Service.exe crash avec code 1073741819

Résolu/Fermé
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007 - 17 mars 2007 à 04:23
 Utilisateur anonyme - 26 mars 2007 à 20:43
Bonjour depuis quelques temps en démarrant mon ordinateur services.exe crash avec le code 1073741819. Ca n'arrive pas toujours...je redémarre quelques fois et ca fini par démarrer normalement. Je me demande si c'est un virus qui pourrait faire ca ou bien si c'est un autre problème.

J'aimerais bien si quelqu'un pourrait m'aider a résoudre ce problème car ca devient assez agacant. On dirait que ca reviens a chaque update de windows. Pas la premiere fois je demande de l'aide ici alors voici un log hijackthis hehehe. Merci à l'avance à ceux qui pourront aider

Logfile of HijackThis v1.99.1
Scan saved at 23:19:14, on 2007-03-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\AccelerometerSt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrateur\Mes documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\AccelerometerSt.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
A voir également:

17 réponses

Utilisateur anonyme
26 mars 2007 à 20:43
Salut

Vide le contenu de ce dossier

- C:\WINDOWS\Downloaded Program Files <--

Ton rapport ets incomplet ..
3
Utilisateur anonyme
18 mars 2007 à 00:12
Quel est-ce programme qui te demande sans arrêt ? ou se situe t-il ?


¤ Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

- Service Partage réseau du Lecteur Windows Media
- InstallDriver Table Manage


¤ Télécharge et installe ces autres anti-spywares.
Mets les à jour et scanne complétement ton PC, supprime tout ce qu'ils pourraient te trouver.

SpyBot-Search & Destroy : gratuit en français
----> http://www.infos-du-net.com/telecharger/Destroy-Search-Spybot,0301-324.html

Si tu as besoin d'aide avec Sybot regarde ce tutoriel :
--> http://www.tutoriaux-excalibur.com/spybot.htm



A² squared : gratuit en français (fait un scan rusé et colle le rapport ici stp)
----> http://www.infos-du-net.com/telecharger/a-squared,0301-1233.html

Si tu as besoin d'aide avec A-squared regarde ce tutoriel :
--> https://kerio.probb.fr/t223-tuto-pour-a-squared-free


Télécharge et installe AVG anti-spyware :
Tu fais un scan complet de ton système, dès qu'il a fini.
Si il te trouve des espions, supprime les. Enregistre le rapport et colle le ici stp

AVG anti-spyware : reste gratuit après la période d'essai en français
---->http://www.infos-du-net.com/telecharger/Anti-Spyware-AVG,0301-7063.html

Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
--> http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

A++
2
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
19 mars 2007 à 02:20
Kapersky n'a rien trouvé et je fais déjà plusieurs nettoyages avec CCleaner à chaque semaine =/
1
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
23 mars 2007 à 20:14
Voila le scan comboscan. Désolé mais j'étais pas à la maison pendant une semaine. Un problème de plus aujourd'hui il m'a fait un crash services.exe avec code 203 avec compte a rebours =/

ComboScan v20070306.20 run by Administrateur on 2007-03-23 at 15:11:54
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Administrateur.exe) --------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 15:11:55, on 2007-03-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\AccelerometerSt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\NOTEPAD.EXE
C:\Documents and Settings\Administrateur\Mes documents\comboscan.exe
C:\DOCUME~1\ADMINI~1\MESDOC~1\Administrateur.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\AccelerometerSt.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)


-- Files created between 2007-02-23 and 2007-03-23 -----------------------------

2007-03-23 15:06:52 114688 --a------ C:\WINDOWS\system32\chg.exe
2007-03-21 13:10:26 0 d-------- C:\Program Files\mIRC
2007-03-17 21:34:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<SPYBOT~1>
2007-03-16 13:56:54 2297552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-03-15 20:22:42 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-03-15 20:22:28 42920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll<VSUTIL~1.DLL>
2007-03-15 20:22:15 0 d-------- C:\WINDOWS\system32\ZoneLabs
2007-03-15 20:21:05 0 d-------- C:\WINDOWS\Internet Logs<INTERN~1>
2007-03-10 13:43:34 4682 --a------ C:\WINDOWS\system32\npptNT2.sys
2007-03-06 12:56:15 153925 --a------ C:\WINDOWS\system32\drivers\dump_wmimmc.sys<DUMP_W~1.SYS>
2007-02-25 23:55:01 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Hamachi
2007-02-25 23:54:51 17480 --a------ C:\WINDOWS\system32\drivers\hamachi.sys


-- Find3M Report ---------------------------------------------------------------

2007-03-23 15:07:03 0 d-------- C:\Documents and Settings\Administrateur\Application Data\OpenOffice.org2<OPENOF~1.ORG>
2007-03-22 15:34:05 0 d-------- C:\Program Files\Mozilla Firefox<MOZILL~1>
2007-03-22 03:16:57 0 d-------- C:\Program Files\eMule
2007-03-21 18:48:55 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-19 13:15:11 0 d-------- C:\Documents and Settings\Administrateur\Application Data\uTorrent
2007-03-18 13:31:56 457392 --a------ C:\WINDOWS\system32\perfh00C.dat
2007-03-18 13:31:56 67524 --a------ C:\WINDOWS\system32\perfc00C.dat
2007-03-17 22:21:39 0 d-------- C:\Program Files\Grisoft
2007-03-15 13:44:54 0 d-------- C:\Documents and Settings\Administrateur\Application Data\AVG7
2007-03-13 15:32:11 0 d-------- C:\Program Files\MSN Messenger<MSNMES~1>
2007-02-15 02:16:21 952 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-02-15 02:16:20 56 -r-hs---- C:\WINDOWS\system32\3FE83BA494.sys<3FE83B~1.SYS>
2007-02-14 22:53:40 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Talkback
2007-02-14 01:23:48 21840 --a-----t C:\WINDOWS\system32\SIntfNT.dll
2007-02-14 01:23:48 17212 --a-----t C:\WINDOWS\system32\SIntf32.dll
2007-02-14 01:23:48 12067 --a-----t C:\WINDOWS\system32\SIntf16.dll
2007-02-09 16:33:35 0 d-------- C:\Program Files\Java
2007-02-07 04:20:03 0 d-------- C:\Documents and Settings\Administrateur\Application Data\GetRightToGo<GETRIG~1>
2007-02-06 00:07:01 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Adobe
2007-02-01 04:39:41 0 d-------- C:\Program Files\uTorrent
2007-01-29 04:58:06 60416 -----n--- C:\WINDOWS\system32\tzchange.exe
2007-01-19 12:53:04 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"MsmqIntCert"="regsvr32 /s mqrt.dll"
"AGRSMMSG"="AGRSMMSG.exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SoundMAX"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe /tray"
"AccelerometerSysTrayApplet"="C:\\WINDOWS\\system32\\AccelerometerSt.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"QlbCtrl"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,48,65,77,6c,65,\
74,74,2d,50,61,63,6b,61,72,64,5c,48,50,20,51,75,69,63,6b,20,4c,61,75,6e,63,\
68,20,42,75,74,74,6f,6e,73,5c,51,6c,62,43,74,72,6c,2e,65,78,65,20,2f,53,74,\
61,72,74,00
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"Recguard"="C:\\WINDOWS\\Sminst\\Recguard.exe"
"PTHOSTTR"="C:\\Program Files\\HPQ\\HP ProtectTools Security Manager\\PTHOSTTR.EXE /Start"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""


