Pb virus virtumonde

Fermé
koonan74 - 7 janv. 2009 à 13:09
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 - 9 janv. 2009 à 21:55
Bonjour, et merci d avance j ai un soucis depuis quelque jour, après avoir effectué un scan avec spybot j ai découvert que j étais infecter par un virus virtumonde, j ai essayé de le supprimer mais impossible et depuis a chaque démarrage j ai une fenêtre qui s ouvre et me dit "impossible de charger programme rundll32 "D:\WINDOWS\system32\jodilose.dll" ,s donc si quelqu'un peut m aider cela serait cool merci d avance
A voir également:

7 réponses

jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
7 janv. 2009 à 13:11
slt,

installe malwarebyte puis mets le a jour puis colle un rapport avec
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/


________________

puis


Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

NB : Les rapports sont sauvegardés dans le dossier C:\rsit
0
d abord merci donc voila le rapport de malwarebytes, par contre j ai oublié de le faire en mode sans échec donc si tu veux je le refais? :

Malwarebytes' Anti-Malware 1.32
Version de la base de données: 1628
Windows 5.1.2600 Service Pack 3

07/01/2009 19:20:27
mbam-log-2009-01-07 (19-20-27).txt

Type de recherche: Examen complet (D:\|)
Eléments examinés: 101950
Temps écoulé: 58 minute(s), 3 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 4
Elément(s) de données du Registre infecté(s): 3
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 19

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
D:\WINDOWS\system32\kiratero.dll (Trojan.Vundo.H) -> Delete on reboot.
D:\WINDOWS\system32\wahewuvu.dll (Trojan.Vundo.H) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5b0b7700-6a02-4f43-be11-eabb8868f2d8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5b0b7700-6a02-4f43-be11-eabb8868f2d8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5b0b7700-6a02-4f43-be11-eabb8868f2d8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wesiwobife (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm9fff7092 (Trojan.Agent) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: d:\windows\system32\kiratero.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: d:\windows\system32\kiratero.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\kiratero.dll -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
D:\WINDOWS\system32\wahewuvu.dll (Trojan.Vundo.H) -> Delete on reboot.
D:\WINDOWS\system32\kiratero.dll (Trojan.Vundo.H) -> Delete on reboot.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP280\A0043633.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP280\A0043634.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP283\A0043894.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP283\A0043895.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP283\A0043948.0ll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP283\A0043949.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP284\A0043956.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP284\A0043957.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP285\A0044009.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP285\A0044010.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\rekowuwu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\safutali.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\wadubebe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\wupudihi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\zapezigo.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\dipagowe.0ll (Trojan.Vundo) -> Quarantined and deleted successfully.
d:\WINDOWS\system32\yoyorena.dll (Trojan.Agent) -> Delete on reboot.

maintenant voila les rapports de RSIT.exe:

abord le log:

Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrateur at 2009-01-07 19:25:47
Microsoft Windows XP Professionnel Service Pack 3
System drive D: has 14 GB (18%) free of 80 GB
Total RAM: 2046 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:25:55, on 07/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\FSGK32.EXE
D:\WINDOWS\System32\FTRTSVC.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FSMB32.EXE
D:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\system32\PnkBstrB.exe
D:\Program Files\Spyware Terminator\sp_rsser.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FCH32.EXE
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
D:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
D:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
D:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Documents and Settings\Administrateur\Bureau\RSIT.exe
D:\Program Files\trend micro\Administrateur.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - D:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - D:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - D:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [LXCGCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [F-Secure Manager] "D:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "D:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [XboxStat] "D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "D:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" boot "D:\Documents and Settings\Administrateur\Local Settings\Application Data\NVIDIA Corporation\nTune\Profiles\osbootpf.nsu"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [wesiwobife] Rundll32.exe "D:\WINDOWS\system32\jodilose.dll",s (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://orange.securitoo.com/ols/fscax.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - D:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: d:\windows\system32\ d:\windows\system32\defadegi.dll d:\windows\system32\gadonesi.dll d:\windows\system32\yoyorena.dll
O23 - Service: ASKService - Unknown owner - D:\Program Files\AskBarDis\bar\bin\AskService.exe (file missing)
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - D:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - D:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - D:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: lxcg_device - - D:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - D:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - D:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - D:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - D:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
7 janv. 2009 à 20:17
télécharge combofix (par sUBs) ici :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

et enregistre le sur le bureau.

déconnecte toi d'internet et ferme toutes tes applications.

désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)


double-clique sur combofix.exe et suis les instructions

à la fin, il va produire un rapport C:\ComboFix.txt

réactive ton parefeu, ton antivirus, la garde de ton antispyware

copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

Tu as un tutoriel complet ici :

https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

____________________

a plus
0
c est fait voila le rapport combofix:

ComboFix 09-01-07.01 - Administrateur 2009-01-07 20:40:03.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2046.1515 [GMT 1:00]
Lancé depuis: d:\documents and settings\Administrateur\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé

[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\Administrateur\Application Data\inst.exe
d:\windows\system32\elemalov.ini
d:\windows\system32\ihizunad.ini
d:\windows\system32\omiguweg.ini

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-07 au 2009-01-07 ))))))))))))))))))))))))))))))))))))
.

2009-01-07 18:36 . 2009-01-07 19:26 <REP> d-------- D:\rapport
2009-01-07 18:34 . 2009-01-07 18:35 <REP> d-------- D:\rsit
2009-01-07 18:34 . 2009-01-07 19:25 <REP> d-------- d:\program files\trend micro
2009-01-07 18:06 . 2009-01-07 18:06 <REP> d-------- d:\program files\Malwarebytes' Anti-Malware
2009-01-07 18:06 . 2009-01-07 18:06 <REP> d-------- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-07 18:06 . 2009-01-07 18:06 <REP> d-------- d:\documents and settings\Administrateur\Application Data\Malwarebytes
2009-01-07 18:06 . 2009-01-04 18:39 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2009-01-07 18:06 . 2009-01-04 18:39 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2009-01-06 18:27 . 2009-01-07 20:34 <REP> d-------- d:\program files\Spybot - Search & Destroy
2009-01-03 14:56 . 2009-01-03 14:56 211 --a------ d:\windows\wininit.ini
2009-01-03 14:37 . 2009-01-03 14:38 <REP> d-------- d:\documents and settings\All Users\Application Data\Lavasoft
2009-01-03 14:21 . 2009-01-07 20:33 <REP> d-------- d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-31 14:57 . 2002-12-12 00:14 1,294,336 --a--c--- d:\windows\system32\dllcache\dsound3d.dll
2008-12-31 14:20 . 2008-12-31 14:20 <REP> d-------- d:\program files\Midway Games
2008-12-27 18:46 . 2008-12-27 18:46 0 --ah----- d:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2008-12-27 18:45 . 2007-02-27 02:15 1,421,216 --a------ d:\windows\system32\WdfCoInstaller01001.dll
2008-12-27 18:45 . 2007-02-27 02:15 61,984 --a------ d:\windows\system32\drivers\xusb21.sys
2008-12-27 18:44 . 2008-12-27 18:45 <REP> d-------- d:\program files\Microsoft Xbox 360 Accessories
2008-12-19 18:41 . 2008-12-19 18:41 <REP> d-------- d:\documents and settings\Administrateur\Application Data\SEGA
2008-12-18 19:01 . 2008-12-18 19:01 199 --a------ D:\DARE.INI
2008-12-15 19:12 . 2008-12-15 19:12 <REP> d-------- d:\documents and settings\All Users\Application Data\Ubisoft
2008-12-15 19:12 . 2008-12-15 19:12 <REP> d-------- d:\documents and settings\All Users\Application Data\InstallShield
2008-12-15 19:03 . 2008-12-15 19:03 <REP> d-------- d:\program files\Ubisoft
2008-12-15 19:03 . 2007-04-27 10:12 78,784 --a------ d:\windows\system32\ISUSPM.cpl
2008-12-14 17:21 . 2008-12-14 17:21 1,700,352 --a------ d:\windows\system32\gdiplus.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 19:33 --------- d-----w d:\program files\Wanadoo
2009-01-07 19:33 --------- d-----w d:\program files\Lx_cats
2009-01-04 22:49 --------- d-----w d:\program files\SpeedFan
2009-01-04 22:48 --------- d-----w d:\documents and settings\Administrateur\Application Data\Azureus
2009-01-04 18:11 --------- d-----w d:\program files\CCleaner
2009-01-03 14:23 --------- d-----w d:\program files\Fichiers communs\Wise Installation Wizard
2009-01-01 23:26 --------- d-----w d:\documents and settings\Administrateur\Application Data\dvdcss
2008-12-31 13:20 --------- d--h--w d:\program files\InstallShield Installation Information
2008-12-25 20:57 --------- d-----w d:\documents and settings\Administrateur\Application Data\Vso
2008-12-25 17:52 --------- d-----w d:\program files\Pcsx2_0.9.4
2008-12-15 18:12 --------- d-----w d:\documents and settings\Administrateur\Application Data\InstallShield
2008-12-15 18:03 --------- d-----w d:\program files\Fichiers communs\InstallShield
2008-12-09 16:32 --------- d-----w d:\documents and settings\Administrateur\Application Data\vlc
2008-12-08 12:07 --------- d-----w d:\program files\AGEIA Technologies
2008-12-03 21:41 --------- d-----w d:\program files\Microsoft Games for Windows - LIVE
2008-12-03 20:34 --------- d-sh--w d:\documents and settings\All Users\Application Data\SecuROM
2008-12-03 18:35 --------- d-----w d:\program files\Rockstar Games
2008-12-03 18:18 --------- d-----w d:\program files\MSBuild
2008-12-03 18:14 --------- d-----w d:\program files\Reference Assemblies
2008-12-02 09:13 453,152 ----a-w d:\windows\system32\NVUNINST.EXE
2008-12-01 18:37 --------- d-----w d:\documents and settings\Administrateur\Application Data\Logitech
2008-12-01 18:36 --------- d-----w d:\program files\Fichiers communs\Logishrd
2008-12-01 18:36 --------- d-----w d:\documents and settings\Administrateur\Application Data\Leadertech
2008-12-01 18:35 0 ---ha-w d:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-01 18:35 0 ---ha-w d:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-12-01 18:35 0 ---ha-w d:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-12-01 18:33 --------- d-----w d:\documents and settings\All Users\Application Data\Logitech
2008-12-01 18:32 --------- d-----w d:\program files\Logitech
2008-12-01 18:32 --------- d-----w d:\documents and settings\All Users\Application Data\LogiShrd
2008-11-22 13:10 --------- d-----w d:\program files\Azureus
2008-11-20 21:50 --------- d-----w d:\program files\Doomsday
2008-11-12 22:36 --------- d-----w d:\program files\MSXML 4.0
2008-10-28 16:41 14,303,392 ----a-w d:\windows\system32\xlive.dll
2008-10-28 16:41 13,643,936 ----a-w d:\windows\system32\xlivefnt.dll
2008-10-23 12:36 286,720 ----a-w d:\windows\system32\gdi32.dll
2008-10-22 16:31 66,872 ----a-w d:\windows\system32\PnkBstrA.exe
2008-10-22 16:31 22,328 ----a-w d:\documents and settings\Administrateur\Application Data\PnkBstrK.sys
2008-10-22 16:31 2,250,024 ----a-w d:\windows\system32\pbsvc.exe
2008-10-22 16:31 107,832 ----a-w d:\windows\system32\PnkBstrB.exe
2008-10-16 13:13 202,776 ----a-w d:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w d:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w d:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w d:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w d:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w d:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w d:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w d:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w d:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w d:\windows\system32\muweb.dll
2008-10-13 08:56 70,936 ----a-w d:\windows\system32\PhysXLoader.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelTraditionalChinese.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelSwedish.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelSpanish.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelSimplifiedChinese.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelPortugese.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelKorean.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelJapanese.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelGerman.dll
2008-10-07 08:13 58,648 ----a-w d:\windows\system32\AgCPanelFrench.dll
2008-10-07 08:13 288,024 ----a-w d:\windows\system32\PhysXCplUI.exe
2008-10-07 08:13 288,024 ----a-w d:\windows\system32\PhysXCompatCplUI.exe
2008-10-07 08:13 23,320 ----a-w d:\windows\system32\PhysXDevice.dll
2008-09-07 12:12 94,208 ----a-w d:\documents and settings\Administrateur\Application Data\ezplay.sys
2008-07-06 09:05 47,360 ----a-w d:\documents and settings\Administrateur\Application Data\pcouffin.sys
2008-06-07 10:39 278,528 ----a-w d:\program files\Fichiers communs\FDEUnInstaller.exe
1601-01-01 00:12 6,144 --sha-w d:\windows\system32\dofodiro.dll
1601-01-01 00:12 102,912 --sha-w d:\windows\system32\rufupiba.dll
1601-01-01 00:12 1,024 --sha-w d:\windows\system32\ruhefife.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"NVIDIA nTune"="d:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-08-18 106496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCGCATS"="d:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"F-Secure Manager"="d:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2007-06-13 176177]
"F-Secure TNB"="d:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2007-06-13 733184]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-12-02 13680640]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-12-02 86016]
"XboxStat"="d:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-28 d:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-12-02 d:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 d:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 10:10 72208 d:\program files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\D:^Documents and Settings^Administrateur^Menu Démarrer^Programmes^Démarrage^Enregistrement de produit Logitech.lnk]
path=d:\documents and settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Enregistrement de produit Logitech.lnk
backup=d:\windows\pss\Enregistrement de produit Logitech.lnkStartup

