cpu 100% [résolu]

Section d'analyse de rapports et de désinfection : malwares en tous genre et autres indésirables. Demandes de nettoyage uniquement. Prise en charge restreinte : équipe spécialisée.

Modérateur: Modérateurs

Règles du forum :arrow: Les désinfections sont prises en charge par un groupe spécifique, tout le monde ne peut pas intervenir pour désinfecter les machines (règles).
:arrow: Les procédures sont sur-mesure, ne faites pas la même chose chez vous (explications).
:arrow: Un topic par machine, chacun crée le sien. ;)

cpu 100% [résolu]

Messagepar jonas_davidson » 28 Oct 2007 17:48

Bon soir,



J'ai un problème avec l'explorer.exe qui ne baisse pas du 100%. Pourriez-vous me dire pourquoi ?
Merci @+
jonas_davidson
 
Messages: 16
Inscription: 28 Oct 2007 17:39

Messagepar Falkra » 28 Oct 2007 17:54

Bonsoir, cela peut venir de bugs logiciels, de logiciels malveillants (spywares, virus au sens large, etc), d'un driver, etc...
Ca le fait dès le démarrage de windows ? (sans que tu ne lances quoi que ce soit toi-même)

Poste un log hijackthis 2.0.2 dans ta prochaine réponse, on y verra plus clair côté logiciel : http://www.libellules.ch/poster_log_hijackthis.php (tuto)
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

cpu 100%

Messagepar jonas_davidson » 28 Oct 2007 19:54

bonsoir

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:03 p.m., on 28/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\Archivos de programa\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Archivos de programa\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Archivos de programa\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Archivos de programa\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Archivos de programa\Eovia\Carrara 5 Pro\Carrara.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libellules.ch/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 212.150.54.250 dv-networks.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35FC2C33-0EB9-4B34-A064-E291ACE41CE1} - C:\WINDOWS\system32\odpdx32d.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [cctray] "C:\Archivos de programa\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Archivos de programa\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Archivos de programa\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Archivos de programa\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Archivos de programa\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/re ... NPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 7879333906
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Archivos de programa\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Archivos de programa\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Archivos de programa\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

--
End of file - 6383 bytes
jonas_davidson
 
Messages: 16
Inscription: 28 Oct 2007 17:39

Messagepar Falkra » 28 Oct 2007 21:00

Merci. :-D

coche ces lignes et fais "fix checked" :
O1 - Hosts: 212.150.54.250 dv-networks.com
O2 - BHO: (no name) - {35FC2C33-0EB9-4B34-A064-E291ACE41CE1} - C:\WINDOWS\system32\odpdx32d.dll

Quel est, dans le gestionnaire de tâches, le programme qui monte le cpu à 100% ? Le nom du processus ou des processus s'il y en a 2 à 50% chacun.
Ca le fait juste après la fin du démarrage ?

Il va falloir faire d'autres diagnostics.
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

cpu 100%

Messagepar jonas_davidson » 29 Oct 2007 01:10

bonsoir

c'est l¡EXPLORER.EXE qui travaille au 100% et ne me laisse pas travailler et ne baisse pas
j'ai deja fait le fix checked sur HijackThis comme tu m'as dit

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:06:42 p.m., on 28/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\Archivos de programa\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Archivos de programa\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\Archivos de programa\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Archivos de programa\CA\CA Internet Security Suite\ccprovsp.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libellules.ch/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [cctray] "C:\Archivos de programa\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Archivos de programa\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Archivos de programa\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Archivos de programa\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Archivos de programa\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/re ... NPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 7879333906
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Archivos de programa\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Archivos de programa\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Archivos de programa\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

--
End of file - 6220 bytes
jonas_davidson
 
Messages: 16
Inscription: 28 Oct 2007 17:39

Messagepar Falkra » 29 Oct 2007 06:50

Re. Il devait y avoir une faute de frappe, c'est Explorer.exe ou Iexplore.exe qui est à 100% ?

---------------------

Télécharge et lance DiagHelp sur ton bureau et décompresse-le comme indiqué ici :
http://www.malekal.com/DiagHelp/DiagHelp.php

Ne lance que l'option 1 et poste le rapport dans ta prochaine réponse.
Dernière édition par Falkra le 29 Oct 2007 10:22, édité 1 fois.
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Messagepar bororo » 29 Oct 2007 10:18

Hello.
C'st assez souvent que l'on voit des questions concernant cette suractivité su processeur proche des 100%
pour ma part,j'avais entièrement desinstallé les codecs de mon pc puis reinstallé un pack propre car certains rentraient en conflit.
depuis je n'ai plus de soucis.
Je ne dis pas que c'est la solution mais le résultat avait été correct.
Avatar de l’utilisateur
bororo
Modérateur
Modérateur
 
Messages: 1984
Inscription: 13 Déc 2003 20:33
Localisation: Bordeaux

cpu 100%

Messagepar jonas_davidson » 29 Oct 2007 16:20

bonjour

c'est explorer.exe


DiagHelp version v1.3 - http://www.malekal.com
excute le 29/10/2007 à 8:43:43.87


Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->29/10/2007 08:43:18 a.m.
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->29/10/2007 08:43:10 a.m.
C:\WINDOWS\prefetch\WINRAR.EXE-25A6EAE3.pf -->29/10/2007 08:41:08 a.m.
C:\WINDOWS\prefetch\IMAPI.EXE-0BF740A4.pf -->29/10/2007 08:40:55 a.m.
C:\WINDOWS\prefetch\LSSAS.EXE-0670E652.pf -->29/10/2007 08:40:40 a.m.
C:\WINDOWS\prefetch\EXPLORER.EXE-082F38A9.pf -->29/10/2007 08:40:40 a.m.
C:\WINDOWS\prefetch\VERCLSID.EXE-3667BD89.pf -->29/10/2007 08:40:21 a.m.
C:\WINDOWS\prefetch\TASKMGR.EXE-20256C55.pf -->29/10/2007 08:39:17 a.m.
C:\WINDOWS\prefetch\QTTASK.EXE-0B6BEE64.pf -->29/10/2007 08:38:48 a.m.
C:\WINDOWS\prefetch\IEXPLORE.EXE-07A56490.pf -->29/10/2007 08:36:39 a.m.

C:\WINDOWS\System32\drivers\pxhelp20.sys -->28/09/2007 10:07:50 a.m.
C:\WINDOWS\System32\drivers\AnyDVD.sys -->07/09/2007 05:48:56 p.m.
C:\WINDOWS\System32\drivers\NSDriver.sys -->13/08/2007 12:20:21 a.m.
C:\WINDOWS\System32\drivers\AWRTRD.sys -->13/08/2007 12:20:20 a.m.
C:\WINDOWS\System32\drivers\ElbyCDIO.sys -->07/08/2007 01:48:33 p.m.
C:\WINDOWS\System32\drivers\vetefile.sys -->23/07/2007 09:09:34 a.m.
C:\WINDOWS\System32\drivers\veteboot.sys -->23/07/2007 09:09:34 a.m.

