exe
[OSBlock.400]
launchbase=Setup\
1=hpzchk01.exe
[OSBlock.410]
launchbase=Setup\
1=hpzchk01.exe
[OSBlock.490]
launchbase=Setup\
1=hpzchk01.exe
[RunAs]
launchbase=Setup\
Qualifier=%OS%
[RunAs.500]
launchbase=Setup\
1=hpzchk01.exe
[RunAs.501]
launchbase=Setup\
1=hpzchk01.exe
[RunAs.501_64]
launchbase=Setup\
1=hpzchk01.exe
[Run1]
launchbase=%sourcepath%setup\
1=hpzpnp%ICE_SUFFIX%.exe
2=hpzpsc01.exe -OSUP
3=hpzrein01.exe
4=hpzwup01.exe
5=hpzshl%ICE_SUFFIX%.exe -m WebPrintShield
6=hpzshl%ICE_SUFFIX%.exe -m DelayedReboot
qualifier=%os%
[Run2]
launchbase=%sourcepath%setup\
1=hpzopt01.exe
2=hpqbhp01.exe
3=hpzpsc01.exe -list ProductReleases -CPE
4=hpzsui01.exe
5=hpzshl%ICE_SUFFIX%.exe -m Printer,ICEPreShield,HPSecurity,CompositeDev,MassStorage,CloseManagerofTrayApp
6=[Run.SetRecovery]
qualifier=%os%
[Run3]
launchbase=%sourcepath%Setup\
1=[PatchesAvailable]
2=hpzprl%ICE_SUFFIX%.exe -m PreloadICEEngineToGUIDFolder
3=hpzprl%ICE_SUFFIX%.exe -m PreloadICEExes
4=[DPInstRunXML]
5=[dot4wrp]
6=[Run.stepbystep]
7=hpznop01.exe -PostRegisteredMessage WM_START_BITMAP_TIMER
8=hpzcdl01.exe -storesourcepath
9=[BucketsAvailable]
10=[Run.easyinstall]
11=hpzfwx01.exe -m postinstallfirewallexceptionlist
12=[Run.CommitFull]
qualifier=%os%
[Run.StepByStep]
1=hpzpnp%ICE_SUFFIX%.exe -clean -gateoncmdline easyinstall -runifoff
2=hpzdui%ICE_SUFFIX%.exe -gateoncmdline easyinstall -runifoff
3=hpzpnp%ICE_SUFFIX%.exe -clean -gateoncmdline easyinstall runifoff
[Run.EasyInstall]
1=hpzpnp%ICE_SUFFIX%.exe -clean -gateoncmdline easyinstall
2=hpzdui%ICE_SUFFIX%.exe -gateoncmdline easyinstall
3=hpzpnp%ICE_SUFFIX%.exe -clean -gateoncmdline easyinstall
[Uninstall]
launchbase=%sourcepath%setup\
1=hpzscr%ICE_SUFFIX%.exe -datfile %ProductScrubberDatfile% -onestop
[ARP.SuppressRebootList]
hpzscr%ICE_SUFFIX%.exe=-r0
msiexec.exe=Reboot="ReallySuppress"
[Prescrub.CPE]
launchbase=%sourcepath%Setup\
SkipOnReinstall=SW
[MSI.FX]
Filename=netfx.msi
RefCount=No
Logfilename=%Temp%hpzFx_Log.txt
CopyToTemp=netfx.msi,netfx1.cab
[MSI.FXLangPack]
Filename=Langpacks\%lang%\langpack.msi
RefCount=No
Logfilename=%Temp%hpzFx%lang%_Log.txt
CopyToTemp=Langpacks\%lang%\langpack.msi,Langpacks\%lang%\langpac1.cab
[MSI.FXLangPack.0x9]
Filename=None.msi
RefCount=No
UI=No
CopyToTemp=hpzmsi01.exe
IgnoreReturnCode=Yes
[MSI.FXLangPack.0x1]
Filename=None.msi
RefCount=No
UI=No
CopyToTemp=hpzmsi01.exe
IgnoreReturnCode=Yes
[MSI.FXLangPack.0xd]
Filename=None.msi
RefCount=No
UI=Yes
CopyToTemp=hpzmsi01.exe
IgnoreReturnCode=Yes
[NetFx]
SkipIfOS=600,600_64
1=StopMSIService
2=Core
3=LangPack
[NetFx.StopMSIService]
1=%sourcepath%setup\hpzwis01.exe -stop
[NetFx.Core]
RegValueToLookFor=OCM
RegKeyToLookFor=SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322
RegValueShouldBeEqualTo=1
1=%sourcepath%setup\hpzmsi01.exe -m FX
[NetFx.LangPack]
Qualifier=%PrimaryLangQualifier%
RegValueToLookFor=OCM
RegKeyToLookFor=SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322\%langid%
RegValueShouldBeEqualTo=1
1=%sourcepath%setup\hpzmsi01.exe -m FXLangPack
[NetFx.LangPack.0x9]
1=%sourcepath%setup\hpznop01.exe
[NetFx.LangPack.0x1]
1=%sourcepath%setup\hpznop01.exe
[NetFx.LangPack.0xd]
1=%sourcepath%setup\hpznop01.exe
[NetFx.LangPack.0xa]
RegKeyToLookFor=SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322\3082
[Setup.Text]
hpznfx01.exe=Installing Microsoft .NET Framework
hpzdxs01.exe=Installing Microsoft DirectX 9.0
HPZpsc01.exe=Searching for installed applications
HPZchk01.exe=Checking System Requirements
HPZwis01.exe=Updating Windows Installer Service
HPZpnp01.exe=Checking hardware
HPZscr01.exe=Uninstalling
HPZwrp01.exe=Installing Additional Software
HPZarp01.exe=Creating Add/Remove Programs entries
HPZrcv01.exe=Setting Recovery Point
HPZdui01.exe=Connecting device
HPZshl01.exe=Inspecting system
HPZopt01.exe=Waiting for user input
HPZsui01.exe=Waiting for user input
HPZrein01.exe=Waiting for user input
HPZtim01.exe=Waiting for user input
HPZdui40.exe=Connecting device
HPZpnp40.exe=Checking hardware
HPZscr40.exe=Uninstalling
HPZshl40.exe=Inspecting system
HPZnui01.exe=Installing Network Device
[Setup.Text.0x804]
hpznfx01.exe=ڰװ Microsoft .NET Framework
hpzdxs01.exe=ڰװ Microsoft DirectX 9.0
HPZpsc01.exe=ѰװӦó
HPZchk01.exe=ϵͳ
HPZwis01.exe= Windows Installer
HPZpnp01.exe=Ӳ
HPZscr01.exe=ж
HPZwrp01.exe=װ
HPZarp01.exe=/ɾĿ
HPZrcv01.exe=ûԭ
HPZdui01.exe=豸
HPZshl01.exe=ϵͳ
HPZopt01.exe=ȴû
HPZsui01.exe=ȴû
HPZrein01.exe=ȴû
HPZtim01.exe=ȴû
HPZdui40.exe=豸
HPZpnp40.exe=Ӳ
HPZscr40.exe=ж
HPZshl40.exe=ϵͳ
HPZnui01.exe=װ豸
[Setup.Text.0x404]
hpznfx01.exe=w Microsoft .NET Framework
hpzdxs01.exe=w Microsoft DirectX 9.0
HPZpsc01.exe=jMww˪ε{
HPZchk01.exe=ˬdtλݨD
HPZwis01.exe=ɯ Windows Installer A
HPZpnp01.exe=ˬdw
HPZscr01.exe=Ѱwˤ
HPZwrp01.exe=w˨Ln
HPZarp01.exe=إ߷sW/{
HPZrcv01.exe=]w״_I
HPZdui01.exe=s˸m
HPZshl01.exe=t
HPZopt01.exe=ݨϥΪ̿J
HPZsui01.exe=ݨϥΪ̿J
HPZrein01.exe=ݨϥΪ̿J
HPZtim01.exe=ݨϥΪ̿J
HPZdui40.exe=s˸m
HPZpnp40.exe=ˬdw
HPZscr40.exe=Ѱwˤ
HPZshl40.exe=t
HPZnui01.exe=w˺˸m
[Setup.Text.0x5]
hpznfx01.exe=Instaluje se Microsoft .NET Framework
hpzdxs01.exe=Instaluje se Microsoft DirectX 9.0
HPZpsc01.exe=Vyhledvn nainstalovanch aplikac
HPZchk01.exe=Kontrola poadavk na systm
HPZwis01.exe=Aktualizace sluby Windows Installer
HPZpnp01.exe=Kontrola hardwaru
HPZscr01.exe=Odinstalace
HPZwrp01.exe=Instalace dalho softwaru
HPZarp01.exe=Vytven poloek v panelu Pidat nebo odebrat programy
HPZrcv01.exe=Nastaven bodu obnoven
HPZdui01.exe=Pipojen zazen
HPZshl01.exe=Kontrola systmu
HPZopt01.exe=ekn na vstup od uivatele
HPZsui01.exe=ekn na vstup od uivatele
HPZrein01.exe=ekn na vstup od uivatele
HPZtim01.exe=ekn na vstup od uivatele
HPZdui40.exe=Pipojen zazen
HPZpnp40.exe=Kontrola hardwaru
HPZscr40.exe=Odinstalace
HPZshl40.exe=Kontrola systmu
HPZnui01.exe=Instalace sovho zazen
[Setup.Text.0x6]
hpznfx01.exe=Installerer Microsoft .NET Framework
hpzdxs01.exe=Installerer Microsoft DirectX 9.0
HPZpsc01.exe=Sger efter allerede installerede programmer
HPZchk01.exe=Undersger systemkrav
HPZwis01.exe=Opdaterer tjenesten Windows Installer
HPZpnp01.exe=Undersger hardware
HPZscr01.exe=Fjerner
HPZwrp01.exe=Installerer yderligere software
HPZarp01.exe=Opretter poster i Tilfj/fjern programmer
HPZrcv01.exe=Indstiller gendannelsespunkt
HPZdui01.exe=Tilslutter enhed
HPZshl01.exe=Undersger system
HPZopt01.exe=Venter p brugerinput
HPZsui01.exe=Venter p brugerinput
HPZrein01.exe=Venter p brugerinput
HPZtim01.exe=Venter p brugerinput
HPZdui40.exe=Tilslutter enhed
HPZpnp40.exe=Undersger hardware
HPZscr40.exe=Fjerner
HPZshl40.exe=Undersger system
HPZnui01.exe=Installerer netvrksenhed
[Setup.Text.0x7]
hpznfx01.exe=Microsoft .NET Framework wird installiert
hpzdxs01.exe=Microsoft DirectX 9.0 wird installiert
HPZpsc01.exe=Installierte Anwendungen werden gesucht
HPZchk01.exe=Systemanforderungen werden geprft
HPZwis01.exe=Windows-Installationsdienst wird aktualisiert
HPZpnp01.exe=Hardware wird geprft
HPZscr01.exe=Deinstallieren
HPZwrp01.exe=Weitere Software wird installiert
HPZarp01.exe=Eintrge zum Hinzufgen/Entfernen von Programmen werden erstellt
HPZrcv01.exe=Wiederherstellungsdaten werden gespeichert
HPZdui01.exe=Gert wird verbunden
HPZshl01.exe=System wird untersucht
HPZopt01.exe=Warten auf Benutzereingabe
HPZsui01.exe=Warten auf Benutzereingabe
HPZrein01.exe=Warten auf Benutzereingabe
HPZtim01.exe=Warten auf Benutzereingabe
HPZdui40.exe=Gert wird verbunden
HPZpnp40.exe=Hardware wird geprft
HPZscr40.exe=Deinstallieren
HPZshl40.exe=System wird untersucht
HPZnui01.exe=Netzwerkgert wird installiert
[Setup.Text.0x8]
hpznfx01.exe= Microsoft .NET Framework
hpzdxs01.exe= Microsoft DirectX 9.0
HPZpsc01.exe=
HPZchk01.exe=
HPZwis01.exe= Windows Installer
HPZpnp01.exe=
HPZscr01.exe=
HPZwrp01.exe=
HPZarp01.exe= " "
HPZrcv01.exe=
HPZdui01.exe=
HPZshl01.exe=
HPZopt01.exe=
HPZsui01.exe=
HPZrein01.exe=
HPZtim01.exe=
HPZdui40.exe=
HPZpnp40.exe=
HPZscr40.exe=
HPZshl40.exe=
HPZnui01.exe=
[Setup.Text.0x9]
hpznfx01.exe=Installing Microsoft .NET Framework
hpzdxs01.exe=Installing Microsoft DirectX 9.0
HPZpsc01.exe=Searching for installed applications
HPZchk01.exe=Checking System Requirements
HPZwis01.exe=Updating Windows Installer Service
HPZpnp01.exe=Checking hardware
HPZscr01.exe=Uninstalling
HPZwrp01.exe=Installing Additional Software
HPZarp01.exe=Creating Add/Remove Programs entries
HPZrcv01.exe=Setting Recovery Point
HPZdui01.exe=Connecting device
HPZshl01.exe=Inspecting system
HPZopt01.exe=Waiting for user input
HPZsui01.exe=Waiting for user input
HPZrein01.exe=Waiting for user input
HPZtim01.exe=Waiting for user input
HPZdui40.exe=Connecting device
HPZpnp40.exe=Checking hardware
HPZscr40.exe=Uninstalling
HPZshl40.exe=Inspecting system
HPZnui01.exe=Installing Network Device
[Setup.Text.0xa]
hpznfx01.exe=Instalando Microsoft .NET Framework
hpzdxs01.exe=Instalando Microsoft DirectX 9.0
HPZpsc01.exe=Buscando aplicaciones instaladas
HPZchk01.exe=Comprobando los requisitos del sistema
HPZwis01.exe=Actualizando el servicio Windows Installer
HPZpnp01.exe=Comprobando el hardware
HPZscr01.exe=Desinstalando
HPZwrp01.exe=Instalando software adicional
HPZarp01.exe=Creando entradas para Agregar o quitar programas
HPZrcv01.exe=Estableciendo punto de recuperacin
HPZdui01.exe=Conectando dispositivo
HPZshl01.exe=Inspeccionando el sistema
HPZopt01.exe=Esperando datos del usuario
HPZsui01.exe=Esperando datos del usuario
HPZrein01.exe=Esperando datos del usuario
HPZtim01.exe=Esperando datos del usuario
HPZdui40.exe=Conectando dispositivo
HPZpnp40.exe=Comprobando el hardware
HPZscr40.exe=Desinstalando
HPZshl40.exe=Inspeccionando el sistema
HPZnui01.exe=Instalando el dispositivo de red
[Setup.Text.0xb]
hpznfx01.exe=Ohjelma asentaa Microsoft .NET Framework -ohjelmaa
hpzdxs01.exe=Ohjelma asentaa Microsoft DirectX 9.0 -ohjelmaa
HPZpsc01.exe=Etsitn asennettuja sovelluksia
HPZchk01.exe=Tarkastetaan jrjestelmvaatimuksia
HPZwis01.exe=Pivitetn Windows Installer -palvelua
HPZpnp01.exe=Tarkastetaan laitteistoa
HPZscr01.exe=Asennusta poistetaan
HPZwrp01.exe=Asennetaan muita ohjelmia
HPZarp01.exe=Luodaan Lis tai poista sovellus -ikkunan tietoja
HPZrcv01.exe=Mritetn palautuspistett
HPZdui01.exe=Kytketn laitetta
HPZshl01.exe=Tarkastetaan jrjestelm
HPZopt01.exe=Odotetaan kyttjn sytett
HPZsui01.exe=Odotetaan kyttjn sytett
HPZrein01.exe=Odotetaan kyttjn sytett
HPZtim01.exe=Odotetaan kyttjn sytett
HPZdui40.exe=Kytketn laitetta
HPZpnp40.exe=Tarkastetaan laitteistoa
HPZscr40.exe=Asennusta poistetaan
HPZshl40.exe=Tarkastetaan jrjestelm
HPZnui01.exe=Asennetaan verkkolaitetta
[Setup.Text.0xc]
hpznfx01.exe=Installation de Microsoft .NET Framework
hpzdxs01.exe=Installation de Microsoft DirectX 9.0
HPZpsc01.exe=Recherche des applications installes
HPZchk01.exe=Vrification de la configuration systme requise
HPZwis01.exe=Mise jour du service Windows Installer
HPZpnp01.exe=Vrification du matriel
HPZscr01.exe=Dsinstallation
HPZwrp01.exe=Installation de logiciel supplmentaire
HPZarp01.exe=Cration d'entres dans la bote de dialogue Ajout/Suppression de programmes
HPZrcv01.exe=Dfinition du point de rcupration
HPZdui01.exe=Connexion du priphrique
HPZshl01.exe=Inspection du systme
HPZopt01.exe=Attente d'une intervention de l'utilisateur
HPZsui01.exe=Attente d'une intervention de l'utilisateur
HPZrein01.exe=Attente d'une intervention de l'utilisateur
HPZtim01.exe=Attente d'une intervention de l'utilisateur
HPZdui40.exe=Connexion du priphrique
