MALWAREBYTES CHAUD CHAUD CHAUD
Fermé
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
-
6 mai 2009 à 21:28
ketty291 Messages postés 635 Date d'inscription samedi 1 juillet 2006 Statut Membre Dernière intervention 1 août 2019 - 8 mai 2009 à 14:19
ketty291 Messages postés 635 Date d'inscription samedi 1 juillet 2006 Statut Membre Dernière intervention 1 août 2019 - 8 mai 2009 à 14:19
A voir également:
- MALWAREBYTES CHAUD CHAUD CHAUD
- Télécharger malwarebytes - Télécharger - Antivirus & Antimalwares
- Malwarebytes adwcleaner - Télécharger - Antivirus & Antimalwares
- Contact chaud avis ✓ - Forum Consommation & Internet
- Branchement a chaud sata - Forum Matériel & Système
- Ordinateur chaud qui ne s'allume plus - Forum Refroidissement
45 réponses
Utilisateur anonyme
7 mai 2009 à 19:31
7 mai 2009 à 19:31
OK , ouvre malewarebytes , va dans quarantaine , supprime tout .
Télécharge Ad-remover ( de C_XX ) sur ton bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
! Déconnecte toi et ferme toutes applications en cours !
* Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .
* Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .
* Au menu principal choisis l'option "A" et tape sur [entrée] .
Laisse travailler l'outil et ne touche à rien ...
--> Poste le rapport qui apparait à la fin , sur le forum ...
( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
Tuto : http://pagesperso-orange.fr/NosTools/ad_remover.html
Télécharge Ad-remover ( de C_XX ) sur ton bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
! Déconnecte toi et ferme toutes applications en cours !
* Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .
* Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .
* Au menu principal choisis l'option "A" et tape sur [entrée] .
Laisse travailler l'outil et ne touche à rien ...
--> Poste le rapport qui apparait à la fin , sur le forum ...
( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
Tuto : http://pagesperso-orange.fr/NosTools/ad_remover.html
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
7 mai 2009 à 19:40
7 mai 2009 à 19:40
je n'arrive pas a telecharger votre lien j'ai cette reponse:
Ad blocked here by SPF.
Ad blocked here by SPF.
Utilisateur anonyme
7 mai 2009 à 19:42
7 mai 2009 à 19:42
ok , met malewarebytes a jours , refais un scan rapide et post le rapport stp
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
7 mai 2009 à 20:13
7 mai 2009 à 20:13
c'est fait
Malwarebytes' Anti-Malware 1.36
Database version: 2089
Windows 5.1.2600 Service Pack 2
07/05/2009 20:12:57
mbam-log-2009-05-07 (20-12-57).txt
Scan type: Quick Scan
Objects scanned: 115244
Time elapsed: 17 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Malwarebytes' Anti-Malware 1.36
Database version: 2089
Windows 5.1.2600 Service Pack 2
07/05/2009 20:12:57
mbam-log-2009-05-07 (20-12-57).txt
Scan type: Quick Scan
Objects scanned: 115244
Time elapsed: 17 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Utilisateur anonyme
7 mai 2009 à 20:21
7 mai 2009 à 20:21
• Télécharge et install UsbFix
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
• Double clic sur le raccourci UsbFix présent sur ton bureau .
• Choisis l'option 1 ( Recherche )
• Laisse travailler l'outil.
• Ensuite post le rapport UsbFix.txt qui apparaitra.
• Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
• Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
• Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
• Double clic sur le raccourci UsbFix présent sur ton bureau .
• Choisis l'option 1 ( Recherche )
• Laisse travailler l'outil.
• Ensuite post le rapport UsbFix.txt qui apparaitra.
• Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
• Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
• Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
7 mai 2009 à 20:41
7 mai 2009 à 20:41
oui
############################## [ UsbFix V3.017 # Scan ]
# User : christelle (Administrateurs) # SN403827370002
# Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 20:35:25 | 07/05/2009
# AMD Sempron(tm) 2600+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# AV : avast! antivirus 4.6.691 [VPS 0527-2] 4.6.691 [ (!) Disabled | (!) Outdated ]
# FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T
# C:\ # Disque fixe local # 69,52 Go (40,83 Go free) [HDD] # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque CD-ROM
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
# J:\ # Disque amovible # 3,72 Go (3,67 Go free) [KINGSTON] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\windows\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.be/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="christelle"
HKLM_logon: "AltDefaultUserName"="christelle"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: IMJPMIG8.1="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
HKLM_Run: PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
HKLM_Run: PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM_Run: SunJavaUpdateSched=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
################## [ Informations ]
################## [ Fichiers # Dossiers infectieux ]
Found ! C:\WINDOWS\system32\tmp.reg
Found ! C:\WINDOWS\system32\tmp.txt
Found ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc12\BearShare\UNWISE.EXE
Found ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc91\Ad-aware 6\Unwise.exe
Found ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc91\Ad-Aware SE Personal\UNWISE.EXE
################## [ Registre # Clés Run infectieuses ]
Found ! HKLM\software\microsoft\security center\\ "AntiVirusOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
Found ! HKLM\software\microsoft\security center\\ "FirewallOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
################## [ Registre # Mountpoints2 ]
HKCU\Software\Microsoft\....\MountPoints2\{09a120fd-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{09a120fd-b012-11dd-82d0-001a9277cc2d}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{09a120fe-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{09a120fe-b012-11dd-82d0-001a9277cc2d}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{14174fa3-a0d4-11dc-82b2-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{14174fa3-a0d4-11dc-82b2-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{46150ea6-a0ad-11dc-82b0-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{46150ea6-a0ad-11dc-82b0-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e8-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e8-92b3-11dc-82ad-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e9-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e9-92b3-11dc-82ad-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2066-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2066-9cf2-11dd-82bf-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2067-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2067-9cf2-11dd-82bf-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{f7da9740-a651-11d9-8609-000ea65580b6}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{f7da9740-a651-11d9-8609-000ea65580b6}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{fc2e0090-323d-11dd-82bb-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{fc2e0090-323d-11dd-82bb-00038a000015}\Shell\AutoRun\command
################## [ ! Fin du rapport # UsbFix V3.017 ! ]
############################## [ UsbFix V3.017 # Scan ]
# User : christelle (Administrateurs) # SN403827370002
# Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 20:35:25 | 07/05/2009
# AMD Sempron(tm) 2600+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# AV : avast! antivirus 4.6.691 [VPS 0527-2] 4.6.691 [ (!) Disabled | (!) Outdated ]
# FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T
# C:\ # Disque fixe local # 69,52 Go (40,83 Go free) [HDD] # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque CD-ROM
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
# J:\ # Disque amovible # 3,72 Go (3,67 Go free) [KINGSTON] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\windows\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.be/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="christelle"
HKLM_logon: "AltDefaultUserName"="christelle"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: IMJPMIG8.1="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
HKLM_Run: PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
HKLM_Run: PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM_Run: SunJavaUpdateSched=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
################## [ Informations ]
################## [ Fichiers # Dossiers infectieux ]
Found ! C:\WINDOWS\system32\tmp.reg
Found ! C:\WINDOWS\system32\tmp.txt
Found ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc12\BearShare\UNWISE.EXE
Found ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc91\Ad-aware 6\Unwise.exe
Found ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc91\Ad-Aware SE Personal\UNWISE.EXE
################## [ Registre # Clés Run infectieuses ]
Found ! HKLM\software\microsoft\security center\\ "AntiVirusOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
Found ! HKLM\software\microsoft\security center\\ "FirewallOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
################## [ Registre # Mountpoints2 ]
HKCU\Software\Microsoft\....\MountPoints2\{09a120fd-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{09a120fd-b012-11dd-82d0-001a9277cc2d}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{09a120fe-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{09a120fe-b012-11dd-82d0-001a9277cc2d}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{14174fa3-a0d4-11dc-82b2-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{14174fa3-a0d4-11dc-82b2-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{46150ea6-a0ad-11dc-82b0-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{46150ea6-a0ad-11dc-82b0-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e8-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e8-92b3-11dc-82ad-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e9-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{654d18e9-92b3-11dc-82ad-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2066-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2066-9cf2-11dd-82bf-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2067-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{d5da2067-9cf2-11dd-82bf-00038a000015}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{f7da9740-a651-11d9-8609-000ea65580b6}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{f7da9740-a651-11d9-8609-000ea65580b6}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{fc2e0090-323d-11dd-82bb-00038a000015}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{fc2e0090-323d-11dd-82bb-00038a000015}\Shell\AutoRun\command
################## [ ! Fin du rapport # UsbFix V3.017 ! ]
Utilisateur anonyme
7 mai 2009 à 20:45
7 mai 2009 à 20:45
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir
• Double clic sur le raccourci UsbFix présent sur ton bureau
• choisis l'option 2 ( Suppression )
• Ton bureau disparaitra et le pc redémarrera .
• Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
• Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .
• Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
• Double clic sur le raccourci UsbFix présent sur ton bureau
• choisis l'option 2 ( Suppression )
• Ton bureau disparaitra et le pc redémarrera .
• Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
• Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .
• Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 05:43
8 mai 2009 à 05:43
bonjour, avec mes remerciements
voici le log
############################## [ UsbFix V3.017 # Cleaning ]
# User : christelle (Administrateurs) # SN403827370002
# Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 05:33:57 | 08/05/2009
# AMD Sempron(tm) 2600+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# AV : avast! antivirus 4.6.691 [VPS 0527-2] 4.6.691 [ (!) Disabled | (!) Outdated ]
# FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T
# C:\ # Disque fixe local # 69,52 Go (40,83 Go free) [HDD] # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque CD-ROM
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
# J:\ # Disque amovible # 3,72 Go (3,67 Go free) [KINGSTON] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Avira\AntiVir Desktop\avwsc.exe
C:\WINDOWS\system32\slrundll.exe
################## [ Fichiers # Dossiers infectieux ]
Deleted ! C:\WINDOWS\system32\tmp.reg
Deleted ! C:\WINDOWS\system32\tmp.txt
Deleted ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc12\BearShare\UNWISE.EXE
################## [ Registre # Clés Run infectieuses ]
# HKLM\software\microsoft\security center\\ "AntiVirusOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !
# HKLM\software\microsoft\security center\\ "FirewallOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{09a120fd-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{09a120fe-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{14174fa3-a0d4-11dc-82b2-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{46150ea6-a0ad-11dc-82b0-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{654d18e8-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{654d18e9-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{d5da2066-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{d5da2067-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{f7da9740-a651-11d9-8609-000ea65580b6}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{fc2e0090-323d-11dd-82bb-00038a000015}\Shell\Auto\command
################## [ Listing des fichiers présent ]
[28/12/2006 22:39|--a--c---|20] - C:\ActiveX.log
[15/11/2005 19:46|--a--c---|921654] - C:\AVIFirstFrame.BMP
[10/01/2005 16:58|-rahsc---|215] - C:\BOOT.BAK
[08/05/2009 05:29|-rahsc---|296] - C:\BOOT.INI
[05/08/2004 15:00|-rahsc---|4952] - C:\Bootfont.bin
[05/08/2004 15:00|-rahs----|263488] - C:\cmldr
[07/05/2009 15:43|--a--c---|4485] - C:\crote.txt
[10/01/2005 17:44|--a--c---|5335] - C:\DWNLOG.TXT
[27/03/2005 08:23|--a--c---|984168] - C:\EasyShareInstall.log
[?|?|?] - C:\hiberfil.sys
[10/01/2005 17:02|-rahsc---|0] - C:\IO.SYS
[10/01/2005 17:04|--ah-c---|732] - C:\IPH.PH
[10/01/2005 17:02|-rahsc---|0] - C:\MSDOS.SYS
[05/08/2004 15:00|-rahs----|47564] - C:\NTDETECT.COM