C:\WINDOWS\System32\settingsbkup.sfm -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\settings.sfm -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000001-00001102-00000004-20021102}.dat -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000004-20021102}.dat -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\BMXState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx -->28/10/2007 10:55:18 p.m.
C:\WINDOWS\System32\perfh00A.dat -->28/10/2007 05:56:04 p.m.
C:\WINDOWS\System32\perfh009.dat -->28/10/2007 05:56:04 p.m.
C:\WINDOWS\System32\perfc00A.dat -->28/10/2007 05:56:04 p.m.
C:\WINDOWS\System32\perfc009.dat -->28/10/2007 05:56:04 p.m.
C:\WINDOWS\System32\PerfStringBackup.INI -->28/10/2007 05:56:03 p.m.
C:\WINDOWS\System32\nvapps.xml -->28/10/2007 05:52:23 p.m.
C:\WINDOWS\System32\Thumbs.db -->28/10/2007 01:19:06 p.m.
C:\WINDOWS\System32\wpa.dbl -->27/10/2007 12:00:17 p.m.
C:\WINDOWS\System32\settings.aaw -->20/10/2007 11:28:17 p.m.
C:\WINDOWS\System32\history.aaw -->20/10/2007 11:28:17 p.m.
C:\WINDOWS\System32\Chip.dll -->10/10/2007 10:51:48 a.m.
C:\WINDOWS\System32\DivXCodecVersionChecker.exe -->28/09/2007 10:08:18 a.m.
C:\WINDOWS\System32\dsm_fr.qm -->28/09/2007 10:07:54 a.m.
C:\WINDOWS\System32\divxsm.tlb -->28/09/2007 10:07:54 a.m.
C:\WINDOWS\System32\DivXsm.exe -->28/09/2007 10:07:54 a.m.
C:\WINDOWS\System32\qt-dx331.dll -->28/09/2007 10:07:52 a.m.
C:\WINDOWS\System32\pxwave.dll -->28/09/2007 10:07:50 a.m.

C:\WINDOWS\WindowsUpdate.log -->29/10/2007 08:19:38 a.m.
C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.CDF -->28/10/2007 10:55:15 p.m.
C:\WINDOWS\QTFont.qfn -->28/10/2007 06:57:09 p.m.
C:\WINDOWS\0.log -->28/10/2007 05:52:02 p.m.
C:\WINDOWS\wiadebug.log -->28/10/2007 05:51:49 p.m.
C:\WINDOWS\wiaservc.log -->28/10/2007 05:51:47 p.m.
C:\WINDOWS\bootstat.dat -->28/10/2007 05:51:22 p.m.
C:\WINDOWS\SchedLgU.Txt -->28/10/2007 02:08:10 p.m.
C:\WINDOWS\setupapi.log -->26/10/2007 09:38:55 p.m.
C:\WINDOWS\QTFont.for -->25/10/2007 09:18:01 p.m.
C:\WINDOWS\DPINST.LOG -->25/10/2007 04:31:09 p.m.
C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.BAK -->15/10/2007 12:10:23 a.m.
C:\WINDOWS\mravo5.dll -->14/10/2007 05:40:40 p.m.
C:\WINDOWS\S9EEB7527.tmp -->14/10/2007 08:41:43 a.m.
C:\WINDOWS\setupact.log -->10/10/2007 06:13:31 p.m.


MD5 des fichiers sensibles
tcpip.sys 1dbf125862891817f374f407626967f4
ndis.sys 558635d3af1c7546d26067d5d9b6959e
null.sys 73c1e1f395918bc2c6dd67af7591a3ad
svchost.exe fa03e1fc17f38fbdba81470d08b3e416


ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - http://www.sysinternals.com

------------------------------------------------------------------------------
explorer.exe pid: 248
Command line: "C:\WINDOWS\explorer.exe"

Base Size Version Path
0x43330000 0xcf000 7.00.6000.16512 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x430b0000 0x45000 7.00.6000.16512 C:\WINDOWS\system32\iertutil.dll
0x58c30000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll
0x10000000 0x170000 6.14.0010.11048 C:\WINDOWS\system32\nview.dll
0x00ca0000 0x50000 6.14.0010.11048 C:\WINDOWS\system32\NVWRSESM.DLL
0x76f90000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x77010000 0xd0000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x00f60000 0x10000 1.00.0000.0008 C:\WINDOWS\system32\ctagent.dll
0x43410000 0x124000 7.00.6000.16512 C:\WINDOWS\system32\urlmon.dll
0x43610000 0x5cb000 7.00.6000.16512 C:\WINDOWS\system32\ieframe.dll
0x01910000 0x15000 6.14.0010.9147 C:\WINDOWS\system32\nvwddi.dll
0x76ae0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
0x7d1f0000 0x2be000 3.01.4000.4039 C:\WINDOWS\system32\msi.dll
0x43560000 0x3c000 7.00.6000.16512 C:\WINDOWS\system32\webcheck.dll
0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
0x00ff0000 0xd000 7.00.0009.0050 C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
0x7c340000 0x56000 7.10.3052.0004 C:\WINDOWS\system32\MSVCR71.dll
0x5a500000 0x4e000 8.01.0178.0000 C:\Archivos de programa\MSN Messenger\fsshext.8.1.0178.00.dll
0x78130000 0x9b000 8.00.50727.0762 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
0x63910000 0xc000 16.02.0054.0000 C:\Archivos de programa\Archivos comunes\Autodesk Shared\AcDwfThmbPrxy16.dll
0x01290000 0x2b000 C:\Archivos de programa\WinRAR\rarext.dll

ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - http://www.sysinternals.com

------------------------------------------------------------------------------
winlogon.exe pid: 1400
Command line: winlogon.exe

Base Size Version Path
0x01000000 0x80000 \??\C:\WINDOWS\system32\winlogon.exe
0x58c30000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll
0x745e0000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x77010000 0xd0000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x76f90000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x76030000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll


El volumen de la unidad C no tiene etiqueta.
El número de serie del volumen es: 141A-2EE1

Directorio de C:\WINDOWS\system

22/12/1997 06:23 p.m. 4,672 wowpost.exe
1 archivos 4,672 bytes
0 dirs 95,879,651,328 bytes libres
El volumen de la unidad C no tiene etiqueta.
El número de serie del volumen es: 141A-2EE1

Directorio de C:\WINDOWS\system32

19/08/2004 07:42 a.m. 6,144 csrss.exe
1 archivos 6,144 bytes
0 dirs 95,879,651,328 bytes libres

Contenu de Downloaded Program Files
El volumen de la unidad C no tiene etiqueta.
El número de serie del volumen es: 141A-2EE1