HPZpnp40.exe=Vrification du matriel
HPZscr40.exe=Dsinstallation
HPZshl40.exe=Inspection du systme
HPZnui01.exe=Installation du priphrique rseau
[Setup.Text.0xe]
hpznfx01.exe=Microsoft .NET Framework teleptse
hpzdxs01.exe=Microsoft DirectX 9.0 teleptse
HPZpsc01.exe=Teleptett alkalmazsok keresse
HPZchk01.exe=Rendszerkvetelmnyek ellenrzse
HPZwis01.exe=Windows teleptszolgltats frisstse
HPZpnp01.exe=Hardver ellenrzse
HPZscr01.exe=Eltvolts
HPZwrp01.exe=Tovbbi programok teleptse
HPZarp01.exe=Elem ltrehozsa a Programok teleptse/trlse rszben
HPZrcv01.exe=Helyrelltsi pont belltsa
HPZdui01.exe=Kapcsolds az eszkzhz
HPZshl01.exe=Rendszer elemzse
HPZopt01.exe=Vrakozs felhasznli adatbevitelre
HPZsui01.exe=Vrakozs felhasznli adatbevitelre
HPZrein01.exe=Vrakozs felhasznli adatbevitelre
HPZtim01.exe=Vrakozs felhasznli adatbevitelre
HPZdui40.exe=Kapcsolds az eszkzhz
HPZpnp40.exe=Hardver ellenrzse
HPZscr40.exe=Eltvolts
HPZshl40.exe=Rendszer elemzse
HPZnui01.exe=Hlzati eszkz teleptse
[Setup.Text.0x10]
hpznfx01.exe=Installazione di Microsoft .NET Framework
hpzdxs01.exe=Installazione di Microsoft DirectX 9.0
HPZpsc01.exe=Ricerca delle applicazioni installate
HPZchk01.exe=Verifica dei requisiti di sistema
HPZwis01.exe=Aggiornamento del servizio Windows Installer
HPZpnp01.exe=Verifica dell'hardware
HPZscr01.exe=Disinstallazione
HPZwrp01.exe=Installazione del software supplementare
HPZarp01.exe=Creazione delle voci di Installazione applicazioni
HPZrcv01.exe=Impostazione del punto di ripristino
HPZdui01.exe=Collegamento della periferica
HPZshl01.exe=Analisi del sistema
HPZopt01.exe=Attesa input utente
HPZsui01.exe=Attesa input utente
HPZrein01.exe=Attesa input utente
HPZtim01.exe=Attesa input utente
HPZdui40.exe=Collegamento della periferica
HPZpnp40.exe=Verifica dell'hardware
HPZscr40.exe=Disinstallazione
HPZshl40.exe=Analisi del sistema
HPZnui01.exe=Installazione della periferica di rete
[Setup.Text.0x11]
hpznfx01.exe=Microsoft .NET Framework CXg[Ă܂
hpzdxs01.exe=Microsoft DirectX 9.0 CXg[Ă܂
HPZpsc01.exe=CXg[ĂAvP[VĂ܂
HPZchk01.exe=VXeKṽ`FbN
HPZwis01.exe=Windows CXg[ T[rX̍XV
HPZpnp01.exe=n[hEFÃ`FbN
HPZscr01.exe=ACXg[
HPZwrp01.exe=̑̃\tgEFACXg[Ă܂
HPZarp01.exe=lj^폜vO Gg쐬Ă܂
HPZrcv01.exe=񕜃|Cg̐ݒ蒆
HPZdui01.exe=foCX̐ڑ
HPZshl01.exe=VXe
HPZopt01.exe=[U[̓͂҂Ă܂
HPZsui01.exe=[U[̓͂҂Ă܂
HPZrein01.exe=[U[̓͂҂Ă܂
HPZtim01.exe=[U[̓͂҂Ă܂
HPZdui40.exe=foCX̐ڑ
HPZpnp40.exe=n[hEFÃ`FbN
HPZscr40.exe=ACXg[
HPZshl40.exe=VXe
HPZnui01.exe=lbg[N foCX̃CXg[
[Setup.Text.0x12]
hpznfx01.exe=Microsoft .NET Framework ġ
hpzdxs01.exe=Microsoft DirectX 9.0 ġ
HPZpsc01.exe=ġ α׷ ã
HPZchk01.exe=ý 䱸 Ȯ
HPZwis01.exe=Windows ġ Ʈϴ
HPZpnp01.exe=ϵ ˻ϴ
HPZscr01.exe=
HPZwrp01.exe=߰ Ʈ ġ
HPZarp01.exe=α׷ ׸ ߰/
HPZrcv01.exe= Ʈ
HPZdui01.exe=ġ
HPZshl01.exe=ý ˻
HPZopt01.exe= Է
HPZsui01.exe= Է
HPZrein01.exe= Է
HPZtim01.exe= Է
HPZdui40.exe=ġ
HPZpnp40.exe=ϵ ˻ϴ
HPZscr40.exe=
HPZshl40.exe=ý ˻
HPZnui01.exe=Ʈũ ġ ġ
[Setup.Text.0x13]
hpznfx01.exe='Microsoft .NET Framework' installeren
hpzdxs01.exe='Microsoft DirectX 9.0' installeren
HPZpsc01.exe=Bezig met zoeken naar genstalleerde toepassingen
HPZchk01.exe=Bezig met controleren van systeemvereisten
HPZwis01.exe=Bezig met bijwerken van Windows Installer-service
HPZpnp01.exe=Bezig met controleren van hardware
HPZscr01.exe=Bezig met ongedaan maken van installatie
HPZwrp01.exe=Bezig met installeren van aanvullende software
HPZarp01.exe=Bezig met aanmaken van items voor Software
HPZrcv01.exe=Bezig met maken van herstelpunt
HPZdui01.exe=Bezig met aansluiten van apparaat
HPZshl01.exe=Bezig met systeemcontrole
HPZopt01.exe=Wachten op invoer van gebruiker
HPZsui01.exe=Wachten op invoer van gebruiker
HPZrein01.exe=Wachten op invoer van gebruiker
HPZtim01.exe=Wachten op invoer van gebruiker
HPZdui40.exe=Bezig met aansluiten van apparaat
HPZpnp40.exe=Bezig met controleren van hardware
HPZscr40.exe=Bezig met ongedaan maken van installatie
HPZshl40.exe=Bezig met systeemcontrole
HPZnui01.exe=Bezig met installeren van netwerkapparaat
[Setup.Text.0x14]
hpznfx01.exe=Installerer 'Microsoft .NET Framework'
hpzdxs01.exe=Installerer 'Microsoft DirectX 9.0'
HPZpsc01.exe=Sker etter installerte programmer
HPZchk01.exe=Kontrollerer systemkrav
HPZwis01.exe=Oppdaterer Windows-installeringstjeneste
HPZpnp01.exe=Kontrollerer maskinvare
HPZscr01.exe=Avinstallerer
HPZwrp01.exe=Installerer tilleggsprogramvare
HPZarp01.exe=Oppretter oppfringer for Legg til / fjern programmer
HPZrcv01.exe=Angir gjenopprettingspunkt
HPZdui01.exe=Kobler til enhet
HPZshl01.exe=Inspiserer system
HPZopt01.exe=Venter p brukerinndata
HPZsui01.exe=Venter p brukerinndata
HPZrein01.exe=Venter p brukerinndata
HPZtim01.exe=Venter p brukerinndata
HPZdui40.exe=Kobler til enhet
HPZpnp40.exe=Kontrollerer maskinvare
HPZscr40.exe=Avinstallerer
HPZshl40.exe=Inspiserer system
HPZnui01.exe=Installere nettverksenhet
[Setup.Text.0x15]
hpznfx01.exe=Instalacja 'Microsoft .NET Framework'
hpzdxs01.exe=Instalacja 'Microsoft DirectX 9.0'
HPZpsc01.exe=Trwa wyszukiwanie zainstalowanych aplikacji
HPZchk01.exe=Trwa sprawdzanie wymaga systemowych
HPZwis01.exe=Trwa aktualizowanie usugi Instalator Windows
HPZpnp01.exe=Trwa sprawdzanie sprztu
HPZscr01.exe=Trwa odinstalowywanie
HPZwrp01.exe=Trwa instalowanie dodatkowego oprogramowania
HPZarp01.exe=Trwa tworzenie wpisw aplikacji Dodaj/Usu programy
HPZrcv01.exe=Trwa ustawianie punktu odzyskiwania danych
HPZdui01.exe=Trwa podczanie urzdzenia
HPZshl01.exe=Trwa inspekcja systemu
HPZopt01.exe=Trwa oczekiwanie na wprowadzenie danych przez uytkownika
HPZsui01.exe=Trwa oczekiwanie na wprowadzenie danych przez uytkownika
HPZrein01.exe=Trwa oczekiwanie na wprowadzenie danych przez uytkownika
HPZtim01.exe=Trwa oczekiwanie na wprowadzenie danych przez uytkownika
HPZdui40.exe=Trwa podczanie urzdzenia
HPZpnp40.exe=Trwa sprawdzanie sprztu
HPZscr40.exe=Trwa odinstalowywanie
HPZshl40.exe=Trwa inspekcja systemu
HPZnui01.exe=Trwa instalowanie urzdzenia sieciowego
[Setup.Text.0x16]
hpznfx01.exe=Instalando o Microsoft .NET Framework
hpzdxs01.exe=Instalando o Microsoft DirectX 9.0
HPZpsc01.exe=Procurando aplicativos instalados
HPZchk01.exe=Verificando exigncias do sistema
HPZwis01.exe=Atualizando o servio Windows Installer
HPZpnp01.exe=Verificando hardware
HPZscr01.exe=Desinstalando
HPZwrp01.exe=Instalando software adicional
HPZarp01.exe=Criando entradas em Adicionar ou Remover Programas
HPZrcv01.exe=Definindo ponto de recuperao
HPZdui01.exe=Conectando dispositivo
HPZshl01.exe=Inspecionando sistema
HPZopt01.exe=Aguardando entrada do usurio
HPZsui01.exe=Aguardando entrada do usurio
HPZrein01.exe=Aguardando entrada do usurio
HPZtim01.exe=Aguardando entrada do usurio
HPZdui40.exe=Conectando dispositivo
HPZpnp40.exe=Verificando hardware
HPZscr40.exe=Desinstalando
HPZshl40.exe=Inspecionando sistema
HPZnui01.exe=Instalando dispositivo de rede
[Setup.Text.0x19]
hpznfx01.exe= Microsoft .NET Framework
hpzdxs01.exe= Microsoft DirectX 9.0
HPZpsc01.exe=
HPZchk01.exe=
HPZwis01.exe= Windows
HPZpnp01.exe=
HPZscr01.exe=
HPZwrp01.exe=
HPZarp01.exe=
HPZrcv01.exe=
HPZdui01.exe=
HPZshl01.exe=
HPZopt01.exe=
HPZsui01.exe=
HPZrein01.exe=
HPZtim01.exe=
HPZdui40.exe=
HPZpnp40.exe=
HPZscr40.exe=
HPZshl40.exe=
HPZnui01.exe=
[Setup.Text.0x1d]
hpznfx01.exe=Installerar Microsoft .NET Framework
hpzdxs01.exe=Installerar Microsoft DirectX 9.0
HPZpsc01.exe=Sker efter installerade program
HPZchk01.exe=Kontrollerar systemkrav
HPZwis01.exe=Uppdaterar tjnsten Windows Installer
HPZpnp01.exe=Kontrollerar maskinvara
HPZscr01.exe=Avinstallerar
HPZwrp01.exe=Installerar ytterligare programvara
HPZarp01.exe=Skapa poster fr Lgg till/Ta bort program
HPZrcv01.exe=Skapar terstllningspunkt
HPZdui01.exe=Ansluter enhet
HPZshl01.exe=Kontrollerar system
HPZopt01.exe=Vntar p anvndarindata
HPZsui01.exe=Vntar p anvndarindata
HPZrein01.exe=Vntar p anvndarindata
HPZtim01.exe=Vntar p anvndarindata
HPZdui40.exe=Ansluter enhet
HPZpnp40.exe=Kontrollerar maskinvara
HPZscr40.exe=Avinstallerar
HPZshl40.exe=Kontrollerar system
HPZnui01.exe=Installera ntverksenhet
[Setup.Text.0x1f]
hpznfx01.exe=Microsoft .NET Framework Ykleniyor
hpzdxs01.exe=Microsoft DirectX 9.0 Ykleniyor
HPZpsc01.exe=Ykl uygulamalar aranyor
HPZchk01.exe=Sistem Gereksinimleri Kontrol Ediliyor
HPZwis01.exe=Windows Ykleyici Hizmeti Gncelletiriliyor
HPZpnp01.exe=Donanm kontrol ediliyor
HPZscr01.exe=Ykleme kaldrlyor
HPZwrp01.exe=Ek Yazlm Ykleniyor
HPZarp01.exe=Program Ekle/Kaldr girileri oluturuluyor
HPZrcv01.exe=Geri Dn Noktas Ayarlanyor
HPZdui01.exe=Aygt balanyor
HPZshl01.exe=Sistem denetleniyor
HPZopt01.exe=Kullanc girii bekleniyor
HPZsui01.exe=Kullanc girii bekleniyor
HPZrein01.exe=Kullanc girii bekleniyor
HPZtim01.exe=Kullanc girii bekleniyor
HPZdui40.exe=Aygt balanyor
HPZpnp40.exe=Donanm kontrol ediliyor
HPZscr40.exe=Ykleme kaldrlyor
HPZshl40.exe=Sistem denetleniyor
HPZnui01.exe=A Aygt Ykleniyor
[Setup.Text.0x1]
hpznfx01.exe= Microsoft .NET Framework
hpzdxs01.exe= Microsoft DirectX 9.0
HPZpsc01.exe=
HPZchk01.exe=
HPZwis01.exe= Windows
HPZpnp01.exe=
HPZscr01.exe=
HPZwrp01.exe=
HPZarp01.exe= '/ '
HPZrcv01.exe=
HPZdui01.exe=
HPZshl01.exe=
HPZopt01.exe=
HPZsui01.exe=
HPZrein01.exe=
HPZtim01.exe=
HPZdui40.exe=
HPZpnp40.exe=
HPZscr40.exe=
HPZshl40.exe=
HPZnui01.exe=
[Setup.Text.0xd]
hpznfx01.exe= Microsoft .NET Framework
hpzdxs01.exe= Microsoft DirectX 9.0
HPZpsc01.exe=
HPZchk01.exe=
HPZwis01.exe= Windows Installer
HPZpnp01.exe=
HPZscr01.exe=
HPZwrp01.exe=
HPZarp01.exe= /
HPZrcv01.exe=
HPZdui01.exe=
HPZshl01.exe=
HPZopt01.exe=
HPZsui01.exe=
HPZrein01.exe=
HPZtim01.exe=
HPZdui40.exe=
HPZpnp40.exe=
HPZscr40.exe=
HPZshl40.exe=
HPZnui01.exe=
[MSI.SelfInstallingPortMonitor]
InstallDir=%System%
Filename=%sourcepath%setup\SIPM\HP_Standard_Port_Monitor.msi
RefCount=No
UI=No
IgnoreNewerVersion=No
SkipIfSilent=No
SkipOnReinstall=DRV
Logfilename=%Temp%%DIVISION%MSI_PortMonitor.log
TRANSFORMS=SIPM\%langid%.MST
[MSI.SelfInstallingPortMonitor_64]
InstallDir=%System%
Filename=%sourcepath%setup\SIPM_64\HP Standard Port Monitor.msi
RefCount=No
UI=No
IgnoreNewerVersion=No
SkipIfSilent=No
SkipOnReinstall=DRV
Logfilename=%Temp%%DIVISION%MSI_PortMonitor.log
TRANSFORMS=SIPM_64\%langid%.MST
[InstallPortMonitor.500]
1=hpzmsi01.exe -m SelfInstallingPortMonitor
[InstallPortMonitor.501]
1=hpzmsi01.exe -m SelfInstallingPortMonitor
[InstallPortMonitor.600]
1=hpzmsi01.exe -m SelfInstallingPortMonitor
[InstallPortMonitor.501_64]
1=hpzmsi01.exe -m SelfInstallingPortMonitor_64
[InstallPortMonitor.502_64]
1=hpzmsi01.exe -m SelfInstallingPortMonitor_64
[InstallPortMonitor.600_64]
1=hpzmsi01.exe -m SelfInstallingPortMonitor_64
[Recovery.LogAnalysis]
CollectLogs=Yes
[Recovery.Startup]
1=%Recovery%setup\hpzrcv01.exe -f ..\%autorunName% -recover
[Recovery.Recover]
1=%Recovery%Setup\hpzscr%ICE_SUFFIX%.exe -datfile .\%ProductScrubberDatfile% -d MsiUninstaller -unattended -forcereboot
[Recovery.SetupQuit]
launchbase=%sourcepath%Setup\
1=hpzrcv01.exe -unsetrecovery
[Uninstall.ERROR_FAILURE_CLEANUP]
launchbase=%sourcepath%Setup\
1=hpzrcv01.exe -recover -logs
[Uninstall.ERROR_FAILURE_CLEANUP.Run4]
launchbase=%sourcepath%Setup\
1=hpzrcv01.exe -recover Run4 -logs
[Recovery.Run4.Recover]
1=%Recovery%Setup\hpzscr%ICE_SUFFIX%.exe -datfile %DeviceInstanceRollbackFile% -unattended -forcereboot
[Recovery.MSIOnly.Startup]
1=%recovery%setup\hpzrcv01.exe -f ..\%autorunName% -recover MSIOnly -logs
[Recovery.MSIOnly.Recover]
SWOnly=Yes
1=%Recovery%Setup\hpzscr%ICE_SUFFIX%.exe -datfile %MsiRollbackDatFile% -unattended -forcereboot
