السلام عليكم و رحمة الله تعالى و بركاته
تسلم من كل سوء
التقرير كما يلي
.
--------------------------\\\ Start Report Of HijackThis ---------------
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:12:59, on 12/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\UberIcon\UberIcon Manager.exe
C:\Windows\System32\VisualTaskTips.exe
C:\Program Files\styler\Styler.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Godlike Developers\XtraTools 2007\rsvr\xttray.exe
C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IDMan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\ExtraTools\ExtraDNS\ExtraDNS.dll
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Comptoir\LOCALS~1\Temp\bntoz\runn.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\Comptoir\LOCALS~1\Temp\bntoz\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IDMIECC.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKLM\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
O4 - HKLM\..\Run: [TransBar] C:\WINDOWS\system32\transbar.exe /s
O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v3] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RAMSaverPro] C:\Program Files\Godlike Developers\RAM Saver Pro\ramsaverpro.exe
O4 - HKCU\..\Run: [XtraToolsTray] C:\Program Files\Godlike Developers\XtraTools 2007\rsvr\xttray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WengoPhoneNG] C:\Program Files\WengoPhone\qtwengophone.exe -b
O4 - HKCU\..\Run: [IDMan] C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U l32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: ExtraDNS.lnk = C:\Program Files\ExtraTools\ExtraDNS\ExtraDNS.exe
O8 - Extra context menu item: Download all links with IDM - C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IEGetAll.htm
O8 - Extra context menu item: Download FLV video with IDM - C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IEExt.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan ) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 127.0.0.1,149.174.211.5
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
--
End of file - 8377 bytes
.
.
--------------------------\\\ End Report Of Of HijackThis ---------------
.
.
.
.
--------------------------\\\ Start Report Of Running Processes ---------------
.
==================================================
Process Name : smss.exe
ProcessID : 604
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Gestionnaire de session Windows NT
Company : Microsoft Corporation
Window Title :
File Size : 50,688
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\System32\smss.exe
Base Address : 0x48580000
Created On : 05/03/29 08:30:22 Õ
Visible Windows : 0
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 412 K
Mem Usage Peak : 432 K
Page Faults : 198
Pagefile Usage : 172 K
Pagefile Peak Usage : 1652 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 660
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title : IEXPLORE.EXE - Erreur d'application
File Size : 6,144
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 05/03/29 08:30:24 Õ
Visible Windows : 1
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 4656 K
Mem Usage Peak : 5836 K
Page Faults : 18028
Pagefile Usage : 2104 K
Pagefile Peak Usage : 4988 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 684
Priority : High
Product Name : Système d'exploitation Microsoft® Windows®
Version : 5.1.2600.2815 (xpsp.051220-1546)
Description : Application d'ouverture de session Windows NT
Company : Microsoft Corporation
Window Title :
File Size : 507,904
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:25 Õ
Visible Windows : 0
Hidden Windows : 1
User Name : AUTORITE NT\SYSTEM
Mem Usage : 6744 K
Mem Usage Peak : 21800 K
Page Faults : 12927
Pagefile Usage : 9104 K
Pagefile Peak Usage : 10468 K
File Attributes : A
==================================================
==================================================
Process Name : services.exe
ProcessID : 728
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Applications Services et Contrôleur
Company : Microsoft Corporation
Window Title :
File Size : 108,544
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\services.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:26 Õ
Visible Windows : 0
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 2672 K
Mem Usage Peak : 10996 K
Page Faults : 5617
Pagefile Usage : 7184 K
Pagefile Peak Usage : 8328 K
File Attributes : A
==================================================
==================================================
Process Name : lsass.exe
ProcessID : 740
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : LSA l (Export Version)
Company : Microsoft Corporation
Window Title :