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
backup=d:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-04-01 10:39 486856 d:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcgmon.exe]
--a------ 2005-07-21 07:07 200704 d:\program files\Lexmark 2300 Series\lxcgmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 10:34 5724184 d:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 d:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
--a------ 2004-08-23 13:50 122880 d:\progra~1\Wanadoo\Shell.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
--------- 2004-10-14 15:55 32768 d:\progra~1\Wanadoo\GestMAJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--------- 2004-08-23 13:49 20480 d:\progra~1\Wanadoo\Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"CamserviceDP"=d:\program files\Hercules\DualPix Exchange\Camservice.exe /startup
"EzPrint"="d:\program files\Lexmark 2300 Series\ezprint.exe"
"FaxCenterServer"="d:\program files\Lexmark Fax Solutions\fm3032.exe" /s

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Azureus\\Azureus.exe"=
"d:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\Program Files\\Ubisoft\\Shaun White Snowboarding\\ShaunWhiteSnowboardingGame.exe"=
"d:\\Program Files\\Ubisoft\\Shaun White Snowboarding\\ShaunWhiteSnowboarding.exe"=
"d:\\Program Files\\Midway Games\\Stranglehold\\Binaries\\Retail-Stranglehold.exe"=
"d:\\Program Files\\Orange\\AntivirusFirewall\\Anti-Virus\\fsav32.exe"=
"d:\\Program Files\\NVIDIA Corporation\\System Update\\UpdateCenterService.exe"=
"d:\\Program Files\\Orange\\AntivirusFirewall\\Anti-Virus\\fsqh.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25865:TCP"= 25865:TCP:BitComet 25865 TCP
"25865:UDP"= 25865:UDP:BitComet 25865 UDP
"17132:TCP"= 17132:TCP:BitComet 17132 TCP
"17132:UDP"= 17132:UDP:BitComet 17132 UDP

R0 FSFW;F-Secure Firewall Driver;d:\windows\system32\drivers\fsdfw.sys [2008-07-20 51072]
R1 F-Secure HIPS;F-Secure HIPS;d:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [2008-07-20 41184]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;d:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [2008-07-20 52736]
R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;d:\windows\system32\drivers\sis163u.sys [2008-06-07 215552]
S3 camfilt2;camfilt2;d:\windows\system32\drivers\camfilt2.sys [2008-06-28 94208]
S3 Video3D;ASUS Video3D Service;d:\windows\system32\Drivers\Video3D32.sys --> d:\windows\system32\Drivers\Video3D32.sys [?]
S4 ASKService;ASKService;d:\program files\AskBarDis\bar\bin\AskService.exe --> d:\program files\AskBarDis\bar\bin\AskService.exe [?]
S4 F-Secure Filter;F-Secure File System Filter;d:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [2008-07-20 33024]
S4 F-Secure Recognizer;F-Secure File System Recognizer;d:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [2008-07-20 18432]
.
Contenu du dossier 'Tâches planifiées'

2009-01-07 d:\windows\Tasks\Scheduled scanning task.job
- d:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2007-06-13 14:58]
.
- - - - ORPHELINS SUPPRIMES - - - -