[Recovery.MSIOnly.Error_Failure_Cleanup]
1=hpzrcv01.exe -recover MSIOnly -logs
[Run.SetRecovery]
launchbase=%sourcepath%setup\
1=hpzprl%ICE_SUFFIX%.exe -m PreloadRecoveryMechanism
2=hpzrcv01.exe -setrecovery
[Run.CommitProduct]
launchbase=%sourcepath%setup\
1=hpzmsi01.exe -commit
2=..\%setupName% -commitGuid %CDGuid%
3=hpzrcv01.exe -unsetrecovery
4=hpzrcv01.exe -setrecovery MSIOnly
[Run.CommitFull]
launchbase=%sourcepath%setup\
1=hpzmsi01.exe -commit
2=hpzrcv01.exe -unsetrecovery
[FilesThatForceReboot]
1=mscoree.dll
2=MICROS~1.NET\FRAMEW~1\V11~1.432
3=Microsoft.NET\Framework\v1.1.4322
[WUP]
SecondsToWaitForConnection=30
SecondsToWaitForDownloadComplete=600
[WUP.OptIn]
1=ProductAssistantOpted
2=ProductAssistantNever
3=HPSUNotify
4=HPSUDays
[Wup.OptOut]
1=ProductAssistantOpted
2=ProductAssistantNever
3=HPSUNotify
4=HPSUDays
[Wup.ProductAssistantOpted]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\Product Assistant
Value=OptInCompleted
OptInData=1
OptOutData=1
[Wup.ProductAssistantOpted.501_64]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard\Product Assistant
[Wup.ProductAssistantOpted.502_64]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard\Product Assistant
[Wup.ProductAssistantOpted.600_64]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard\Product Assistant
[Wup.ProductAssistantNever]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HP Software Update\Product Assistant
Value=Never
OptOutData=1
OptInData=0
[Wup.ProductAssistantNever.501_64]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard\HP Software Update\Product Assistant
[Wup.ProductAssistantNever.502_64]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard\HP Software Update\Product Assistant
[Wup.ProductAssistantNever.600_64]
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard\HP Software Update\Product Assistant
[Wup.HPSUNotify]
Key=HKEY_LOCAL_MACHINE\Software\Hewlett-Packard\HP Software Update
Value=Notify
OptInData=1
OptOutData=0
[WUP.HPSUNotify.501_64]
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Hewlett-Packard\HP Software Update
[Wup.HPSUNotify.502_64]
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Hewlett-Packard\HP Software Update
[Wup.HPSUNotify.600_64]
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Hewlett-Packard\HP Software Update
[Wup.HPSUDays]
Key=HKEY_LOCAL_MACHINE\Software\Hewlett-Packard\HP Software Update
Value=nDays
OptInData=7
OptOutData=30
[WUP.HPSUDays.501_64]
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Hewlett-Packard\HP Software Update
[Wup.HPSUDays.502_64]
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Hewlett-Packard\HP Software Update
[Wup.HPSUDays.600_64]
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Hewlett-Packard\HP Software Update
[Shield.ICEPreShield]
1=SynTPEnh
2=QTTask
3=.NETUninstall
4=CommonAdminTools
5=MsiExec
6=PlugPlay
7=LocalSoftware
8=LocalSystem
9=EnumRegKey
10=Config.Msi
11=ICE RegKey
12=ClassesRoot
13=softpubDll
14=wintrustDll
15=initpkiDll
16=cryptextDll
17=dssenhDll
18=rsaenhDll
19=gpkcspDll
20=sccbaseDll
21=slbcspDll
22=cryptdlgDll
23=DevicePathRegValue
24=Wow64LocalSoftware
25=Wow64ClassRoot
26=CryptSvc
27=Wow64softpubDll
28=Wow64wintrustDll
29=Wow64dssenhDll
30=Wow64rsaenhDll
31=Wow64gpkcspDll
32=Wow64sccbaseDll
33=Wow64slbcspDll
34=Wow64cryptdlgDll
[Shield.DevicePathRegValue.500]
Data=%SystemRoot%\inf
ReplaceWith=%SystemRoot%\inf
Type=EXPAND_SZ
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Value=DevicePath
BlockIfFail=Yes
[Shield.DevicePathRegValue.501]
Data=%SystemRoot%\inf
ReplaceWith=%SystemRoot%\inf
Type=EXPAND_SZ
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Value=DevicePath
BlockIfFail=Yes
[Shield.DevicePathRegValue.501_64]
Data=%SystemRoot%\inf
ReplaceWith=%SystemRoot%\inf
Type=EXPAND_SZ
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Value=DevicePath
BlockIfFail=Yes
[Shield.DevicePathRegValue.600]
Data=%SystemRoot%\inf
ReplaceWith=%SystemRoot%\inf
Type=EXPAND_SZ
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Value=DevicePath
BlockIfFail=Yes
[Shield.DevicePathRegValue.600_64]
Data=%SystemRoot%\inf
ReplaceWith=%SystemRoot%\inf
Type=EXPAND_SZ
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Value=DevicePath
BlockIfFail=Yes
[Shield.CloseIZApps]
1=hpqselsk
2=hpqcopy
3=hpqgalry
4=hpqiscfg
5=hpqimvac
6=hpqpos
7=hpqvapa
[Shield.SynTPEnh]
IssueType=Process
MaxVersion=0x0005000000000893
MinVersion=0x0005000000000893
Manufacturer=HP
Action=Autofix
BlockIfFail=Yes
[Shield.QTTask]
IssueType=Process
MaxVersion=0x0006000100000000
MinVersion=0x0000000000000000
Manufacturer=Apple
Action=Autofix
BlockIfFail=Yes
[Shield..NETUninstall]
IssueType=RebootFile
Manufacturer=Microsoft
Action=Autofix
1=mscoree.dll
2=MICROS~1.NET\FRAMEW~1\V11~1.432
3=Microsoft.NET\Framework\v1.1.4322
Return=Reboot
BlockIfFail=No
[Shield.CommonAdminTools]
Manufacturer=Microsoft
IssueType=RegData
Condition=Contains
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Value=Common Administrative Tools
Data=<Common Administrative Tools>.All Users\
ReplaceWith=%ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools
Type=EXPAND_SZ
BlockIfFail=Yes
[Shield.MsiExec]
IssueType=Service
ServiceName=MSIServer
Manufacturer=Microsoft
Action=FIX
Condition=DISABLED
DisplayName=Windows Installer
BlockIfFail=Yes
[Shield.PlugPlay]
IssueType=Service
ServiceName=PlugPlay
Manufacturer=Microsoft
Action=FIX
Condition=STOPPED
DisplayName=Plug and Play
BlockIfFail=Yes
[Shield.LocalSoftware.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.LocalSoftware.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.LocalSoftware.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.LocalSoftware.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.LocalSoftware.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.Wow64LocalSoftware.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.Wow64LocalSoftware.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node
DisplayName=LocalSoftware
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.LocalSystem.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SYSTEM
DisplayName=LocalSystem
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
[Shield.LocalSystem.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SYSTEM
DisplayName=LocalSystem
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
[Shield.LocalSystem.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SYSTEM
DisplayName=LocalSystem
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
[Shield.LocalSystem.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SYSTEM
DisplayName=LocalSystem
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
[Shield.LocalSystem.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=NotWriteable
Key=HKEY_LOCAL_MACHINE\SYSTEM
DisplayName=LocalSystem
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
[Shield.EnumRegKey.500]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=Enum
Key=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=No
CheckAccess=SystemAccess
SetAccess=SystemAccess
Timeout=10
[Shield.EnumRegKey.501]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=Enum
Key=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=No
CheckAccess=SystemAccess
SetAccess=SystemAccess
Timeout=10
[Shield.EnumRegKey.501_64]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=Enum
Key=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=No
CheckAccess=SystemAccess
SetAccess=SystemAccess
Timeout=10
[Shield.Config.Msi]
IssueType=Folder
Manufacturer=Microsoft Corporation
FolderName=%WindowsDrive%Config.Msi
Action=AUTOFIX
Condition=~EXIST
HIDDEN=Y
[Shield.ICE RegKey]
IssueType=RegKey
Manufacturer=HP
DisplayName=ICE
Key=HKEY_LOCAL_MACHINE\SOFTWARE\ICE
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.ClassesRoot.500]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.ClassesRoot.501]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.ClassesRoot.501_64]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.ClassesRoot.600]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.ClassesRoot.600_64]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.Wow64ClassRoot.501_64]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.Wow64ClassRoot.600_64]
IssueType=RegKey
Manufacturer=Microsoft
DisplayName=HKEY_CLASSES_ROOT
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes
Condition=NotWriteable
Action=Autofix
BlockIfFail=Yes
Recurse=No
OverwriteDacl=No
SetOnlyIfInvalid=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
CheckCreatedKey=Yes
[Shield.DXQVPFix]
1=QVP32
[Shield.QVP32]
Manufacturer=Microsoft
IssueType=RegData
Condition=Contains
Action=Autofix
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Value=DXDllRegExe
Data=dxdllreg.exe
ReplaceWith=%system%dxdllreg.exe
BlockIfFail=Yes
[Shield.CompositeDev]
1=USBInf
2=certclas
3=USBCCGP
[Shield.USBCheck]
1=USBInf
2=USBPrint
3=USBStor
4=USBScan
5=NTPrint
6=certclas
7=USBCCGP
[Shield.Printer]
1=PrintSpooler
2=ReadOnlyPNFs
3=USBPrint
4=NTPrint
5=certclas
6=PrintCoinstaller
[Shield.PnP.Printer]
1=USBPrint
[Shield.MassStorage]
1=Roxio
2=USBStor
3=certclas
4=hpusbfd
[Shield.PnP.MassStorage]
1=USBStor
[Shield.Scanner]
1=ReadOnlyPNFs
2=USBScan
3=certclas
[Shield.PnP.Scanner]
1=USBScan
[Shield.Camera]
1=ReadOnlyPNFs
2=certclas
[Shield.PnPFiles]
1=USBInf
2=certclas
3=USBCCGP
[Shield.USBInf.500]
DisplayName=USB.inf
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usb.inf
DriverSysName=usbhub.sys
SectionToInstall=Composite.Dev.NT
MinVersion=5000008870001
DriverSysMinVersion=5000008850001
Manufacturer=Microsoft
[Shield.USBInf.501]
DisplayName=USB.inf
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usb.inf
DriverSysName=usbccgp.sys
SectionToInstall=Composite.Dev.NT
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.USBInf.501_64]
DisplayName=USB.inf
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usb.inf
DriverSysName=usbccgp.sys
SectionToInstall=Composite.Dev.NT
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.USBPrint.500]
DisplayName=USBPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usbprint.inf
DriverSysName=usbprint.sys
SectionToInstall=USBPRINT_Inst.NT
MinVersion=5000008870001
DriverSysMinVersion=5000008740001
Manufacturer=Microsoft
[Shield.USBPrint.501]
DisplayName=USBPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usbprint.inf
DriverSysName=usbprint.sys
SectionToInstall=USBPRINT_Inst.NT
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.USBPrint.501_64]
DisplayName=USBPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usbprint.inf
DriverSysName=usbprint.sys
SectionToInstall=USBPRINT_Inst.NT
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.NTPrint.500]
DisplayName=NTPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=ntprint.inf
DriverSysName=
SectionToInstall=
MinVersion=0
Manufacturer=Microsoft
[Shield.NTPrint.501]
DisplayName=NTPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=ntprint.inf
DriverSysName=
SectionToInstall=
MinVersion=0
Manufacturer=Microsoft
[Shield.NTPrint.501_64]
DisplayName=NTPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=ntprint.inf
DriverSysName=
SectionToInstall=
MinVersion=0
Manufacturer=Microsoft
[Shield.NTPrint.600]
DisplayName=NTPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=ntprint.inf
DriverSysName=
SectionToInstall=
MinVersion=0
Manufacturer=Microsoft