File Size : 13,312
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\lsass.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:26 Õ
Visible Windows : 0
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 1464 K
Mem Usage Peak : 7528 K
Page Faults : 31653
Pagefile Usage : 4792 K
Pagefile Peak Usage : 5744 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 916
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:26 Õ
Visible Windows : 0
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 5712 K
Mem Usage Peak : 5760 K
Page Faults : 1634
Pagefile Usage : 3760 K
Pagefile Peak Usage : 24140 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1004
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:27 Õ
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 6440 K
Mem Usage Peak : 6440 K
Page Faults : 2046
Pagefile Usage : 3916 K
Pagefile Peak Usage : 3916 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1100
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:27 Õ
Visible Windows : 0
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 22504 K
Mem Usage Peak : 25072 K
Page Faults : 13703
Pagefile Usage : 15332 K
Pagefile Peak Usage : 23144 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1212
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:27 Õ
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3860 K
Mem Usage Peak : 3876 K
Page Faults : 5159
Pagefile Usage : 1740 K
Pagefile Peak Usage : 1764 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1288
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:27 Õ
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3520 K
Mem Usage Peak : 3528 K
Page Faults : 933
Pagefile Usage : 1452 K
Pagefile Peak Usage : 1476 K
File Attributes : A
==================================================
==================================================
Process Name : spoolsv.exe
ProcessID : 1408
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2696 (xpsp.050610-1527)
Description : Spooler SubSystem App
Company : Microsoft Corporation
Window Title :
File Size : 57,856
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\spoolsv.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:27 Õ
Visible Windows : 0
Hidden Windows : 0
User Name : AUTORITE NT\SYSTEM
Mem Usage : 6556 K
Mem Usage Peak : 6700 K
Page Faults : 3270
Pagefile Usage : 4148 K
Pagefile Peak Usage : 7636 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 1708
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)
Description : Explorateur Windows
Company : Microsoft Corporation
Window Title : Program Manager
File Size : 1,789,952
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 05/03/29 08:30:29 Õ
Visible Windows : 2
Hidden Windows : 31
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 142788 K
Mem Usage Peak : 142880 K
Page Faults : 828973
Pagefile Usage : 48488 K
Pagefile Peak Usage : 48576 K
File Attributes : A
==================================================
==================================================
Process Name : sidebar.exe
ProcessID : 1912
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 6.0.6000.16386 (vista_rtm.061101-2205)
Description : Volet Windows
Company : Microsoft Corporation
Window Title : AppBar Bullet
File Size : 1,235,456
File Created Date : 04/11/28 03:58:08 ã
File Modified Date : 21/12/27 08:59:10 ã
Filename : C:\Program Files\Windows Sidebar\sidebar.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:30 Õ
Visible Windows : 2
Hidden Windows : 6
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 9872 K
Mem Usage Peak : 11056 K
Page Faults : 8087
Pagefile Usage : 5704 K
Pagefile Peak Usage : 6920 K
File Attributes : A
==================================================
==================================================
Process Name : UberIcon Manager.exe
ProcessID : 1920
Priority : High
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 122,880
File Created Date : 04/11/28 03:58:26 ã
File Modified Date : 21/06/27 10:16:46 ã
Filename : C:\Program Files\UberIcon\UberIcon Manager.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:30 Õ
Visible Windows : 0
Hidden Windows : 4
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 4132 K
Mem Usage Peak : 4404 K
Page Faults : 49683
Pagefile Usage : 1252 K
Pagefile Peak Usage : 1532 K
File Attributes : A
==================================================
==================================================
Process Name : VisualTaskTips.exe
ProcessID : 1928
Priority : Normal
Product Name : Visual Task Tips
Version : 2, 0, 0, 0
Description : Visual Task Tips
Company : VisualTaskTips.com
Window Title :
File Size : 36,864