MSConfigStartUp-wesiwobife - d:\windows\system32\modubelo.dll


.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=%s
IE: { - d:\program files\Messenger\msmsgs.exe
FF - ProfilePath - d:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\g3j8tzgy.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
FF - component: d:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: d:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: d:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: d:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-07 20:47:23
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 d:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\Administrator\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
"??"=hex:8c,dc,e5,ac,02,20,a3,b3,e1,74,73,32,65,a7,91,28,4f,65,a4,aa,d7,89,87,\
e8,7b,43,39,72,6b,71,4f,50,06,b8,10,b4,bf,f8,0e,44,0a,9b,78,a8,77,13,3a,48,\
17,1f,be,bd,db,76,1d,a6,a6,f0,42,05,04,15,80,5b,91,41,1b,a2,39,26,e7,81,2e,\
cb,9c,11,01,f2,33,07,9a,f6,58,e9,41,f5,38,57,8e,02,00,ef,0c,34,bf,88,4e,4e,\
50,a9,35,26,49,c8,05,47,e7,6a,b4,d7,83,68,db,46,f2,3f,6d,f5,83,bb,10,0e,fb,\
a1,9b,71,81,20,44,0b,7f,9f,e0,9c,75,1d,ba,f8,bd,0f,8a,36,db,f8,47,eb,15,0a,\
18,72,6b,d9,2e,5a,4b,e9,56,a8,8c,0d,59,92,7e,3b,cc,9c,6e,33,31,91,9e,e6,f0,\
d6,9f,cb,66,b1,08,23,1a,8a,ef,a1,04,50,84,1d,7c,3a,31,7d,18,e6,13,63,c5,50,\
de,c1,e1,a9,2f,72,77,2e,f7,51,f2,9d,84,bb,3a,84,50,da,91,b2,14,be,dc,06,66,\
16,50,fa,6b,21,a9,13,dc,fd,ac,c1,11,2a,70,98,d6,9a,7d,1c,1e,11,8f,85,86,9c,\
20,83,7e,8a,4d,c1,e6,b6,70,7a,6b,76,b7,e5,7b,7e,bf,4c,ed,eb,bb,8e,ce,b4,95,\
5d,7a,8d,e1,fa,f0,96,6a,f2,5a,0d,d6,87,70,19,f6,04,c8,f9,b7,e5,b4,cb,f1,e6,\
d3,ae,94,a8,98,0a,0a,3d,94,b2,32,ca,1a,04,25,fb,34,ec,3f,2a,ef,07,12,2b,b7,\
a4,86,e1,1b,95,c7,c2,5c,4b,25,dc,b7,1f,31,49,14,1b,5a,bc,94,ea,c9,7a,55,0c,\
31,f9,82,18,1e,6c,51,eb,9f,79,63,21,21,00,05,bb,8b,0f,2c,19,00,66,a5,16,04,\
e2,25,44,09,e6,b3,f5,81,9d,37,34,53,3b,d0,8f,72,a5,20,3c,e3,10,6b,60,34,50,\
c5,b1,ca,6b,44,5b,66,72,42,6c,50,32,86,fe,41,bc,28,d4,43,c6,03,1e,74,e0,a2,\
6f,59,d3,cc,6b,c2,d7,c6,d0,69,6f,50,5f,00,29,e9,6c,1a,14,a1,63,8c,c5,89,2a,\
47,db,88,52,71,a0,79,f9,50,97,19,b8,ae,9e,94,b1,23,5f,b1,85,dd,c5,c1,a0,e5,\
25,4f,94,42,30,1e,75,b0,0e,8f,97,5b,7c,a0,50,c5,31,e2,44,94,8c,a9,ed,9f,cf,\
31,39,6b,25,86,90,53,6a,25,da,59,bf,45,44,77,ef,68,40,4f,ec,86,71,e0,c8,4e,\
a1,fd,4c,9d,9e,de,29,f3,8e,82,9a,ab,75,ff,30,bf,44,cd,48,2c,c5,eb,85,61,20,\
7f,e7,49,3a,f5,45,f9,8d,06,99,3f,fd,ed,20,66,70,86,f7,83,c4,5d,72,df,e8,3e,\
d0,1b,58,0b,ff,84,3b,4f,4b,a7,24,49,eb,c4,f8,16,55,53,60,7a,79,51,49,eb,27,\
ba,a7,25,d3,d7,9d,18,b7,92,31,03,4a,c2,6d,99,3c,17,8c,aa,12,91,fc,87,e6,36,\
ec,35,23,77,12,b3,e1,f9,44,e0,e3,9f,b2,40,9e,77,65,79,ad,78,bc,aa,f6,d5,b6,\
2b,b0,ff,13,f9,7b,d6,4b,5c,54,eb,55,e1,61,c5,fc,ab,30,4d,90,42,f4,68,f5,cf,\
6e,f1,1b,4e,f1,b1,00,9d,c5,2f,94,60,20,e6,05,d7,ec,b2,57,56,f4,86,13,67,35,\
8d,b4,50,6e,0a,e3,f1,f2,d8,13,57,21,cb,b6,3a,ca,56,f6,20,f5,af,e9,e5,96,35,\
18,d1,96,a8,bf,e6,da,00,50,0e,5a,dc,5b,ca,0c,a1,5c,74,e2,6d,1b,db,5e,34,7f,\
3b,05,2c,00,1b,7d,99,64,e3,c9,55,46,f9,89,f3,40,42,48,73,d2,06,f0,1d,b1,46,\
1b,64,55,8e,d9,57,31,9d,ae,d9,b1,84,50,89,ec,80,05,e7,63,64,c8,ca,a7,3e,f8,\
f1,f7,9a,5c,c8,f5,49,8b,f8,81,da,b2,88,8d,64,b3,97,8c,8c,45,3d,13,b3,c2,8f,\
f8,92,45,06,1d,f0,02,6a,3a,b2,42,e3,53,6b,58,37,db,31,28,6c,48,5b,5b,0f,c8,\
b8,b1,da,4e,10,2f,02,4b,5a,94,82,ee,5c,74,19,d8,9c,c1,ee,d1,1c,dc,8b,13,6e,\
c4,78,62,b6,57,c8,af,d1,9d,55,02,4f,12,1e,02,13,cc,27,ce,8f,3a,73,0b,93,f4,\
17,e2,65,d7,65,a9,72,1c,54,98,68,f7,ab,fb,c6,46,1a,64,2b,e1,c9,df,56,96,8e,\
be,8a,b2,f6,8d,cd,9a,2c,3a,a3,a1,ba,c0,e7,62,5a,a6,a2,28,fd,59,89,ca,5d,6c,\
1d,1c,45,03,4d,5b,ab,92,08,26,7b,6d,e2,9e,ba,12,1e,4f,50,99,2f,fb,7f,ec,ff,\
9f,1c,e1,de,a6,6e,f0,05,31,44,02,b4,0a,64,21,7b,7b,e7,c2,c5,49,4b,e5,94,54,\
25,c3,97,fb,ce,55,32,46,9c,dc,8d,b7,6f,e3,8e,72,3a,37,58,5a,ed,87,9d,4c,53,\
71,f0,f1,1a,dd,be,cb,39,8c,a3,02,c1,53,7f,be,c7,f3,3b,22,06,94,c4,13,be,b0,\
34,cf,0d,5b,63,30,32,86,6c,70,b5,3d,2c,80,a8,97,93,aa,71,7f,6a,18,b8,cb,79,\
0a,85,0a,04,f1,1d,d7,74,d4,75,3b,ca,63,7b,cf,d6,0f,c0,66,99,5f,ce,78,b6,3a,\
04,d0,93,40,87,24,d4,a8,aa,13,ef,3a,72,c4,07,64,c2,26,7f,bb,c5,6c,67,46,90,\
ca,6b,fe,26,2f,55,7c,73,f1,81,e6,7a,a4,40,55,21,10,69,e9,1f,e9,56,68,9b,ec,\
b3,6c,dd,51,ef,6a,59,28,6f,40,f4,74,2d,fb,98,26,4a,b8,6a,7e,06,07,07,b1,2a,\
d3,67,f6,eb,ea,eb,18,8f,a5,4f,49,fc,d7,c1,11,89,b2,93,75,b6,00,05,05,ed,db,\
ce,05,3c,e3,f6,c4,8d,a1,19,09,b3,25,18,f1,0b,c4,34,60,10,d4,80,76,9e,6a,67,\
3e,10,15,a2,08,20,cc,4e,67,2c,5f,72,32,0c,9d,73,4e,28,17,38,1c,c5,b9,44,c9,\
39,2c,d3,fd,7f,37,a0,94,f2,4c,8e,d9,c8,0b,de,22,3d,33,e8,ed,a6,31,7c,6f,3e,\
2c,e0,e4,58,6b,2f,07,37,18,e9,be,e3,9e,d3,d6,98,a4,b7,8b,06,b0,39,fc,96,ac,\
38,94,57,2b,cb,c3,3a,c2,a9,ff,9d,04,60,8d,19,c6,9e,34,ba,f8,41,93,5b,96,74,\
41,17,2e,bb,48,f9,dd,8a,b8,2c,25,b2,1f,0a,6f,ae,c8,2b,1a,b5,63,fc,d3,1c,62,\
08,47,14,d8,d8,3b,8c,c7,6a,5b,61,4a,4e,5f,06,0d,e9,f8,06,e3,5e,19,e7,ae,6f,\
87,07,26,6b,9e,ea,a0,7e,9d,78,df,19,93,f1,4c,77,6d,2d,37,43,27,36,e0,93,db,\
60,0c,10,d4,23,71,cf,39,9c,3b,6d,36,da,37,b5,b1,bc,5f,60,8b,3a,e6,f2,96,b2,\
bd,cf,fe,fc,3f,5c,43,db,9b,19,ce,71,cc,4b,c4,d4,79,5b,19,d1,c3,68,d0,e2,91,\
ff,a0,35,bd,b0,4f,3d,78,bc,25,10,40,13,c1,2c,02,03,02,c3,b0,f7,a5,32,a5,a9,\
46,ce,99,1e,23,45,23,c1,e0,cf,93,a5,9d,10,5b,41,00,f9,31,80,87,25,22,74,94,\
46,d4,1e,18,93,cb,4d,46,f5,00,e2,2b,a3,3c,d8,b9,32,0e,0f,c8,21,ce,29,e2,81,\
85,4a,c4,2e,44,9b,de,ed,9e,c3,79,17,33,e6,95,e4,b0,a1,d7,f7,9e,f7,0a,83,2f,\
95,1b,8c,66,56,36,a0,f1,9a,41,4d,c9,24,f6,55,92,34,ee,13,c4,6e,c7,12,d2,98,\
61,ba,4a,97,50,df,be,2d,18,ac,7b,88,6d,ae,4e,c3,73,67,c1,ae,77,40,7c,3a,6a,\
c9,34,91,2b,9d,f5,2a,c2,12,bc,6d,b4,bb,b4,4d,4f,4c,d9,f7,58,3a,b2,ea,c3,25,\
2e,f0,d0,2b,af,13,f9,4f,9b,c8,8e,4e,cb,db,77,29,8e,94,10,82,ed,32,50,71,4f,\
59,a9,29,8a,f7,d3,96,aa,51,b4,33,13,c7,08,08,80,62,67,10,09,4c,1c,0a,fc,96,\
92,36,67,ae,7b,1a,91,aa,9a,6d,7e,4c,fd,14,30,fb,08,74,d7,a4,1c,32,60,76,bf,\
72,33,0e,ca,f4,f1,fc,56,8b,eb,6d,50,9e,b2,34,f5,f8,b9,67,ad,0f,81,62,74,19,\
97,6f,6f,52,9d,97,4b,6d,36,06,7c,07,ca,9c,16,3b,2b,6c,90,b4,55,ec,66,1d,7e,\
92,24,40,a4,6a,12,8a,05,d4,a5,39,67,31,2f,15,07,bf,2b,b0,61,59,97,f9,22,02,\
d7,e5,40,bf,db,cd,3e,dc,79,5d,da,b2,a7,08,8b,4d,8b,7f,0a,b3,a9,9f,43,7a,e4,\
a6,19,72,7f,61,04,1e,af,4a,27,90,74,b6,da,f8,4b,43,3e,78,c3,0c,a7,20,a9,b2,\
5d,cb,0c,7f,7f,21,22,63,2d,c7,30,8e,37,a2,96,43,ac,cf,d8,91,c4,dc,ea,23,bd,\
96,aa,ed,99,99,f5,bd,22,59,38,e6,4b,78,e0,7d,37,f3,8b,42,3d,ca,3f,0c,2d,42,\
13,89,99,d0,e1,58,73,7f,29,52,f9,bd,02,9e,a8,49,46,2d,89,79,e7,4b,36,93,ba,\
06,5c,e4,eb,89,87,88,60,3c,63,af,08,ad,a3,0e,f4,94,c0,ad,fc,3d,45,87,66,af,\
50,a5,3c,e7,ed,5d,cb,f0,04,cc,68,55,7e,c2,68,80,75,ff,bb,9b,f2,7d,16,dd,9d,\
dc,e1,7f,e6,34,10,84,b4,62,8c,26,f1,98,f8,fa,cd,ba,f1,e7,8e,60,09,a2,3b,8f,\
c1,dc,3f,c8,77,6c,33,c3,91,c0,60,8e,93,c7,52,1d,16,ca,cb,c8,42,68,34,71,cd,\
48,03,11,cd,bc,06,0e,a1,e9,42,94,bf,24,a8,3d,a0,e0,e4,22,65,61,4b,09,1a,e6,\
11,ec,d9,09,4f,64,cb,2b,78,22,02,85,f1,2a,4a,90,62,3c,96,f1,e3,19,7c,1d,2b,\
f4,f2,37,71,a9,18,ca,a2,22,03,2b,38,93,25,19,f0,b2,3e,df,1d,5b,c7,0b,a2,52,\
4d,d8,a8,f5,11,64,2e,e2,14,99,c1,01,48,9e,8a,8b,27,b0,3f,38,6d,57,89,c9,ca,\
b8,0a,95,49,ec,94,58,05,96,54,d3,96,a5,93,ca,7e,b6,16,56,18,d2,f5,01,46,84,\
a4,cf,b6,54,81,22,e7,fb,45,ec,a5,31,46,2a,32,f3,d1,da,b9,47,e3,cd,e3,e5,ec,\
3c,5a,2c,23,84,86,0b,e2,ee,77,18,24,52,34,89,4f,98,df,d6,54,87,bc,ee,6d,00,\