Directorio de C:\WINDOWS\Downloaded Program Files

25/10/2007 09:21 p.m. <DIR> .
25/10/2007 09:21 p.m. <DIR> ..
30/04/2007 02:52 a.m. 65 desktop.ini
25/07/2002 04:13 p.m. 24,576 dwusplay.dll
25/07/2002 04:13 p.m. 196,608 dwusplay.exe
05/03/2005 03:59 p.m. 1,706,800 gdiplus.dll
05/03/2005 03:59 p.m. 283,296 IDrop.ocx
05/03/2005 03:59 p.m. 114,848 IDropENU.dll
19/09/2003 01:22 p.m. 299,008 isusweb.dll
20/06/2006 02:44 p.m. 379,704 MsnPUpld.dll
19/06/2006 01:40 p.m. 393 MsnPUpld.inf
22/09/2004 02:59 p.m. 110,592 PURen-us.dll
09/01/2007 07:28 a.m. 110,592 PURes-us.dll
15/10/2004 06:54 a.m. 110,592 PURes-xx.dll
14/02/2007 03:30 p.m. 144 setup.inf
05/03/2005 03:59 p.m. 114,688 vizable.ocx
26/05/2005 03:19 a.m. 291 wuweb.inf
15 archivos 3,452,197 bytes

Total de archivos en la lista:
15 archivos 3,452,197 bytes
2 dirs 95,879,647,232 bytes libres

Recherche de rootkit! (Merci S!Ri)

Recherche d'infections connues

Export des clefs sensibles..


Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Archivos de programa\\e frontier\\Poser 7\\Poser.exe"="C:\\Archivos de programa\\e frontier\\Poser 7\\Poser.exe:*:Enabled:Poser executable file"
"C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\RM.exe"="C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\RM.exe:*:Enabled:Render Manager"
"C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\Studio.exe"="C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\Studio.exe:*:Enabled:Studio"
"C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"="C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\umi.exe"="C:\\Archivos de programa\\Pinnacle\\Studio 11\\programs\\umi.exe:*:Enabled:umi"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Archivos de programa\\eMule\\emule.exe"="C:\\Archivos de programa\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Precargador Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Demonio de caché de las categorías de componente"



exports des policies
REGEDIT4

[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001



Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...

KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (http://www.security.org.sg)

Process list by traversal of KiWaitListHead

248 - explorer.exe
280 - svchost.exe
320 - svchost.exe
476 - rundll32.exe
660 - alg.exe
700 - cctray.exe
916 - svchost.exe
988 - MDM.EXE
1016 - taskmgr.exe
1056 - svchost.exe
1128 - nvsvc32.exe
1208 - iexplore.exe
1224 - csrss.exe
1384 - Tablet.exe
1400 - winlogon.exe
1476 - aawservice.exe
1536 - services.exe
1544 - svchost.exe
1608 - lsass.exe
2352 - cmd.exe
2532 - LVCOMSX.EXE
2624 - CTHELPER.EXE
3000 - CTSysVol.exe

Total number of processes = 23
NOTE: Under WinXP, this will not show all processes.

KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (http://www.security.org.sg)