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\Windows\System32\VisualTaskTips.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:30 Õ
Visible Windows : 0
Hidden Windows : 5
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 4808 K
Mem Usage Peak : 24956 K
Page Faults : 714164
Pagefile Usage : 2160 K
Pagefile Peak Usage : 22348 K
File Attributes : A
==================================================
==================================================
Process Name : Styler.exe
ProcessID : 1952
Priority : Normal
Product Name : Styler
Version : 1, 4, 0, 1
Description : Style Change Application
Company : ta2027
Window Title :
File Size : 307,200
File Created Date : 04/11/28 03:58:25 ã
File Modified Date : 05/04/27 10:48:46 Õ
Filename : C:\Program Files\styler\Styler.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:30 Õ
Visible Windows : 0
Hidden Windows : 48
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 2912 K
Mem Usage Peak : 9620 K
Page Faults : 14019
Pagefile Usage : 4232 K
Pagefile Peak Usage : 9112 K
File Attributes : A
==================================================
==================================================
Process Name : RUNDLL32.EXE
ProcessID : 2036
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Exécuter une DLL en tant qu'application
Company : Microsoft Corporation
Window Title :
File Size : 33,792
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\RUNDLL32.EXE
Base Address : 0x01000000
Created On : 05/03/29 08:30:31 Õ
Visible Windows : 0
Hidden Windows : 3
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 32636 K
Mem Usage Peak : 32640 K
Page Faults : 9745
Pagefile Usage : 2344 K
Pagefile Peak Usage : 9536 K
File Attributes : A
==================================================
==================================================
Process Name : sidebar.exe
ProcessID : 228
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 6.0.6000.16386 (vista_rtm.061101-2205)
Description : Volet Windows
Company : Microsoft Corporation
Window Title : Horloge
File Size : 1,235,456
File Created Date : 04/11/28 03:58:08 ã
File Modified Date : 21/12/27 08:59:10 ã
Filename : C:\Program Files\Windows Sidebar\sidebar.exe
Base Address : 0x01000000
Created On : 05/03/29 08:30:31 Õ
Visible Windows : 4
Hidden Windows : 11
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 20108 K
Mem Usage Peak : 20268 K
Page Faults : 2372653
Pagefile Usage : 12484 K
Pagefile Peak Usage : 14516 K
File Attributes : A
==================================================
==================================================
Process Name : fppdis3a.exe
ProcessID : 232
Priority : Normal
Product Name : pdfFactory
Version : 3.22
Description : pdfFactory
Company : FinePrint Software, LLC
Window Title :
File Size : 507,904
File Created Date : 15/02/29 02:50:48 ã
File Modified Date : 27/10/28 11:39:35 Õ
Filename : C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe
Base Address : 0x21000000
Created On : 05/03/29 08:30:31 Õ
Visible Windows : 0
Hidden Windows : 2
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 5060 K
Mem Usage Peak : 5068 K
Page Faults : 1475
Pagefile Usage : 1544 K
Pagefile Peak Usage : 1580 K
File Attributes : A
==================================================
==================================================
Process Name : ctfmon.exe
ProcessID : 280
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : CTF Loader
Company : Microsoft Corporation
Window Title :
File Size : 25,088
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\ctfmon.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:31 Õ
Visible Windows : 0
Hidden Windows : 5
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 11620 K
Mem Usage Peak : 11620 K
Page Faults : 3188
Pagefile Usage : 1260 K
Pagefile Peak Usage : 1264 K
File Attributes : A
==================================================
==================================================
Process Name : xttray.exe
ProcessID : 480
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 135,712
File Created Date : 20/08/28 08:02:19 Õ
File Modified Date : 20/08/28 08:02:19 Õ
Filename : C:\Program Files\Godlike Developers\XtraTools 2007\rsvr\xttray.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:32 Õ
Visible Windows : 0
Hidden Windows : 2
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 3540 K
Mem Usage Peak : 3540 K
Page Faults : 970
Pagefile Usage : 1116 K
Pagefile Peak Usage : 1120 K
File Attributes : A
==================================================
==================================================
Process Name : IDMan.exe
ProcessID : 944
Priority : Normal
Product Name : Internet Download Manager (IDM)
Version : 5.12.1.0
Description : Internet Download Manager (IDM)
Company : Tonec Inc.