Répondre à caroline2

44

caroline2, le 19 dc 2008 à 17:36:03

[Shield.NTPrint.600_64]
DisplayName=NTPrint
IssueType=SystemDriver
Condition=~Exists
DriverInfName=ntprint.inf
DriverSysName=
SectionToInstall=
MinVersion=0
Manufacturer=Microsoft
[Shield.certclas.500]
DisplayName=Certclas.inf
IssueType=SystemDriver
Condition=~Exists
DriverInfName=certclas.inf
DriverSysName=
SectionToInstall=
MinVersion=5000008870001
Manufacturer=Microsoft
[Shield.CertClas.501]
DisplayName=Certclas.inf
IssueType=SystemDriver
Condition=~Exists
DriverInfName=Certclas.inf
DriverSysName=
SectionToInstall=
MinVersion=5000109E70000
Manufacturer=Microsoft
[Shield.CertClas.501_64]
DisplayName=Certclas.inf
IssueType=SystemDriver
Condition=~Exists
DriverInfName=Certclas.inf
DriverSysName=
SectionToInstall=
MinVersion=5000109E70000
Manufacturer=Microsoft
[Shield.USBStor.500]
DisplayName=USBStor
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usbstor.inf
DriverSysName=usbstor.sys
SectionToInstall=USBSTOR_BULK.NT
MinVersion=5000008870001
DriverSysMinVersion=50000085A0001
Manufacturer=Microsoft
[Shield.USBStor.501]
DisplayName=USBStor
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usbstor.inf
DriverSysName=usbstor.sys
SectionToInstall=USBSTOR_BULK.NT
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.USBStor.501_64]
DisplayName=USBStor
IssueType=SystemDriver
Condition=~Exists
DriverInfName=usbstor.inf
DriverSysName=usbstor.sys
SectionToInstall=USBSTOR_BULK.NT
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.USBScan.500]
DisplayName=USBScan
IssueType=SystemDriver
Condition=~Exists
DriverInfName=sti.inf
DriverSysName=usbscan.sys
SectionToInstall=STI.USBSection
MinVersion=5000008870001
DriverSysMinVersion=5000008670001
Manufacturer=Microsoft
[Shield.USBScan.501]
DisplayName=USBScan
IssueType=SystemDriver
Condition=~Exists
DriverInfName=sti.inf
DriverSysName=usbscan.sys
SectionToInstall=STI.USBSection
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.USBScan.501_64]
DisplayName=USBScan
IssueType=SystemDriver
Condition=~Exists
DriverInfName=sti.inf
DriverSysName=usbscan.sys
SectionToInstall=STI.USBSection
MinVersion=500010A280000
DriverSysMinVersion=500010A280000
Manufacturer=Microsoft
[Shield.PrintCoinstaller.500]
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Clas­s\{4D36E979-E325-11CE-BFC1-08002BE10318}
Value=Installer32
BlockIfFail=Yes
Data=ntprint.dll,ClassInstall32
ReplaceWith=ntprint.dll,ClassInstall32
[Shield.PrintCoinstaller.501]
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Clas­s\{4D36E979-E325-11CE-BFC1-08002BE10318}
Value=Installer32
BlockIfFail=Yes
Data=ntprint.dll,ClassInstall32
ReplaceWith=ntprint.dll,ClassInstall32
[Shield.PrintCoinstaller.501_64]
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Clas­s\{4D36E979-E325-11CE-BFC1-08002BE10318}
Value=Installer32
BlockIfFail=Yes
Data=ntprint.dll,ClassInstall32
ReplaceWith=ntprint.dll,ClassInstall32
[Shield.PrintCoinstaller.600]
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Clas­s\{4D36E979-E325-11CE-BFC1-08002BE10318}
Value=Installer32
BlockIfFail=Yes
Data=ntprint.dll,ClassInstall32
ReplaceWith=ntprint.dll,ClassInstall32
[Shield.PrintCoinstaller.600_64]
Manufacturer=Microsoft
IssueType=RegData
Condition=Missing
Action=Autofix
Key=HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Clas­s\{4D36E979-E325-11CE-BFC1-08002BE10318}
Value=Installer32
BlockIfFail=Yes
Data=ntprint.dll,ClassInstall32
ReplaceWith=ntprint.dll,ClassInstall32
[Shield.PrintSpooler]
IssueType=Service
ServiceName=Spooler
Manufacturer=Microsoft
Action=FIX
Condition=STOPPED
DisplayName=Print Spooler
BlockIfFail=Yes
AutoStartService=Yes
[Shield.hpusbfd]
Manufacturer=Hewlett-Packard
IssueType=RegData
Condition=Contains
Action=Autofix
Key=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Clas­s\{36FC9E60-C465-11CF-8056-444553540000}
Value=UpperFilter
Data=hpusbfd
Type=MULTI_SZ
ReplaceWith=*
BlockIfFail=Yes
[Shield.Roxio.500]
IssueType=File
Manufacturer=Roxio
MaxVersion=0x0002000000000046
MinVersion=0x0002000000000046
Action=STOP
Condition=EXIST
DisplayName=Easy CD Creator 5
BlockIfFail=Yes
FileName=%system%drivers\PrtSeqRd.sys
SpecialText=Shield.Roxio.Text
[Shield.Roxio.501]
IssueType=File
Manufacturer=Roxio
MaxVersion=0x0002000000000046
MinVersion=0x0002000000000046
Action=STOP
Condition=EXIST
DisplayName=Easy CD Creator 5
FileName=%system%drivers\PrtSeqRd.sys
BlockIfFail=Yes
SpecialText=Shield.Roxio.Text
[Shield.Roxio.501_64]
IssueType=File
Manufacturer=Roxio
MaxVersion=0x0002000000000046
MinVersion=0x0002000000000046
Action=STOP
Condition=EXIST
DisplayName=Easy CD Creator 5
FileName=%system%drivers\PrtSeqRd.sys
BlockIfFail=Yes
SpecialText=Shield.Roxio.Text
[Shield.Roxio.600]
IssueType=File
Manufacturer=Roxio
MaxVersion=0x0002000000000046
MinVersion=0x0002000000000046
Action=STOP
Condition=EXIST
DisplayName=Easy CD Creator 5
FileName=%system%drivers\PrtSeqRd.sys
BlockIfFail=Yes
SpecialText=Shield.Roxio.Text
[Shield.Roxio.600_64]
IssueType=File
Manufacturer=Roxio
MaxVersion=0x0002000000000046
MinVersion=0x0002000000000046
Action=STOP
Condition=EXIST
DisplayName=Easy CD Creator 5
FileName=%system%drivers\PrtSeqRd.sys
BlockIfFail=Yes
SpecialText=Shield.Roxio.Text
[Shield.Firewalls]
1=Smc
2=Zapro
3=Ccapp
4=BlackIce
5=MpfAgent
6=Ca
7=ccEvtMgr
8=SndSrvc
9=ccProxy
10=ccPwdSvc
11=ccSetMgr
12=Zlclient
13=Pavfires
[Shield.Smc.500]
IssueType=Service
ServiceName=SmcService
DisplayName=Sygate Security Agent: Firewall
Manufacturer=Sygate Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Smc.501]
IssueType=Service
ServiceName=SmcService
DisplayName=Sygate Security Agent: Firewall
Manufacturer=Sygate Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Smc.501_64]
IssueType=Service
ServiceName=SmcService
DisplayName=Sygate Security Agent: Firewall
Manufacturer=Sygate Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Smc.600]
IssueType=Service
ServiceName=SmcService
DisplayName=Sygate Security Agent: Firewall
Manufacturer=Sygate Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Smc.600_64]
IssueType=Service
ServiceName=SmcService
DisplayName=Sygate Security Agent: Firewall
Manufacturer=Sygate Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Zapro.500]
IssueType=Service
ServiceName=vsmon
DisplayName=Zone Alarm TrueVector Internet Monitor
Manufacturer=Broderbund/Zone Labs,LLC
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Zapro.501]
IssueType=Service
ServiceName=vsmon
DisplayName=Zone Alarm TrueVector Internet Monitor
Manufacturer=Broderbund/Zone Labs,LLC
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Zapro.501_64]
IssueType=Service
ServiceName=vsmon
DisplayName=Zone Alarm TrueVector Internet Monitor
Manufacturer=Broderbund/Zone Labs,LLC
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Zapro.600]
IssueType=Service
ServiceName=vsmon
DisplayName=Zone Alarm TrueVector Internet Monitor
Manufacturer=Broderbund/Zone Labs,LLC
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Zapro.600_64]
IssueType=Service
ServiceName=vsmon
DisplayName=Zone Alarm TrueVector Internet Monitor
Manufacturer=Broderbund/Zone Labs,LLC
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Ccapp.500]
IssueType=Service
ServiceName=Symantec Core LC
DisplayName=Symantec Core LC: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Ccapp.501]
IssueType=Service
ServiceName=Symantec Core LC
DisplayName=Symantec Core LC: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Ccapp.501_64]
IssueType=Service
ServiceName=Symantec Core LC
DisplayName=Symantec Core LC: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Ccapp.600]
IssueType=Service
ServiceName=Symantec Core LC
DisplayName=Symantec Core LC: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Ccapp.600_64]
IssueType=Service
ServiceName=Symantec Core LC
DisplayName=Symantec Core LC: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.BlackIce.500]
IssueType=Service
ServiceName=BlackICE
DisplayName=BlackICE: Firewall
Manufacturer=Internet Security Systems
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.BlackIce.501]
IssueType=Service
ServiceName=BlackICE
DisplayName=BlackICE: Firewall
Manufacturer=Internet Security Systems
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.BlackIce.501_64]
IssueType=Service
ServiceName=BlackICE
DisplayName=BlackICE: Firewall
Manufacturer=Internet Security Systems
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.BlackIce.600]
IssueType=Service
ServiceName=BlackICE
DisplayName=BlackICE: Firewall
Manufacturer=Internet Security Systems
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.BlackIce.600_64]
IssueType=Service
ServiceName=BlackICE
DisplayName=BlackICE: Firewall
Manufacturer=Internet Security Systems
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.MpfAgent.500]
IssueType=Service
ServiceName=MpfService
DisplayName=McAfee Personal Firewall Service
Manufacturer=McAfee Security
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.MpfAgent.501]
IssueType=Service
ServiceName=MpfService
DisplayName=McAfee Personal Firewall Service
Manufacturer=McAfee Security
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.MpfAgent.501_64]
IssueType=Service
ServiceName=MpfService
DisplayName=McAfee Personal Firewall Service
Manufacturer=McAfee Security
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.MpfAgent.600]
IssueType=Service
ServiceName=MpfService
DisplayName=McAfee Personal Firewall Service
Manufacturer=McAfee Security
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.MpfAgent.600_64]
IssueType=Service
ServiceName=MpfService
DisplayName=McAfee Personal Firewall Service
Manufacturer=McAfee Security
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccEvtMgr.500]
IssueType=Service
ServiceName=ccEvtMgr
DisplayName=Symantec Event Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccEvtMgr.501]
IssueType=Service
ServiceName=ccEvtMgr
DisplayName=Symantec Event Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccEvtMgr.501_64]
IssueType=Service
ServiceName=ccEvtMgr
DisplayName=Symantec Event Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccEvtMgr.600]
IssueType=Service
ServiceName=ccEvtMgr
DisplayName=Symantec Event Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccEvtMgr.600_64]
IssueType=Service
ServiceName=ccEvtMgr
DisplayName=Symantec Event Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.SndSrvc.500]
IssueType=Service
ServiceName=SndSrvc
DisplayName=Symantec Network Drivers Service : Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.SndSrvc.501]
IssueType=Service
ServiceName=SndSrvc
DisplayName=Symantec Network Drivers Service : Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.SndSrvc.501_64]
IssueType=Service
ServiceName=SndSrvc
DisplayName=Symantec Network Drivers Service : Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.SndSrvc.600]
IssueType=Service
ServiceName=SndSrvc
DisplayName=Symantec Network Drivers Service : Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.SndSrvc.600_64]
IssueType=Service
ServiceName=SndSrvc
DisplayName=Symantec Network Drivers Service : Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccProxy.500]
IssueType=Service
ServiceName=ccProxy
DisplayName=Symantec Network Proxy: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccProxy.501]
IssueType=Service
ServiceName=ccProxy
DisplayName=Symantec Network Proxy: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccProxy.501_64]
IssueType=Service
ServiceName=ccProxy
DisplayName=Symantec Network Proxy: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccProxy.600]
IssueType=Service
ServiceName=ccProxy
DisplayName=Symantec Network Proxy: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccProxy.600_64]
IssueType=Service
ServiceName=ccProxy
DisplayName=Symantec Network Proxy: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccPwdSvc.500]
IssueType=Service
ServiceName=ccPwdSvc
DisplayName=Symantec Password Validation: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccPwdSvc.501]
IssueType=Service
ServiceName=ccPwdSvc
DisplayName=Symantec Password Validation: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccPwdSvc.501_64]
IssueType=Service
ServiceName=ccPwdSvc
DisplayName=Symantec Password Validation: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccPwdSvc.600]
IssueType=Service
ServiceName=ccPwdSvc
DisplayName=Symantec Password Validation: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccPwdSvc.600_64]
IssueType=Service
ServiceName=ccPwdSvc
DisplayName=Symantec Password Validation: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccSetMgr.500]
IssueType=Service
ServiceName=ccSetMgr
DisplayName=Symantec Settings Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccSetMgr.501]
IssueType=Service
ServiceName=ccSetMgr
DisplayName=Symantec Settings Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccSetMgr.501_64]
IssueType=Service
ServiceName=ccSetMgr
DisplayName=Symantec Settings Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccSetMgr.600]
IssueType=Service
ServiceName=ccSetMgr
DisplayName=Symantec Settings Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.ccSetMgr.600_64]
IssueType=Service
ServiceName=ccSetMgr
DisplayName=Symantec Settings Manager: Firewall
Manufacturer=Symantec
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Pavfires.500]
IssueType=Service
ServiceName=PAVFIRES
DisplayName=Panda Firewall Service
Manufacturer=TruPrevent Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Pavfires.501]
IssueType=Service
ServiceName=PAVFIRES
DisplayName=Panda Firewall Service
Manufacturer=TruPrevent Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.Pavfires.600]
IssueType=Service
ServiceName=PAVFIRES
DisplayName=Panda Firewall Service
Manufacturer=TruPrevent Technologies
Action=NoFix
Condition=Running
SpecialText=Shield.Firewalls.Text
[Shield.HPSecurity]
1=HP RegKey
2=Hewlett-Packard RegKey
3=Hewlett Packard RegKey
4=LEAD Technologies RegKey
5=WoW64 HP RegKey
6=WoW64 Hewlett-Packard RegKey
7=WoW64 Hewlett Packard RegKey
8=WoW64 LEAD Technologies RegKey
[Shield.HP RegKey.500]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.HP RegKey.501]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.HP RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.HP RegKey.600]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.HP RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett-Packard RegKey.500]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett-Packard RegKey.501]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett-Packard RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett-Packard RegKey.600]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett-Packard RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett Packard RegKey.500]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett Packard RegKey.501]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett Packard RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett Packard RegKey.600]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.Hewlett Packard RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.LEAD Technologies RegKey.500]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.LEAD Technologies RegKey.501]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.LEAD Technologies RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.LEAD Technologies RegKey.600]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.LEAD Technologies RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 HP RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 HP RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=HP
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\HP
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 Hewlett-Packard RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 Hewlett-Packard RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett-Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett-Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 Hewlett Packard RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 Hewlett Packard RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=Hewlett Packard
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hewlett Packard
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 LEAD Technologies RegKey.501_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.WoW64 LEAD Technologies RegKey.600_64]
IssueType=RegKey
Manufacturer=HP
DisplayName=LEAD Technologies, Inc.
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LEAD Technologies, Inc.
Condition=NotWriteable
Action=AutoFix
BlockIfFail=Yes
Recurse=Yes
OverwriteDacl=Yes
CheckAccess=CommonSidList
SetAccess=CommonSidList
Timeout=10
[Shield.CommonSidList]
S-1-5-32-544=0x000f003f
S-1-5-18=0x000f003f
S-1-5-32-545=0x00020019
[Shield.SystemAccess]
S-1-1-0=0x00020019
S-1-5-18=0x000f003f
[Shield.ReadOnlyPNFs.500]
IssueType=File
launchbase=%sourcepath%setup\
Manufacturer=Microsoft
DisplayName=Read Only PNF files
Action=Autofix
FileName=%system%attrib.exe
Condition=Exists
1=hpzwrp01.exe -m SetPnfAttrib
[Shield.ReadOnlyPNFs.501]
IssueType=File
launchbase=%sourcepath%setup\
Manufacturer=Microsoft
DisplayName=Read Only PNF files
Action=Autofix
FileName=%system%attrib.exe
Condition=Exists
1=hpzwrp01.exe -m SetPnfAttrib
[Shield.ReadOnlyPNFs.501_64]
IssueType=File
launchbase=%sourcepath%setup\
Manufacturer=Microsoft
DisplayName=Read Only PNF files
Action=Autofix
FileName=%system%attrib.exe
Condition=Exists
1=hpzwrp01.exe -m SetPnfAttrib
[Shield.ReadOnlyPNFs.600]
IssueType=File
launchbase=%sourcepath%setup\
Manufacturer=Microsoft
DisplayName=Read Only PNF files
Action=Autofix
FileName=%system%attrib.exe