[05/08/2004 15:00|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[07/05/2009 19:24|--a--c---|6382] - C:\rapport.txt
[15/10/2006 11:55|--a--c---|0] - C:\report.txt
[10/01/2005 01:11|--a--c---|1088] - C:\SAUDIT.TXT
[09/06/2005 15:36|--a--c---|168] - C:\setupfax.log
[30/04/2007 10:14|--ah-c---|148] - C:\sqmdata00.sqm
[27/07/2007 18:34|--ah-c---|268] - C:\sqmdata01.sqm
[07/09/2007 08:33|--ah-c---|268] - C:\sqmdata02.sqm
[07/09/2007 09:33|--ah-c---|268] - C:\sqmdata03.sqm
[07/01/2007 08:23|--ah-c---|208] - C:\sqmdata04.sqm
[19/02/2007 13:54|--ah-c---|268] - C:\sqmdata05.sqm
[22/02/2007 12:37|--ah-c---|268] - C:\sqmdata06.sqm
[27/02/2007 19:10|--ah-c---|268] - C:\sqmdata07.sqm
[27/02/2007 19:23|--ah-c---|172] - C:\sqmdata08.sqm
[09/03/2007 08:59|--ah-c---|268] - C:\sqmdata09.sqm
[11/03/2007 23:45|--ah-c---|268] - C:\sqmdata10.sqm
[13/03/2007 18:27|--ah-c---|268] - C:\sqmdata11.sqm
[19/03/2007 19:16|--ah-c---|268] - C:\sqmdata12.sqm
[25/03/2007 09:51|--ah-c---|268] - C:\sqmdata13.sqm
[16/04/2007 14:38|--ah-c---|268] - C:\sqmdata14.sqm
[16/04/2007 15:15|--ah-c---|268] - C:\sqmdata15.sqm
[30/04/2007 10:14|--ah-c---|268] - C:\sqmdata16.sqm
[30/04/2007 10:14|--ah-c---|136] - C:\sqmdata17.sqm
[26/05/2007 16:15|--ah-c---|268] - C:\sqmdata18.sqm
[19/08/2007 08:46|--ah-c---|268] - C:\sqmdata19.sqm
[30/04/2007 10:14|--ah-c---|136] - C:\sqmnoopt00.sqm
[26/05/2007 16:15|--ah-c---|244] - C:\sqmnoopt01.sqm
[27/07/2007 18:34|--ah-c---|244] - C:\sqmnoopt02.sqm
[19/08/2007 08:46|--ah-c---|244] - C:\sqmnoopt03.sqm
[07/09/2007 08:33|--ah-c---|244] - C:\sqmnoopt04.sqm
[07/09/2007 09:33|--ah-c---|244] - C:\sqmnoopt05.sqm
[07/01/2007 08:23|--ah-c---|244] - C:\sqmnoopt06.sqm
[07/01/2007 08:23|--ah-c---|136] - C:\sqmnoopt07.sqm
[19/02/2007 13:54|--ah-c---|244] - C:\sqmnoopt08.sqm
[22/02/2007 12:37|--ah-c---|244] - C:\sqmnoopt09.sqm
[27/02/2007 19:10|--ah-c---|244] - C:\sqmnoopt10.sqm
[27/02/2007 19:23|--ah-c---|172] - C:\sqmnoopt11.sqm
[09/03/2007 08:59|--ah-c---|244] - C:\sqmnoopt12.sqm
[11/03/2007 23:45|--ah-c---|244] - C:\sqmnoopt13.sqm
[13/03/2007 18:27|--ah-c---|244] - C:\sqmnoopt14.sqm
[19/03/2007 19:16|--ah-c---|244] - C:\sqmnoopt15.sqm
[25/03/2007 09:51|--ah-c---|244] - C:\sqmnoopt16.sqm
[16/04/2007 14:38|--ah-c---|244] - C:\sqmnoopt17.sqm
[16/04/2007 15:15|--ah-c---|244] - C:\sqmnoopt18.sqm
[30/04/2007 10:14|--ah-c---|244] - C:\sqmnoopt19.sqm
[07/05/2009 16:46|--a--c---|4765] - C:\TB.txt
[29/08/2006 14:40|--ahsc---|4096] - C:\Thumbs.db
[08/05/2009 05:38|--a--c---|7049] - C:\UsbFix.txt
[08/10/2006 14:46|--a--c---|89] - C:\wl.err
[08/11/2006 19:45|--a--c---|150] - C:\YServer.txt
[04/05/2009 19:58|--a------|16742799] - J:\vlc-0.9.9-win32.exe
[05/05/2009 11:02|--a------|30143928] - J:\avira_antivir_personal_fr.exe
[05/05/2009 11:03|--a------|0] - J:\spybotsd162.exe
[05/05/2009 11:04|--a------|2967800] - J:\mbam-setup.exe
[05/05/2009 11:05|--a------|3227536] - J:\ccsetup219.exe
[05/05/2009 11:06|--a------|812344] - J:\HJTInstall.exe
[06/05/2009 20:56|--a------|3063649] - J:\Norton_Removal_Tool.exe
[26/04/2009 18:44|--ah-----|296] - J:\WMPInfo.xml
################## [ Vaccination ]
# C:\autorun.inf -> Folder created by UsbFix.
# J:\autorun.inf -> Folder created by UsbFix.
################## [ Cracks / Keygens / Serials ]