Window Title :
File Size : 2,573,744
File Created Date : 28/02/29 02:51:51 ã
File Modified Date : 12/12/28 07:16:52 ã
Filename : C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IDMan.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:33 Õ
Visible Windows : 0
Hidden Windows : 7
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 15448 K
Mem Usage Peak : 15708 K
Page Faults : 10306
Pagefile Usage : 6404 K
Pagefile Peak Usage : 7408 K
File Attributes : A
==================================================
==================================================
Process Name : nvsvc32.exe
ProcessID : 1428
Priority : Normal
Product Name : NVIDIA Driver Helper Service, Version 82.65
Version : 6.14.10.8265
Description : NVIDIA Driver Helper Service, Version 82.65
Company : NVIDIA Corporation
Window Title :
File Size : 143,427
File Created Date : 14/11/26 06:51:00 Õ
File Modified Date : 14/11/26 06:51:00 Õ
Filename : C:\WINDOWS\system32\nvsvc32.exe
Base Address : 0x00400000
Created On : 05/03/29 08:30:36 Õ
Visible Windows : 0
Hidden Windows : 2
User Name : AUTORITE NT\SYSTEM
Mem Usage : 3852 K
Mem Usage Peak : 5032 K
Page Faults : 3090
Pagefile Usage : 2260 K
Pagefile Peak Usage : 4852 K
File Attributes : A
==================================================
==================================================
Process Name : ExtraDNS.dll
ProcessID : 1832
Priority : Normal
Product Name : ExtraDNS
Version : 3.00.0004
Description : ExtraDNS
Company : ExtraTools
Window Title : ExtraDNS
File Size : 540,688
File Created Date : 21/01/29 04:47:19 ã
File Modified Date : 05/03/29 08:30:37 Õ
Filename : C:\Program Files\ExtraTools\ExtraDNS\ExtraDNS.dll
Base Address : 0x00400000
Created On : 05/03/29 08:30:37 Õ
Visible Windows : 2
Hidden Windows : 10
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 11856 K
Mem Usage Peak : 11864 K
Page Faults : 17435
Pagefile Usage : 4760 K
Pagefile Peak Usage : 11492 K
File Attributes : R
==================================================
==================================================
Process Name : IEXPLORE.EXE
ProcessID : 788
Priority : Normal
Product Name : Windows® Internet Explorer
Version : 7.00.6000.16574 (vista_gdr.071008-1500)
Description : Internet Explorer
Company : Microsoft Corporation
Window Title : Windows Internet Explorer
File Size : 625,152
File Created Date : 04/11/28 03:49:17 ã
File Modified Date : 29/09/28 11:00:59 Õ
Filename : C:\Program Files\Internet Explorer\IEXPLORE.EXE
Base Address : 0x00400000
Created On : 05/03/29 09:18:21 Õ
Visible Windows : 1
Hidden Windows : 68
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 59436 K
Mem Usage Peak : 191876 K
Page Faults : 3327105
Pagefile Usage : 147328 K
Pagefile Peak Usage : 219908 K
File Attributes : A
==================================================
==================================================
Process Name : wintems.exe
ProcessID : 1780
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,684
File Created Date : 09/01/29 05:59:58 ã
File Modified Date : 05/03/29 12:34:06 ã
Filename : C:\WINDOWS\system32\wintems.exe
Base Address : 0x00400000
Created On : 05/03/29 12:34:11 ã
Visible Windows : 0
Hidden Windows : 0
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 7044 K
Mem Usage Peak : 7092 K
Page Faults : 1856
Pagefile Usage : 2380 K
Pagefile Peak Usage : 2436 K
File Attributes :
==================================================
==================================================
Process Name : runn.exe
ProcessID : 128
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,680
File Created Date : 05/03/29 02:12:54 ã
File Modified Date : 24/01/29 01:24:25 Õ
Filename : C:\DOCUME~1\Comptoir\LOCALS~1\Temp\bntoz\runn.exe
Base Address : 0x00400000
Created On : 05/03/29 02:12:54 ã
Visible Windows : 0
Hidden Windows : 0
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 2320 K
Mem Usage Peak : 2324 K
Page Faults : 667