Driver/Module list by traversal of PsLoadedModuleList

804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806E3000 - \WINDOWS\system32\hal.dll
BADA8000 - \WINDOWS\system32\KDCOM.DLL
BACB8000 - \WINDOWS\system32\BOOTVID.dll
BA6D0000 - sptd.sys
BADAA000 - \WINDOWS\System32\Drivers\WMILIB.SYS
BA6B8000 - \WINDOWS\System32\Drivers\SCSIPORT.SYS
BA689000 - ACPI.sys
BA678000 - pci.sys
BA8A8000 - isapnp.sys
BAE70000 - pciide.sys
BAB28000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
BA8B8000 - MountMgr.sys
BA659000 - ftdisk.sys
BADAC000 - dmload.sys
BA633000 - dmio.sys
BAB30000 - PartMgr.sys
BA8C8000 - VolSnap.sys
BAB38000 - VClone.sys
BA61B000 - atapi.sys
BA8D8000 - disk.sys
BA8E8000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
BA5FB000 - fltMgr.sys
BA5E9000 - sr.sys
BA8F8000 - PxHelp20.sys
BA5D2000 - KSecDD.sys
BA545000 - Ntfs.sys
BA518000 - NDIS.sys
BA908000 - ohci1394.sys
BA918000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
BA4FD000 - Mup.sys
BA938000 - \SystemRoot\system32\DRIVERS\nic1394.sys
BA948000 - \SystemRoot\system32\DRIVERS\intelppm.sys
BA08D000 - \SystemRoot\system32\DRIVERS\nv4_mini.sys
BA079000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
BA054000 - \SystemRoot\system32\DRIVERS\HDAudBus.sys
BAB90000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
BA031000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
BAB98000 - \SystemRoot\system32\DRIVERS\usbehci.sys
B9FD7000 - \SystemRoot\system32\drivers\ctaud2k.sys
B9FB5000 - \SystemRoot\system32\drivers\portcls.sys
BA968000 - \SystemRoot\system32\drivers\drmk.sys
B9F92000 - \SystemRoot\system32\drivers\ks.sys
B9F66000 - \SystemRoot\system32\drivers\ctoss2k.sys
BADBA000 - \SystemRoot\System32\drivers\ctprxy2k.sys
BA4C0000 - \SystemRoot\system32\DRIVERS\gameenum.sys
B9F3E000 - \SystemRoot\system32\DRIVERS\e100b325.sys
B9F2A000 - \SystemRoot\system32\DRIVERS\parport.sys
B9F19000 - \SystemRoot\system32\DRIVERS\serial.sys
BA4B4000 - \SystemRoot\system32\DRIVERS\serenum.sys
BA988000 - \SystemRoot\system32\DRIVERS\imapi.sys
B9F03000 - \SystemRoot\System32\Drivers\AnyDVD.sys
BADC0000 - \SystemRoot\System32\Drivers\ElbyDelay.sys
BABB0000 - \SystemRoot\system32\drivers\ASAPIW2k.sys
BA4A4000 - \SystemRoot\system32\drivers\pfc.sys
BA998000 - \SystemRoot\system32\DRIVERS\cdrom.sys
BA9A8000 - \SystemRoot\system32\DRIVERS\redbook.sys
BADC2000 - \SystemRoot\system32\DRIVERS\wacomvhid.sys
BA9B8000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
BABD0000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
BADC4000 - \SystemRoot\system32\DRIVERS\WacomVKHid.sys
BAFA2000 - \SystemRoot\system32\DRIVERS\audstub.sys
BAA18000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
BA48C000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
B9EC4000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
BAA28000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
BAA38000 - \SystemRoot\system32\DRIVERS\raspptp.sys
BABF0000 - \SystemRoot\system32\DRIVERS\TDI.SYS
B9EB3000 - \SystemRoot\system32\DRIVERS\psched.sys
BAA48000 - \SystemRoot\system32\DRIVERS\msgpc.sys
BAC00000 - \SystemRoot\system32\DRIVERS\ptilink.sys
BAC10000 - \SystemRoot\system32\DRIVERS\raspti.sys
B9E82000 - \SystemRoot\system32\DRIVERS\rdpdr.sys
BAA58000 - \SystemRoot\system32\DRIVERS\termdd.sys
BAC18000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
BAC20000 - \SystemRoot\system32\DRIVERS\mouclass.sys
BADDE000 - \SystemRoot\system32\DRIVERS\swenum.sys
B9D89000 - \SystemRoot\system32\DRIVERS\update.sys
BA468000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
B9D5B000 - \SystemRoot\system32\DRIVERS\MarvinBus.sys
BA460000 - \SystemRoot\system32\DRIVERS\mouhid.sys
BAC30000 - \SystemRoot\system32\DRIVERS\wacommousefilter.sys
BA454000 - \SystemRoot\system32\DRIVERS\kbdhid.sys
BAA78000 - \SystemRoot\System32\Drivers\NDProxy.SYS
BAAA8000 - \SystemRoot\system32\DRIVERS\usbhub.sys
BADF4000 - \SystemRoot\system32\DRIVERS\USBD.SYS
B7BE6000 - \SystemRoot\System32\drivers\hap16v2k.sys
B7B09000 - \SystemRoot\System32\drivers\ha10kx2k.sys
B7AE7000 - \SystemRoot\System32\drivers\emupia2k.sys
B7AC7000 - \SystemRoot\System32\drivers\ctsfm2k.sys
B7A29000 - \SystemRoot\System32\drivers\ctac32k.sys
BA484000 - \SystemRoot\System32\Drivers\VETFDDNT.SYS
BADF8000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
B793D000 - \SystemRoot\System32\Drivers\VETEFILE.SYS
BA46C000 - \SystemRoot\System32\Drivers\VET-REC.SYS
BACB0000 - \SystemRoot\System32\Drivers\VET-FILT.SYS
BAB80000 - \SystemRoot\System32\Drivers\VETMONNT.SYS
B78FD000 - \SystemRoot\System32\Drivers\VETEBOOT.SYS
BAED1000 - \SystemRoot\System32\Drivers\Null.SYS
BA45C000 - \SystemRoot\system32\DRIVERS\hidusb.sys
BAE00000 - \SystemRoot\System32\Drivers\Beep.SYS
BABA0000 - \SystemRoot\System32\drivers\vga.sys
BAE06000 - \SystemRoot\System32\Drivers\mnmdd.SYS
BABA8000 - \SystemRoot\system32\DRIVERS\usbccgp.sys
BAE0A000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
BABC8000 - \SystemRoot\System32\Drivers\Msfs.SYS
BABD8000 - \SystemRoot\System32\Drivers\Npfs.SYS
B7C23000 - \SystemRoot\system32\DRIVERS\rasacd.sys
B78CA000 - \SystemRoot\system32\DRIVERS\ipsec.sys
B7872000 - \SystemRoot\system32\DRIVERS\tcpip.sys
B784A000 - \SystemRoot\system32\DRIVERS\netbt.sys
B7829000 - \SystemRoot\system32\DRIVERS\ipnat.sys
BAA08000 - \SystemRoot\system32\DRIVERS\wanarp.sys
B7807000 - \SystemRoot\System32\drivers\afd.sys
B9E62000 - \SystemRoot\system32\DRIVERS\arp1394.sys
B9E52000 - \SystemRoot\system32\DRIVERS\netbios.sys
B77ED000 - \??\C:\WINDOWS\system32\drivers\srosa.sys
B77C2000 - \SystemRoot\system32\DRIVERS\rdbss.sys
B7753000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
B9E42000 - \SystemRoot\System32\Drivers\Fips.SYS
BAC70000 - \SystemRoot\system32\DRIVERS\USBSTOR.SYS
BAA68000 - \SystemRoot\System32\Drivers\Cdfs.SYS
B7713000 - \SystemRoot\System32\Drivers\dump_atapi.sys
BAE30000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \SystemRoot\System32\win32k.sys
B7915000 - \SystemRoot\System32\drivers\Dxapi.sys
BAC98000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
BAECB000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\nv4_disp.dll
B6C0E000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
BFFA0000 - \SystemRoot\System32\ATMFD.DLL
B6175000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
BAE40000 - \SystemRoot\System32\Drivers\ParVdm.SYS
B6C4E000 - \SystemRoot\System32\Drivers\Aspi32.SYS
BAC90000 - \SystemRoot\System32\Drivers\ElbyCDIO.sys
B6171000 - \??\C:\WINDOWS\system32\drivers\PfModNT.sys
B5FE3000 - \SystemRoot\system32\DRIVERS\srv.sys
B5D26000 - \SystemRoot\system32\drivers\wdmaud.sys
B6C82000 - \SystemRoot\system32\drivers\sysaudio.sys
B5147000 - \SystemRoot\System32\Drivers\HTTP.sys
ACF29000 - \SystemRoot\system32\drivers\kmixer.sys
BAF69000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys

Total number of drivers = 143

Liste des programmes installes

Actualización de seguridad para el Reproductor de Windows Media (KB911564)
Actualización de seguridad para el Reproductor de Windows Media 11 (KB936782)
Actualización de seguridad para el Reproductor de Windows Media 6.4 (KB925398)
Actualización de seguridad para Windows Internet Explorer 7 (KB928090)
Actualización de seguridad para Windows Internet Explorer 7 (KB929969)
Actualización de seguridad para Windows Internet Explorer 7 (KB931768)
Actualización de seguridad para Windows Internet Explorer 7 (KB933566)
Actualización de seguridad para Windows Internet Explorer 7 (KB937143)
Actualización de seguridad para Windows Internet Explorer 7 (KB938127)
Actualización de seguridad para Windows XP (KB893756)
Actualización de seguridad para Windows XP (KB896358)
Actualización de seguridad para Windows XP (KB896423)
Actualización de seguridad para Windows XP (KB896428)
Actualización de seguridad para Windows XP (KB899587)
Actualización de seguridad para Windows XP (KB899591)
Actualización de seguridad para Windows XP (KB900725)
Actualización de seguridad para Windows XP (KB901017)
Actualización de seguridad para Windows XP (KB901214)
Actualización de seguridad para Windows XP (KB902400)
Actualización de seguridad para Windows XP (KB904706)
Actualización de seguridad para Windows XP (KB905414)
Actualización de seguridad para Windows XP (KB905749)
Actualización de seguridad para Windows XP (KB908519)
Actualización de seguridad para Windows XP (KB911562)
Actualización de seguridad para Windows XP (KB911927)
Actualización de seguridad para Windows XP (KB913580)
Actualización de seguridad para Windows XP (KB914388)
Actualización de seguridad para Windows XP (KB914389)
Actualización de seguridad para Windows XP (KB917422)
Actualización de seguridad para Windows XP (KB917953)
Actualización de seguridad para Windows XP (KB918118)
Actualización de seguridad para Windows XP (KB918439)
Actualización de seguridad para Windows XP (KB919007)
Actualización de seguridad para Windows XP (KB920213)
Actualización de seguridad para Windows XP (KB920670)
Actualización de seguridad para Windows XP (KB920683)
Actualización de seguridad para Windows XP (KB920685)
Actualización de seguridad para Windows XP (KB921503)
Actualización de seguridad para Windows XP (KB922819)
Actualización de seguridad para Windows XP (KB923191)
Actualización de seguridad para Windows XP (KB923414)
Actualización de seguridad para Windows XP (KB923694)
Actualización de seguridad para Windows XP (KB923789)
Actualización de seguridad para Windows XP (KB923980)
Actualización de seguridad para Windows XP (KB924191)
Actualización de seguridad para Windows XP (KB924270)
Actualización de seguridad para Windows XP (KB924667)
Actualización de seguridad para Windows XP (KB925902)
Actualización de seguridad para Windows XP (KB926255)
Actualización de seguridad para Windows XP (KB926436)
Actualización de seguridad para Windows XP (KB927779)
Actualización de seguridad para Windows XP (KB927802)
Actualización de seguridad para Windows XP (KB928255)
Actualización de seguridad para Windows XP (KB928843)
Actualización de seguridad para Windows XP (KB929123)
Actualización de seguridad para Windows XP (KB930178)
Actualización de seguridad para Windows XP (KB931261)
Actualización de seguridad para Windows XP (KB931784)
Actualización de seguridad para Windows XP (KB932168)
Actualización de seguridad para Windows XP (KB935839)
Actualización de seguridad para Windows XP (KB935840)
Actualización de seguridad para Windows XP (KB936021)
Actualización de seguridad para Windows XP (KB938829)
Actualización para Windows XP (KB894391)
Actualización para Windows XP (KB898461)
Actualización para Windows XP (KB900485)
Actualización para Windows XP (KB908531)
Actualización para Windows XP (KB910437)
Actualización para Windows XP (KB911280)
Actualización para Windows XP (KB916595)
Actualización para Windows XP (KB920872)
Actualización para Windows XP (KB922582)
Actualización para Windows XP (KB927891)
Actualización para Windows XP (KB930916)
Actualización para Windows XP (KB931836)
Actualización para Windows XP (KB933360)
Actualización para Windows XP (KB936357)
Actualización para Windows XP (KB938828)
Ad-Aware 2007
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color EU Recommended Settings
Adobe Color JA Extra Settings
Adobe Color NA Extra Settings
Adobe Color NA Recommended Settings
Adobe Common File Installer
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Encore CS3
Adobe Encore CS3
Adobe Encore CS3 Codecs
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit 2
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Photoshop CS3
Adobe Premiere Pro CS3
Adobe Premiere Pro CS3
Adobe Premiere Pro CS3 Functional Content
Adobe Premiere Pro CS3 Third Party Content
Adobe Premiere Pro CS3 Third Party Content
Adobe Reader 7.0.9
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Shockwave Player
Adobe Soundbooth CS3
Adobe Soundbooth CS3
Adobe Soundbooth CS3 Codecs
Adobe Stock Photos CS3
Adobe SVG Viewer 3.0
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
Amapi Pro 7.52
Archiveur WinRAR
Autodesk 3ds Max 8
AutoUpdate
AVS DVD Player version 2.4
CA Anti-Virus
CamStudio 2.02 Fr
Canon Camera WIA Driver
Canon EOS Kiss_N REBEL_XT 350D WIA Driver
Canopus ProCoder 2
Carrara
Carrara 6 Pro
CloneDVD2
Controlador de Logitech® Camera
Creative MediaSource
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DVC5.0 Driver
eMule
GOM Player
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
hp photosmart 140 series
HP Software Update
Información del sistema de Creative
Intel(R) PRO Network Connections
Java(TM) 6 Update 2
Java(TM) SE Runtime Environment 6 Update 1
Logitech Desktop Messenger
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 1.1 Spanish Language Pack
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Tool Web Package : EXCTRLST.EXE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0.0.6)
Mpeg2Decoder 1.3
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
msxml4
Nero 7 Demo
NVIDIA Drivers
PDF Settings
Photosmart 140,240,7200,7600,7700,7900 Series
Pinnacle Instant DVD Recorder
Poser 7
proDAD Vitascene 1.0
PS140
PSShortcutsP
PSUsage
QFolder
QuickTime
Recover Files 2.1
Reproductor de Windows Media 11
Revisión de Windows XP - KB873339
Revisión de Windows XP - KB885835
Revisión de Windows XP - KB885836
Revisión de Windows XP - KB886185
Revisión de Windows XP - KB887472
Revisión de Windows XP - KB888302
Revisión de Windows XP - KB890859
Revisión de Windows XP - KB891781
Revisión para el Reproductor de Windows Media 11 (KB939683)
Revo Uninstaller 1.34
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Software Logitech QuickCam
Sound Blaster Audigy 2 ZS
Studio 11
Studio 11
Tableta
TitleDeko
TubeMaster
Unlocker 1.8.5
VideoLAN VLC media player 0.8.6b
VirtualCloneDrive
What's Running 2.2
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11



El volumen de la unidad C no tiene etiqueta.
El número de serie del volumen es: 141A-2EE1