[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b58c7df7-391c-11db-b4bb-0013025c184c}]
Shell\AutoRun\command G:\Autorun\Launch.exe


-- End of ComboScan: finished at 2007-03-23 at 15:12:09 ------------------------
1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
24 mars 2007 à 10:50
Salut

Rends toi sur se site, en haut à droite clique sur "choose"
Tu vas dans C:, windows, system32 tu cherches le processus ci-dessous et tu clic sur "ouvrir" dès que c'est fait, clic sur "send"
Tu attends un peu et colle les rapports ici une fois qu'il a terminé stp

http://www.virustotal.com/en/virustotalx.html


C:\WINDOWS\system32\3FE83BA494.sys
C:\WINDOWS\system32\drivers\dump_wmimmc.sys
1
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
17 mars 2007 à 22:14
Ad-Aware et non je partage pas de réseau.
J'ai zone-alarm et il bloque tout ce qui entre et qui ne devrait pas et me demande toujours si je veux débloquer ou non un programme.
0
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
18 mars 2007 à 03:17
Euh j'ai du mal m'exprimer sur le firewall. Je voulais juste dire qu'il est configuré pour me demander chaque fois qu'un programme veut acceder a internet. Il ne me demande pas rien quand services.exe crash.

Voila le scan de a-squared

Réglages Scan:

Objets: Mémoire, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: Marche
Heuristiques: Marche
Scan ADS: Marche

Début du scan: 2007-03-17 21:05:32

C:\Documents and Settings\Administrateur\Cookies\administrateur@atdmt[2].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[2].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Cookies\administrateur@mediaplex[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:14 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:17 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:19 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:20 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:21 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:36 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:37 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:39 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:40 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:41 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:42 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:72 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:74 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:75 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:76 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:77 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:78 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:79 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:80 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:81 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:83 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:88 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:107 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:121 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:122 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:140 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:141 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:143 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:153 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:167 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:228 Détecter: Trace.TrackingCookie
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt:245 Détecter: Trace.TrackingCookie

Scanné

Fichiers: 102642
Traces: 101873
Cookies: 329
Processus: 43

Trouver

Fichiers: 0
Traces: 0
Cookies: 35
Processus: 0
Clés de Registre: 0

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 22:16:43 2007-03-17

+ Résultat de l'analyse:



:mozilla.6:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.7:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.8:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.10:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.111:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.9:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Administrateur\Cookies\administrateur@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.12:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.13:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.150:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.159:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.160:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.17:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.18:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.45:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Clickzs : Aucune action entreprise.
:mozilla.46:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Clickzs : Aucune action entreprise.
:mozilla.40:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Com : Aucune action entreprise.
:mozilla.14:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
:mozilla.15:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
:mozilla.16:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
:mozilla.221:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Googleadservices : Aucune action entreprise.
:mozilla.116:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Overture : Aucune action entreprise.
:mozilla.117:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Overture : Aucune action entreprise.
:mozilla.118:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Overture : Aucune action entreprise.
:mozilla.234:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Paypal : Aucune action entreprise.
:mozilla.120:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.121:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.132:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Realmedia : Aucune action entreprise.
:mozilla.133:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Revsci : Aucune action entreprise.
:mozilla.134:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Revsci : Aucune action entreprise.
:mozilla.135:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Revsci : Aucune action entreprise.
:mozilla.136:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Revsci : Aucune action entreprise.
:mozilla.236:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.237:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.238:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.144:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.
:mozilla.182:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Webtrends : Aucune action entreprise.
:mozilla.154:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.155:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.156:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.157:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.158:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\nikhzhp1.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.


Fin du rapport
0
Utilisateur anonyme
17 mars 2007 à 06:52
Salut

qu'as-tu comme anti-spywares ? Tu partages ton réseau avec un autre ordi ?

Vérifie que ton pare-feu ne comporte rien de susepct.
-1
Utilisateur anonyme
18 mars 2007 à 05:04
Salut

Fait ce nettoyage: à faire réguliérement

¤ Télécharge et installe CCleaner (n'installe pas la barre d'outil Yahoo)
---> http://www.infos-du-net.com/telecharger/CCleaner,0301-1039.html

- Dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, clic sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites, tu pourra les supprimer si ton ordinateur n'a plus de problémes.

- Relance Ccleaner, vas dans l'onglet "nettoyeur" présent sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

Si tu as besoin d'aide avec Ccleaner, regarde ce tutoriel :
https://kerio.probb.fr/t242-tuto-ccleaner-v-2


¤ Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clique dessus et choisit "accepter l'active X" pour faire fonctionner le scan anti-virus.
Une fois qu'il a terminé colle le rapport ici stp

---> https://www.kaspersky.fr/downloads

- Kaspersky Online Scanner
- Accept
-1
Utilisateur anonyme
19 mars 2007 à 03:25
Ton PC il redémarre ou tu as juste l'erreur qui s'affiche ?

¤ Télécharge ComboScan sur ton bureau.
http://www.techsupportforum.com/sectools/Deckard/comboscan.exe

Ferme toutes les applications en cours : antivirus, pare-feu, etc .. C'est important !
Double-clic sur comboscan.exe.
A la fenêtre de prévention, clique sur OK.
L'analyse peut prendre quelques minutes.
A la fenêtre indiquant la fin de l'analyse, clique sur OK.
Le rapport Comboscan.txt s'affichera, copie et colle le contenu de ce rapport ici.
-1
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
24 mars 2007 à 18:16
Bah le premier fichier n'existait plus quand je suis allé pour scanner et voici les résultats sur le deuxième

Complete scanning result of "dump_wmimmc.sys", received in VirusTotal at 03.24.2007, 18:04:33 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.3.24.1 03.24.2007 no virus found
AntiVir 7.3.1.44 03.23.2007 no virus found
Authentium 4.93.8 03.24.2007 no virus found
Avast 4.7.936.0 03.23.2007 no virus found
AVG 7.5.0.447 03.23.2007 no virus found
BitDefender 7.2 03.24.2007 no virus found
CAT-QuickHeal 9.00 03.23.2007 no virus found
ClamAV devel-20070312 03.24.2007 no virus found
DrWeb 4.33 03.24.2007 no virus found
eSafe 7.0.14.0 03.22.2007 no virus found
eTrust-Vet 30.6.3506 03.23.2007 no virus found
Ewido 4.0 03.24.2007 no virus found
FileAdvisor 1 03.24.2007 Not analyzed yet
Fortinet 2.85.0.0 03.24.2007 suspicious
F-Prot 4.3.1.45 03.23.2007 no virus found
F-Secure 6.70.13030.0 03.24.2007 no virus found
Ikarus T3.1.1.3 03.24.2007 no virus found
Kaspersky 4.0.2.24 03.24.2007 no virus found
McAfee 4991 03.23.2007 no virus found
Microsoft 1.2306 03.24.2007 no virus found
NOD32v2 2142 03.24.2007 no virus found
Norman 5.80.02 03.23.2007 no virus found
Panda 9.0.0.4 03.24.2007 no virus found
Prevx1 V2 03.24.2007 no virus found
Sophos 4.15.0 03.23.2007 no virus found
Sunbelt 2.2.907.0 03.24.2007 VIPRE.Suspicious
Symantec 10 03.24.2007 no virus found
TheHacker 6.1.6.080 03.23.2007 no virus found
UNA 1.83 03.16.2007 no virus found
VBA32 3.11.2 03.24.2007 no virus found
VirusBuster 4.3.7:9 03.24.2007 no virus found
Webwasher-Gateway 6.0.1 03.24.2007 Win32.Malware.gen!88 (suspicious)