0d,d9,0f,cc,25,50,88,3d,7f,88,b1,26,ae,14,bb,44,46,d8,51,bb,ab,18,a0,06,6c,\
fd,e4,46,3f,d1,09,89,4b,53,ae,47,a9,ca,b0,57,30,a7,5b,3c,a3,c6,07,89,32,20,\
26,c9,b7,ab,48,a1,5a,17,a9,28,d3,84,70,2c,9d,2d,63,1b,8d,de,79,9a,e0,1f,e5,\
a7,eb,5c,93,83,9a,5e,88,a6,2f,c9,c6,34,9c,28,53,a8,4b,6c,44,eb,fb,95,5c,7c,\
3f,96,76,0a,26,52,ed,78,d7,17,cd,7e,43,31,4e,78,7b,44,46,9b,a3,5a,b6,a9,df,\
38,5f,7d,fe,c4,c6,83,26,94,8b,a1,a6,94,c1,3c,42,18,71,27,30,21,87,7f,8c,fc,\
98,f6,98,5e,94,77,57,b5,43,a6,33,0f,e6,13,6d,fb,0f,cc,28,74,94,b3,84,ab,71,\
0d,65,a2,85,76,4c,58,6e,5b,0f,28,11,40,7e,0f,ce,51,e3,28,90,3c,2e,9f,14,2f,\
7a,fe,c3,a9,3a,e5,1f,a5,f2,7c,9b,5c,6f,0f,d7,7e,b6,8f,e1,e3,6f,48,58,67,a4,\
8c,a2,86,a0,80,14,48,61,8f,c6,fb,42,85,3c,c1,d4,4d,ac,3a,ee,df,9f,fc,23,1f,\
91,cc,5c,30,a0,ef,26,29,60,1d,e4,85,96,48,f2,b8,ad,c0,c4,32,49,7b,bc,44,af,\
b5,95,a5,e3,4e,9e,dd,18,d7,f0,04,88,a3,71,88,87,c6,6b,2e,9f,a2,fb,32,fe,25,\
a2,5b,cb,97,cb,23,d5,a7,07,e5,ea,de,31,a6,99,d8,a3,ad,a1,f5,b6,09,db,8e,10,\
fb,b0,cc,9c,77,12,35,0a,5b,04,68,f4,7f,dd,59,af,1c,ab,96,14,17,26,b1,21,34,\
66,0f,20,74,88,a3,75,2f,16,f4,12,57,43,87,4f,9a,a7,03,1d,b0,5e,a4,8f,37,2e,\
5f,ba,dd,b8,69,e8,d7,cb,95,8f,0e,86,99,11,43,54,6c,6b,0e,23,31,4f,92,17,58,\
54,7e,eb,a5,cf,65,50,a2,ef,8b,92,f1,de,09,eb,cd,8c,46,2b,e0,cb,2d,e1,4d,33,\
ea,01,cc,e9,2d,16,5b,38,a9,fb,2e,af,fb,e3,e7,1b,64,0a,35,a1,39,8f,cf,4d,32,\
49,53,50,41,c7,e5,6b,34,16,fb,ab,d4,9b,e1,c8,0e,b7,17,06,95,cc,b5,bb,41,d0,\
ca,46,bb,9e,b5,08,2f,92,50,86,f8,a4,3e,e8,a4,20,ec,da,73,fa,c4,3a,57,79,b0,\
7b,d8,51,47,ee,37,26,08,02,5d,dd,e2,da,c4,a3,1f,9f,99,ce,7c,b2,54,a0,c6,3f,\
fa,ee,28,82,d9,c3,ed,2c,e5,12,ac,0d,59,28,d3,40,e4,b4,77,02,35,f0,71,d7,4f,\
c9,74,c7,a1,b3,dc,a6,2c,91,fa,19,f9,c0,38,2c,1f,99,83,d0,db,bd,6f,1e,b5,51,\
d6,35,7b,fd,af,28,27,27,de,41,8a,42,83,49,ac,29,32,55,d6,e5,da,23,cd,37,d4,\
3f,5f,c8,d1,26,6e,e5,81,0f,47,10,72,46,cc,78,92,50,76,18,03,a2,87,49,f6,4b,\
43,b4,07,e4,3c,68,13,80,21,c2,71,e1,45,e0,63,00,e7,23,ba,99,88,65,c6,f4,86,\
6d,79,04,45,7d,d2,94,81,42,bd,55,3f,98,09,5e,75,ed,ba,b1,27,00,f0,30,d6,b0,\
58,6a,2f,3c,51,35,58,c5,40,b9,48,1a,e2,99,7e,c0,4b,3e,6c,b7,e9,b5,5d,19,1a,\
b1,29,67,6c,5a,9c,ca,c7,07,b7,82,55,11,bf,36,9c,56,b7,5f,93,df,6b,5b,10,17,\
ac,73,bc,73,af,c4,b5,e2,1d,c2,fa,8f,6f,ac,2b,a7,7b,eb,e4,b3,c2,48,20,4c,c1,\
6e,c2,eb,ef,48,22,cf,b9,26,dc,3c,59,03,67,29,24,2a,ff,04,ec,af,64,50,c3,be,\
36,0c,38,12,26,8a,ae,0a,bf,b3,17,39,52,e1,28,21,be,5d,99,62,68,87,80,9c,ee,\
27,92,e3,e4,7f,19,5f,7d,30,f9,58,fa,13,54,7d,c9,1c,83,46,bf,6a,9f,e6,9a,9c,\
96,ea,6d,d6,ed,29,4e,7b,8c,f8,a2,b7,62,0b,f8,9f,18,ef,d3,c1,36,13,89,97,29,\
be,29,4b,ce,fb,4e,6e,74,25,8c,e7,fe,75,03,aa,fb,fb,4c,a0,93,79,06,8d,3b,d2,\
bb,fc,fb,be,d0,e8,66,a5,cf,80,9b,ce,30,b0,70,fa,fc,22,6d,d0,18,24,0e,3d,1e,\
0e,91,30,e7,cb,86,f1,04,17,77,bf,88,6b,7e,bf,dd,32,5b,45,f3,5d,3a,ac,17,5e,\
84,a7,5e,72,80,d0,ea,45,e5,a0,88,76,ef,20,75,0d,fb,4a,b8,12,09,72,e7,ad,f8,\
b0,a6,0d,42,5d,54,3f,5f,ef,1c,b2,a2,51,ec,e2,4c,a8,63,b7,91,d7,75,eb,5d,7a,\
a2,0a,78,24,74,40,8f,55,11,09,bd,63,5f,1d,dc,6b,76,0e,14,93,31,14,5a,f1,35,\
6c,4e,d7,29,69,35,af,11,b7,d8,1b,bb,72,9d,57,98,34,a8,f3,8d,9f,b8,db,50,64,\
78,71,ea,44,91,28,a4,2e,60,74,67,cb,a9,8c,4e,fe,d5,00,8d,10,c3,c1,2e,89,cb,\
b4,27,8d,fc,d7,65,bb,93,1b,ab,4a,64,e7,20,0e,6e,b6,cc,2e,06,b3,7f,6c,52,e3,\
9e,df,a7,f0,87,4f,a1,12,f9,ac,e1,14,62,24,d1,f7,71,5d,c1,89,28,f5,ef,99,b6,\
e9,d1,54,8e,79,9e,cc,86,ee,38,1b,e8,e2,7a,91,76,21,ed,01,08,86,09,1b,08,15,\
f8,15,d1,b5,a8,34,40,ff,5f,03,0d,dd,73,12,59,93,c7,e7,b8,34,5d,d2,b8,eb,34,\
e0,6b,80,df,79,02,80,3b,50,5e,e1,30,85,9f,a1,05,7a,e4,aa,f0,a7,c4,01,8e,39,\
79,88,4c,bd,bf,7a,0c,5a,98,5d,1a,f2,f8,1f,04,9d,78,5f,53,dc,3a,3d,22,8d,d3,\
5c,c5,4a,96,ab,0b,fa,04,0e,af,50,ba,0a,ed,68,13,06,06,d2,8f,26,b8,41,96,70,\
1b,dc,03,27,44,50,1f,aa,ad,1c,ab,85,e7,fa,8c,d3,ae,49,bf,86,7c,0a,1b,2e,40,\
a8,0b,c6,b7,2c,ad,46,e9,f4,9c,cd,37,a8,b0,b3,ce,ea,ad,fc,05,57,8d,dd,41,2d,\
1c,86,83,54,e6,d2,23,b9,b4,e3,36,23,8c,a6,32,28,c2,fa,ca,14,e3,27,7c,59,a3,\
bf,40,3a,bd,e9,1a,4c,60,43,f3,0e,87,9b,3d,59,10,48,30,2a,e8,00,4c,35,1d,cf,\
dc,72,7f,9a,66,4e,44,04,92,1a,de,3f,cb,f0,64,39,6d,8d,ec,70,19,f7,ff,ad,b8,\
82,2a,8c,d9,a9,1c,e2,65,7a,18,cf,63,4f,27,dc,74,16,90,a4,16,de,ce,1d,8b,45,\
17,8d,d3,52,e6,c7,82,ff,69,4e,70,8f,c0,b7,70,12,1a,68,c7,51,86,b0,25,96,10,\
a8,b6,20,9f,0a,ec,d4,7d,3f,9c,15,9f,1b,29,b6,8e,ef,f5,50,49,b4,a0,f2,2d,c0,\
6e,38,97,80,ff,6d,04,00,c8,65,93,59,40,57,cc,84,78,04,c1,da,c9,74,64,2f,24,\
db,5b,ad,8e,c6,90,4a,60,22,f6,f5,f0,ab,f5,c2,72,99,0d,a8,9d,ab,52,8c,b6,44,\
d4,6d,d6,c0,d7,91,5c,2c,be,07,a8,32,8b,62,a3,d7,60,0d,6f,26,d1,02,e9,77,46,\
b5,a7,99,a9,7f,33,8e,0c,cf,38,15,7e,d3,86,65,d0,65,76,db,9d,f2,4f,db,90,07,\
a1,eb,42,30,bb,9e,2a,20,43,7a,39,3d,12,2c,74,6d,b5,4a,4d,e0,79,d5,ae,b8,e4,\
7e,b3,3f,3c,ce,43,5a,4e,7f,c6,65,97,2b,a6,1a,92,cd,b4,40,b4,8a,ce,77,62,e5,\
72,22,6c,78,5a,85,cf,b4,11,00,68,39,f2,3a,5f,4c,6d,86,61,c0,f1,e1,40,ff,ac,\
6f,15,82,79,f9,7a,eb,68,e8,33,59,42,91,8b,8d,6c,60,d2,4d,04,0b,bb,48,4f,5b,\
a3,79,ab,d5,d7,23,22,85,8c,43,ee,3d,e1,47,01,54,ba,df,2f,58,6c,db,ec,c7,4b,\
57,a7,54,f6,5e,a4,f1,e0,ec,33,48,ab,b2,36,8c,57,88,1d,14,cb,e9,ba,7e,fd,42,\
a5,a9,9d,10,2f,bc,86,0e,20,5a,4c,43,69,18,17,32,9f,23,f7,ca,b8,0b,6e,a5,b9,\
b3,5a,7c,e2,d1,60,53,8f,52,ae,ef,f8,d4,f6,ea,9b,5c,8b,5b,70,a4,eb,4e,38,b8,\
e8,27,50,f7,3f,44,59,3b,f5,0e,e5,73,ed,4b,c9,48,f3,79,36,e4,ea,d4,b9,74,a4,\
72,e1,d5,8d,f0,bf,66,c0,b0,21,dc,3c,a3,3d,c3,01,b2,1a,73,99,86,14,f2,f9,b3,\
54,c1,52,d0,0c,4e,08,82,e0,3c,df,4d,ea,3e,78,a8,34,c7,5a,2f,41,85,fd,31,8d,\
21,74,ec,a7,8d,00,28,fb,d2,88,5a,ec,e2,d9,a8,60,8c,bd,87,77,00,66,9c,86,ec,\
cc,67,84,5c,74,5f,fb,47,d9,9f,9e,8b,e5,0a,ef,db,5a,eb,45,05,67,83,72,ad,da,\
58,cc,64,82,ec,af,57,32,7c,14,8a,c7,3a,94,07,39,13,f0,6a,e5,48,61,af,f1,90,\
02,30,e2,cc,de,df,80,0c,70,1a,f9,11,d3,8b,c8,e1,b1,ce,24,fe,10,9f,9b,db,46,\
85,01,dc,3f,0f,d6,bd,af,77,2c,02,a9,1d,2a,cf,a0,2a,48,3b,06,d6,0d,57,ea,d2,\
c2,20,1d,10,30,f6,99,de,38,a1,f7,f1,4e,5e,8a,63,b9,75,94,11,87,ad,39,3c,95,\
c4,07,e8,18,59,4d,a1,69,35,35,69,df,8f,0f,24,30,72,e3,bc,1a,2f,fd,64,c6,fc,\
75,18,ab,f7,0c,03,a9,b3,eb,67,1c,20,48,18,73,bc,53,8c,80,3b,36,ba,9b,b5,ac,\
95,7d,65,d4,b2,a1,36,16,16,66,be,46,dc,c3,07,68,ea,45,d9,cc,0a,b2,63,14,20,\
53,4e,30,71,2a,d9,9b,f8,e8,33,66,9c,74,c8,4d,f8,ca,d1,5d,ee,b3,1d,6a,19,95,\
47,32,c5,2e,27,20,e9,94,80,f4,67,84,96,0e,ac,c1,08,2a,d0,6b,15,88,22,b2,a3,\
ab,df,ea,46,23,2e,f9,04,0f,5b,5b,0a,03,ca,ea,8a,8a,7f,f5,07,b0,e2,3e,1b,22,\
23,a4,9e,88,a9,47,18,00,3d,f7,fd,79,5b,4f,e3,b1,15,c0,37,eb,6e,b0,27,90,2d,\
20,34,32,2e,31,b8,7b,5c,7f,d0,46,b4,c7,f6,c6,9e,c5,fa,65,e3,0e,eb,d1,9f,74,\
5a,7d,f6,84,01,d2,d2,a6,45,2e,c2,3b,fd,e1,96,df,1d,ce,fb,6d,1a,4d,7b,50,68,\
0a,6c,3c,bd,d8,fd,05,12,49,31,55,f9,ab,29,06,6c,27,24,b1,66,2c,e2,39,09,5b,\
43,8d,f9,81,5e,3d,1a,53,9d,e1,59,8e,c2,c8,0f,74,e8,69,77,a6,65,0b,44,4f,af,\
e1,00,90,2a,03,21,ae,e7,cb,b4,cd,64,fa,51,69,90,8f,e1,94,08,0b,5c,00,13,33,\
c2,29,db,c4,c3,08,05,f5,d6,8e,ed,60,b7,b4,73,15,ef,2d,05,6a,dd,7b,92,4e,57,\
6d,ff,65,1f,d9,61,13,81,98,81,a2,6a,ff,25,46,f1,2c,ad,f4,05,5b,4a,09,c7,a8,\
a7,8c,bc,73,3a,d9,d4,46,10,c8,78,63,43,3e,99,57,35,3d,80,d5,1d,76,ec,8e,07,\
5f,59,dd,57,5d,84,2f,7d,76,4e,c9,6a,fe,52,02,c3,11,a1,71,32,7d,11,18,39,14,\
84,47,8b,31,61,b0,9b,10,81,87,8c,7d,72,ed,55,22,83,77,ef,7e,cd,ee,70,d6,d3,\
ea,49,e0,08,04,01,56,e0,1f,e4,f3,54,5e,0b,d7,9b,fc,be,fc,4c,05,76,59,fe,95,\
4d,b4,53,27,2b,d3
"??"=hex:a0,61,76,1a,b3,c8,9b,e0,05,2e,95,a9,c8,c9,59,e4