Directorio de C:\Archivos de programa

25/10/2007 08:04 a.m. <DIR> .
25/10/2007 08:04 a.m. <DIR> ..
24/10/2007 12:31 p.m. <DIR> Adobe
23/05/2007 01:31 p.m. <DIR> Alcohol Soft
24/10/2007 12:27 p.m. <DIR> Archivos comunes
10/10/2007 02:47 p.m. <DIR> Autodesk
10/10/2007 02:46 p.m. <DIR> Autodesk Revit Building 9.1
08/09/2017 06:26 p.m. <DIR> Avid
09/09/2007 08:36 p.m. <DIR> AVSMedia
29/04/2007 02:21 p.m. <DIR> CA
09/09/2007 08:24 p.m. <DIR> CamStudio
18/09/2007 07:06 p.m. <DIR> Canon
21/09/2007 12:34 p.m. <DIR> Canopus
30/04/2007 02:50 a.m. <DIR> ComPlus Applications
22/09/2007 09:44 p.m. <DIR> Creative
19/09/2007 10:38 p.m. <DIR> DAZ
24/10/2007 12:23 p.m. <DIR> Deskshare
28/10/2007 10:04 p.m. <DIR> DivX
13/09/2007 06:57 p.m. <DIR> e frontier
24/08/2007 08:11 a.m. <DIR> Elaborate Bytes
27/10/2007 09:52 a.m. <DIR> eMule
09/06/2007 02:40 p.m. <DIR> Eovia
24/10/2007 12:40 p.m. <DIR> FairUse Wizard 2
10/07/2007 02:04 p.m. <DIR> Family Games
10/07/2007 09:44 a.m. <DIR> FreshDevices
01/06/2007 07:16 a.m. <DIR> Google
31/05/2007 05:31 p.m. <DIR> GRETECH
01/09/2007 10:26 a.m. <DIR> Hewlett-Packard
01/09/2007 10:26 a.m. <DIR> HP
29/04/2007 02:07 p.m. <DIR> Intel
14/08/2007 05:55 p.m. <DIR> Internet Explorer
04/08/2007 02:41 p.m. <DIR> Java
11/06/2007 05:13 p.m. <DIR> Lavasoft
10/10/2007 06:52 p.m. <DIR> Live_TV
16/09/2007 08:54 a.m. <DIR> Logitech
29/04/2007 03:18 p.m. <DIR> Messenger
30/04/2007 02:53 a.m. <DIR> microsoft frontpage
05/09/2007 06:58 p.m. <DIR> Microsoft Office
29/04/2007 02:23 p.m. <DIR> Microsoft Visual Studio
29/04/2007 02:23 p.m. <DIR> Microsoft Works
23/09/2007 12:58 p.m. <DIR> Minnetonka Audio Software
30/04/2007 02:51 a.m. <DIR> Movie Maker
20/09/2007 09:05 p.m. <DIR> Mpeg2Decoder
30/04/2007 02:49 a.m. <DIR> MSN
30/04/2007 02:50 a.m. <DIR> MSN Gaming Zone
25/10/2007 04:29 p.m. <DIR> MSN Messenger
29/04/2007 02:04 p.m. <DIR> MSXML 4.0
10/09/2007 06:53 a.m. <DIR> MSXML 6.0
29/04/2007 02:36 p.m. <DIR> Nero
30/04/2007 02:51 a.m. <DIR> NetMeeting
12/06/2007 09:42 p.m. <DIR> Outlook Express
24/10/2007 12:16 p.m. <DIR> Pegasys Inc
27/08/2007 08:00 p.m. <DIR> Pinnacle
08/09/2007 06:43 p.m. <DIR> proDAD
12/08/2007 11:34 a.m. <DIR> QuickTime
19/09/2007 09:19 a.m. <DIR> Recover Files
12/07/2007 02:04 p.m. <DIR> Resource Kit
30/04/2007 02:52 a.m. <DIR> Servicios en línea
26/05/2007 08:22 p.m. <DIR> SlySoft
12/08/2007 11:34 a.m. <DIR> SmartSound Software
05/06/2007 10:10 p.m. <DIR> Tablet
26/09/2007 10:00 p.m. <DIR> Trend Micro
08/06/2007 11:17 p.m. <DIR> Unlocker
03/06/2007 11:25 p.m. <DIR> VideoLAN
11/09/2007 09:33 p.m. <DIR> VS Revo Group
17/09/2007 05:41 p.m. <DIR> WhatsRunning
05/09/2007 06:11 p.m. <DIR> Windows Media Connect 2
29/04/2007 03:20 p.m. <DIR> Windows Media Player
30/04/2007 02:50 a.m. <DIR> Windows NT
05/09/2007 06:12 p.m. <DIR> WinRAR
30/04/2007 02:53 a.m. <DIR> xerox
0 archivos 0 bytes
71 dirs 95,874,088,960 bytes libres
El volumen de la unidad C no tiene etiqueta.
El número de serie del volumen es: 141A-2EE1

Directorio de C:\

25/03/2002 08:52 a.m. 644,976 BootVis.exe
1 archivos 644,976 bytes
0 dirs 95,874,084,864 bytes libres