# -> Nothing found !
################## [ ! Fin du rapport # UsbFix V3.017 ! ]
voici le log
############################## [ UsbFix V3.017 # Cleaning ]
# User : christelle (Administrateurs) # SN403827370002
# Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 05:33:57 | 08/05/2009
# AMD Sempron(tm) 2600+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# AV : avast! antivirus 4.6.691 [VPS 0527-2] 4.6.691 [ (!) Disabled | (!) Outdated ]
# FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T
# C:\ # Disque fixe local # 69,52 Go (40,83 Go free) [HDD] # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque CD-ROM
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
# J:\ # Disque amovible # 3,72 Go (3,67 Go free) [KINGSTON] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Avira\AntiVir Desktop\avwsc.exe
C:\WINDOWS\system32\slrundll.exe
################## [ Fichiers # Dossiers infectieux ]
Deleted ! C:\WINDOWS\system32\tmp.reg
Deleted ! C:\WINDOWS\system32\tmp.txt
Deleted ! C:\recycler\S-1-5-21-3460183548-3191515321-1128167637-500\Dc12\BearShare\UNWISE.EXE
################## [ Registre # Clés Run infectieuses ]
# HKLM\software\microsoft\security center\\ "AntiVirusOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !
# HKLM\software\microsoft\security center\\ "FirewallOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{09a120fd-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{09a120fe-b012-11dd-82d0-001a9277cc2d}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{14174fa3-a0d4-11dc-82b2-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{46150ea6-a0ad-11dc-82b0-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{654d18e8-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{654d18e9-92b3-11dc-82ad-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{d5da2066-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{d5da2067-9cf2-11dd-82bf-00038a000015}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{f7da9740-a651-11d9-8609-000ea65580b6}\Shell\Auto\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{fc2e0090-323d-11dd-82bb-00038a000015}\Shell\Auto\command
################## [ Listing des fichiers présent ]
[28/12/2006 22:39|--a--c---|20] - C:\ActiveX.log
[15/11/2005 19:46|--a--c---|921654] - C:\AVIFirstFrame.BMP
[10/01/2005 16:58|-rahsc---|215] - C:\BOOT.BAK
[08/05/2009 05:29|-rahsc---|296] - C:\BOOT.INI
[05/08/2004 15:00|-rahsc---|4952] - C:\Bootfont.bin
[05/08/2004 15:00|-rahs----|263488] - C:\cmldr
[07/05/2009 15:43|--a--c---|4485] - C:\crote.txt
[10/01/2005 17:44|--a--c---|5335] - C:\DWNLOG.TXT
[27/03/2005 08:23|--a--c---|984168] - C:\EasyShareInstall.log
[?|?|?] - C:\hiberfil.sys
[10/01/2005 17:02|-rahsc---|0] - C:\IO.SYS
[10/01/2005 17:04|--ah-c---|732] - C:\IPH.PH
[10/01/2005 17:02|-rahsc---|0] - C:\MSDOS.SYS
[05/08/2004 15:00|-rahs----|47564] - C:\NTDETECT.COM
[05/08/2004 15:00|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[07/05/2009 19:24|--a--c---|6382] - C:\rapport.txt
[15/10/2006 11:55|--a--c---|0] - C:\report.txt
[10/01/2005 01:11|--a--c---|1088] - C:\SAUDIT.TXT
[09/06/2005 15:36|--a--c---|168] - C:\setupfax.log
[30/04/2007 10:14|--ah-c---|148] - C:\sqmdata00.sqm
[27/07/2007 18:34|--ah-c---|268] - C:\sqmdata01.sqm
[07/09/2007 08:33|--ah-c---|268] - C:\sqmdata02.sqm
[07/09/2007 09:33|--ah-c---|268] - C:\sqmdata03.sqm
[07/01/2007 08:23|--ah-c---|208] - C:\sqmdata04.sqm
[19/02/2007 13:54|--ah-c---|268] - C:\sqmdata05.sqm
[22/02/2007 12:37|--ah-c---|268] - C:\sqmdata06.sqm
[27/02/2007 19:10|--ah-c---|268] - C:\sqmdata07.sqm
[27/02/2007 19:23|--ah-c---|172] - C:\sqmdata08.sqm
[09/03/2007 08:59|--ah-c---|268] - C:\sqmdata09.sqm
[11/03/2007 23:45|--ah-c---|268] - C:\sqmdata10.sqm