[HKEY_USERS\Administrator\Software\SecuROM\License information*NULL*]
"datasecu"=hex:19,b6,dc,01,06,43,90,8c,a7,49,90,9e,b8,e8,b0,12,bb,f1,45,65,cd,\
02,c7,f0,5b,3d,ea,e8,b4,34,0f,9e,a2,08,0e,3b,c9,22,0c,f3,96,50,d1,07,01,a5,\
8d,cb,cc,c8,e8,ec,8a,24,bf,95,de,b1,49,23,22,c5,24,50,51,37,f9,b5,ad,d4,e6,\
62,bb,11,49,21,86,b3,f1,8b,51,52,29,7e,12,e9,1b,d5,b2,fd,d8,cf,76,e0,d1,60,\
83,9a,f4,25,1a,19,55,d0,ac,22,26,b0,8d,9c,c2,2c,d1,87,46,ee,dc,03,e1,fe,3d,\
04,e0,5e,11,df,13,4f,7e,d1,70,e7,73,64,ee,c0,5d,27,20,8c,0a,b8,79,79,2c,f8,\
22,3b,2f,be,59,8c,76,63,8b,1d,46,31,8f,64,e3,9b,61,d0,40,64,b4,37,63,0a,11,\
85,63,64,8f,62,e1,a9,16,9d,62,19,c7,41,55,89,ce,4f,b9,a7,f8,4e,09,b2,d7,0b,\
71,71,7c,21,fb,d7,32,9c,0f,cf,6a,47,2c,ab,6b,1e,0c,1b,dc,82,d4,e0,f2,a8,20,\
2d,bc,23,05,67,fa,12,96,ee,8f,e2,21,18,f2,5f,83,83,84,2b,60,d6,a3,2d,0c,69,\
5c,55,44,a2,79,94,c0,3f,78,a8,9e,dc,57,a9,8c,bd,6b,3e,7d,40,5d,11,b1,ff,61,\
d3,0d,57,44,5d,f6,6c,a7,c5,6a,88,e2,2c,71,1f,6e,45,19,82,d4,de,21,8e,d2,1e,\
d5,49,5e,26,7f,85,83,13,9f,14,2b,c9,9c,98,4f,49,76,ad,11,42,34,51,fa,37,8d,\
a2,d4,09,63,60,6e,ee,23,84,98,ed,53,8f,09,6d,c0,db,f7,4d,cf,ce,b1,f5,1b,04,\
6a,e1,e2,bb,5e,a1,94,ca,24,42,8c,ee,75,52,31,c3,17,f7,05,fa,8e,be,d6,22,33,\
d8,b9,b6,e9,ba,30,6c,fe,a9,7a,ca,24,57,a8,ed,8b,c5,75,bb,7b,98,06,34,28,bb,\
4d,24,7e,aa,3c,8e,79,37,84,44,aa,a9,93,73,47,19,80,7e,02,26,fb,25,f5,7d,b0,\
2d,3d,3c,fb,29,f0,d9,8e,2d,b1,7a,69,e0,72,dd,69,29,38,08,9d,f5,90,24,fd,5e,\
1b,6c,a3,99,1d,1d,8a,59,1c,f9,57,c8,5b,02,d8,a6,53,de,88,47,88,b1,9d,1c,6c,\
90,92,57,18,97,e0,e2,09,fd,76,d2,71,79,99,bf,18,d8,50,e8,85,90,94,20,5c,cf,\
2f,ed,bf,d3,64,4e,1e,79,5e,a1,9c,ea,7e,3c,52,cb,9a,06,7e,1d,9f,14,7d,d4,2b,\
cb,9a,42,8d,0a,e5,36,ac,0a,81,53,78,58,f5,a1,d4,d2,41,7b,42,23,e6,3f,d2,95,\
77,29,f4,b5,0b,26,0b,d5,da,46,98,64,50,b0,a8,75,17,90,c2,7d,af,c6,97,d0,b7,\
68,a8,d2,94,af,f7,43,f7,f4,2d,84,bc,82,2a,56,c1,8d,c2,f0,20,e0,35,54,50,64,\
49,91,a0,dd,d0,33,7b,8f,dc,d1,5f,de,42,b9,7d,20,39,56,fa,e7,8e,4d,04,77,0e,\
6c,72,1e,84,57,be,43,6a,42,02,07,a7,1c,c0,ec,18,39,42,5b,5e,58,c1,b1,93,ad,\
41,06,e0,4b,6c,bd,25,db,c0,7f,0b,62,de,e8,a8,34,f8,df,ec,ad,54,53,99,7c,93,\
69,30,63,68,c5,db,63,7c,4d,54,43,ca,b8,12,84,37,36,71,bb,0d,35,8b,eb,8d,4b,\
5b,0a,95,f7,62,df,8f,f5,a1,5b,4e,7e,1b,30,c3,a6,99,26,77,6e,b7,14,15,cc,4f,\
6e,86,e2,67,87,61,4d,09,3a,e1,d5,6f,2d,95,e1,dc,67,c1,e8,2f,49,c6,ef,82,54,\
ff,a7,ac,cd,f6,07,73,27,29,0f,af,8d,dc,90,b2,14,e8,3e,28,61,c9,aa,37,c6,b8,\
41,07,e2,19,f0,01,64,75,34,f8,0c,ff,60,36,46,30,e8,a1,5c,d0,49,be,27,aa,7e,\
cf,00,9a,7f,a3,6b,a0,bb,94,ec,a3,a0,9c,75,b3,66,5f,9d,80,02,fb,63,14,8a,15,\
08,40,37,ab,74,11,d6,48,a0,8e,46,a3,d1,f6,95,91,7b,23,84,17,77,41,34,6d,2e,\
a4,85,92,89,4e,cd,36,c9,08,90,61,04,15,93,5d,74,5d,06,75,d4,db,6b,c1,b5,be,\
72,21,ee,bc,a5,3d,51,bb,f5,43,04,c7,8d,7e,ad,96,c8,0f,fd,47,e7,cd,90,c0,bb,\
da,58,db,b6,f5,c9,04,7d,1d,35,a7,4d,5e,1b,b5,d4,3f,5c,66,74,20,08,67,5b,36,\
5f,51,7c,1d,a2,48,24,88,30,cc,16,12,81,e0,43,e3,8e,7d,52,18,a7,8d,f7,c7,8c,\
aa,56,1e,ca,fa,fc,a3,87,cb,0f,dd,51,e2,48,c8,64,39,02,90,ea,cd,2e,aa,5f,b9,\
c7,04,fc,ca,bc,d6,20,17,e7,8e,34,d1,dc,0c,bb,e5,ff,41,4e,e6,d6,a1,b6,1b,90,\
09,ed,14,da,76,eb,84,7d,e4,9f,00,ec,e2,7e,3a,e7,ea,2b,a6,c9,51,4a,bb,f3,dc,\
f4,71,a1,ac,cc,f4,a2,f4,40,e0,17,84,e3,78,62,98,98,09,84,46,56,b5,9a,eb,03,\
a6,72,cc,38,b2,31,a1,0a,ce,46,c4,20,bc,03,9c,db,f9,30,32,67,e8,07,39,06,57,\
07,85,7a,0e,eb,68,fd,cf,57,a8,b6,9e,08,ce,19,fc,09,da,c7,f3,f3,66,87,c3,d0,\
56,a3,c4,47,45,c5,e0,48,52,34,e3,c8,14,82,2a,98,ee,a6,5c,fe,77,39,d6,24,e7,\
9a,32,4d,94,7d,c4,fc,d7,71,83,bd,0a,83,e7,c5,02,bf,58,45,b4,d0,d2,dd,6a,6b,\
86,11,83,23,42,d2,71,f3,8c,70,a4,82,d9,c4,05,8a,a1,9b,bc,32,e3,6f,df,3f,08,\
fd,9f,44,5e,02,95,68,16,76,b5,c2,c2,6c,23,c6,ab,1d,bc,d4,7e,e2,cc,38,45,37,\
e3,19,17,ab,9f,cb,a0,c8,d9,72,62,bd,df,f3,37,4d,37,f3,b8,4e,4e,d4,bb,0e,0f,\
3f,6f,df,90,12,a2,65,96,f2,35,1a,46,79,fb,5b,d1,39,b4,f0,44,0c,63,64,e2,0d,\
1e,d0,f1,2f,07,e9,b3,9b,d7,6a,c8,98,03,e2,28,c0,b3,cf,85,d6,9b,b7,82,ba,df,\
dd,60,50,84,f5,53,79,d3,97,a2,14,29,34,e4,72,c6,9b,07,14,3c,11,fe,5b,7a,e6,\
51,fe,d2,83,79,90,b8,87,f1,8d,9c,66,dc,78,06,e3,4e,7b,3a,83,47,a7,45,c1,5f,\
8d,e1,9f,1d,ea,ff,54,09,d5,8b,42,16,38,f9,49,22,76,b6,06,a7,c4,76,47,8f,04,\
28,4f,75,84,3a,6d,9a,fa,88,d8,da,40,69,d7,58,e2,39,17,96,d9,b7,c7,90,5f,9c,\
3b,11,35,22,4f,21,92,b9,90,5b,0e,b1,17,6c,ee,8a,2c,75,56,14,5e,60,ec,d8,14,\
1a,41,e9,5f,e2,75,33,b9,8d,f2,90,1f,dd,c0,11,42,0d,88,04,20,cb,3e,bb,e2,3b,\
a5,f1,ae,cb,55,b8,8c,58,52,14,b6,40,ca,65,06,5d,4c,4e,8a,e4,7a,6b,1c,8e,4d,\
5b,7f,86,97,3c,03,e8,2a,4d,4a,8b,1a,46,d2,73,14,7f,27,27,eb,e4,d0,c4,3c,ef,\
70,53,59,47,02,17,f2,a6,54,7d,2f,8e,b1,5c,c3,d1,26,9f,75,7f,35,5d,81,dc,4f,\
45,44,ad,64,6a,5c,3d,90,d1,a8,17,df,71,74,b3,8a,2d,6b,e5,2e,16,da,7a,4d,49,\
1e,9b,a5,1e,1a,1a,5c,25,76,93,0f,1f,14,2f,ac,11,5c,a5,f0,ac,a7,1c,0b,69,a1,\
01,c3,3e,cc,ac,1a,bb,12,38,ae,70,c9,cc,c2,9a,3b,c8,d1,0c,3f,6d,87,71,6c,88,\
bc,df,d1,4e,02,89,17,96,fa,5b,f3,65,60,46,fb,15,df,4f,c7,5e,cd,a1,04,4d,64,\
55,5c,8e,2f,42,72,26,e7,09,af,32,67,7c,03,47,c8,c1,61,25,d4,83,bb,07,f8,4a,\
c4,12,0e,e5,2a,b1,37,6e,f9,0f,fc,e1,a3,36,9e,8c,99,a8,fd,0d,3b,ec,c2,57,95,\
28,a6,d3,49,8c,df,bc,c9,5f,b7,8d,0f,53,45,c9,d5,a0,3a,40,72,58,a8,53,90,ec,\
1d,1e,12,d0,4b,86,c0,3d,ff,5f,fe,7f,c8,2a,15,18,a4,5e,d4,86,f6,b6,9f,b1,12,\
ee,da,d2,6e,e5,68,80,84,f3,f7,42,ac,76,d9,ba,53,81,08,ea,d2,0d,84,14,e7,5c,\
d2,01,c1,cf,51,62,b7,0a,ea,d4,e6,24,f8,65,17,d9,e7,68,56,81,02,b1,1b,7d,a7,\
18,41,85,4a,62,15,ba,f2,35,aa,36,c4,f4,72,70,c0,0e,18,b2,30,18,4d,57,e4,23,\
12,58,78,f3,d8,55,9c,28,5f,b9,0d,d6,f0,4c,58,7a,9b,c6,8c,79,a5,7b,cb,cb,83,\
8a,e7,20,52,f6,95,9f,48,d4,dc,bb,46,de,b5,fe,25,68,4f,ec,be,46,07,c1,32,1f,\
37,7f,92,e6,0c,07,45,68,87,9c,6b,f9,7c,63,a9,2e,42,92,15,af,14,0b,ac,f9,40,\
a1,94,92,e9,af,b3,91,39,80,a6,93,a5,6e,57,63,fd,b1,a0,b2,ab,94,07,45,91,4f,\
34,44,bc,ba,5f,b7,ff,08,4a,bb,97,09,a5,3b,0d,be,88,32,ee,67,7a,55,9d,00,8f,\