Condition=Exists
1=hpzwrp01.exe -m SetPnfAttrib
[Shield.ReadOnlyPNFs.600_64]
IssueType=File
launchbase=%sourcepath%setup\
Manufacturer=Microsoft
DisplayName=Read Only PNF files
Action=Autofix
FileName=%system%attrib.exe
Condition=Exists
1=hpzwrp01.exe -m SetPnfAttrib
[SetPnfAttrib]
Open=%system%attrib -r %windows%inf\oem*.pnf
[Shield.DelayedReboot]
1=CheckForFiles
[Shield.CheckForFiles]
IssueType=RebootFile
Manufacturer=HP
Action=Autofix
1=Digital Imaging
2=%division%
3=system32\hpz
4=system\hpz
5=hpf
6=twain_32\hpsj
Return=Reboot
BlockIfFail=No
result=Reboot
[Shield.DelayedRebootCUE]
1=CUECheckForFiles
[Shield.CUECheckForFiles]
IssueType=RebootFile
Manufacturer=HP
Action=Autofix
1=Digital Imaging
Return=Reboot
BlockIfFail=No
result=Reboot
[Shield.CryptSvc.501]
IssueType=Service
ServiceName=Cryptsvc
Manufacturer=Microsoft
Action=AUTOFIX
Condition=STOPPED
DisplayName=Windows Cryptographic Service
BlockIfFail=Yes
[Shield.CryptSvc.501_64]
IssueType=Service
ServiceName=Cryptsvc
Manufacturer=Microsoft
Action=AUTOFIX
Condition=STOPPED
DisplayName=Windows Cryptographic Service
BlockIfFail=Yes
[Shield.CryptSvc.600]
IssueType=Service
ServiceName=Cryptsvc
Manufacturer=Microsoft
Action=AUTOFIX
Condition=STOPPED
DisplayName=Windows Cryptographic Service
BlockIfFail=Yes
[Shield.CryptSvc.600_64]
IssueType=Service
ServiceName=Cryptsvc
Manufacturer=Microsoft
Action=AUTOFIX
Condition=STOPPED
DisplayName=Windows Cryptographic Service
BlockIfFail=Yes
[Shield.softpubDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Provi­ders\Trust\Initialization\{64B9D180-8DA2-11CF-8736-00AA00A48­5EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=regsvr32 /s softpub.dll
[Shield.softpubDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Provi­ders\Trust\Initialization\{64B9D180-8DA2-11CF-8736-00AA00A48­5EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=regsvr32 /s softpub.dll
[Shield.softpubDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Provi­ders\Trust\Initialization\{64B9D180-8DA2-11CF-8736-00AA00A48­5EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=regsvr32 /s softpub.dll
[Shield.softpubDll.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Provi­ders\Trust\Initialization\{64B9D180-8DA2-11CF-8736-00AA00A48­5EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=regsvr32 /s softpub.dll
[Shield.softpubDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Provi­ders\Trust\Initialization\{64B9D180-8DA2-11CF-8736-00AA00A48­5EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=regsvr32 /s softpub.dll
[Shield.Wow64softpubDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Crypto­graphy\Providers\Trust\Initialization\{64B9D180-8DA2-11CF-87­36-00AA00A485EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s softpub.dll
[Shield.Wow64softpubDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Crypto­graphy\Providers\Trust\Initialization\{64B9D180-8DA2-11CF-87­36-00AA00A485EB}
DisplayName=softpub.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s softpub.dll
[Shield.wintrustDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=regsvr32 /s wintrust.dll
[Shield.wintrustDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=regsvr32 /s wintrust.dll
[Shield.wintrustDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=regsvr32 /s wintrust.dll
[Shield.wintrustDll.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=regsvr32 /s wintrust.dll
[Shield.wintrustDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=regsvr32 /s wintrust.dll
[Shield.Wow64wintrustDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Crypto­graphy\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s wintrust.dll
[Shield.Wow64wintrustDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Crypto­graphy\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
DisplayName=wintrust.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s wintrust.dll
[Shield.initpkiDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_CLASSES_ROOT\CLSID\{7444C717-39BF-11D1-8CD9-00C04FC­29D45}\ProgID
DisplayName=initpki.dll
BlockIfFail=Yes
1=regsvr32 /s initpki.dll
[Shield.initpkiDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_CLASSES_ROOT\CLSID\{7444C717-39BF-11D1-8CD9-00C04FC­29D45}\ProgID
DisplayName=initpki.dll
BlockIfFail=Yes
1=regsvr32 /s initpki.dll
[Shield.initpkiDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_CLASSES_ROOT\CLSID\{7444C717-39BF-11D1-8CD9-00C04FC­29D45}\ProgID
DisplayName=initpki.dll
BlockIfFail=Yes
1=regsvr32 /s initpki.dll
[Shield.cryptextDll.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_CLASSES_ROOT\CLSID\{7444C717-39BF-11D1-8CD9-00C04FC­29D45}\ProgID
DisplayName=cryptext.dll
BlockIfFail=Yes
1=regsvr32 /s cryptext.dll
[Shield.cryptextDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_CLASSES_ROOT\CLSID\{7444C717-39BF-11D1-8CD9-00C04FC­29D45}\ProgID
DisplayName=cryptext.dll
BlockIfFail=Yes
1=regsvr32 /s cryptext.dll
[Shield.dssenhDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssbase.dll
1=regsvr32 /s dssbase.dll
[Shield.dssenhDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssenh.dll
1=regsvr32 /s dssenh.dll
[Shield.dssenhDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssenh.dll
1=regsvr32 /s dssenh.dll
[Shield.dssenhDll.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssenh.dll
1=regsvr32 /s dssenh.dll
[Shield.dssenhDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssenh.dll
1=regsvr32 /s dssenh.dll
[Shield.Wow64dssenhDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssenh.dll
1=%SYSWOW64%regsvr32 /s dssenh.dll
[Shield.Wow64dssenhDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Microsoft Base DSS Cryptographic Provider
BlockIfFail=Yes
DisplayName=dssenh.dll
1=%SYSWOW64%regsvr32 /s dssenh.dll
[Shield.rsaenhDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsabase.dll
1=regsvr32 /s rsabase.dll
[Shield.rsaenhDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsaenh.dll
1=regsvr32 /s rsaenh.dll
[Shield.rsaenhDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsaenh.dll
1=regsvr32 /s rsaenh.dll
[Shield.rsaenhDll.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsaenh.dll
1=regsvr32 /s rsaenh.dll
[Shield.rsaenhDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsaenh.dll
1=regsvr32 /s rsaenh.dll
[Shield.Wow64rsaenhDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsaenh.dll
1=%SYSWOW64%regsvr32 /s rsaenh.dll
[Shield.Wow64rsaenhDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0
BlockIfFail=Yes
DisplayName=rsaenh.dll
1=%SYSWOW64%regsvr32 /s rsaenh.dll
[Shield.gpkcspDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Gemplus GemSAFE Card CSP v1.0
DisplayName=gpkcsp.dll
BlockIfFail=Yes
1=regsvr32 /s gpkcsp.dll
[Shield.gpkcspDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Gemplus GemSAFE Card CSP v1.0
DisplayName=gpkcsp.dll
BlockIfFail=Yes
1=regsvr32 /s gpkcsp.dll
[Shield.gpkcspDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Gemplus GemSAFE Card CSP v1.0
DisplayName=gpkcsp.dll
BlockIfFail=Yes
1=regsvr32 /s gpkcsp.dll
[Shield.Wow64gpkcspDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Gemplus GemSAFE Card CSP v1.0
DisplayName=gpkcsp.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s gpkcsp.dll
[Shield.sccbaseDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Infineon SICRYPT Base Smart Card CSP
DisplayName=sccbase.dll
BlockIfFail=Yes
1=regsvr32 /s sccbase.dll
[Shield.sccbaseDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Infineon SICRYPT Base Smart Card CSP
DisplayName=sccbase.dll
BlockIfFail=Yes
1=regsvr32 /s sccbase.dll
[Shield.Wow64sccbaseDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Infineon SICRYPT Base Smart Card CSP
DisplayName=sccbase.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s sccbase.dll
[Shield.slbcspDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Schlumberger Cryptographic Service Provider
DisplayName=slbcsp.dll
BlockIfFail=Yes
1=regsvr32 /s slbcsp.dll
[Shield.slbcspDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Schlumberger Cryptographic Service Provider
DisplayName=slbcsp.dll
BlockIfFail=Yes
1=regsvr32 /s slbcsp.dll
[Shield.slbcspDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defau­lts\Provider\Schlumberger Cryptographic Service Provider
DisplayName=slbcsp.dll
BlockIfFail=Yes
1=regsvr32 /s slbcsp.dll
[Shield.Wow64slbcspDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Crypto­graphy\Defaults\Provider\Schlumberger Cryptographic Service Provider
DisplayName=slbcsp.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s slbcsp.dll
[Shield.cryptdlgDll.500]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=regsvr32 /s cryptdlg.dll
[Shield.cryptdlgDll.501]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=regsvr32 /s cryptdlg.dll
[Shield.cryptdlgDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=regsvr32 /s cryptdlg.dll
[Shield.cryptdlgDll.600]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=regsvr32 /s cryptdlg.dll
[Shield.cryptdlgDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\E­ncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=regsvr32 /s cryptdlg.dll
[Shield.Wow64cryptdlgDll.501_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Crypto­graphy\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s cryptdlg.dll
[Shield.Wow64cryptdlgDll.600_64]
Manufacturer=Microsoft
IssueType=RegKey
Action=Autofix
Condition=~Exist
Key=HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Crypto­graphy\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
DisplayName=cryptdlg.dll
BlockIfFail=Yes
1=%SYSWOW64%regsvr32 /s cryptdlg.dll
[Shield.SLPService]
1=hpslpsvc
[Shield.hpslpsvc]
IssueType=Service
ServiceName=HPSLPSVC32
Manufacturer=Hewlett-Packard
DisplayName=HP Network Devices Support
BlockIfFail=Yes
[Shield.hpslpsvc.501_64]
IssueType=Service
ServiceName=HPSLPSVC64
Manufacturer=Hewlett-Packard
DisplayName=HP Network Devices Support
BlockIfFail=Yes
[Shield.hpslpsvc.600_64]
IssueType=Service
ServiceName=HPSLPSVC64
Manufacturer=Hewlett-Packard
DisplayName=HP Network Devices Support
BlockIfFail=Yes
[Shield.CloseManagerOfTrayApp]
1=StopCtxManService
2=StopDDService
[Shield.StopCtxManService]
IssueType=Service
ServiceName=hpqcxs08
Manufacturer=HP
Action=AutoFix
Condition=Running
DisplayName=HP Context Manager Service
BlockIfFail=Yes
[Shield.StopDDService]
IssueType=Service
ServiceName=hpqddsvc
Manufacturer=HP
Action=AutoFix
Condition=Running
DisplayName=HP CUE DeviceDiscovery Service
BlockIfFail=Yes
[Shield.Roxio.Text.0x1]
1= .
2= .
3= , '/ ' ' ' Window.
4= , http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l .
5= ' ' .
[Shield.Firewalls.Text.0X1]
1= . .
2= HP .
3= : , , .
4= .
[Shield.Roxio.Text.0x404]
1=w˪{Pn餣ۮeC
2=zѰw˩ΤɯŦ{Awˤ~~C
3=nѰw˦{AЦ Windows [x] [sW/{]C
4=pGzܤɯŦ{AгyX http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­lAnMUɯšC
5=нT{{wɯũΤwѰwˡAM@U [] ~wˡC
[Shield.Firewalls.Text.0X404]
1=bqW즳nCi|ܻPw˦­ĵܹܤC
2=zdݳoĵi䤤@ĵiɡAФ\ϥ HP {iBzC
3=\{檺`γNyGBOB\M\C
4=w˵{NiɭPw˥ѡC
[Shield.Roxio.Text.0x804]
1=װĴ˳뱾ݡ
2=жػ˳򣬲ܼװ
3=Ҫжش˳ת Windows еġ/ɾ򡱡
4=ѡ˳ http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l עᲢ
5=ȷóжأȻ󵥻ԡװ
[Shield.Firewalls.Text.0x804]
1=ڼϼ⵽ǽ˷ǽʾ밲װйصľ­Ի
2=Щеһʱ HP ִС
3=һеһЩѱõģȡֹ­Ǻ
4=ֹװܿܵ°װʧܡ
[Shield.Roxio.Text.0x405]
1=Tento program je nainstalovn a nen se softwarem kompatibiln.
2=Ne bude mon pokraovat v instalaci, muste tento program odinstalovat nebo aktualizovat.
3=Chcete-li tento program odinstalovat, pejdte v systmu Windows na Ovldac panely a vyberte poloku Pidat nebo odebrat programy.
4=Pokud se rozhodnete tento program aktualizovat, mete si aktualizaci sthnout a registrovat na strnce http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l.
5=Zkontrolujte, zda je progrm aktualizovn nebo odinstalovn. Pot pokraujte v instalaci klepnutm na tlatko Opakovat.
[Shield.Firewalls.Text.0X405]
1=Na tomto potai byl rozpoznn software bezpenostn brny. Tento firewall me zobrazovat upozornn tkajc se instalace.
2=Kdy se objev nkter zvarovnch upozornn, umonte prosm dal bh program spolenosti HP.
3=Nkter z obvyklch vraz, kter se pouvaj pro povolen bhu programu jsou: Odblokovat, Ano, Umonit a Povolit.
4=Blokovn instalanho programu pravdpodobn zabrn spn instalaci aplikace.
[Shield.Roxio.Text.0x406]
1=Dette program er installeret og er inkompatibel med denne software.
2=Du skal enten fjerne eller opgradere programmet, fr du fortstter denne installation.
3=bn kontrolpanelet i Windows, og vlg Tilfj/fjern programmer for at fjerne programmet.
4=Hvis du vlger at opgradere det pgldende program, skal du besge http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l for at registrere og hente opgraderingen.
5=Kontroller, at programmet er opgraderet eller fjernet, og klik derefter p Forsg igen for at fortstte installationen.
[Shield.Firewalls.Text.0X406]
1=Der blev fundet firewall-software p denne computer. Denne firewall viser muligvis advarsler i forbindelse med installationen.
2=Lad HP-programmer fortstte, nr du ser en af disse advarsler.
3=De mest almindelige ord, der bruges til lade en proces fortstte, er: Fjern blokering, Ja og Tillad.
4=Hvis du blokerer et installationsprogram, gennemfres installationen sandsynligvis ikke.
[Shield.Roxio.Text.0x407]
1=Diese Anwendung ist installiert und mit dieser Software inkompatibel.
2=Bevor Sie mit der Installation fortfahren, mssen Sie diese Anwendung entweder deinstallieren oder aktualisieren.
3=Die Anwendung kann in der Windows-Systemsteuerung unter 'Software' deinstalliert werden.
4=Wenn Sie diese Anwendung aktualisieren mchten, besuchen Sie http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l fr die Registrierung und den Download der neuesten Version.
5=Stellen Sie sicher, dass die Anwendung aktualisiert oder deinstalliert wurde, und klicken Sie anschlieend auf 'Wiederholen', um die Installation fortzusetzen.
[Shield.Firewalls.Text.0X407]
1=Auf diesem Computer ist Firewall-Software vorhanden. Von dieser Firewall werden ggf. Warnmeldungen in Bezug auf die Installation angezeigt.
2=Bitte erlauben Sie HP Programmen fortzufahren, wenn eine dieser Warnungen angezeigt wird.
3=Einige hufige Begriffe, die ein Fortfahren ermglichen, lauten: Entsperren, Ja, Erlauben und Zulassen.
4=Wenn Sie ein Installationsprogramm sperren, wird die Installation nicht ausgefhrt.
[Shield.Roxio.Text.0x408]
1= .
2= .
3= , "Add/Remove Programs" (" ") .
4= , http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtml .
5= "" .
[Shield.Firewalls.Text.0X408]
1= . .
2= HP .
3= : , , , .
4= .
[Shield.Roxio.Text.0x409]
1=This program is installed and is incompatible with this software.
2=You must either uninstall or upgrade this program before continuing this installation.
3=To uninstall this program, go to Add/Remove Programs in the Windows Control Panel.
4=If you choose to upgrade this program, visit http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtml to register and download the upgrade.
5=Ensure the program is upgraded or uninstalled and then click Retry to continue installation.
[Shield.Firewalls.Text.0X409]
1=Firewall software has been detected on this computer.This firewall might display alert dialogs related to the installation.
2=Please allow HP programs to proceed when you see one of these alerts.
3=Some commonly used terms to allow a process to proceed are: Unblock, Yes, Allow, and Permit.
4=Blocking an installation program will likely cause the installation to fail.
[Shield.Roxio.Text.0x40a]
1=El programa est instalado y es compatible con este software.
2=Antes de continuar con la instalacin, debe desinstalar o actualizar este programa.
3=Para desinstalar este programa, vaya a Agregar o quitar programas en el Panel de control de Windows.
4=Si decide actualizar el programa, visite http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtml para registrarse y descargar la actualizacin.
5=Asegrese de que el programa est actualizado o desinstalado y, a continuacin, haga clic en Reintentar para continuar con la instalacin.
[Shield.Firewalls.Text.0X40a]
1=Se ha detectado software de servidor de seguridad en este equipo. Es posible que el firewall muestre dilogos de advertencia relacionados con el proceso de instalacin.
2=Cuando aparezca uno de estos avisos, permita que los programas de HP se sigan ejecutando.
3=Algunos trminos utilizados habitualmente para permitir la ejecucin de un proceso son: Desbloquear, S y Permitir.
4=Si se bloquea un programa de instalacin, es muy probable que no se lleve a cabo la instalacin.
[Shield.Roxio.Text.0x40b]
1=Tm ohjelma on asennettu, eik se ole yhteensopiva ohjelmiston kanssa.
2=Sinun on poistettava tai pivitettv ohjelma, ennen kuin jatkat asentamista.
3=Voit poistaa ohjelman valitsemalla Windowsin Ohjauspaneelista Lis tai poista sovellus.
4=Jos ptt pivitt tmn ohjelman, rekisteri ja lataa pivitys osoitteessa http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtml.
5=Varmista, ett ohjelma on pivitetty tai poistettu. Jatka sitten asennusta valitsemalla Yrit uudelleen.
[Shield.Firewalls.Text.0X40b]
1=Tietokoneessa on havaittu palomuuriohjelmisto. Palomuuri saattaa nytt asennukseen liittyvi hlytysikkunoita.
2=Jos nyttn tulee jokin nist varoituksista, anna HP:n ohjelmien jatkaa toimintaansa.
3=Toiminnon jatkaminen sallitaan tavallisesti komennolla Salli tai Kyll.
4=Asennusohjelman toiminnan estminen keskeytt asennuksen.
[Shield.Roxio.Text.0x40c]
1=Ce programme est install mais n'est pas compatible avec ce logiciel.
2=Vous devez dsinstaller ou mettre niveau ce programme pour poursuivre l'installation.
3=Pour dsinstaller ce programme, ouvrez la fentre Ajout/Suppression de programmes du Panneau de configuration Windows.
4=Si vous choisissez de mettre niveau ce programme, visitez