[13/03/2007 18:27|--ah-c---|268] - C:\sqmdata11.sqm
[19/03/2007 19:16|--ah-c---|268] - C:\sqmdata12.sqm
[25/03/2007 09:51|--ah-c---|268] - C:\sqmdata13.sqm
[16/04/2007 14:38|--ah-c---|268] - C:\sqmdata14.sqm
[16/04/2007 15:15|--ah-c---|268] - C:\sqmdata15.sqm
[30/04/2007 10:14|--ah-c---|268] - C:\sqmdata16.sqm
[30/04/2007 10:14|--ah-c---|136] - C:\sqmdata17.sqm
[26/05/2007 16:15|--ah-c---|268] - C:\sqmdata18.sqm
[19/08/2007 08:46|--ah-c---|268] - C:\sqmdata19.sqm
[30/04/2007 10:14|--ah-c---|136] - C:\sqmnoopt00.sqm
[26/05/2007 16:15|--ah-c---|244] - C:\sqmnoopt01.sqm
[27/07/2007 18:34|--ah-c---|244] - C:\sqmnoopt02.sqm
[19/08/2007 08:46|--ah-c---|244] - C:\sqmnoopt03.sqm
[07/09/2007 08:33|--ah-c---|244] - C:\sqmnoopt04.sqm
[07/09/2007 09:33|--ah-c---|244] - C:\sqmnoopt05.sqm
[07/01/2007 08:23|--ah-c---|244] - C:\sqmnoopt06.sqm
[07/01/2007 08:23|--ah-c---|136] - C:\sqmnoopt07.sqm
[19/02/2007 13:54|--ah-c---|244] - C:\sqmnoopt08.sqm
[22/02/2007 12:37|--ah-c---|244] - C:\sqmnoopt09.sqm
[27/02/2007 19:10|--ah-c---|244] - C:\sqmnoopt10.sqm
[27/02/2007 19:23|--ah-c---|172] - C:\sqmnoopt11.sqm
[09/03/2007 08:59|--ah-c---|244] - C:\sqmnoopt12.sqm
[11/03/2007 23:45|--ah-c---|244] - C:\sqmnoopt13.sqm
[13/03/2007 18:27|--ah-c---|244] - C:\sqmnoopt14.sqm
[19/03/2007 19:16|--ah-c---|244] - C:\sqmnoopt15.sqm
[25/03/2007 09:51|--ah-c---|244] - C:\sqmnoopt16.sqm
[16/04/2007 14:38|--ah-c---|244] - C:\sqmnoopt17.sqm
[16/04/2007 15:15|--ah-c---|244] - C:\sqmnoopt18.sqm
[30/04/2007 10:14|--ah-c---|244] - C:\sqmnoopt19.sqm
[07/05/2009 16:46|--a--c---|4765] - C:\TB.txt
[29/08/2006 14:40|--ahsc---|4096] - C:\Thumbs.db
[08/05/2009 05:38|--a--c---|7049] - C:\UsbFix.txt
[08/10/2006 14:46|--a--c---|89] - C:\wl.err
[08/11/2006 19:45|--a--c---|150] - C:\YServer.txt
[04/05/2009 19:58|--a------|16742799] - J:\vlc-0.9.9-win32.exe
[05/05/2009 11:02|--a------|30143928] - J:\avira_antivir_personal_fr.exe
[05/05/2009 11:03|--a------|0] - J:\spybotsd162.exe
[05/05/2009 11:04|--a------|2967800] - J:\mbam-setup.exe
[05/05/2009 11:05|--a------|3227536] - J:\ccsetup219.exe
[05/05/2009 11:06|--a------|812344] - J:\HJTInstall.exe
[06/05/2009 20:56|--a------|3063649] - J:\Norton_Removal_Tool.exe
[26/04/2009 18:44|--ah-----|296] - J:\WMPInfo.xml
################## [ Vaccination ]
# C:\autorun.inf -> Folder created by UsbFix.
# J:\autorun.inf -> Folder created by UsbFix.
################## [ Cracks / Keygens / Serials ]
# -> Nothing found !
################## [ ! Fin du rapport # UsbFix V3.017 ! ]
Utilisateur anonyme
8 mai 2009 à 08:31
8 mai 2009 à 08:31
Salut ,
Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.
ensuite refais un scan RSIT et post log.txt stp
Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.
ensuite refais un scan RSIT et post log.txt stp
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 08:52
8 mai 2009 à 08:52
oui , voila le log et je vais faire RSIT maintenant
JavaRa 1.12 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Fri May 08 08:45:57 2009
Found and removed: C:\Program Files\Java\j2re1.4.2_05
Found and removed: C:\Program Files\Java\jre1.6.0_07
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4
Found and removed: Software\JavaSoft\Java2D\1.5.0_06
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\JavaPlugin.150_06
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Classes\JavaPlugin.142_05
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_04
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_05
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\JavaPlugin.142_04
Found and removed: Software\Classes\JavaPlugin.142_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\
------------------------------------
Finished reporting.