e8,f1,81,e3,39,32,76,42,70,00,94,fe,be,0f,6a,14,44,c3,09,df,1c,27,4e,b4,2e,\
b3,0a,e3,26,34,6e,9a,d2,8c,71,04,25,83,42,39,2f,b2,df,60,e9,e5,e7,ab,82,c4,\
ad,1d,2c,b1,c1,b6,f8,c8,70,00,2a,a3,60,45,31,6f,2a,89,aa,74,6c,4d,c4,6a,03,\
90,cb,61,02,9e,94,32,6d,58,05,4e,37,71,03,d7,57,c8,0e,7c,16,48,30,f8,a4,ae,\
cc,75,90,0f,c2,3c,ba,24,b1,d1,84,c8,e9,a5,0f,84,18,a0,12,d5,14,54,4a,b1,9c,\
21,3e,ff,8c,e2,52,10,04,18,ed,6e,52,f0,a1,de,e4,12,ca,cd,0b,43,12,fc,a5,f5,\
25,7e,ad,c5,5c,8f,45,cd,ce,31,ef,83,69,48,d2,94,ac,97,bd,db,cd,a9,6f,95,3e,\
7d,ee,c8,7d,43,f0,ae,a4,4d,56,e1,fd,c0,e8,55,59,75,21,25,3a,26,0b,52,fa,10,\
a9,f6,17,d1,a4,24,49,38,69,06,6a,c3,d1,6f,82,b7,4e,db,5d,88,b1,10,0a,c9,af,\
39,e4,67,81,2a,cf,4e,fb,e5,0f,da,0b,4b,12,23,85,cc,bf,2a,3b,39,6b,ff,27,9e,\
64,b8,67,ea,45,e6,ab,44,dd,26,96,7a,93,56,24,70,e2,17,91,db,26,7e,de,15,cc,\
7b,33,12,f4,7a,a5,55,4e,24,ba,e6,3e,ec,09,39,98,bf,28,fa,02,25,46,59,60,03,\
3d,d1,e3,7c,35,bd,87,fd,57,31,a7,67,14,71,39,2c,60,16,7f,5c,82,30,41,b7,78,\
e8,f3,5f,d3,86,22,fb,cd,5b,af,39,0f,10,8b,29,34,bc,30,5e,66,37,90,58,84,ce,\
16,82,55,70,17,92,4c,6a,a1,52,17,6f,e6,9e,0d,86,59,15,2d,16,ec,46,ff,b2,07,\
8b,e7,ac,f8,72,64,2a,c5,21,6b,e0,0b,37,13,3c,7d,37,b6,c8,67,71,bb,d0,b8,f6,\
06,8f,7e,59,56,d5,ca,13,d8,27,a1,8f,47,de,1f,f6,d8,b7,ba,f3,e7,bb,70,6d,fa,\
7b,0d,ae,63,3d,ee,19,9d,28,c8,28,1b,3b,33,f0,70,a9,f1,50,8d,9b,0d,c8,79,7d,\
6d,fc,67,e4,9c,42,c2,f6,92,05,82,06,67,82,0b,6c,1a,57,ed,e7,0c,8a,e4,d8,2e,\
d5,60,02,90,11,b7,24,5e,e8,ca,b0,ff,cc,de,6b,90,e7,1f,ec,34,a1,78,81,65,83,\
ec,f5,85,1d,3a,f0,ee,7b,92,e9,b2,5d,61,7f,79,07,a5,3d,48,ca,04,38,6e,93,41,\
53,10,4a,0a,5e,41,df,bf,d9,c9,d6,87,d4,c2,f5,f5,46,53,34,46,8f,0f,4a,55,e0,\
19,b9,9e,45,cd,f4,91,47,c7,f0,5b,18,f8,0d,c0,59,59,c3,09,f1,72,bb,12,6e,09,\
c8,b3,aa,11,9d,ba,a5,db,30,07,33,a3,98,2c,02,23,75,07,fd,0b,0a,0f,46,7c,a1,\
5b,ef,92,d0,87,b1,2c,14,8c,0a,50,da,12,24,cc,42,13,8b,58,d2,df,26,89,ea,ba,\
4a,20,f4,d4,bf,69,b4,52,87,ea,cd,ef,8d,5c,d5,8b,32,48,f0,c7,25,e0,b7,7c,3b,\
d5,2b,6e,89,30,07,01,aa,54,8f,37,0d,71,32,cb,1e,60,5b,b6,04,68,7d,76,e6,1e,\
83,69,a5,9e,7d,2a,4e,c5,f4,a2,18,be,0c,f8,ea,21,91,c4,ca,6f,4f,89,0e,7f,e1,\
23,3c,2c,6c,76,f7,ae,ed,80,98,6d,c7,03,b7,ba,04,f7,01,44,04,96,26,f6,d2,24,\
7b,5d,a0,84,c6,f8,bb,e9,e2,24,6c,f8,dd,bf,2d,af,8d,f6,7a,cc,1f,06,35,9d,8e,\
fb,13,22,17,f3,4e,0f,d5,19,c9,3f,71,be,c8,b6,82,ff,e8,c0,05,87,99,f5,29,0d,\
03,bc,6d,16,a0,c4,dc,aa,07,b4,41,0d,72,9c,89,87,2b,aa,ae,01,d9,d7,62,a0,96,\
df,56,bc,55,58,36,f7,d6,01,4c,a7,0e,8b,b3,90,f5,48,4b,de,92,2f,2c,e0,48,f7,\
58,ce,f0,5c,9c,87,7a,e7,7b,1e,c4,2c,e8,79,e1,03,d4,b5,a9,90,86,98,ba,f9,35,\
a9,7a,a5,dd,15,fc,cc,da,63,57,d7,91,5c,38,d5,b8,52,0f,1d,dd,95,9d,75,7d,b3,\
ae,d8,36,05,3d,55,28,e1,7f,8b,c0,36,89,dc,6b,66,6e,6c,16,29,c8,5c,31,ff,e3,\
0f,c7,7a,7f,5e,c7,34,b7,12,bc,2d,e1,61,a7,b7,4b,c4,e6,18,41,a9,29,24,ba,8e,\
30,f0,c3,68,1d,34,9f,06,e1,b9,03,c9,3a,7d,c7,0e,d6,82,ad,e9,5c,2e,d6,34,4f,\
19,94,dd,da,b5,8a,39,0f,7f,d9,13,e5,23,06,99,2b,c8,95,77,85,e5,87,71,4d,bf,\
12,01,c0,81,f7,47,56,98,56,49,ad,5f,67,d0,25,36,af,9d,c9,18,bc,ac,53,48,db,\
a0,5b,fa,fa,20,ec,60,f0,a5,c6,ae,ae,98,a9,5e,52,1d,98,24,b9,f1,d4,af,6d,b2,\
29,4d,7d,8e,41,bc,6e,2b,f3,e7,63,93,bd,95,df,e3,5e,0f,9c,51,e7,78,bc,57,f5,\
2b,6b,98,86,5b,f1,10,30,7c,56,86,d6,bc,f0,48,2b,01,bb,e0,88,35,e7,24,eb,a7,\
68,fa,40,68,7b,d1,e3,7b,e7,26,d1,fa,6b,bc,76,78,3c,0a,05,d3,9f,6a,a7,19,7c,\
de,b2,15,d1,57,16,f4,4e,cd,dc,55,47,80,af,12,4d,e5,3a,d1,78,82,40,8f,86,18,\
5a,05,07,7d,f8,02,22,7e,f9,62,df,1e,34,94,03,f1,8e,d9,21,ab,c2,29,c3,c4,8c,\
18,d6,14,e1,a0,62,1c,7c,b7,5d,f1,fd,44,8a,27,fc,57,09,a8,91,dc,27,fa,e0,b2,\
96,e9,13,50,1c,53,af,f8,a1,88,f6,b1,1d,e0,57,f1,a9,d9,88,cc,91,48,fc,62,5d,\
04,d8,e5,bd,22,72,b0,b3,c2,ba,e8,9f,c1,d4,6d,0c,dc,0f,03,59,38,c2,b6,f1,20,\
ee,15,7c,93,2c,a8,97,eb,28,9c,d6,98,ef,85,5b,9e,3b,23,21,16,c0,02,03,ed,01,\
8e,49,62,b3,67,c5,02,70,be,00,98,b9,73,24,53,f7,5b,f0,80,48,8d,99,05,41,fd,\
47,7e,0c,1c,74,23,68,a7,f0,26,5f,06,32,e4,d6,86,f2,08,f3,83,d0,56,0f,6d,49,\
05,eb,ea,55,68,0a,2f,49,f6,bc,c7,e7,ff,6f,cd,27,e7,e9,2b,89,8b,72,99,90,ee,\
99,f0,93,a9,1d,64,6a,44,c0,f5,2b,a4,5d,48,73,b0,11,90,b0,a7,7c,f9,ff,1d,d3,\
30,7e,c8,2c,d1,67,66,ce,17,e9,c9,49,5f,97,04,c8,8f,a5,7c,06,6d,c3,0c,a8,1d,\
17,25,15,91,6e,28,d9,c1,a6,67,0d,07,83,f8,85,0d,86,d6,b6,ea,3e,ca,3b,d9,55,\
98,3b,35,6c,78,45,a0,1a,42,ce,2b,de,eb,dd,2b,b6,86,ee,6a,82,88,6a,38,e2,4f,\
48,2b,2b,2e,ef,73,03,3e,a2,56,8b,7c,33,93,3e,65,d4,7e,17,f5,04,2b,90,f0,bd,\
80,28,d4,85,1d,c1,1e,4f,18,3c,73,95,2b,d6,e3,18,cd,4c,80,56,72,79,8b,ca,f5,\
84,33,39,c0,c7,a0,af,48,95,49,2f,8f,3d,83,4e,2d,4c,a4,7e,8b,6d,05,c8,e5,15,\
53,e3,dc,0b,e2,20,66,e4,dd,7e,5b,f2,95,6e,36,42,5f,ac,68,f3,f5,01,d1,f9,7c,\
80,f0,5b,92,12,b8,e0,2a,c7,cb,4e,60,53,b5,e5,5c,20,f5,0e,c4,dd,1d,70,a4,a7,\
77,1c,fa,b0,3b,b7,df,66,1c,8a,46,7f,e3,10,fd,ae,56,8f,de,7c,91,3b,1f,44,0c,\
93,17,07,4e,18,b8,33,31,eb,69,b9,d7,18,5d,6d,69,c9,8f,21,d6,0b,ce,bc,db,f9,\
47,28,bb,40,03,fb,fd,0f,5a,69,7a,8b,5f,50,e3,ee,6e,e4,da,27,1d,73,fa,bd,55,\
e0,cf,e0,7c,d0,81,0d,95,b6,91,8a,03,63,10,41,05,53,01,7a,2f,a9,54,58,9f,fc,\
54,46,d7,b4,59,13,cc,5c,14,32,02,d8,f8,95,3d,1f,17,6c,e9,81,68,24,6e,64,78,\
c0,95,86,c7,04,50,48,27,af,d2,1b,3b,54,6f,9e,26,4a,f8,e0,97,f3,89,67,4f,55,\
5b,f9,48,b9,1b,b7,99,91,bc,3e,e1,9c,5a,46,69,ce,73,52,4f,6c,54,80,ac,29,79,\
8b,15,66,32,c0,4a,31,6c,e5,ac,21,b0,41,f3,13,f9,9d,96,f5,4e,ec,65,73,df,98,\
cc,5b,0d,6c,b8,8c,a7,bf,fd,93,e4,03,fb,ec,8a,17,d6,ad,cc,71,c6,13,3d,a0,76,\
0d,f2,d7,da,d7,2b,d6,43,b7,5e,6e,fe,95,82,d8,f7,7f,cd,8d,bb,64,1f,d6,cd,21,\
e1,d3,58,43,9b,6e,4d,5e,2e,9f,5b,24,75,86,f5,ca,38,9a,ef,a0,38,aa,e7,60,28,\
aa
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(964)
d:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
d:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
d:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