Pagefile Usage : 764 K
Pagefile Peak Usage : 844 K
File Attributes : A
==================================================
==================================================
Process Name : cmd.exe
ProcessID : 1628
Priority : Normal
Product Name : Système d'exploitation Microsoft® Windows®
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Interpréteur de commandes Windows
Company : Microsoft Corporation
Window Title :
File Size : 403,968
File Created Date : 13/07/25 01:00:00 ã
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\cmd.exe
Base Address : 0x4AD00000
Created On : 05/03/29 02:12:54 ã
Visible Windows : 0
Hidden Windows : 1
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 3100 K
Mem Usage Peak : 3208 K
Page Faults : 1042
Pagefile Usage : 2152 K
Pagefile Peak Usage : 2324 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 2268
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 16/01/29 09:14:36 Õ
File Modified Date : 13/07/25 01:00:00 ã
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 05/03/29 02:12:56 ã
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 6348 K
Mem Usage Peak : 6348 K
Page Faults : 1629
Pagefile Usage : 3512 K
Pagefile Peak Usage : 6452 K
File Attributes : A
==================================================
==================================================
Process Name : CProcess.exe
ProcessID : 2272
Priority : Normal
Product Name : CurrProcess
Version : 1.11
Description : CurrProcess
Company : NirSoft
Window Title :
File Size : 35,840
File Created Date : 05/03/29 02:12:53 ã
File Modified Date : 08/06/26 07:46:34 Õ
Filename : C:\DOCUME~1\Comptoir\LOCALS~1\Temp\bntoz\CProcess.exe
Base Address : 0x00400000
Created On : 05/03/29 02:13:00 ã
Visible Windows : 0
Hidden Windows : 0
User Name : 222D8DD945164A8\Comptoir
Mem Usage : 2340 K
Mem Usage Peak : 2388 K
Page Faults : 906
Pagefile Usage : 960 K
Pagefile Peak Usage : 1024 K
File Attributes : A
==================================================
.
.
--------------------------\\\ End Report Of Running Processes ---------------
.
.
.
.
--------------------------\\\ Windows XP Startup List ---------------
.
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
autocheck autochk *
Utilitaire de vérification automatique
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\autochk.exe
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
rdpclip
rdpclip
RDP Clip Monitor
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
Application d'ouverture de session Userinit
Microsoft Corporation
5.01.2600.2943
c:\windows\system32\userinit.exe
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\l
Explorer.exe
Explorer.exe
Explorateur Windows
Microsoft Corporation
6.00.2900.3156
c:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\l
Explorer.exe
Explorer.exe
Explorateur Windows
Microsoft Corporation
6.00.2900.3156
c:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sidebar
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
Volet Windows
Microsoft Corporation
6.00.6000.16386
c:\program files\windows sidebar\sidebar.exe
UberIcon
"C:\Program Files\UberIcon\UberIcon Manager.exe"
c:\program files\ubericon\ubericon manager.exe
VisualTaskTips
C:\Windows\System32\VisualTaskTips.exe
Visual Task Tips
VisualTaskTips.com
2.00.0000.0000
c:\windows\system32\visualtasktips.exe
Vistadrv
C:\WINDOWS\system32\Vistadrive\vsdrv.exe
3.01.0000.0015
c:\windows\system32\vistadrive\vsdrv.exe
TransBar
C:\WINDOWS\system32\transbar.exe /s
TransBar
AKSoftware
1.04.0002.0000
c:\windows\system32\transbar.exe
Styler
C:\Program Files\styler\Styler.exe
Style Change Application
ta2027
1.04.0000.0001
c:\program files\styler\styler.exe
NvCplDaemon
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
NVIDIA Display Properties Extension
NVIDIA Corporation
6.14.0010.8265
c:\windows\system32\nvcpl.dll
nwiz
nwiz.exe /install
NVIDIA nView Wizard, Version 110.14