c:\Documents and Settings\Admin\Configuración local\Archivos temporales de Internet\Content.IE5\SHVFZRWY\vegaspro80-trial_enu[1].exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer2344\Setup.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer2344\redist\WindowsInstaller-KB893803-v2-x86.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer2344\redist\WindowsServer2003-KB898715-ia64-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer2344\redist\WindowsServer2003-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer2344\redist\WindowsServer2003-KB898715-x86-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer2344\redist\WindowsXP-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer3848\Setup.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer3848\redist\WindowsInstaller-KB893803-v2-x86.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer3848\redist\WindowsServer2003-KB898715-ia64-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer3848\redist\WindowsServer2003-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer3848\redist\WindowsServer2003-KB898715-x86-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Installer3848\redist\WindowsXP-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Configuración local\Datos de programa\Mozilla\Firefox\Mozilla Firefox\updates\0\updater.exe
c:\Documents and Settings\Admin\Configuración local\Temp\hwxov0d8.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Installer.exe
c:\Documents and Settings\Admin\Configuración local\Temp\mpeg2decoder.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Div1.tmp\DivXInstaller.exe
c:\Documents and Settings\Admin\Configuración local\Temp\ins1.tmp\LDMClient.exe
c:\Documents and Settings\Admin\Configuración local\Temp\mia143.tmp\setup_blazemp.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher1220\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher1220\StagingArea\11622.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher1376\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher1712\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher1944\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher2184\Installer\PatcherApplication.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher2184\Installer\Required\PatcherApplication.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher2640\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher2824\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher2940\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher2940\StagingArea\6555.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3076\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3076\StagingArea\1393.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3076\StagingArea\1423.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3076\StagingArea\1732.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3152\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3180\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3196\Installer\PatcherApplication.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3196\Installer\Required\PatcherApplication.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3596\Installer\PatcherApplication.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3596\Installer\Required\PatcherApplication.exe
c:\Documents and Settings\Admin\Configuración local\Temp\Patcher\Patcher3880\RTPatch\patch.exe
c:\Documents and Settings\Admin\Configuración local\Temp\{A68BDC76-5178-40D8-A909-96FC2712824D}\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\InstFiles.exe
c:\Documents and Settings\Admin\Configuración local\Temp\{A68BDC76-5178-40D8-A909-96FC2712824D}\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\KT.exe
c:\Documents and Settings\Admin\Configuración local\Temp\{A68BDC76-5178-40D8-A909-96FC2712824D}\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\MSIZap.exe
c:\Documents and Settings\Admin\Configuración local\Temp\{A68BDC76-5178-40D8-A909-96FC2712824D}\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\ShFolder.Exe
c:\Documents and Settings\Admin\Datos de programa\Adobe\Acrobat\7.0\Updater\AdbeRdr709_en_US.exe
c:\Documents and Settings\Admin\Datos de programa\m\flec006.exe
c:\Documents and Settings\Admin\Datos de programa\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
c:\Documents and Settings\Admin\Datos de programa\Microsoft\Installer\{DDA2B32F-EB16-4C96-A130-4E4A4C1E6B12}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
c:\Documents and Settings\Admin\Datos de programa\Sony Setup\64993CD0-67D1-4244-A2BC-FD73F4DA5B62\dotnetfx3.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\catchme.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\diff.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\dumphive.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\find2.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\Fport.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\grep.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\gzip.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\KProcCheck.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\LFiles.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\md5sums.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\pslist.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\streams.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\swreg.exe
c:\Documents and Settings\Admin\Escritorio\DiagHelp\tar.exe
c:\Documents and Settings\Admin\Mis documentos\Cover.exe
c:\Documents and Settings\Admin\Mis documentos\Daz3D - ps_ac1973 - Wildcat Hair 3of3 - DS.exe
c:\Documents and Settings\Admin\Mis documentos\filmerit_30fr.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\QuickZip 2.22 + Crack\quickzip.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\WinAce 2.55 Fr + Key\w25b5_fr.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\WinAce 2.55 Fr + Key\wace25b5i.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\WinRar 3.42 Fr + Crack\wrar342fr.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\WinZip 9.0 Fr + Keygen\Winzip 9.0 Keygen.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\WinZip 9.0 Fr + Keygen\WinZip Patch Fr.exe
c:\Documents and Settings\Admin\Mis documentos\Adobe\WinZip 9.0 Fr + Keygen\Setup Winzip 9.0\SETUP.EXE
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\r_setup.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\Setup.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\SetupAnyDVDHD6170.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\w_setup.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\Keygen\Keygen.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\NetMeeting\SDVC03CAP.EXE
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\NetMeeting\Setup.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\redist\WindowsInstaller-KB893803-v2-x86.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\redist\WindowsServer2003-KB898715-ia64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\redist\WindowsServer2003-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\redist\WindowsServer2003-KB898715-x86-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\redist\WindowsXP-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\Setup.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\Keygen\Keygen.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\redist\WindowsInstaller-KB893803-v2-x86.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\redist\WindowsServer2003-KB898715-ia64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\redist\WindowsServer2003-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\redist\WindowsServer2003-KB898715-x86-enu.exe
c:\Documents and Settings\Admin\Mis documentos\GomPlayer\resources\redist\WindowsXP-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Adobe Photoshop Cs3 10 Activation Crack Serial Keygen.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Adobe.Photoshop.CS3.v10.0.Extended.Keygen.SSG.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\American Hog Motorcycle (Harley).exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Bonez.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Patch.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Pinnacle Liquid Edition 6 Keygen.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Road Hog Action.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Setup.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\Skeleton King.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\vitascene-10-pinstudio-patch.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\redist\WindowsInstaller-KB893803-v2-x86.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\redist\WindowsServer2003-KB898715-ia64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\redist\WindowsServer2003-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\redist\WindowsServer2003-KB898715-x86-enu.exe
c:\Documents and Settings\Admin\Mis documentos\Incoming\redist\WindowsXP-KB898715-x64-enu.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Daz3D - ps_ac1860b - Glorious Hair V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Daz3D - ps_ac1935b - Juni Hair.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Poser 6 KeyGen.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Poser 7 - High Stakes Content Pack.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Poser 7 Setup.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\SpyGirl.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\The Clubbin' Collection for the Girl - ps_ac918b.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\The Dress for the Girl - ps_ac887.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\the Girl 2nd Skins - ps_tx775b.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Victoria 4.1 Base.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Victoria 4.1 Morphs++.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Aphroditeion.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Appliances Pack.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Bareback Rider.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - African Lily.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Dead Bushes.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Grasses & Flowers.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Indian Grass.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Jungle Mist.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Palm Trees.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Petunia.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals - Tropicals.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Botanicals Hanging Plants.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Complex Global Lighting Pack 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Daz3D - ps_tx824b - Lisa's Botanicals - Jungle Mist.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Dystopia City Blocks 001.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Emotimotions.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Fish Tank.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\FlameZ.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Laptop.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Lisa's Botanicals - Gazania.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Lisa's Botanicals - Honeysuckle.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Modern Furniture Add-Ons.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Shoes - Anklewrap Pumps for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Sports Balls Pack.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\The Aquarium.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\The Backstreets Part1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Trilogy Lentes.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Ultimate P6 Lights.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Accesprios\Urban Future.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Animals - Eagle 2.0.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Battle Grade Dragon.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Big Bad Wolf.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Charger Horse.Exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Daz3D - Millenium Horse - Spinebender And Astral Armor - Ps Ac788.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Daz3D - Poseamation Vol 1 - Eagle Motion Pack - Ps Mo003B.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Daz3D - ps_an038 - Tx069 - Charger HorseM.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Daz3D - ps_an080b - Millennium Horse Unicorn.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Daz3D - ps_bn017 - Millennium Horse Bundle.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\'Drago' for Millennium Dragon.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Dragon Action.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Dragon Lord Horse Armor Part 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Dragon Lord Horse Armor Part 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Eagle 2 Animation Pack 1 - Flying.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\East Dragon.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\EastDragonT.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Eastern Jewels.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Gorilla -Poses.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Horse - Equine Textures.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Horse - SpineBender and Astral Armor TX - Ps Tx642.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Horse Texture Pack 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Horse Unicorn.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Horse.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Horseback Combat.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Large Charger Horse Map Pack (4).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\MilBigCatLE.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\MilDrag2 - FireDragon-[1of2].exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Mildrag2Tex1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\MilDrag2Tex2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\MilDragon2T.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millenium Horse Spinebender And Astralarmor Textures 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dog Bundle.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2 part 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2 part 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2 part 3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2 Part 4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2 Textures pt 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2 Textures pt 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon 2.0 Upgrade [an048].exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon Animations - Ps Mo071.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Dragon Textures.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Gorilla.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Horse Bundle.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Horse Texture Pack 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Horse Unicorn Poses 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Millennium Horse Unicorn.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Panthers.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Safari Bundle - ps_bn001.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Silverback Gorilla.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Tyrannosaurus Rex.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Animales\Watercolors Ii.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\3D Celebrity - Belle.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\3D Celebrity Genesis (1of4).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\3D Celebrity Genesis (2of4).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\3D Celebrity Genesis (3of4).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\3D Celebrity Lola.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Ambrosia - Poses for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Calendar Girls for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Celebrity Genesis (4of4).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ac1892b - LostRealms for V4 - Templates.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ac1892b - LostRealms for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ac2016 - Victoria 4.1 Creature Creator Morphs.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ac2017 - Victoria 4.1 Creature Creator – Add Ons (2of3).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ac2017 - Victoria 4.1 Creature Creator – Add Ons (3of3).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ac2017 - Victoria 4.1 Creature Creator - Add Ons 4of4 - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ch154b - Helena for V4 - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_ch154b - Helena for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_mo248b - Ambrosia - Poses for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_mr240b - Grace for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_mr259 - Victoria 4.1 Muscle Morphs.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe069 - Victoria 4 Base - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe069 - Victoria 4 Base -Templates.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe069 - Victoria 4 Base.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe070 - Morphforms to Transforms Scripts.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe070 - Victoria 4 Developer Kit.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe070 - Victoria 4 Morphs++.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_pe070 - Victoria 4.0 Morphs++ DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1276 - Victoria 4 Skin Maps (High Res) - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1276 - Victoria 4 Skin Maps (High Res) (1of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1276 - Victoria 4 Skin Maps (High Res) (2of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1277- Victoria 4 Skin Maps (Std Res) - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1277- Victoria 4 Skin Maps (Std Res).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1279 - Victoria 4 Wet Maps - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1279 - Victoria 4 Wet Maps.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1280b - Emma for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1380 - Victoria 4.1 Muscle Maps 1of3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1380 - Victoria 4.1 Muscle Maps 2of3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - ps_tx1380 - Victoria 4.1 Muscle Maps 3of3 - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - Stephanie 3.0 Petite Base - ps_pe042.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - Victoria 3.0 Body Morphs - ps_mr018.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D - Victoria 3.0 Head Morph Pak - ps_mr017.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\DAZ3D Michael 3.0 Full.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Daz3D V3 M3 Head & Body Morphs - ps_bn039.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Emma for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Grace for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Head Morph Pak.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Heart Of The Jungle.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Helena for V4 - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Helena for V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\m3bodymorphUP.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Michael 3.0 Base Upgrade.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Michael 3.0 Body Morph Pak.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Michael 3.0 Head & Body Morphs.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Millennium Dynamic Deformers.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Morphforms to Transforms Scripts.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Nerd3D - Walk Designer For Victoria 3 P5.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Poser - Daz3D - Renderosity - Playboy Bikini Textures For v3 Bikini.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Poser - Daz3D - Victoria 3 - Morphing Face Mask.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Poser - Daz3D - Victoria 3.0 Base Package - ps_pe036.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\ps_ac421-V3FaceMaskT.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\ps_mo251b_WalkDesignV4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\ps_mr049 - Michael 3.0 Body Morph Pak.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Rayne.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Real Emotions For Victoria 4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Stephanie 3.0 Petite Base - ps_pe042.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Stephanie 3.0 Petite Base 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Stephanie 3.0 Petite Base.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Stephanie 3.0 Petite BaseUp.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Stephanie 3.0 Petite Body Morphs.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Stephanie 3.0 Petite Head Morphs - Ps Mr060.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\SuperStar V4 Base Set [1of2].exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\SuperStar V4 Base Set [2of2].exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\SuperStar V4 Base Set [DS].exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Trixie for the Girl - ps_tx751b.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\update 1 mr017-SR1.1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\update 2 ps_mr017-tthfix.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\V3 Morph Expansion Pak 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\V3 New Generation 2005.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\v4-Brooke [1of2].exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\v4-Brooke Part 2.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\v4-Fanny.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\v4-Lex.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\V4-WyldCatz.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 3 - Morphing Face Mask.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 3.0 Base_SR-1.1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 3.0 Body Morphs - ps_mr018.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 3.0 Body Morphs.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 3.0 Head & Body Morphs 1.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 3.0 Head Morph Pak.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Base - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Base -Templates.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Base.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Developer Kit.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Morphs++.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Skin Maps (High Res) - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Skin Maps (High Res) (1of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Skin Maps (High Res) (2of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Skin Maps (Std Res) - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Skin Maps (Std Res).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Wet Maps - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Wet Maps Ds.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4 Wet Maps.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4.0 Morphs++ DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4.1 Base.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria 4.1 Morphs++.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Morphs\Victoria4 Morphs.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Amante Hair.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Amarseda Hair - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Amarseda Hair - Templates.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Amarseda Hair.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1556b - Ultimate Hair.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1806b - Shigi Hair (1of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1806b - Shigi Hair (2of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1982b - Wild Dreads - Templates.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1982b - Wild Dreads 1of3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1982b - Wild Dreads 2of3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_ac1982b - Wild Dreads 3of3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D - ps_tx824b - Lisa's Botanicals - Jungle Mist.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Daz3D ps_ac1924b Sensual Hair V4.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Gypsy Hair.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Shigi Hair (1of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\Pelos\Shigi Hair (2of2).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\American Pinup Jamie.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\Anghell for V2 and V3.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\AngHell Texture.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\As Shanim - Skorpio Rising.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\Classic Western Collection.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\Daz3D - ps_ac1824 - V4 Basicwear - DS.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\Daz3D - ps_ac1824 - V4 Basicwear - Templates.exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\Daz3D - ps_ac1824 - V4 Basicwear (1of4).exe
c:\Documents and Settings\Admin\Mis documentos\POSER\ropa\Daz3D - ps_ac1824 - V4 Basicwear (2of4).exe
c:
jonas_davidson
 