- - - - - - - > 'lsass.exe'(1020)
d:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

- - - - - - - > 'csrss.exe'(940)
d:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
------------------------ Autres processus actifs ------------------------
.
d:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
d:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32.exe
d:\program files\Orange\AntivirusFirewall\Common\FSMA32.EXE
d:\windows\system32\FTRTSVC.exe
d:\program files\NVIDIA Corporation\nTune\nTuneService.exe
d:\program files\Orange\AntivirusFirewall\Common\FSMB32.EXE
d:\windows\system32\nvsvc32.exe
d:\windows\system32\PnkBstrA.exe
d:\windows\system32\PnkBstrB.exe
d:\program files\NVIDIA Corporation\System Update\UpdateCenterService.exe
d:\program files\Orange\AntivirusFirewall\Common\FCH32.EXE
d:\program files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
d:\program files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
d:\program files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
d:\program files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
d:\program files\Orange\AntivirusFirewall\FWES\program\fsdfwd.exe
d:\program files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
d:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav32.exe
d:\progra~1\Orange\ANTIVI~1\Common\FSM32.EXE
d:\windows\system32\rundll32.exe
d:\progra~1\Orange\ANTIVI~1\FSGUI\fsguidll.exe
.
**************************************************************************
.
Heure de fin: 2009-01-07 21:15:00 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-07 20:14:51