NVIDIA Corporation
6.14.0010.11014
c:\windows\system32\nwiz.exe
SW20
C:\WINDOWS\system32\sw20.exe
sw20 MFC Application
1.00.0000.0001
c:\windows\system32\sw20.exe
SW24
C:\WINDOWS\system32\sw24.exe
c:\windows\system32\sw24.exe
NvMediaCenter
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
NVIDIA Media Center Library
NVIDIA Corporation
6.14.0010.8265
c:\windows\system32\nvmctray.dll
GrooveMonitor
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
GrooveMonitor Utility
Microsoft Corporation
12.00.4518.1014
c:\program files\microsoft office\office12\groovemonitor.exe
IMJPMIG8.1
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
Microsoft IME
Microsoft Corporation
8.01.4202.0000
c:\windows\ime\imjp8_1\imjpmig.exe
MSPY2002
C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
c:\windows\system32\ime\pintlgnt\imscinst.exe
PHIME2002ASync
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
???????? 2002a
Microsoft Corporation
5.02.0000.2801
c:\windows\system32\ime\tintlgnt\tintsetp.exe
PHIME2002A
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
???????? 2002a
Microsoft Corporation
5.02.0000.2801
c:\windows\system32\ime\tintlgnt\tintsetp.exe
TkBellExe
"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
RealNetworks Scheduler
RealNetworks, Inc.
0.01.0001.0045
c:\program files\fichiers communs\real\update_ob\realsched.exe
pdfFactory Pro Dispatcher v3
"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
pdfFactory
FinePrint Software, LLC
3.22.0000.0000
c:\windows\system32\spool\drivers\w32x86\3\fppdis3a.exe
SunJavaUpdateSched
"C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
Java(TM) Platform SE binary
Sun Microsystems, Inc.
6.00.0050.0013
c:\program files\java\jre1.6.0_05\bin\jusched.exe
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
ExtraDNS.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\ExtraDNS.lnk
ExtraDNS
ExtraTools <
>
3.00.0000.0004
c:\program files\extratools\extradns\extradns.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
CTF Loader
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\ctfmon.exe
RAMSaverPro
C:\Program Files\Godlike Developers\RAM Saver Pro\ramsaverpro.exe
c:\program files\godlike developers\ram saver pro\ramsaverpro.exe
XtraToolsTray
C:\Program Files\Godlike Developers\XtraTools 2007\rsvr\xttray.exe
c:\program files\godlike developers\xtratools 2007\rsvr\xttray.exe
Sidebar
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
Volet Windows
Microsoft Corporation
6.00.6000.16386
c:\program files\windows sidebar\sidebar.exe
WengoPhoneNG
C:\Program Files\WengoPhone\qtwengophone.exe -b
File not found: C:\Program Files\WengoPhone\qtwengophone.exe
IDMan
C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IDMan.exe /onboot
Internet Download Manager (IDM)
Tonec Inc.
5.12.0001.0000
c:\documents and settings\default user\local settings\temp\bsasee3y5d\idman.exe
Task Scheduler
1-Click Maintenance.job
C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe /schedulestart
c:\program files\tuneup utilities 2008\oneclickstarter.exe
BugDoctorComptoir.job
C:\Program Files\Bug Doctor\BugDoctor.exe scan
File not found: C:\Program Files\Bug Doctor\BugDoctor.exe scan
ErrorKiller Scheduled Scan.job
C:\Program Files\ErrorKiller\ErrorKiller.exe scheduled
File not found: C:\Program Files\ErrorKiller\ErrorKiller.exe scheduled
ErrorSweeper Scheduled Scan.job
C:\Program Files\ErrorSweeper\ErrorSweeper.exe scheduled
File not found: C:\Program Files\ErrorSweeper\ErrorSweeper.exe scheduled
Maintenance en 1 clic.job
C:\Program Files\TuneUp Utilities 2008\OneClick.exe /schedulestart
TuneUp 1-Click Maintenance
TuneUp Software GmbH
7.00.8002.0267
c:\program files\tuneup utilities 2008\oneclick.exe
Uniblue SpeedUpMyPC Nag.job
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
File not found: C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
.
----------- End Report ---------------