Aditional Information
File size: 153925 bytes
MD5: 70adedf99ef3a1d4d2e0f9f9c11a49c3
SHA1: 010eab8f22fe882e15b189dd60bdfdbd61d8a9c4
Bit9 info: http://fileadvisor.bit9.com/services/extinfo.aspx?md5=70adedf99ef3a1d4d2e0f9f9c11a49c3
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.
-1
Utilisateur anonyme
24 mars 2007 à 18:21
Ok, tu peux supprimer celui que tu as fait analysé.

Puis fais ceci :

Télécharge SmitfraudFix et enregistre le sur le bureau. Si ton anti-virus t'alerte d'un virus, désactive-le.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip

décompresse SmitfraudFix
Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisit l option 1 copie le rapport ici stp
-1
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
24 mars 2007 à 21:54
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\Favoris


»»»»»»»»»»»»»»»»»»»»»»»» Bureau


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32

pe386 détecté, utilisez un scanner de Rootkit

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin
-1
Utilisateur anonyme
25 mars 2007 à 04:05
Télécharge ce fichier
---> http://www.uploads.ejvindh.net/rustbfix.exe

Double clic rustbfix.exe
Si une infection est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer l'ordi.
Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis.
Suite au(x) redémarrage(s), deux rapports s'ouvriront : avenger.txt et pelog.txt
Copie et colle le contenu de ces deux rapports.
-1
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
25 mars 2007 à 09:18
Avenger

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\yrjjviqd

*******************

Script file located at: \??\C:\WINDOWS\system32\iybfrolr.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver PE386 unloaded successfully.
Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.


Pelog

************************* Rustock.b-fix -- By ejvindh *************************
2007-03-25 3:13:32,95

******************* Pre-run Status of system *******************

Rootkit driver PE386 is found. Starting the unload-procedure....

Rustock.b-ADS attached to the System32-folder:
:lzx32.sys 80118
Total size: 80118 bytes.
Attempting to remove ADS...
system32: deleted 80118 bytes in 1 streams.

Looking for Rustock.b-files in the System32-folder:
No Rustock.b-files found in system32


******************* Post-run Status of system *******************

Rustock.b-driver on the system: NONE!

Rustock.b-ADS attached to the System32-folder:
No System32-ADS found.

Looking for Rustock.b-files in the System32-folder:
No Rustock.b-files found in system32


******************************* End of Logfile ********************************
-1
Utilisateur anonyme
25 mars 2007 à 11:19
Ok, très bien :-)

Télécharge ceci :
http://greatis.com/reanimator.zip

Dézippe le contenu.
Double clic sur reanimator.exe
Clic sur Scan for virus. Dès qu'il a terminé clic sur "Fix problems".
Clic en haut à gauche sur "file" puis "save log to file"
Enregistre le rapport ou tu le trouveras facilement, ferme le logiciel puis copie et colle ici le contenu de ce même rapport, il se peut qu'il soit long vérifie que le contenu soit en entier ;-)
-1
Althar89 Messages postés 14 Date d'inscription jeudi 15 février 2007 Statut Membre Dernière intervention 2 avril 2007
25 mars 2007 à 19:03
SpyHolesList Version:1.7
25.03.2007 12:58:46
WinDir=C:\WINDOWS
Startup=C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\
Common Startup=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
Microsoft Windows XP Service Pack 2 (5.1.2600)
Internet Explorer 6.0.2900.2180
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://www.hp.com
[Current Home Page] :HKCU Start Page=http://www.google.ca/
[Current Home Page] :HKCU HOMEOldSP=""
[Search URL Template] :HKLM 1=www.%s.com
[Search URL Template] :HKLM 2=www.%s.org
[Search URL Template] :HKLM 3=www.%s.net
[Search URL Template] :HKLM 4=www.%s.edu
[All Users Search] :HKLM Default_Search_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[All Users Search] :HKLM Search Page=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[Current Users Search] :HKCU Search Page=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=C:\WINDOWS\system32\blank.htm
[IE Local Blank Page] :HKLM Local Page=%SystemRoot%\system32\blank.htm
[Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[Browser Helper Objects] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
[Browser Helper Objects] {7E853D72-626A-48EC-A868-BA8D5E23E045}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default Value"=""
[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=%SystemRoot%\system32\shdocvw.dll
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[URL Default Prefixes] :HKLM gopher=gopher://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[Safe Sites] :HKLM ie.search.msn.com=http://ie.search.msn.com/*
[AboutURLs] :HKLM NavigationFailure=res://shdoclc.dll/navcancl.htm
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://shdoclc.dll/navcancl.htm
[AboutURLs] :HKLM NavigationCanceled=res://shdoclc.dll/navcancl.htm
[AboutURLs] :HKLM OfflineInformation=res://shdoclc.dll/offcancl.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM PostNotCached=res://mshtml.dll/repost.htm
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKUS User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[User Style Sheet] :HKUS Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=1
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=0
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=Liens
[Explorer Bars] :HKLM {4D5C8C25-D075-11d0-B416-00C04FB90376}=%SystemRoot%\system32\shdocvw.dll
[IE Extensions - All Users] :HKLM {08B0E5C0-4FCB-11CF-AAA5-00401C608501}=%SystemRoot%\system32\shdocvw.dll
[IE Extensions - All Users] :HKLM {85d1f590-48f4-11d9-9669-0800200c9a66}=%windir%\bdoscandel.exe
[IE Extensions - All Users] :HKLM {FB5F1910-F110-11d2-BB9E-00C04F795683}=C:\Program Files\Messenger\msmsgs.exe
[Context menu items] :HKCU Envoyer à &Bluetooth=C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
[Proxy] :HKCU ProxyServer=""
[Proxy] :HKCU ProxyEnable=0
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Hosts File Contents] :HKLM 127.0.0.1 localhost
[Hosts File Contents] :HKLM 127.0.0.1 vip.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip1.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip2.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip3.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip4.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip5.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip6.towalker.com
[Hosts File Contents] :HKLM 127.0.0.1 vip7.towalker.com
[Domain Name] :HKLM Domain=""
[Name Server] {9AD565F3-ED5D-40CE-A714-5F9C244414AA}=24.200.241.37 24.201.245.77 24.200.243.189
[WinSock2 Components] :HKLM mswsock.dll=%SystemRoot%\System32\mswsock.dll
[WinSock2 Components] :HKLM winrnr.dll=%SystemRoot%\System32\winrnr.dll
[WinSock2 Components] :HKLM rsvpsp.dll=%SystemRoot%\system32\rsvpsp.dll
[Software Components]
[Internet Components] :HKLM C:\WINDOWS\bdoscandel.exe=C:\WINDOWS\bdoscandel.exe
[Internet Components] :HKLM C:\WINDOWS\bdoscandellang.ini=C:\WINDOWS\bdoscandellang.ini
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\bdcore.dll=C:\WINDOWS\Downloaded Program Files\bdcore.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\bdupd.dll=C:\WINDOWS\Downloaded Program Files\bdupd.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MessengerStatsPAClient.dll=C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MessengerStatsPAClient.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\ipsupd.dll=C:\WINDOWS\Downloaded Program Files\ipsupd.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\lang.ini=C:\WINDOWS\Downloaded Program Files\lang.ini
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\libfn.dll=C:\WINDOWS\Downloaded Program Files\libfn.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\live.ini=C:\WINDOWS\Downloaded Program Files\live.ini
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll=C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll=C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\msgrchkr.dll=C:\WINDOWS\Downloaded Program Files\msgrchkr.dll
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\oscan8.ocx=C:\WINDOWS\Downloaded Program Files\oscan8.ocx
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\oscan81.ocx_x=C:\WINDOWS\Downloaded Program Files\oscan81.ocx_x
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\scanoptions.tsi=C:\WINDOWS\Downloaded Program Files\scanoptions.tsi
[Internet Components] :HKLM C:\WINDOWS\Downloaded Program Files\ZIntro.ocx=C:\WINDOWS\Downloaded Program Files\ZIntro.ocx
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
[System.ini] shell=Explorer.exe
[Main File Extensions] :HKLM .exe="%1" %*
[Main File Extensions] :HKLM .com="%1" %*
[Main File Extensions] :HKLM .pif="%1" %*
[Main File Extensions] :HKLM .cmd="%1" %*
[Main File Extensions] :HKLM .scr="%1" /S
[Main File Extensions] :HKLM .jpg=rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_Fullscreen %1
[Main File Extensions] :HKLM .jpeg=rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_Fullscreen %1
[Shell Execute Hooks] :HKLM {AEB6717E-7E19-11d0-97EE-00C04FD91972}=shell32.dll
[UserInit Value] :HKLM UserInit=C:\WINDOWS\system32\userinit.exe,
[Winlogon Notification] :HKLM AtiExtEvent=Ati2evxx.dll
[Winlogon Notification] :HKLM crypt32chain=crypt32.dll
[Winlogon Notification] :HKLM cryptnet=cryptnet.dll
[Winlogon Notification] :HKLM cscdll=cscdll.dll
[Winlogon Notification] :HKLM ScCertProp=wlnotify.dll
[Winlogon Notification] :HKLM Schedule=wlnotify.dll
[Winlogon Notification] :HKLM sclgntfy=sclgntfy.dll
[Winlogon Notification] :HKLM SensLogn=WlNotify.dll
[Winlogon Notification] :HKLM termsrv=wlnotify.dll
[Winlogon Notification] :HKLM WgaLogon=WgaLogon.dll
[Winlogon Notification] :HKLM wlballoon=wlnotify.dll
[Shell Services DelayLoad] :HKLM PostBootReminder=%SystemRoot%\system32\SHELL32.dll
[Shell Services DelayLoad] :HKLM CDBurn=%SystemRoot%\system32\SHELL32.dll
[Shell Services DelayLoad] :HKLM WebCheck=%SystemRoot%\system32\webcheck.dll
[Shell Services DelayLoad] :HKLM SysTray=C:\WINDOWS\system32\stobject.dll
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[SharedTaskScheduler] :HKLM {438755C2-A8BA-11D1-B96B-00A0C90312E1}=%SystemRoot%\system32\browseui.dll
[SharedTaskScheduler] :HKLM {8C7461EF-2B13-11d2-BE35-3078302C2030}=%SystemRoot%\system32\browseui.dll
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\inf\unregmp2.exe /ShowWMP
[Bootexecute] :HKLM BootExecute=autocheck autochk *