Répondre à caroline2

43

Lyonnais92, le 19 dc 2008 à 17:35:11

Re,

erreur de ma part, c'est bien le rapport.

Courage.

@+
Faitescequel'onvousdemande,niplus,nimoins.
Necrezpasdedoublons,nisurCCMnisurunautresite.M­erci

Répondre à Lyonnais92

45

caroline2, le 19 dc 2008 à 18:00:18

Je continue :


1=Ce programme est install mais n'est pas compatible avec ce logiciel.
2=Vous devez dsinstaller ou mettre niveau ce programme pour poursuivre l'installation.
3=Pour dsinstaller ce programme, ouvrez la fentre Ajout/Suppression de programmes du Panneau de configuration Windows.
4=Si vous choisissez de mettre niveau ce programme, visitez http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l pour enregistrer et tlcharger la mise niveau.
5=Vrifiez que le programme est mis niveau ou dsinstall, puis cliquez sur Ressayer pour poursuivre l'installation.
[Shield.Firewalls.Text.0X40c]
1=Un logiciel pare-feu a t dtect sur cet ordinateur. Il est possible que ce pare-feu affiche des alertes lies l'installation.
2=Veuillez laisser les programmes HP s'excuter lorsque l'une de ces alertes s'affiche.
3=Certains termes dsignent couramment l'autorisation d'excuter ces programmes, tels que Dbloquer, Oui, Autoriser, Permettre.
4=Le blocage d'un programme peut entraner l'chec de son installation.
[Shield.Roxio.Text.0xd]
1= .
2= .
3= , / (Add/Remove Programs) (Control Panel) Windows.
4= , http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l .
5= ' ' .
[Shield.Firewalls.Text.0Xd]
1= (Firewall) . - .
2= , HP.
3= : , , .
4= .
[Shield.Roxio.Text.0x40E]
1=Ez a program teleptve van, s nem kompatibilis ezzel a szoftverrel.
2=A telepts folytatsa eltt el kell tvoltania vagy frisstenie kell a szoftvert.
3=A program eltvoltshoz vlassza a Vezrlpult Programok teleptse/trlse lehetsgt.
4=Ha a program frisstse mellett dnt, akkor ltogassa meg a http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l oldalt, s regisztrci utn tltse le a frisstst.
5=Gyzdjn meg rla, hogy a program frisstve van vagy el lett tvoltva, majd a telepts folytatshoz nyomja meg az jra gombot.
[Shield.Firewalls.Text.0X40E]
1=A szmtgpen tzfalprogram tallhat. A tzfal a teleptssel kapcsolatban figyelmeztet prbeszdablakokat kldhet.
2=Ha e figyelmeztetsek valamelyikt ltja, hagyja, hogy a HP programok tovbb mkdjenek.
3=A folyamat folytatsval kapcsolatban ltalnosan hasznlt nhny kifejezs: felold, igen, enged s engedlyez.
4=A teleptprogram blokkolsa valsznleg sikertelen teleptst eredmnyez.
[Shield.Roxio.Text.0x410]
1=Questo programma installato e non compatibile con il software.
2= necessario disinstallare o aggiornare il programma prima di continuare l'installazione.
3=Per disinstallare il programma, scegliere Installazione applicazioni nel Pannello di controllo di Windows.
4=Se si sceglie di aggiornare questo programma, visitare http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l per registrarsi e scaricare l'aggiornamento.
5=Verificare che il programma sia aggiornato e fare clic su Riprova per continuare l'installazione.
[Shield.Firewalls.Text.0X410]
1=Il software del firewall stato rilevato sul computer. Questo firewall potrebbe visualizzare delle finestre di avviso correlate all'installazione.
2=Quando appare uno di questi avvisi, consentire ai programmi HP di procedere.
3=Alcuni termini di uso frequente per consentire ad un processo di continuare sono: Sblocca, S, Consenti.
4=Se si blocca un programma di installazione, l'installazione potrebbe non essere completata con successo.
[Shield.Roxio.Text.0x11]
1=CXg[vÓÃ\tgEFAɏĂ­܂B
2=CXg[𑱍sOɁÃvOACXg[­܂͍XVKv܂B
3=Windows Rg[pl [AvP[V̒ljƍ폜] gāAvOACXg[܂B
4=vOXVꍇ́Ahttp://www.roxio.com/en/suppor­t/ecdc/ecdc_plat_535_updt.jhtml ɓo^āAXV_E[h܂B
5=vO̍XV܂̓ACXg[̊mF A[Ďs] NbNăCXg[𑱍s܂B
[Shield.Firewalls.Text.0X11]
1=̃Rs[^ɂ̓t@CAEH[ \tgEFAoĂ܂Bt@CAEH[̉ʂɁAC­Xg[Ɋ֘Ax_CAO\ꍇ܂­B
2=ȉ̃A[g\ꂽƂ́AHP vÔ܂܎sł悤ɂĂB
3=spۂɈʂɕ\郆[U[ C^tF[X: Unblock(֎~̉)AYes (͂)AAllow()APermit()
4=CXg[ vO̎s֎~ƁACXg[sꍇ­܂B
[Shield.Roxio.Text.0x12]
1=α׷ ġǰ Ʈ ȣȯ ʽϴ.
2=ġ Ϸ α׷ ϰų ׷̵ؾ մϴ.
3=α׷ Ϸ Windows [α׷ ߰/] ϴ.
4=α׷ ׷̱ϵ ϸ http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l ϰ ׷̵带 ٿεմϴ.
5=α׷ ׷̵ǰų ŵǾ Ȯ [ٽ õ] ġ Ͻʽÿ.
[Shield.Firewalls.Text.0X12]
1=ȭ Ʈ ǻͿ ˻Ǿϴ. ȭ ġ õ ȭ ڸ ǥ ֽϴ.
2= ϳ ǥõ HP α׷ ֵ ֽʽÿ.
3= ϴ Ϲ Ǵ : , , 㰡
4=ġ α׷ ϸ ġ ֽϴ.
[Shield.Roxio.Text.0x413]
1=Dit programma is genstalleerd en is niet compatibel met deze software.
2=U moet de installatie van dit programma ongedaan maken of een upgrade voor dit programma uitvoeren voordat u verder kunt gaan met installeren.
3=Als u de installatie van dit programma ongedaan wilt maken, gaat u naar Software in het Configuratiescherm van Windows.
4=Als u een upgrade voor dit programma wilt uitvoeren, gaat u naar http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l om de upgrade te registeren en te downloaden.
5=Zorg dat het programma is bijgewerkt of dat de installatie ervan ongedaan is gemaakt en klik vervolgens op Opnieuw om verder te gaan met installeren.
[Shield.Firewalls.Text.0X413]
1=Op deze computer is firewall-software gevonden. Door de firewall kunnen waarschuwingsmeldingen worden weergegeven die betrekking hebben op deze installatie.
2=Laat HP-programma's uitvoeren als u een dergelijke waarschuwing ziet.
3=Het laten uitvoeren van een proces gebeurt doorgaans met opties als Blokkering opheffen, Deblokkeren, Ja en Toestaan.
4=Als u een installatieprogramma blokkeert, zal de installatie mislukken.
[Shield.Roxio.Text.0x414]
1=Dette programmet er installert og er inkompatibelt med denne programvaren.
2=Du m enten avinstallere eller oppgradere dette programmet fr du fortsetter installasjonen.
3=G til Legg til / fjern programmer i Kontrollpanel i Windows for avinstallere programmet.
4=Hvis du velger oppgradere dette programmet, gr du til http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l for registrere deg og laste ned oppgraderingen.
5=Kontroller at programmet er oppgradert eller avinstallert, og klikk deretter p Prv p nytt for fortsette installasjonen.
[Shield.Firewalls.Text.0X414]
1=Det er funnet brannmurprogramvare p denne datamaskinen. Brannmuren kan vise advarsler i forbindelse med installeringen.
2=Vennligst la HP-programmer fortsette nr du ser et av disse varslene.
3=Enkelte vanlige termer som brukes for la en prosess fortsette, er: Opphev blokkering, Ja og Tillat.
4=Blokkering av et installeringsprogram vil mest sannsynlig fre til at installeringen mislykkes.
[Shield.Roxio.Text.0x415]
1=Program ten zosta zainstalowany i nie jest on zgodny z tym oprogramowaniem.
2=Program ten naley odinstalowa albo zaktualizowa przed kontynuacj instalacji.
3=Aby odinstalowa ten program, przejd do opcji Dodaj/Usu programy w panelu sterowania Windows.
4=Jeeli program ma zosta zaktualizowany, odwied http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l, aby zarejestrowa i pobra aktualizacj oprogramowania.
5=Sprawd, czy program zosta zaktualizowany lub odinstalowany, a nastpnie kliknij przycisk Ponw prb, aby kontynuowa instalacj.
[Shield.Firewalls.Text.0X415]
1=Wykryto programow zapor firewall na tym komputerze. Zapora firewall moe spowodowa wywietlenie komunikatw zwizanych z instalacj.
2=Jeeli zauwaysz jedno z poniszych powiadomie, pozwl na kontynuowanie pracy programw HP.
3=Niektre z czsto stosowanych terminw zezwalajcych na kontynuowanie procesu to: Odblokuj, Tak, Zezwl i Pozwl.
4=Zablokowanie programu instalacyjnego najprawdopodobniej spowoduje zakoczenie instalacji niepowodzeniem.
[Shield.Roxio.Text.0x416]
1=O programa est instalado e incompatvel com o software.
2=Voc deve desinstalar ou atualizar o programa antes de continuar com a instalao.
3=Para desinstalar o programa, v para Adicionar ou Remover Programas no Painel de Controle do Windows.
4=Se optar por atualizar o programa, visite http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l para se registrar e fazer o download da atualizao.
5=Verifique se o programa foi atualizado ou desinstalado e clique em Repetir para continuar com a instalao.
[Shield.Firewalls.Text.0X416]
1=O software de firewall foi detectado neste computador. O firewall pode exibir um dilogo de alerta relacionado instalao.
2=Por favor deixe os programas da HP prosseguirem quando voc vir um desses alertas.
3=Os termos mais usados para permitir o prosseguimento de um processo so: Desbloquear, Sim e Permitir.
4=O bloqueio de um programa de instalao provavelmente causar falha na instalao.
[Shield.Roxio.Text.0x419]
1= .
2= .
3= , Windows.
4= , http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l, .
5= , .
[Shield.Firewalls.Text.0X419]
1= . .
2= HP.
3= , : , , .
4= .
[Shield.Roxio.Text.0x41d]
1=Programmet har installerats men r inte kompatibelt med den hr programvaran.
2=Du mste avinstallera eller uppdatera programmet innan du fortstter med installationen.
3=Du avinstallerar programmet genom att g till Lgg till/ta bort program i Kontrollpanelen i Windows.
4=Om du vljer att uppdatera programmet gr du http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l fr att registrera dig och hmta uppdateringen.
5=Kontrollera att du uppdaterat eller avinstallerat programmet och klicka p Frsk igen s fortstter installationen .
[Shield.Firewalls.Text.0X41d]
1=Brandvggsprogramvara har upptckts p datorn. Denna brandvgg kan visa dialogrutor med varningar relaterade till installationen.
2=Tillt HP-program att fortstta nr du ser en av fljande varningar.
3=Ngra vanliga termer som tillter en process att fortstta r: Hv blockering, Ja, Tillt och Godknn.
4=Om ett installationsprogram blockeras, misslyckas troligen installationen.
[Shield.Roxio.Text.0x41F]
1=Bu program ykl ve bu yazlmla uyumlu deil.
2=Ykleme ilemine devam etmeden nce bu program kaldrmal veya ykseltmelisiniz.
3=Bu program kaldrmak iin, Windows Denetim Masas'nda Program Ekle/Kaldr'a gidin.
4=Bu program ykseltmeyi seerseniz, http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l sitesini ziyaret ederek kayt olun ve ykseltme srmn indirin.
5=Programn ykseltildiinden veya kaldrldndan emin olun ve yklemeye devam etmek iin Yeniden Dene'yi tklatn.
[Shield.Firewalls.Text.0X41F]
1=Bu bilgisayarda gvenlik duvar yazlm algland. Bu gvenlik duvar yklemeye ilikin uyar iletiim kutular grntleyebilir.
2=Bu uyarlardan birini grdnzde ltfen HP programlarnn devam etmesine izin verin.
3=lemin devam etmesine izin vermek iin genellikle kullanlan baz terimler unlardr: Engeli kaldr, Evet, zin ver ve Brak.
4=Ykleme programn engellemek, muhtemelen yklemenin baarsz olmasna neden olur.
[shield.roxio.text]
1=[%lang%] This program is installed and is incompatible with this software.
2=[%lang%] You must either uninstall or upgrade this program before continuing this installation.
3=[%lang%] To uninstall this program, go to Add/Remove Programs in the Windows Control Panel.
4=[%lang%] If you choose to upgrade this program, visit http://www.roxio.com/en/support/ecdc/ecdc_plat_535_updt.jhtm­l to register and download the upgrade.
5=[%lang%] Ensure the program is upgraded or uninstalled and then click Retry to continue installation.
[Shield.Firewalls.Text]
1=[%lang%] Firewall software has been detected on this computer.
2=[%lang%] Disable the software firewall before continuing so the HP installation software can detect the device on the network.You can enable the software firewall after completing the installation.
3=[%lang%] See your software firewall documentation for information about how to temporarily disable it.
4=[%lang%] For more information, including how to protect your system when the firewall is disabled visit: http://www.hp.com/support choose your product and search for "network installation with firewalls".
[DirectX]
Version=0x0004000900000384
[setup.bitmap.text.0x1]
1= HP.
2= HP
6=
7=
8=
[Setup.bitmap.eSupport.text.0x1]
1= , , .
[Setup.bitmap.PSE.text.0x1]
1=
2=
3= , -
4=
5=
6= - , , , ,
7= HP , ,
8=
9=
10= Snapfish ( / )
[Setup.bitmap.DTSS.text.0x1]
1= HP "Shop for HP Supplies" ( HP)
[Setup.bitmap.WebPrint.text.0x1]
1=
[setup.bitmap.text]
1=[%lang] Thank you for choosing HP
2=[%lang] Exceptional Product Offers and Discounts for HP Customers
6=Make copies without turning on your computer
7=Print beautiful photos from your digital camera
8=Scan photos and documents to your computer
[Setup.bitmap.eSupport.text]
1=[%lang] Your one-stop for accessing key product features, documentation, troubleshooting, and online supplies shopping
[Setup.bitmap.PSE.text]
1=[%lang] Photo software that simply lets you tell amazing stories
2=[%lang] New personalized homepage elevates your most relevant photos for instant use
3=[%lang] Get the prints you want the first time, in a variety of sizes - no surprises
4=[%lang] Easy templates let you print album collage pages right at home
5=[%lang] Share entire photo albums with friends and family without the hassle of attachments
6=[%lang] Easily find your photos the way you want - Date, Tag, Folders, Search, Favorites
7=[%lang] Let HP automatically fix photos, remove red eye, pet green eye
8=[%lang] Learn to do more - take the onscreen tour
9=[%lang] Make sure to update to get the latest exciting free features and benefits
10=[%lang] Order professional prints and photo products from Snapfish (where available in select regions)
[Setup.bitmap.DTSS.text]
1=[%lang] Quickly and easily order Original HP replacement ink cartridges with "Shop for HP Supplies" software
[Setup.bitmap.WebPrint.text]
1=[%lang] Simple, predictable web printing with control over what you want and how you want it printed
[Setup.bitmap.text.0x404]
1=P±z HP ~C
2= HP ΤᴣѪS~ufM馩
6=b}ҹqpUivL
7=qzƦ۾CLX}Gۤ
8=NۤP󱽴yܱzq
[Setup.bitmap.eSupport.text.0x404]
1=sDn~\BBƸѩM{uWʪ@]One-Stop^\C
[Setup.bitmap.PSE.text.0x404]
1=ۤnizPz_GơC
2=sөʤƭi@zYɨϥΪKۤ
3=YĤ@NozQnPjpCL
4=²ҪOizbaNCLïN
5=ηФHNiHP˪Bnͦ@ɾӬï
6=PHzQn覡Mۤ BаOBɮקBjMBڪ̷RC
7= HP ۰ʭץۤBMd
8=Aѧh iJ@ù
9=TOsAHo̷sBEʤHߪKO\Muf
10=q Snapfish qʱM~CLMۤ~]ȭYǦaϡ^