Messages: 16
Inscription: 28 Oct 2007 17:39

Messagepar Airwave » 29 Oct 2007 16:24

Ca je laisserais pas trop comme ca... Y'a quand meme des trucs louches... de ta part! Moultes Keygen et moultes cracks!
Avatar de l’utilisateur
Airwave
Super Libellulien
Super Libellulien
 
Messages: 1221
Inscription: 21 Juin 2003 16:31
Localisation: Geneve

Messagepar Falkra » 29 Oct 2007 16:28

Il manque la fin du rapport, mais je vois une infection par le virus Bagle.

Télécharge Elibagla ici (en bas de page) :
http://www.zonavirus.com/datos/descarga ... ibagla.asp
Clique sur le bouton Descargar Elibagla cela va télécharger le fichier, place le sur le bureau.
Double-clique dessus pour l'ouvrir
Assure-toi que dans le menu déroulant Unidad, tu as bien C:\
Vérifie aussi que l'option en bas de la fenêtre Eliminar Ficheros Automaticamente est bien cochée
Clique sur le bouton Explorar pour lancer l'analyse


Après, télécharge ce fichier reg et double clique dessus pour l'ajouter au registre :
http://www.malekal.com/download/SafeBoot.reg
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

cpu 100%

Messagepar jonas_davidson » 29 Oct 2007 17:44

bonsoir


merci falkra j'ai deja elimine le bagle mais l'explorer.exe continue au 100%
que nous pouvons faire pour le baisse


merci
jonas_davidson
 
Messages: 16
Inscription: 28 Oct 2007 17:39

Messagepar Falkra » 29 Oct 2007 17:51

Le fichier suivant est un reste de Bagle alors, Elibagla l'éliminera proprement, lui et d'autres restes :
C:\WINDOWS\system32\drivers\srosa.sys
Je te recommande donc de nettoyer avec cet outil dans un premier temps.

Côté antivirus, un scan complet avec antivir serait une option, mais tu as déjà un antivirus (payant) en place, il faudrait le désactiver le temps d'un scan complet avec Antivir.
Tuto : http://www.libellules.ch/tuto_antivir.php

Bagle infeste de cracks les dossiers mes documents, à éliminer également, mais Antivir fera le tri lui-même.
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

cpu 100%

Messagepar jonas_davidson » 30 Oct 2007 01:39

bonjour


Merci Falkra ça y est, j'ai réussi , il y avait une bonne vingtaine de saletés . Je continue avec mon antivirus qui s'appelle CA anti-virus ou ANTIVIR ??
Merci encore , tu es le meilleur !
jonas_davidson
 
Messages: 16
Inscription: 28 Oct 2007 17:39

Messagepar Falkra » 30 Oct 2007 12:12

S'il n'y avait que moi pour choisir, ce serait Antivir sans aucun doute, et tout seul, c'est à dire désinstaller l'autre antivirus.

Par contre attention, si tu as une suite complète, il faut après trouver un firewall de remplacement. Kerio ou Jetico sont de bons choix.

Plus de cpu à 100% ?
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1


Retourner vers Désinfections et demandes d'analyse

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 1 invité