Avant-CF: 15 147 245 568 octets libres
Après-CF: 15,107,485,696 octets libres

609 --- E O F --- 2009-01-01 13:00:32

alors c est ok ou bien, en tout merci déjà pour le coup de patte a plus
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
8 janv. 2009 à 10:54
ok parfait tu ne devrait plus avoir de vundo!
mais encore quelques manip a faire:

__________________

utilise pour supprimer tes traces

CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo
(dans les options puis avancé :désactive la case: effacer les fichiers de plus de 48 heures)
https://www.malekal.com/tutoriel-ccleaner/
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
_________________


mettre a jour internet explorer
https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html


mettre à jour adobe reader
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html







Mettre a jour java:

Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.

si cela ne fonctionne pas

https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

tu peux désinstaller les vieilles versions.

__________________________


Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
0
donc voila les 2 rapports mais internet explorer n a pas voulu se mettre a jour j ai essayer 3 fois:

JavaRa 1.13 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Thu Jan 08 12:59:34 2009

Found and removed: D:\Program Files\Java\jre1.6.0_07

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\JavaSoft\Java2D\1.6.0_06

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.

voila tb:


-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Default System BIOS
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : AntiVirus Firewall 7.00 7.00 (Activated)
Firewall : AntiVirus Firewall 7.00 7.00 (Activated)
C:\ (Local Disk) - NTFS - Total:232 Go (Free:228 Go)
D:\ (Local Disk) - NTFS - Total:78 Go (Free:13 Go)
E:\ (Local Disk) - NTFS - Total:154 Go (Free:31 Go)
F:\ (CD or DVD)
G:\ (CD or DVD)
H:\ (CD or DVD)
I:\ (CD or DVD)
J:\ (CD or DVD)

"D:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 08/01/2009|13:01 )

-----------\\ Recherche de Fichiers / Dossiers ...

[Service] ASKService
D:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="D:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.orange.fr/portail"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

D:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\FAR_CRY_2_CLONEDVD_NOCRACK[www.reload-paradise.net].torrent



1 - "D:\ToolBar SD\TB_1.txt" - 08/01/2009|13:02 - Option : [1]

-----------\\ Fin du rapport a 13:02:32,98

encore merci et a toute
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
8 janv. 2009 à 17:40
refais toolbar sd choisi l'option 2 et colles l rapport

_______________

lance zeb restore et repare internet explorer puis retente de mettre la version 7 ou sinon la 8 beta 2:

http://www.microsoft.com/downloads/details.aspx?familyid=33fb40fd-2ee2-476a-a152-ed03734691b3&displaylang=fr


http://www.microsoft.com/downloads/details.aspx?familyid=33fb40fd-2ee2-476a-a152-ed03734691b3&displaylang=fr
__________________


colle le rapport d'un scan en ligne
avec un des suivants:


bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html

Panda en ligne :
http://pandasoftware.fr

Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
0
donc voila le rapport toolbar mais par contre impossible pour ie 7et ie8 a partir du 6 sa bloque a l installation et mon antivirus a trouver trojan.spy.win32.agent.kgi :
rapport toolbar

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Default System BIOS
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : AntiVirus Firewall 7.00 7.00 (Not Activated)
Firewall : AntiVirus Firewall 7.00 7.00 (Not Activated)
C:\ (Local Disk) - NTFS - Total:232 Go (Free:228 Go)
D:\ (Local Disk) - NTFS - Total:78 Go (Free:13 Go)
E:\ (Local Disk) - NTFS - Total:154 Go (Free:31 Go)
F:\ (CD or DVD)
G:\ (CD or DVD)
H:\ (CD or DVD)
I:\ (CD or DVD)
J:\ (CD or DVD)

"D:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 08/01/2009|18:41 )

-----------\\ SUPPRESSION

Supprime! - [Service] ASKService
Supprime! - D:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="D:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.orange.fr/portail"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

D:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\FAR_CRY_2_CLONEDVD_NOCRACK[www.reload-paradise.net].torrent



1 - "D:\ToolBar SD\TB_1.txt" - 08/01/2009|13:02 - Option : [1]
2 - "D:\ToolBar SD\TB_2.txt" - 08/01/2009|18:42 - Option : [2]

-----------\\ Fin du rapport a 18:42:32,40


puis le rapport bit defender:

Rapport d'analyse généré à: Thu, Jan 08, 2009 - 20:03:49









Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;















Statistiques

Temps


00:41:52

Fichiers


105395

Directoires


5825

Secteurs de boot


0

Archives


2015

Paquets programmes


10222







Résultats

Virus identifiés


1

Fichiers infectés


2

Fichiers suspects


0

Avertissements


0

Désinfectés


0

Fichiers effacés


2







Info sur les moteurs

Définition virus


2413415

Version des moteurs


AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Analyse des plugins


17

Archive des plugins


45

Unpack des plugins


7

E-mail plugins


6

Système plugins


4







Paramètres d'analyse

Première action


Désinfecté

Seconde Action


Supprimé

Heuristique


Oui

Acceptez les avertissements


Oui

Extensions analysées


exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

Excludez les extensions




Analyse d'emails


Oui

Analyse des Archives


Oui

Analyser paquets programmes


Oui

Analyse des fichiers


Oui

Analyse de boot


Oui








Fichier analysé


Statut

E:\logiciel\Nero 8.1.1.3 Lite et Micro FRA + cerise\Nero_Plugins_KeyGen.exe


Infecté par: Trojan.Zlob.487

E:\logiciel\Nero 8.1.1.3 Lite et Micro FRA + cerise\Nero_Plugins_KeyGen.exe


Supprimé

E:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP293\A0045248.exe


Infecté par: Trojan.Zlob.487

E:\System Volume Information\_restore{DC0883E0-A534-4DD6-9626-2AF0B7997EA0}\RP293\A0045248.exe


Supprimé


donc voila et encore merci
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
8 janv. 2009 à 20:21
ok vire ce crack:

D:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\FAR_CRY_2_CLONEDVD_NOCRACK[www.reload-paradise.net].torrent


________________

Télécharge ToolsCleaner sur ton bureau.
--> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

__________________

Désactive ta restauration systeme puis redemarre ton ordi puis réactive là comme ceci:
https://www.informatruc.com

____________________


si tu ne peux mettre a jour internet explorer alors ne l'utilise plus et surf avec:
firefox ou opera ou safari ou google chrome

http://www.mozilla-europe.org/fr/firefox/
https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/61.html


____________________

encore des problèmes?
0
apparemment tout est ok, mille fois merci voila le rapport, il n'y a que combofix qui n a pas était supprimé, est ce grave? autrement je le met de cote et je n y touche pas, un grand merci a toi tu as sauvé mon pc vive jlpjlp

voila le rapport:

[ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

D:\Combofix.txt: trouvé !
D:\rapport_clean.txt: trouvé !
D:\TB.txt: trouvé !
D:\Qoobox: trouvé !
D:\Toolbar SD: trouvé !
D:\Rsit: trouvé !
D:\nettoyage\ComboFix.exe: trouvé !
D:\nettoyage\ToolBarSD.exe: trouvé !
D:\nettoyage\Rsit.exe: trouvé !
D:\Program Files\trend micro\HijackThis.exe: trouvé !
D:\Program Files\trend micro\hijackthis.log: trouvé !
D:\rapport\TB.txt: trouvé !

---------------------------------
-->- Suppression:

D:\nettoyage\ComboFix.exe: ERREUR DE SUPPRESSION !!
D:\nettoyage\ToolBarSD.exe: supprimé !
D:\Program Files\trend micro\HijackThis.exe: supprimé !
D:\Combofix.txt: supprimé !
D:\rapport_clean.txt: supprimé !
D:\TB.txt: supprimé !
D:\nettoyage\Rsit.exe: supprimé !
D:\Program Files\trend micro\hijackthis.log: supprimé !
D:\rapport\TB.txt: supprimé !
D:\Qoobox: supprimé !
D:\Toolbar SD: supprimé !
D:\Rsit: supprimé !

encore merci
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
9 janv. 2009 à 21:55
ok parfait pour combofix tu le vire manuelllement comme tu fais avec tous les autres fichiers en appuyant dessus avec le bouton Droit

bonne suite
0