Répondre à caroline2

47

caroline2, le 19 dc 2008 à 18:07:24

[Setup.bitmap.DTSS.text.0x404]
1=ϥΡuʶR HP ӧvnֳtBPaqʭ HP 󴫾XC
[Setup.bitmap.WebPrint.text.0x404]
1=²BiwCLizzQnCL榡M覡
[Setup.bitmap.text.0x804]
1=лѡ HP Ʒ
2=Ϊ HP ûṩرƷŻݺۿ
6=ô򿪼ɽиӡ
7=ӡƬ
8=Ƭĵɨ赽
[Setup.bitmap.eSupport.text.0x804]
1=ҪƷܡĵŽϢʵ߹IJĵһ­վʽ
[Setup.bitmap.PSE.text.0x804]
1=չʾͬѰƬ
2=ʽԻҳṩƬԱ㼴ʱʹ
3=һξõĶֳߴĴӡ һһ
4=ģڼҼɴӡƴҳ
5=跢˵ĸѹͬ
6=ϣķʽ ڡǩļСղؼзҵƬ
7= HP Զ޸Ƭۺͳ
8=ѧϰ༼ ͨĻ鿴
9=ȷ£Իȡµ˾ϲѹܺŻ
10=ͨ SnapfishijЩרҵӡƬƷ
[Setup.bitmap.DTSS.text.0x804]
1=ͨ HP IJġݵضԭװ HP ī
[Setup.bitmap.WebPrint.text.0x804]
1=򵥡Ԥ Web ӡܹƴӡݺʹӡʽ
[Setup.bitmap.text.0x5]
1=Dkujeme vm, e jste si vybrali spolenost Hewlett-Packard.
2=Mimodn nabdky produkt a slevy pro zkaznky spolenosti HP
6=Koprovn bez zapnut potae
7=Tisk ndhernch fotografi zdigitlnho fotoapartu
8=Skenovn fotografi a dokument do potae
[Setup.bitmap.eSupport.text.0x5]
1=V pm pstup ke klovm funkcm produktu, dokumentaci, een problm a online nkupu spotebnho materilu
[Setup.bitmap.PSE.text.0x5]
1=Fotografick software, kter vm umouje jednodue vyprvt vzruujc pbhy
2=Nov personalizovan domovsk strnka vm umouje mt nejdanj fotografie pipraven k okamitmu pouit
3=Na prvn pokus vytisknte obzky, kter chcete, v rznch velikostech - dn nepjemn pekvapen
4=Jednoduch ablony vm pomohou tisknout album kol - doma
5=Sdlejte alba fotografi s pteli a rodinou - bez nutnosti pout obtnch ploh
6=Jednodue vyhledvejte fotografie zpsobem, kter se vm hod - podle data, oznaen, vyhledn, oblben
7=Nechte HP, aby za vs korigoval fotografie - efekt ervench o, zelen oi domcch mazlk
8=Poute se, jak lpe vyut - prohldnte si interaktivn presentaci
9=Provete aktualizaci, abyste zskali pstup k nejnovjm, zdarma poskytovanm funkcm a benefitm
10=Objednejte si profesionln tisky a fotografick produkty od Snapfish (pokud je dostupn ve vybranch oblastech)
[Setup.bitmap.DTSS.text.0x5]
1=Jednodue a rychle si objednejte originln nhradn inkoustov kazety HP pomoc software "Shop for HP Supplies"
[Setup.bitmap.WebPrint.text.0x5]
1=Jednoduch a pedvdateln tisk na internetu s monost urit co a jak chcete vytisknout
[Setup.bitmap.text.0x6]
1=Tak, fordi du valgte HP.
2=Exceptionelle produkttilbud og rabatter til HP-kunder
6=Lav kopier uden at tnde computeren
7=Udskriv flotte fotos fra dit digitalkamera
8=Scan fotos og dokumenter til computeren
[Setup.bitmap.eSupport.text.0x6]
1=Her fr du adgang til produktegenskaber, dokumentation, fejlfinding samt online-kb af forbrugsvarer
[Setup.bitmap.PSE.text.0x6]
1=Fotosoftware, som du kan bruge til at fortlle spndende historier.
2=Ny tilpasset hjemmeside, hvor dine nyeste billeder er klar til jeblikkelig brug
3=F de rigtige udskrifter i frste forsg, i mange forskellige strrelser ingen overraskelser
4=Brugervenlige skabeloner, s du kan udskrive albumsider derhjemme
5=Del hele fotoalbum med venner og familie uden at bekymre dig om vedhftede filer
6=Du finder nemt de fotos, du skal bruge - Dato, Label, Mapper, Sg, Foretrukne
7=Lad HP fjerne rde jne automatisk
8=F mere at vide se prsentationen p skrmen
9=Husk at opdatere, s du fr de nyeste gratis funktioner og fordele
10=Bestil professionelle udskrifter og fotoprodukter fra Snapfish (findes kun i nogle omrder)
[Setup.bitmap.DTSS.text.0x6]
1=Bestil nemt og hurtigt originale HP-blkpatroner med programmet "Kb HP-forbrugsvarer"
[Setup.bitmap.WebPrint.text.0x6]
1=Enkel og forudsigelig webudskrivning, hvor du har styr p, hvad der udskrives, og hvordan det udskrives
[Setup.bitmap.text.0x7]
1=Vielen Dank, dass Sie sich fr HP entschieden haben.
2=Einmalige Produktangebote und Rabatte fr HP Kunden
6=Erstellen Sie Kopien, ohne den Computer einzuschalten
7=Drucken Sie schne Fotos von Ihrer Digitalkamera
8=Scannen Sie ber den Computer Fotos und Dokumente
[Setup.bitmap.eSupport.text.0x7]
1=Zentrale Anlaufstelle bzgl. Produktfunktionen, Dokumentation, Fehlerbehebung und Online-Shop fr Verbrauchsmaterialien
[Setup.bitmap.PSE.text.0x7]
1=Foto-Software, mit der Sie auf einfache Weise beeindruckende Geschichten erzhlen knnen.
2=Auf der neuen persnlichen Homepage werden immer die relevantesten Fotos zur sofortigen Verwendung angezeigt.
3=Erstellen Sie die gewnschten Ausdrucke gleich beim ersten Mal, auch in verschiedenen Gren - ohne bse berraschungen.
4=Mit einfachen Vorlagen knnen Sie zuhause Collagenseiten aus Alben drucken.
5=Zeigen Sie Ihren Freunden und Verwandten ganze Fotoalben, ohne sich mit E-Mail-Anhngen herumplagen zu mssen.
6=Suchen Sie Ihre Fotos anhand der von Ihnen festgelegten Kriterien - Datum, Kennung, Ordner, Suche, Favoriten.
7=Lassen Sie HP automatisch Fotos korrigieren und rote bzw. grne Augen (bei Tieren) entfernen.
8=Lernen Sie alle verfgbaren Funktionen kennen - nehmen Sie an der Online-Tour teil.
9=Aktualisieren Sie die Software, um auf die neuesten kostenlosen Funktionen zugreifen und Vorteile nutzen zu knnen.
10=Bestellen Sie professionelle Ausdrucke und Fotoprodukte ber Snapfish (in ausgewhlten Regionen verfgbar).
[Setup.bitmap.DTSS.text.0x7]
1=Bestellen Sie schnell und einfach original HP Ersatztintenpatronen mit der Software "Shop for HP Supplies".
[Setup.bitmap.WebPrint.text.0x7]
1=Einfaches, zuverlssiges Web-Drucken, bei dem Sie steuern knnen, was Sie drucken und wie Sie es drucken.
[Setup.bitmap.text.0x8]
1= HP.
2= HP
6=
7=
8=
[Setup.bitmap.eSupport.text.0x8]
1= , , , online
[Setup.bitmap.PSE.text.0x8]
1=
2=
3= , -
4=
5=
6= - , , , ,
7= HP ,
8= -
9=
10= Snapfish ( )
[Setup.bitmap.DTSS.text.0x8]
1= HP "Shop for HP Supplies" ( HP)
[Setup.bitmap.WebPrint.text.0x8]
1=, web
[setup.bitmap.text.0x9]
1=Thank you for choosing HP
2=Exceptional Product Offers and Discounts for HP Customers
6=Make copies without turning on your computer
7=Print beautiful photos from your digital camera
8=Scan photos and documents to your computer
[Setup.bitmap.eSupport.text.0x9]
1=Your one-stop for accessing key product features, documentation, troubleshooting, and online supplies shopping
[Setup.bitmap.PSE.text.0x9]
1=Photo software that simply lets you tell amazing stories
2=New personalized homepage elevates your most relevant photos for instant use
3=Get the prints you want the first time, in a variety of sizes - no surprises
4=Easy templates let you print album collage pages right at home
5=Share entire photo albums with friends and family without the hassle of attachments
6=Easily find your photos the way you want - Date, Tag, Folders, Search, Favorites
7=Let HP automatically fix photos, remove red eye, pet green eye
8=Learn to do more - take the onscreen tour
9=Make sure to update to get the latest exciting free features and benefits
10=Order professional prints and photo products from Snapfish (where available in select regions)
[Setup.bitmap.DTSS.text.0x9]
1=Quickly and easily order Original HP replacement ink cartridges with "Shop for HP Supplies" software
[Setup.bitmap.WebPrint.text.0x9]
1=Simple, predictable web printing with control over what you want and how you want it printed
[Setup.bitmap.text.0xa]
1=Gracias por elegir HP.
2=Ofertas y descuentos excepcionales para los clientes de HP
6=Realice copias sin encender el equipo
7=Imprima excelentes fotografas desde su cmara digital
8=Escanee y guarde fotografas y documentos en su equipo
[Setup.bitmap.eSupport.text.0xa]
1=Un nico punto de acceso a funciones esenciales del producto, documentacin, solucin de problemas y compra de consumibles en lnea
[Setup.bitmap.PSE.text.0xa]
1=Software fotogrfico para que pueda contar historias sorprendentes
2=Nueva pgina principal personalizada que incorpora sus fotografas ms importantes para su uso inmediato
3=Consiga las impresiones que quiere a la primera, en distintos tamaos, sin sorpresas
4=Plantillas de fcil uso para imprimir pginas con montajes de lbumes directamente en casa
5=Comparta sus lbumes de fotografas con los amigos y familiares sin la complicacin de los archivos adjuntos.
6=Encuentre fcilmente sus fotografas y de la forma que prefiera: por fecha, etiquetas, carpetas, con la opcin de bsqueda, en favoritos
7=Deje que HP arregle las fotos automticamente, elimine el efecto ojos rojos u ojos verdes (en fotos de animales).
8=Aprenda a hacer ms, siga la presentacin en pantalla
9=Asegrese de actualizar su aplicacin para disfrutar de las prestaciones y ventajas gratuitas ms atractivas y novedosas
10=Solicite copias y fotografas profesionales a Snapfish (si est disponible en determinadas zonas)
[Setup.bitmap.DTSS.text.0xa]
1=Pida cartuchos de tinta de repuesto originales de HP, rpida y fcilmente, con el software "Shop for HP Supplies"
[Setup.bitmap.WebPrint.text.0xa]
1=Impresin de Internet sencilla y previsible con control sobre lo que quiere imprimir y sobre cmo imprimirlo
[Setup.bitmap.text.0xb]
1=Kiitos, ett valitsit HP:n.
2=Tuotteiden erikoistarjouksia ja alennuksia HP:n asiakkaille
6=Ota kopioita kynnistmtt tietokonetta
7=Tulosta kauniita kuvia digitaalikamerasta
8=Skannaa valokuvia ja asiakirjoja tietokoneeseen
[Setup.bitmap.eSupport.text.0xb]
1=Tst saat kyttsi kaiken, tuotteen trkeimmt ominaisuudet, julkaisut ja vianmrityksen, ja voit osaa tarvikkeita verkosta
[Setup.bitmap.PSE.text.0xb]
1=Valokuvien ksittelyohjelmisto, jonka avulla voit kertoa mahtavia tarinoita
2=Uusi muokattu kotisivu antaa parhaimmat kuvasi heti kyttn
3=Tee haluamasi kuvat heti ensimmisell yrityksell ja oikean kokoisina - ei ylltyksi
4=Helpot mallit auttavat tulostamaan albumisivuja kotona
5=Jaa kokonaisia valokuva-albumeja ystvien ja perheen kesken liitetiedostoja kyttmtt
6=Lydt valokuvat helposti haluamallasi tavalla: pivmrn, merkin tai kansion perusteella, hakutoiminnolla tai suosikeista
7=Anna HP:n korjata kuvat automaattisesti, poistaa punasilmisyyden tai lemmikkien vihresilmisyyden
8=Opettele tekemn enemmn - seuraa opetusohjelmaa nytss
9=Muista pivitt. Saat uusimmat kivat ominaisuudet ja edut ilmaiseksi
10=Tilaa ammattimaisia tulosteita ja valokuvatuotteita Snapfish-palvelusta (kytss tietyill alueilla)
[Setup.bitmap.DTSS.text.0xb]
1=Alkuperisten HP:n vaihtomustekasettien tilaaminen on nopeaa ja ktev "Shop for HP Supplies" -ohjelmistolla
[Setup.bitmap.WebPrint.text.0xb]
1=Yksinkertaista ja luotettavaa Web-tulostusta. Voit ptt, mit ja kuinka haluat tulostaa
[Setup.bitmap.text.0xc]
1=Merci d'avoir choisi HP !
2=Offres de produits et promotions exceptionnelles pour les clients HP
6=Ralisez des copies sans allumer votre ordinateur
7=Imprimez de superbes photos partir de votre appareil photo numrique
8=Numrisez photos et documents sur votre ordinateur
[Setup.bitmap.eSupport.text.0xc]
1=Votre point d'accs centralis aux principales fonctionnalits du produit, au dpannage et l'achat de consommables urnitures en ligne
[Setup.bitmap.PSE.text.0xc]
1=Un logiciel photo qui vous permet de raconter simplement des rcits stupfiants !
2=Une nouvelle page d'accueil personnalise qui met en valeur vos plus belles photos pour une utilisation immdiate
3=Obtenez les preuves que vous voulez ds la premire fois, dans divers formats, sans surprises
4=Des modles faciles pour imprimer des photocollages de pages de votre album depuis chez vous
5=Partagez intgralement vos albums de photos avec vos proches sans toutes les complications des pices jointes
6=Trouvez facilement vos photos par le biais de votre choix : Date, Marquage, Dossiers, Rechercher ou Favoris
7=Laissez la correction automatique HP suprprimer l'effet yeux rouges, ou yeux verts pour les animaux
8=Pour voir comment vous perfectionner, laissez-vous guider !
9=Installez la mise jour pour obtenir notre toute dernire offre gratuire de fonctionnalits et d'avantages
10=Commandez des tirages professionnels et des produits photos partir de Snapfish (disponible dans plusieurs rgions)
[Setup.bitmap.DTSS.text.0xc]
1=Commandez rapidement et facilement des cartouches d'encre HP d'origine avec le logiciel "Achat de consommables HP"
[Setup.bitmap.WebPrint.text.0xc]
1=L'impression Web, simple et prvisible avec la possibilit de choisir l'lment imprimer et le mode d'impression
[setup.bitmap.text.0xd]
1= -HP.
2= HP
6=
7=
8=
[Setup.bitmap.eSupport.text.0xd]
1= , ,
[Setup.bitmap.PSE.text.0xd]
1=
2=
3= , -
4= '
5=
6= - , , , ,
7= -HP , ,
8= - -
9= -
10= -Snapfish ( / )
[Setup.bitmap.DTSS.text.0xd]
1= HP "Shop for HP Supplies" ( HP)
[Setup.bitmap.WebPrint.text.0xd]
1=
[Setup.bitmap.text.0xe]
1=Ksznjk, hogy HP termket vlasztott.
2=Rendkvli termkajnlatok s rengedmnyek a HP vsrli szmra
6=Msolatok ksztse a szmtgp bekapcsolsa nlkl
7=Kivl minsg fnykpek nyomtatsa a digitlis fnykpezgprl
8=Fnykpek s dokumentumok beolvassa a szmtgpbe
[Setup.bitmap.eSupport.text.0xe]
1=Kzponti webhely a legfontosabb termkszolgltatsok, dokumentcik, hibaelhrtsi informcik s online megvsrolhat kellkek elrshez
[Setup.bitmap.PSE.text.0xe]
1=Fnykpkezel szoftver, mellyel trtneteket meslhet
2=Az j, szemlyre szabott kezdlap kiemeli a legfontosabb fnykpeket az azonnali felhasznlhatsg rdekben
3=Nincs tbb meglepets: azonnal a kvnt paprkpeket rendelheti meg, klnbz mretekben
4=A knnyen hasznlhat sablonokkal otthon is nyomtathat montzsoldalakat albumaihoz
5=Akr teljes fotalbumokat is megoszthat bartaival s csaldtagjaival e-mail mellkletek nlkl
6=Knnyedn megkeresheti a kvnt fnykpeket dtum, cmke, mappa s kereskifejezs alapjn, vagy a Kedvencek kztt
7=A HP automatikus fotjavtsi szolgltatsaival knnyedn eltvolthatja a vrsszem- s zldszem-effektust
8=Tbbre kvncsi? Tekintse meg az online bemutatt
9=Frisstsen rendszeresen, hogy mindig a legjabb ingyenes szolgltatsokat hasznlhassa
10=Rendeljen professzionlis minsg paprkpeket s fotzsi kellkeket a Snapfish webhelyrl (ha elrhet az n rgijban)
[Setup.bitmap.DTSS.text.0xe]
1=A HP-kellkek vsrlsa szolgltatssal gyorsan s knnyedn rendelhet eredeti HP-cserepatronokat
[Setup.bitmap.WebPrint.text.0xe]
1=Egyszer, megjsolhat eredmnyeket produkl webes nyomtats, ahol n dnti el mit s hogyan szeretne kinyomtatni
[Setup.bitmap.text.0x10]
1=Grazie per aver scelto HP.
2=Eccezionali offerte e sconti per i clienti HP
6=Effettuare copie senza accendere il computer
7=Stampare foto eccezionali dalla fotocamera digitale
8=Acquisire tramite scansione foto e documenti sul computer
[Setup.bitmap.eSupport.text.0x10]
1=Per accedere a: funzioni principali, documentazione, risoluzione dei problemi e acquisto materiali di consumo
[Setup.bitmap.PSE.text.0x10]
1=Il software per le foto consente di raccontare storie meravigliose
2=La nuova pagina iniziale personalizzata consente di mettere in primo piano le foto pi importanti per un uso immediato
3=Si pu stampare ci che si vuole, subito e in diversi formati - senza brutte sorprese
4=Modelli di facile uso consentono di stampare collage di foto per un album direttamente a casa propria
5=Si possono condividere interi album con amici e parenti senza l'ingombro di allegati
6=Le foto sono sempre reperibili secondo il criterio desiderato - data, tag, cartella, ricerca, preferite
7=HP corregge automaticamente le foto, elimina l'effetto occhi rossi per le persone od occhi verdi per gli animali
8=Per imparare altre cose, basta avvalersi del tour online
9=Gli aggiornamenti consentono di avere sempre il meglio in termini di nuove funzionalit e vantaggi
10=Snapfish consente di ordinare stampe e foto di qualit professionale (nelle zone in cui questo servizio disponibile)
[Setup.bitmap.DTSS.text.0x10]
1=Il software "Shop for HP Supplies" consente di ordinare facilmente e rapidamente nuove cartucce d'inchiostro originali HP
[Setup.bitmap.WebPrint.text.0x10]
1=Stampare via Internet facile e prevedibile con un controllo completo su ci che si desidera stampare e come si desidera stamparlo
[Setup.bitmap.text.0x11]
1=HP iグ܂Ă肪Ƃ܂
2=HP ̂ql HP i₨
6=Rs[^̓dȂĂRs[ł܂B
7=fW^J̎ʐ^YɈ܂B
8=ʐ^ƃhLgRs[^ɃXL܂B
[Setup.bitmap.eSupport.text.0x11]
1=i̎vȋ@\A}jAAguV[eBOAՕĩIC VbsOȂǂɃANZX邽߂̃Xgbvł
[Setup.bitmap.PSE.text.0x11]
1=h̗ǂAoȒPɍ쐬łtHg \tgEFA
2=Vp[\iCYꂽz[y[Wł́AɎg悤ɖړIɍɏォʐ^\܂
3=܂܂ȃTCỸvg܂
4=vg Ao R[W y[Wō쐬łAȒPȃev[gł
5=킸킵Ytt@CȂɁAFlƑƃtHg AoŜLł܂
6=tA^OAtH_AACɓȂǁAD݂̕@ŊȒPɎʐ^‚邱Ƃł܂
7=HP IɎʐ^̏CAԖڂybg̗Ζڂ̏s܂
8=ɏڂ邽߁AIXN[ cA[s܂
9=ŐV–̋@\ƃbg悤ɍXV܂
10=Snapfish ̃vʐ^vgƎʐ^i܂ (ꕔn̂)
[Setup.bitmap.DTSS.text.0x11]
1=p HP pCN J[gbWuHP TvCi̍wv\tgEFAŊȒPɂw܂
[Setup.bitmap.WebPrint.text.0x11]
1=ǂ̎ʐ^ǂ̂悤ɃvĝȒP—\ǂɒłAWeb vgł
[Setup.bitmap.text.0x12]
1=HP ̿ ּż մϴ.
2=HP ǰ Ư
6=ǻ͸ ʰ ֽϴ.
7= ī޶󿡼 μ ֽϴ.
8= ǻͷ ĵ ֽϴ.
[Setup.bitmap.eSupport.text.0x12]
1=ٽ ǰ , , ذ ¶ Ҹǰ ο ׼
[Setup.bitmap.PSE.text.0x12]
1= ߾ ִ Ʈ
2= Ȩ ٷ ϱ⿡ ̰ մϴ.
3=ó ϴ μ⹰ پ ũ μ ֽϴ. ƴմϴ.
4= ø ٹ ݶ ٷ μ ֽϴ.
5=÷ ̵ ü ٹ ģ ֽϴ.
6=¥, ±, , ˻, ã ϴ ã ֽϴ.
7=HP ڵ ϰ ϵ մϴ.
8=ڼ ˾ƺ - ȭ ѷϴ.
9=Ʈ ̷ο ֽ ֽϴ.
10=Snapfish μ ǰ ֹ(Ϻ ̿ )
[Setup.bitmap.DTSS.text.0x12]
1="Shop for HP Supplies" Ʈ ǰ HP ü ũ īƮ ֹ
[Setup.bitmap.WebPrint.text.0x12]
1=ϴ ϴ μ ִ ϰ
[Setup.bitmap.text.0x13]
1=Bedankt dat u hebt gekozen voor HP.