JavaRa 1.12 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Fri May 08 08:45:57 2009
Found and removed: C:\Program Files\Java\j2re1.4.2_05
Found and removed: C:\Program Files\Java\jre1.6.0_07
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4
Found and removed: Software\JavaSoft\Java2D\1.5.0_06
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\JavaPlugin.150_06
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Classes\JavaPlugin.142_05
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_04
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_05
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\JavaPlugin.142_04
Found and removed: Software\Classes\JavaPlugin.142_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\
------------------------------------
Finished reporting.
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 08:57
8 mai 2009 à 08:57
voici le log RSIT
Logfile of random's system information tool 1.06 (written by random/random)
Run by christelle at 2009-05-08 08:55:53
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 43 GB (60%) free of 71 GB
Total RAM: 191 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:55:59, on 08/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\christelle\Bureau\Nouveau dossier\outils de netoyage\RSIT.exe
C:\Program Files\trend micro\christelle.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {27E7C3BE-4662-70E0-659C-3765097DC2D5} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:\PROGRA~1\BEARSH~3\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nickelodeon.fr/
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{68AB83EC-876E-4379-AF8D-80D168787380}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{78004490-FE29-4827-AB72-85F876FE3B4B}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{E6720F91-BDBB-42B5-B440-36F5C95F4AFC}: NameServer = 85.237.87.160,217.20.114.119
O17 - HKLM\System\CCS\Services\Tcpip\..\{E87C3838-FE50-4F6D-99D0-B5D047DE38C4}: NameServer = 85.237.87.160,217.20.114.119
O17 - HKLM\System\CS1\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
Logfile of random's system information tool 1.06 (written by random/random)
Run by christelle at 2009-05-08 08:55:53
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 43 GB (60%) free of 71 GB
Total RAM: 191 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:55:59, on 08/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\christelle\Bureau\Nouveau dossier\outils de netoyage\RSIT.exe
C:\Program Files\trend micro\christelle.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {27E7C3BE-4662-70E0-659C-3765097DC2D5} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:\PROGRA~1\BEARSH~3\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nickelodeon.fr/
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{68AB83EC-876E-4379-AF8D-80D168787380}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{78004490-FE29-4827-AB72-85F876FE3B4B}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{E6720F91-BDBB-42B5-B440-36F5C95F4AFC}: NameServer = 85.237.87.160,217.20.114.119
O17 - HKLM\System\CCS\Services\Tcpip\..\{E87C3838-FE50-4F6D-99D0-B5D047DE38C4}: NameServer = 85.237.87.160,217.20.114.119
O17 - HKLM\System\CS1\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
Utilisateur anonyme
8 mai 2009 à 09:13
8 mai 2009 à 09:13
OK , on y voit plus clair .
tu as des traces de avast :
Pour désinstaller Avast telecharge cet outil
https://www.avast.com/fr-fr/uninstall-utility
-----------------------------------------------------
Va a ce fichier : C:\Program Files\trend micro\christelle.exe c est hijackthis .
double clic dessus , choisis "do a system scan only"
coches ces lignes :
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {27E7C3BE-4662-70E0-659C-3765097DC2D5} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:\PROGRA~1\BEARSH~3\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nickelodeon.fr/
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E6720F91-BDBB-42B5-B440-36F5C95F4AFC}: NameServer = 85.237.87.160,217.20.114.119
O17 - HKLM\System\CCS\Services\Tcpip\..\{E87C3838-FE50-4F6D-99D0-B5D047DE38C4}: NameServer = 85.237.87.160,217.20.114.119
Tu les coches et tu clic sur fix checked .