[KnownDLLs] :HKLM advapi32=advapi32.dll
[KnownDLLs] :HKLM comdlg32=comdlg32.dll
[KnownDLLs] :HKLM DllDirectory=%SystemRoot%\system32
[KnownDLLs] :HKLM gdi32=gdi32.dll
[KnownDLLs] :HKLM imagehlp=imagehlp.dll
[KnownDLLs] :HKLM kernel32=kernel32.dll
[KnownDLLs] :HKLM lz32=lz32.dll
[KnownDLLs] :HKLM ole32=ole32.dll
[KnownDLLs] :HKLM oleaut32=oleaut32.dll
[KnownDLLs] :HKLM olecli32=olecli32.dll
[KnownDLLs] :HKLM olecnv32=olecnv32.dll
[KnownDLLs] :HKLM olesvr32=olesvr32.dll
[KnownDLLs] :HKLM olethk32=olethk32.dll
[KnownDLLs] :HKLM rpcrt4=rpcrt4.dll
[KnownDLLs] :HKLM shell32=shell32.dll
[KnownDLLs] :HKLM url=url.dll
[KnownDLLs] :HKLM urlmon=urlmon.dll
[KnownDLLs] :HKLM user32=user32.dll
[KnownDLLs] :HKLM version=version.dll
[KnownDLLs] :HKLM wininet=wininet.dll
[KnownDLLs] :HKLM wldap32=wldap32.dll
[Environment - Path] :HKLM Path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[Auto Services] Ati HotKey Poller
[Auto Services] AudioSrv
[Auto Services] Avg7Alrt
[Auto Services] Avg7UpdSvc
[Auto Services] AVGEMS
[Auto Services] Browser
[Auto Services] btwdins
[Auto Services] CryptSvc
[Auto Services] DcomLaunch
[Auto Services] Dhcp
[Auto Services] dmserver
[Auto Services] Dnscache
[Auto Services] ERSvc
[Auto Services] Eventlog
[Auto Services] helpsvc
[Auto Services] hpqwmiex
[Auto Services] lanmanserver
[Auto Services] lanmanworkstation
[Auto Services] LmHosts
[Auto Services] MSMQ
[Auto Services] MSMQTriggers
[Auto Services] PCA
[Auto Services] PlugPlay
[Auto Services] PolicyAgent
[Auto Services] ProtectedStorage
[Auto Services] RemoteRegistry
[Auto Services] RpcSs
[Auto Services] SamSs
[Auto Services] SCardSvr
[Auto Services] Schedule
[Auto Services] seclogon
[Auto Services] SENS
[Auto Services] SharedAccess
[Auto Services] ShellHWDetection
[Auto Services] Spooler
[Auto Services] srservice
[Auto Services] Themes
[Auto Services] TrkWks
[Auto Services] UMWdf
[Auto Services] vsmon
[Auto Services] W32Time
[Auto Services] WebClient
[Auto Services] winmgmt
[Auto Services] wscsvc
[Auto Services] wuauserv
[Auto Services] WZCSVC
[Drivers] ntkrnlpa.exe=C:\WINDOWS\SYSTEM32\NTKRNLPA.EXE
[Drivers] hal.dll=C:\WINDOWS\SYSTEM32\HAL.DLL
[Drivers] KDCOM.DLL=C:\WINDOWS\SYSTEM32\KDCOM.DLL
[Drivers] BOOTVID.dll=C:\WINDOWS\SYSTEM32\BOOTVID.DLL
[Drivers] sptd.sys=C:\WINDOWS\system32\DRIVERS\sptd.sys
[Drivers] WMILIB.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS
[Drivers] SPTD7469.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\SPTD7469.SYS
[Drivers] ACPI.sys=C:\WINDOWS\system32\DRIVERS\ACPI.sys
[Drivers] pci.sys=C:\WINDOWS\system32\DRIVERS\pci.sys
[Drivers] isapnp.sys=C:\WINDOWS\system32\DRIVERS\isapnp.sys
[Drivers] ohci1394.sys=C:\WINDOWS\system32\DRIVERS\ohci1394.sys
[Drivers] 1394BUS.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\1394BUS.SYS
[Drivers] compbatt.sys=C:\WINDOWS\system32\DRIVERS\compbatt.sys
[Drivers] BATTC.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\BATTC.SYS
[Drivers] pciide.sys=C:\WINDOWS\system32\DRIVERS\pciide.sys
[Drivers] PCIIDEX.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDEX.SYS
[Drivers] intelide.sys=C:\WINDOWS\system32\DRIVERS\intelide.sys
[Drivers] viaide.sys=C:\WINDOWS\system32\DRIVERS\viaide.sys
[Drivers] aliide.sys=C:\WINDOWS\system32\DRIVERS\aliide.sys
[Drivers] pcmcia.sys=C:\WINDOWS\system32\DRIVERS\pcmcia.sys
[Drivers] MountMgr.sys=C:\WINDOWS\system32\DRIVERS\MountMgr.sys
[Drivers] ftdisk.sys=C:\WINDOWS\system32\DRIVERS\ftdisk.sys
[Drivers] dmload.sys=C:\WINDOWS\system32\DRIVERS\dmload.sys
[Drivers] dmio.sys=C:\WINDOWS\system32\DRIVERS\dmio.sys
[Drivers] ACPIEC.sys=C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
[Drivers] OPRGHDLR.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\OPRGHDLR.SYS
[Drivers] PartMgr.sys=C:\WINDOWS\system32\DRIVERS\PartMgr.sys
[Drivers] VolSnap.sys=C:\WINDOWS\system32\DRIVERS\VolSnap.sys
[Drivers] atapi.sys=C:\WINDOWS\system32\DRIVERS\atapi.sys
[Drivers] iaStor.sys=C:\WINDOWS\system32\DRIVERS\iaStor.sys
[Drivers] disk.sys=C:\WINDOWS\system32\DRIVERS\disk.sys
[Drivers] CLASSPNP.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\CLASSPNP.SYS
[Drivers] fltMgr.sys=C:\WINDOWS\system32\DRIVERS\fltMgr.sys
[Drivers] sr.sys=C:\WINDOWS\system32\DRIVERS\sr.sys
[Drivers] KSecDD.sys=C:\WINDOWS\system32\DRIVERS\KSecDD.sys
[Drivers] Ntfs.sys=C:\WINDOWS\system32\DRIVERS\Ntfs.sys
[Drivers] NDIS.sys=C:\WINDOWS\system32\DRIVERS\NDIS.sys
[Drivers] srescan.sys=C:\WINDOWS\system32\DRIVERS\srescan.sys
[Drivers] Mup.sys=C:\WINDOWS\system32\DRIVERS\Mup.sys
[Drivers] hpdskflt.sys=C:\WINDOWS\system32\DRIVERS\hpdskflt.sys
[Drivers] intelppm.sys=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[Drivers] ati2mtag.sys=C:\WINDOWS\SYSTEM32\DRIVERS\ATI2MTAG.SYS
[Drivers] VIDEOPRT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\VIDEOPRT.SYS
[Drivers] HDAudBus.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[Drivers] b57xp32.sys=C:\WINDOWS\SYSTEM32\DRIVERS\B57XP32.SYS
[Drivers] w39n51.sys=C:\WINDOWS\SYSTEM32\DRIVERS\W39N51.SYS
[Drivers] usbuhci.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[Drivers] USBPORT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBPORT.SYS
[Drivers] usbehci.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[Drivers] tifm21.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TIFM21.SYS
[Drivers] sdbus.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
[Drivers] gtipci21.sys=C:\WINDOWS\SYSTEM32\DRIVERS\GTIPCI21.SYS
[Drivers] SMCLIB.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\SMCLIB.SYS
[Drivers] serial.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[Drivers] serenum.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[Drivers] parport.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[Drivers] IFXTPM.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\IFXTPM.SYS
[Drivers] i8042prt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[Drivers] kbdclass.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[Drivers] SynTP.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTP.SYS
[Drivers] USBD.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBD.SYS
[Drivers] mouclass.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[Drivers] imapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS
[Drivers] cdrom.sys=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[Drivers] redbook.sys=C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS
[Drivers] ks.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KS.SYS
[Drivers] Accelerometer.sys=C:\WINDOWS\SYSTEM32\DRIVERS\ACCELEROMETER.SYS
[Drivers] cpqbttn.sys=C:\WINDOWS\SYSTEM32\DRIVERS\CPQBTTN.SYS
[Drivers] HIDCLASS.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\HIDCLASS.SYS
[Drivers] HIDPARSE.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\HIDPARSE.SYS
[Drivers] CmBatt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[Drivers] wmiacpi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[Drivers] btkrnl.sys=C:\WINDOWS\SYSTEM32\DRIVERS\BTKRNL.SYS
[Drivers] audstub.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS
[Drivers] rasl2tp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[Drivers] ndistapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[Drivers] ndiswan.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[Drivers] raspppoe.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[Drivers] raspptp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[Drivers] TDI.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\TDI.SYS
[Drivers] psched.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS
[Drivers] msgpc.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS
[Drivers] ptilink.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS
[Drivers] raspti.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS
[Drivers] rdpdr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[Drivers] termdd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
[Drivers] swenum.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[Drivers] update.sys=C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS
[Drivers] mssmbios.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[Drivers] kbdhid.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[Drivers] NDProxy.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
[Drivers] ADIHdAud.sys=C:\WINDOWS\SYSTEM32\DRIVERS\ADIHDAUD.SYS
[Drivers] portcls.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PORTCLS.SYS
[Drivers] drmk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DRMK.SYS
[Drivers] AEAudio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AEAUDIO.SYS
[Drivers] AGRSM.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AGRSM.SYS
[Drivers] Modem.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[Drivers] usbhub.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[Drivers] Fs_Rec.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FS_REC.SYS
[Drivers] Null.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS
[Drivers] Beep.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS
[Drivers] avgclean.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVGCLEAN.SYS
[Drivers] vga.sys=C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
[Drivers] mnmdd.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS
[Drivers] RDPCDD.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
[Drivers] Msfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS
[Drivers] Npfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS
[Drivers] rasacd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[Drivers] ipsec.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS
[Drivers] tcpip.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[Drivers] netbt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[Drivers] ipnat.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[Drivers] afd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[Drivers] wanarp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[Drivers] netbios.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[Drivers] eabfiltr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\EABFILTR.SYS
[Drivers] rdbss.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[Drivers] mrxsmb.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[Drivers] Fips.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS
[Drivers] ATSwpDrv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\ATSWPDRV.SYS
[Drivers] hidusb.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[Drivers] avg7core.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVG7CORE.SYS
[Drivers] mouhid.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[Drivers] avg7rsw.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVG7RSW.SYS
[Drivers] avg7rsxp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVG7RSXP.SYS
[Drivers] Fastfat.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FASTFAT.SYS
[Drivers] Cdfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[Drivers] iaStor.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DUMP_IASTOR.SYS
[Drivers] win32k.sys=C:\WINDOWS\SYSTEM32\WIN32K.SYS
[Drivers] Dxapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXAPI.SYS
[Drivers] watchdog.sys=C:\WINDOWS\SYSTEM32\WATCHDOG.SYS
[Drivers] dxg.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXG.SYS
[Drivers] dxgthk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXGTHK.SYS
[Drivers] ati2dvag.dll=C:\WINDOWS\SYSTEM32\ATI2DVAG.DLL
[Drivers] ati2cqag.dll=C:\WINDOWS\SYSTEM32\ATI2CQAG.DLL
[Drivers] atikvmag.dll=C:\WINDOWS\SYSTEM32\ATIKVMAG.DLL
[Drivers] ati3duag.dll=C:\WINDOWS\SYSTEM32\ATI3DUAG.DLL
[Drivers] ativvaxx.dll=C:\WINDOWS\SYSTEM32\ATIVVAXX.DLL
[Drivers] ndisuio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[Drivers] vsdatant.sys=C:\WINDOWS\SYSTEM32\VSDATANT.SYS
[Drivers] mrxdav.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[Drivers] avgtdi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVGTDI.SYS
[Drivers] mqac.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MQAC.SYS
[Drivers] srv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[Drivers] RMCast.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RMCAST.SYS
[Drivers] secdrv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS
[Drivers] wdmaud.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS
[Drivers] sysaudio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS
[Drivers] HTTP.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[Drivers] kmixer.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS
[Drivers] npptNT2.sys=C:\WINDOWS\SYSTEM32\NPPTNT2.SYS
[Drivers] npkcrypt.sys=D:\LINEAGE II\SYSTEM\NPKCRYPT.SYS
[Drivers] regguard.sys=C:\WINDOWS\SYSTEM32\DRIVERS\REGGUARD.SYS
[Drivers] ntdll.dll=C:\WINDOWS\SYSTEM32\NTDLL.DLL
[Drivers] ntkrnlpa.exe=C:\WINDOWS\SYSTEM32\NTKRNLPA.EXE
[Auto Start Apps]
[Registry Run] :HKCU CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
[Registry Run] :HKLM MsmqIntCert=regsvr32 /s mqrt.dll
[Registry Run] :HKLM AGRSMMSG=AGRSMMSG.exe
[Registry Run] :HKLM SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
[Registry Run] :HKLM SoundMAX=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
[Registry Run] :HKLM AccelerometerSysTrayApplet=C:\WINDOWS\system32\AccelerometerSt.exe
[Registry Run] :HKLM ATICCC="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
[Registry Run] :HKLM SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[Registry Run] :HKLM QlbCtrl=%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
[Registry Run] :HKLM Cpqset=C:\Program Files\HPQ\Default Settings\cpqset.exe
[Registry Run] :HKLM Recguard=C:\WINDOWS\Sminst\Recguard.exe
[Registry Run] :HKLM PTHOSTTR=C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
[Registry Run] :HKLM SunJavaUpdateSched="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
[Registry Run] :HKLM AVG7_CC=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
[Registry Run] :HKLM Zone Labs Client="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
[Win.ini] load=""
[Win.ini] run=""
[Startup Folder] OpenOffice.org 2.0.lnk=C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
[Common Startup Folder] BTTray.lnk=C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
[Common Startup Folder] Lancement rapide d'Adobe Reader.lnk=C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[In memory]
[Running Processes] C:\WINDOWS\SYSTEM32\SMSS.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\WINLOGON.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\SERVICES.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\LSASS.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\ZONELABS\VSMON.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[Running Processes] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
[Running Processes] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGUPSVC.EXE
[Running Processes] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
[Running Processes] C:\PROGRAM FILES\WIDCOMM\LOGICIEL BLUETOOTH\BIN\BTWDINS.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\MQSVC.EXE
[Running Processes] C:\PROGRAM FILES\HEWLETT-PACKARD\SHARED\HPQWMIEX.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
[Running Processes] C:\WINDOWS\EXPLORER.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\MQTGSVC.EXE