Répondre à caroline2

46

Lyonnais92, le 19 dc 2008 à 18:02:46

Re,


Tu vas la fin du rapport, tu donnes les 100 dernires lignes !

@+
Faitescequel'onvousdemande,niplus,nimoins.
Necrezpasdedoublons,nisurCCMnisurunautresite.M­erci

Répondre à Lyonnais92

48

caroline2, le 19 dc 2008 à 18:10:57

--------------- [ Lecteur C ] ----------------

C: - Lecteur fixe
+- Listing des fichiers prsents :

[14/02/2006 02:39][--a------] C:\AUTOEXEC.BAT
[14/02/2006 02:39][--a------] C:\icremov.bat
[18/12/2008 14:20][--a------] C:\boot.ini.comodofirewall
[18/12/2008 14:20][--a------] C:\NTDETECT.COM
[15/12/2008 18:47][--a------] C:\SmitfraudFix.exe
[19/12/2008 09:06][-rahs----] C:\boot.ini
[19/12/2008 09:33][--a------] C:\ComboFix.txt
[19/12/2008 09:33][--a------] C:\rapport.txt
[19/12/2008 09:33][--a------] C:\SWSTAMP.TXT
[19/12/2008 09:33][--a------] C:\UsbFix.txt
[14/02/2006 02:39][--a------] C:\CONFIG.SYS
[14/02/2006 02:39][--a------] C:\hiberfil.sys
[14/02/2006 02:39][--a------] C:\IO.SYS
[14/02/2006 02:39][--a------] C:\MSDOS.SYS
[14/02/2006 02:39][--a------] C:\pagefile.sys

--------------- [ Lecteur D ] ----------------

D: - Lecteur fixe
+- Listing des fichiers prsents :

[22/01/2007 22:53][--a------] D:\AUTOREUSSITE Francais V2.0.exe
[22/01/2007 22:53][--a------] D:\baby_1.exe
[22/01/2007 22:53][--a------] D:\IE7RC1-WindowsXP-x86-fra.exe
[22/01/2007 22:53][--a------] D:\setupSNK.exe

--------------- [ Lecteur E ] ----------------

E: - Lecteur de CD-ROM
+- Listing des fichiers prsents :

[20/05/2007 23:43][-r-------] E:\HPZstub.exe
[20/05/2007 23:43][-r-------] E:\Setup.exe
[20/05/2007 23:43][-r-------] E:\hpzsetup.exe
[12/11/2006 18:12][-r-------] E:\PS_AIO_02_webreg.ini
[05/09/2007 14:31][-r-------] E:\autorun.inf
[05/09/2007 14:31][-r-------] E:\hpohsla.inf
[05/09/2007 14:31][-r-------] E:\hpohsls.inf
[05/09/2007 14:31][-r-------] E:\hposcu12.inf
[05/09/2007 14:31][-r-------] E:\hpounppsaio2_09.inf
[05/09/2007 14:31][-r-------] E:\hpounppsaio2_64.inf
[05/09/2007 14:31][-r-------] E:\hpzid413.inf
[05/09/2007 14:31][-r-------] E:\hpzipa13.inf
[05/09/2007 14:31][-r-------] E:\hpzipa23.inf
[05/09/2007 14:31][-r-------] E:\hpzipr13.inf
[05/09/2007 14:31][-r-------] E:\hpzipr23.inf
[05/09/2007 14:31][-r-------] E:\hpzius13.inf
[05/09/2007 14:31][-r-------] E:\hpzius23.inf
[05/09/2007 14:31][-r-------] E:\hpzusfnt.inf
[11/03/2004 23:50][-r-------] E:\license.txt

--------------- [ Lecteur H ] ----------------

H: - Lecteur amovible
+- Listing des fichiers prsents :


--------------- [ Registre / Startup ] ----------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
TOSCDSPD=C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
Skype="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
DU Meter=C:\Program Files\DU Meter\DUMeter.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
ATIPTA="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Toshiba Hotkey Utility="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
TPSMain=TPSMain.exe
NDSTray.exe=NDSTray.exe
SmoothView=C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
DLA=C:\WINDOWS\System32\DLA\DLACTRLW.EXE
AdslTaskBar=rundll32.exe stmctrl.dll,TaskBar
Share-to-Web Namespace Daemon=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
CFSServ.exe=CFSServ.exe -NoClient
ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
vptray=C:\PROGRA~1\SYMANT~1\VPTray.exe
VX3000=C:\WINDOWS\vVX3000.exe
LifeCam="C:\Program Files\Microsoft LifeCam\LifeExp.exe"
QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
ZoneAlarm Client="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
HP Software Update=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=

--------------- [ Registre / Mountpoint2 ] ----------------


-> Recherche ngative.

--------------- [ Nettoyage des disques ] ----------------

Supprim ! - [19/12/2008 11:15][--a------] C:\WINDOWS\system32\tmp.reg
Supprim ! - [19/12/2008 11:15][--a------] C:\WINDOWS\system32\tmp.txt
Echec de la supression !! - [05/09/2007 14:31] E:\autorun.inf
Echec de la supression !! - [05/09/2007 14:31] E:\autorun.inf
Echec de la supression !! - [05/09/2007 14:31] E:\autorun.inf

--------------- [ Resum ] ----------------

-> /!\ Le resultat doit etre interprt par un spcialiste /!\

[14/02/2006 02:39][--a------] C:\AUTOEXEC.BAT
[14/02/2006 02:39][--a------] C:\icremov.bat
[18/12/2008 14:20][--a------] C:\boot.ini.comodofirewall
[18/12/2008 14:20][--a------] C:\NTDETECT.COM
[15/12/2008 18:47][--a------] C:\SmitfraudFix.exe
[19/12/2008 09:06][-rahs----] C:\boot.ini
[22/01/2007 22:53][--a------] D:\AUTOREUSSITE Francais V2.0.exe
[22/01/2007 22:53][--a------] D:\baby_1.exe
[22/01/2007 22:53][--a------] D:\IE7RC1-WindowsXP-x86-fra.exe
[22/01/2007 22:53][--a------] D:\setupSNK.exe
[20/05/2007 23:43][-r-------] E:\HPZstub.exe
[20/05/2007 23:43][-r-------] E:\Setup.exe
[20/05/2007 23:43][-r-------] E:\hpzsetup.exe
[12/11/2006 18:12][-r-------] E:\PS_AIO_02_webreg.ini
[05/09/2007 14:31][-r-------] E:\autorun.inf
[05/09/2007 14:31][-r-------] E:\hpohsla.inf
[05/09/2007 14:31][-r-------] E:\hpohsls.inf
[05/09/2007 14:31][-r-------] E:\hposcu12.inf
[05/09/2007 14:31][-r-------] E:\hpounppsaio2_09.inf
[05/09/2007 14:31][-r-------] E:\hpounppsaio2_64.inf
[05/09/2007 14:31][-r-------] E:\hpzid413.inf
[05/09/2007 14:31][-r-------] E:\hpzipa13.inf
[05/09/2007 14:31][-r-------] E:\hpzipa23.inf
[05/09/2007 14:31][-r-------] E:\hpzipr13.inf
[05/09/2007 14:31][-r-------] E:\hpzipr23.inf
[05/09/2007 14:31][-r-------] E:\hpzius13.inf
[05/09/2007 14:31][-r-------] E:\hpzius23.inf
[05/09/2007 14:31][-r-------] E:\hpzusfnt.inf

--------------- ! Fin du rapport ! ----------------

Répondre à caroline2

50

caroline2, le 19 dc 2008 à 19:33:27

Sault lyonnais92,
penses-tu que je derais voir mon probleme de connexion sur le forum RESEAU ou bien a doit tre li ces antivirus 360, Rapidantiirus, RegisterDefender, Spyware Guard 2008 ....

Répondre à caroline2
Collection CommentÇaMarche.net