[Running Processes] C:\WINDOWS\AGRSMMSG.EXE
[Running Processes] C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\ACCELEROMETERST.EXE
[Running Processes] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE
[Running Processes] C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
[Running Processes] C:\PROGRAM FILES\HEWLETT-PACKARD\HP QUICK LAUNCH BUTTONS\QLBCTRL.EXE
[Running Processes] C:\PROGRAM FILES\HPQ\HP PROTECTTOOLS SECURITY MANAGER\PTHOSTTR.EXE
[Running Processes] C:\PROGRAM FILES\JAVA\JRE1.5.0_11\BIN\JUSCHED.EXE
[Running Processes] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE
[Running Processes] C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
[Running Processes] C:\WINDOWS\SYSTEM32\CTFMON.EXE
[Running Processes] C:\PROGRAM FILES\WIDCOMM\LOGICIEL BLUETOOTH\BTTRAY.EXE
[Running Processes] C:\PROGRAM FILES\OPENOFFICE.ORG 2.0\PROGRAM\SOFFICE.EXE
[Running Processes] C:\PROGRAM FILES\OPENOFFICE.ORG 2.0\PROGRAM\SOFFICE.BIN
[Running Processes] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE
[Running Processes] C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
[Running Processes] C:\PROGRAM FILES\MSN MESSENGER\USNSVC.EXE
[Running Processes] C:\DOCUMENTS AND SETTINGS\ADMINISTRATEUR\BUREAU\L2WALKER CRACK.EXE
[Running Processes] C:\DOCUMENTS AND SETTINGS\ADMINISTRATEUR\MES DOCUMENTS\L2WALKER\L2WALKER.EXE
[Running Processes] C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
[Running Processes] C:\DOCUMENTS AND SETTINGS\ADMINISTRATEUR\MES DOCUMENTS\DFHDH\REANIMATOR.EXE
[Loaded DLLs] C:\WINDOWS\system32\mstask.dll
[Loaded DLLs] C:\WINDOWS\system32\RICHED32.DLL
[Loaded DLLs] C:\WINDOWS\system32\OLEPRO32.DLL
[Loaded DLLs] C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\components\spellchk.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\nssckbi.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\freebl3.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
[Loaded DLLs] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\components\jar50.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\components\myspell.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\xpcom_compat.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\ssl3.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\softokn3.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\nss3.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\smime3.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\plds4.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\plc4.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\xpcom_core.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\nspr4.dll
[Loaded DLLs] C:\Program Files\Mozilla Firefox\js3250.dll
[Loaded DLLs] C:\Documents and Settings\Administrateur\Mes documents\L2Walker\lineageii.dll
[Loaded DLLs] C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL
[Loaded DLLs] C:\WINDOWS\system32\msi.dll
[Loaded DLLs] C:\WINDOWS\system32\jscript.dll
[Loaded DLLs] C:\WINDOWS\system32\shdoclc.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\usnsvcps.dll
[Loaded DLLs] C:\WINDOWS\system32\wmadmod.dll
[Loaded DLLs] C:\WINDOWS\system32\WMASF.DLL
[Loaded DLLs] C:\WINDOWS\system32\wmvcore.dll
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCP80.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\dfsr.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\custsat.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\abssm.dll
[Loaded DLLs] C:\WINDOWS\system32\msimtf.dll
[Loaded DLLs] C:\WINDOWS\system32\RichEd20.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\contact.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\lmcdata.dll
[Loaded DLLs] C:\WINDOWS\system32\sirenacm.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\MSGSWCAM.dll
[Loaded DLLs] C:\WINDOWS\system32\dpnhupnp.dll
[Loaded DLLs] C:\WINDOWS\system32\D3DIM700.DLL
[Loaded DLLs] C:\WINDOWS\system32\DCIMAN32.dll
[Loaded DLLs] C:\WINDOWS\system32\DDRAW.dll
[Loaded DLLs] C:\WINDOWS\system32\quartz.dll
[Loaded DLLs] C:\WINDOWS\system32\devenum.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\RTMPLTFM.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\lcres.dll
[Loaded DLLs] C:\WINDOWS\system32\msdmo.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\lcapi.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\msgsres.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll
[Loaded DLLs] C:\WINDOWS\system32\inetres.dll
[Loaded DLLs] C:\WINDOWS\system32\MSOERT2.dll
[Loaded DLLs] C:\WINDOWS\system32\inetcomm.dll
[Loaded DLLs] C:\WINDOWS\system32\CRYPTNET.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\ContactsUX.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\msidcrl40.dll
[Loaded DLLs] C:\Program Files\MSN Messenger\MSNCore.dll
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\atixclib.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displaysmanager.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.caste.graphics.wizard.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.caste.graphics.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\aem.foundation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\branding.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\aticccom.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.component.runtime.dll
[Loaded DLLs] c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_fr_b77a5c561934e089\mscorlib.resources.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.component.wizard.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.foundation.clients.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.component.wizard.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\log.foundation.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\log.foundation.service.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.foundation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\log.foundation.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\emser680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\oleautobridge.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\spl680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\msci_uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\fwk680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\jvmaccess3MSC.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\j680mi_g.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\xcr680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\sb680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\fwe680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\sfx680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\ucpfile1.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\fwi680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\fwl680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\ucb1.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\uriproc.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\behelper.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\localebe1.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\sax.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\sysmgr1.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\typeconverter.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\configmgr2.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\regtypeprov.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\store3.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\reg3.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\security.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\implreg.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\typemgr.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\nestedreg.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\simplereg.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\shlibloader.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\servicemgr.uno.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\libxml2.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\jvmfwk3.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\tk680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\svt680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\svl680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\icudt26l.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\icuuc26.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\ucbhelper3MSC.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\cppuhelper3MSC.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\comphelp4MSC.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\salhelper3MSC.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\utl680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\basegfx680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\vos3MSC.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\sal3.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\cppu3.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\tl680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\sot680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\vcl680mi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\MSVCR71.dll
[Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll
[Loaded DLLs] C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll
[Loaded DLLs] C:\WINDOWS\system32\CSH.dll
[Loaded DLLs] C:\WINDOWS\system32\btrez.dll
[Loaded DLLs] C:\Program Files\WIDCOMM\Logiciel Bluetooth\BtBalloon.dll
[Loaded DLLs] C:\WINDOWS\system32\CFGMGR32.dll
[Loaded DLLs] C:\WINDOWS\system32\btwhidcs.DLL
[Loaded DLLs] C:\WINDOWS\system32\btosif.dll
[Loaded DLLs] C:\WINDOWS\system32\wbtapi.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\security_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\security.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\programs_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\privacy_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\idlock_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\firewall_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\filter_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\email_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\email.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\cam_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\cam.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\alert_Loc040c.zap
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
[Loaded DLLs] C:\WINDOWS\system32\vsmonapi.dll
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\zlclient_Loc040c.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\fbl.dll
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\framewrk_Loc040c.dll
[Loaded DLLs] C:\WINDOWS\system32\VSUTIL_Loc040c.dll
[Loaded DLLs] C:\Program Files\Zone Labs\ZoneAlarm\framewrk.dll
[Loaded DLLs] C:\WINDOWS\system32\VSPUBAPI.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemsui.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgrep.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgvault.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgcckrn.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\AVGRES.DLL
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgf.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\AvgSet.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\AvgTRes.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\AvgTest.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\AvgAbout.dll
[Loaded DLLs] C:\WINDOWS\system32\MSVFW32.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\MFC71.DLL
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\AvgCtrl.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\AvgTMgr.dll
[Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll
[Loaded DLLs] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\hpqExec.dll
[Loaded DLLs] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBSERVICE.dll
[Loaded DLLs] C:\WINDOWS\system32\SynTPAPI.dll
[Loaded DLLs] C:\WINDOWS\system32\SynCOM.dll
[Loaded DLLs] C:\WINDOWS\system32\perfproc.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\apm.foundation.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demumaframebuffersettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdisplaysmanageroptionssettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demoverdrive3settings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicedfp2settings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicedfpsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicetvsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicetv2settings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecomponentvideosettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicelcdsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecommon2settings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecommonsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecrtsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.workstationsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demvpurecoverinfo.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demvideooverlaysettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demvideotheatermodesettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.mmoverlaysettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demmultivpusettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.dempowerplaysettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demoverdrivesettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demsmartgartsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.videooverlay.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.mmdeintlacingsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdisplayscoloursettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demverylargedesktopsettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.dematidisplaysmanagersettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demosmodeinfo.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
[Loaded DLLs] c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\atidemgr.dll
[Loaded DLLs] c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
[Loaded DLLs] c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_fr_b77a5c561934e089\mscorlib.resources.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demdriversettings.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.dematiadapterinfo.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demosadapterinfo.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.graphics.demosinfo.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\dem.foundation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.component.runtime.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.caste.graphics.runtime.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll
[Loaded DLLs] c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_fr_b77a5c561934e089\system.windows.forms.resources.dll
[Loaded DLLs] c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_006209c0\system.drawing.dll
[Loaded DLLs] c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\aem.foundation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\aticccom.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.component.runtime.dll
[Loaded DLLs] c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
[Loaded DLLs] c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_53978cb8\system.xml.dll
[Loaded DLLs] c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll
[Loaded DLLs] c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_3768633b\system.dll
[Loaded DLLs] c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\log.foundation.shared.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\log.foundation.service.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.foundation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\log.foundation.dll
[Loaded DLLs] c:\program files\ati technologies\ati.ace\cli.implementation.dll
[Loaded DLLs] c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_cbab7535\system.windows.forms.dll
[Loaded DLLs] c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
[Loaded DLLs] c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_c0992129\mscorlib.dll
[Loaded DLLs] c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll
[Loaded DLLs] c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
[Loaded DLLs] C:\WINDOWS\system32\mscoree.dll
[Loaded DLLs] C:\WINDOWS\system32\accelerometerDLL.dll
[Loaded DLLs] C:\WINDOWS\system32\MFC42u.dll
[Loaded DLLs] C:\WINDOWS\system32\KsUser.dll
[Loaded DLLs] C:\WINDOWS\system32\DSound.dll
[Loaded DLLs] C:\Program Files\Analog Devices\Core\SMWDMIF.dll
[Loaded DLLs] C:\Windows\System32\MQTRIG.DLL
[Loaded DLLs] C:\WINDOWS\system32\mqrt.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgse.dll
[Loaded DLLs] C:\Program Files\WinRAR\rarext.dll
[Loaded DLLs] C:\WINDOWS\system32\zipfldr.dll
[Loaded DLLs] C:\WINDOWS\system32\mydocs.dll
[Loaded DLLs] C:\WINDOWS\system32\btncopy.dll
[Loaded DLLs] C:\Program Files\WIDCOMM\Logiciel Bluetooth\btkeyind.dll
[Loaded DLLs] C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll
[Loaded DLLs] C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\MSVCP71.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\stlport_vc7145.dll
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\uwinapi.dll
[Loaded DLLs] C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll
[Loaded DLLs] C:\WINDOWS\system32\DUSER.dll
[Loaded DLLs] C:\WINDOWS\system32\MLANG.dll
[Loaded DLLs] C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[Loaded DLLs] C:\WINDOWS\system32\browselc.dll
[Loaded DLLs] C:\WINDOWS\system32\wzcdlg.dll
[Loaded DLLs] C:\WINDOWS\System32\davclnt.dll
[Loaded DLLs] C:\WINDOWS\System32\NETUI1.dll
[Loaded DLLs] C:\WINDOWS\System32\NETUI0.dll
[Loaded DLLs] C:\WINDOWS\System32\ntlanman.dll
[Loaded DLLs] C:\WINDOWS\System32\drprov.dll
[Loaded DLLs] C:\WINDOWS\system32\shdoclc.dll
[Loaded DLLs] C:\WINDOWS\system32\BatMeter.dll
[Loaded DLLs] C:\WINDOWS\system32\stobject.dll
[Loaded DLLs] C:\WINDOWS\system32\webcheck.dll
[Loaded DLLs] C:\WINDOWS\system32\msi.dll
[Loaded DLLs] C:\WINDOWS\system32\urlmon.dll
[Loaded DLLs] C:\WINDOWS\system32\ntshrui.dll
[Loaded DLLs] C:\WINDOWS\system32\LINKINFO.dll
[Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll
[Loaded DLLs] C:\WINDOWS\system32\msutb.dll
[Loaded DLLs] C:\WINDOWS\system32\actxprxy.dll
[Loaded DLLs] C:\WINDOWS\system32\MSIMG32.dll
[Loaded DLLs] C:\WINDOWS\system32\themeui.dll
[Loaded DLLs] C:\WINDOWS\system32\SHDOCVW.dll
[Loaded DLLs] C:\WINDOWS\system32\BROWSEUI.dll
[Loaded DLLs] C:\WINDOWS\system32\Ati2edxx.dll
[Loaded DLLs] C:\WINDOWS\system32\MSDTCPRX.dll
[Loaded DLLs] C:\WINDOWS\system32\xolehlp.dll
[Loaded DLLs] C:\WINDOWS\system32\MqLogMgr.dll
[Loaded DLLs] C:\WINDOWS\system32\Security.dll
[Loaded DLLs] C:\WINDOWS\system32\mqsec.dll
[Loaded DLLs] C:\WINDOWS\system32\mqutil.dll
[Loaded DLLs] C:\WINDOWS\system32\MQQM.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemcps.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgmail.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\saslplain.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\sasllogin.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\sasldigestmd5.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\saslcrammd5.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgunarc.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgscan.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\libsasl.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgupsvc.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgklib.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgupd.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgamsps.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgamint.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avglng.dll
[Loaded DLLs] C:\Program Files\Grisoft\AVG Free\avgcfg.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\avglog.dll
[Loaded DLLs] C:\WINDOWS\system32\MSVCR71.dll
[Loaded DLLs] C:\WINDOWS\system32\MSVCP71.dll
[Loaded DLLs] C:\PROGRA~1\Grisoft\AVGFRE~1\avgklib.dll
[Loaded DLLs] C:\WINDOWS\system32\inetpp.dll
[Loaded DLLs] C:\WINDOWS\system32\NETRAP.dll
[Loaded DLLs] C:\WINDOWS\system32\win32spl.dll
[Loaded DLLs] C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp042.dll
[Loaded DLLs] C:\WINDOWS\system32\wsnmp32.dll
[Loaded DLLs] C:\WINDOWS\system32\snmpapi.dll
[Loaded DLLs] C:\WINDOWS\system32\mgmtapi.dll
[Loaded DLLs] C:\WINDOWS\system32\tcpmib.dll
[Loaded DLLs] C:\WINDOWS\system32\tcpmon.dll
[Loaded DLLs] C:\WINDOWS\system32\MFC42LOC.DLL
[Loaded DLLs] C:\WINDOWS\system32\MFC42.DLL
[Loaded DLLs] C:\WINDOWS\system32\wbtapi.dll
[Loaded DLLs] C:\WINDOWS\system32\WidcommSdk.dll
[Loaded DLLs] C:\WINDOWS\system32\bthcrp.dll
[Loaded DLLs] C:\WINDOWS\system32\HPBHealr.dll
[Loaded DLLs] C:\WINDOWS\system32\usbmon.dll
[Loaded DLLs] C:\WINDOWS\system32\pjlmon.dll
[Loaded DLLs] C:\WINDOWS\system32\hpdomon.dll
[Loaded DLLs] C:\WINDOWS\system32\hpbmmon.dll
[Loaded DLLs] C:\WINDOWS\system32\cnbjmon.dll
[Loaded DLLs] C:\WINDOWS\system32\localspl.dll
[Loaded DLLs] C:\WINDOWS\system32\SPOOLSS.DLL
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
[Loaded DLLs] C:\WINDOWS\system32\sensapi.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\camupd.dll
[Loaded DLLs] C:\WINDOWS\system32\LIBEAY32_0.9.6l.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\srescan.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\zlsre_Loc040c.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\zlsre.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\scheduler.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\qrbase.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\zlquarantine_Loc040c.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
[Loaded DLLs] C:\WINDOWS\system32\wbem\wbemprox.dll
[Loaded DLLs] C:\WINDOWS\system32\vswmi.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\vsvault.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\VSRULEDB_Loc040c.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\VSRULEDB.DLL
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\vsdb.dll
[Loaded DLLs] C:\WINDOWS\system32\ZLCommDB.dll
[Loaded DLLs] C:\WINDOWS\system32\zlcomm.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\fbl.dll
[Loaded DLLs] C:\WINDOWS\system32\vsxml.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
[Loaded DLLs] C:\WINDOWS\system32\VSDATA.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\lib\pyd\_socket.pyd
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\lib\pyd\pyexpat.pyd
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\lib\pyd\pyvsinit.pyd
[Loaded DLLs] C:\WINDOWS\system32\ZoneLabs\lib\pyd\signedDll.pyd
[Loaded DLLs] C:\WINDOWS\system32\
-1