----------------------------------------------------------------------------
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:files
C:\UsbFix.txt
C:\UsbFix
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\Agent.OMZ.Fix.exe
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\swxcacls.exe
C:\WINDOWS\system32\swsc.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\swreg.exe
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\Process.exe
C:\rapport.txt
C:\TB.txt
C:\ToolBar SD
C:\crote.txt
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
:commands
[emptytemp]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
---------------------------------------------------------------------
Télécharge WORT de pc-system.fr sur ton bureau :
> http://pc-system.fr/
* Double clique sur WORT.exe pour lancer l'installation de l'outil .
* Double clic sur WareOut_Removal_Tool.bat (qui est apparu sur ton bureau ) pour lancer l'outil et laisse toi guider ...
> Choisis l'option 1 et laisse travailler l'outil ...
Une fois terminé, poste le rapport obtenu .
( Il te sera proposé d'éxécuter le fichier WORTregfix.reg, accepte. )
tu as des traces de avast :
Pour désinstaller Avast telecharge cet outil
https://www.avast.com/fr-fr/uninstall-utility
-----------------------------------------------------
Va a ce fichier : C:\Program Files\trend micro\christelle.exe c est hijackthis .
double clic dessus , choisis "do a system scan only"
coches ces lignes :
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {27E7C3BE-4662-70E0-659C-3765097DC2D5} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:\PROGRA~1\BEARSH~3\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nickelodeon.fr/
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E6720F91-BDBB-42B5-B440-36F5C95F4AFC}: NameServer = 85.237.87.160,217.20.114.119
O17 - HKLM\System\CCS\Services\Tcpip\..\{E87C3838-FE50-4F6D-99D0-B5D047DE38C4}: NameServer = 85.237.87.160,217.20.114.119
Tu les coches et tu clic sur fix checked .
----------------------------------------------------------------------------
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:files
C:\UsbFix.txt
C:\UsbFix
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\Agent.OMZ.Fix.exe
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\swxcacls.exe
C:\WINDOWS\system32\swsc.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\swreg.exe
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\Process.exe
C:\rapport.txt
C:\TB.txt
C:\ToolBar SD
C:\crote.txt
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
:commands
[emptytemp]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
---------------------------------------------------------------------
Télécharge WORT de pc-system.fr sur ton bureau :
> http://pc-system.fr/
* Double clique sur WORT.exe pour lancer l'installation de l'outil .
* Double clic sur WareOut_Removal_Tool.bat (qui est apparu sur ton bureau ) pour lancer l'outil et laisse toi guider ...
> Choisis l'option 1 et laisse travailler l'outil ...
Une fois terminé, poste le rapport obtenu .
( Il te sera proposé d'éxécuter le fichier WORTregfix.reg, accepte. )
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 10:08
8 mai 2009 à 10:08
========== FILES ==========
C:\UsbFix.txt moved successfully.
C:\UsbFix\Tools moved successfully.
C:\UsbFix moved successfully.
C:\WINDOWS\system32\VACFix.exe moved successfully.
C:\WINDOWS\system32\o4Patch.exe moved successfully.
C:\WINDOWS\system32\IEDFix.exe moved successfully.
C:\WINDOWS\system32\IEDFix.C.exe moved successfully.
C:\WINDOWS\system32\Agent.OMZ.Fix.exe moved successfully.
C:\WINDOWS\system32\404Fix.exe moved successfully.
C:\WINDOWS\system32\WS2Fix.exe moved successfully.
C:\WINDOWS\system32\VCCLSID.exe moved successfully.
C:\WINDOWS\system32\swxcacls.exe moved successfully.
C:\WINDOWS\system32\swsc.exe moved successfully.
C:\WINDOWS\system32\SrchSTS.exe moved successfully.
C:\WINDOWS\system32\dumphive.exe moved successfully.
C:\WINDOWS\system32\swreg.exe moved successfully.
C:\WINDOWS\system32\Process.exe moved successfully.
File/Folder C:\WINDOWS\system32\Process.exe not found.
C:\rapport.txt moved successfully.
C:\TB.txt moved successfully.
C:\ToolBar SD\Backup-TB\Reg moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1\Temp moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\Cookies moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1 moved successfully.
C:\ToolBar SD\Backup-TB moved successfully.
C:\ToolBar SD moved successfully.
C:\crote.txt moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\\ deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\HZH3JB0O\affich-12338688-malwarebytes-chaud-chaud-chaud[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1e0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05082009_100001
C:\UsbFix.txt moved successfully.
C:\UsbFix\Tools moved successfully.
C:\UsbFix moved successfully.
C:\WINDOWS\system32\VACFix.exe moved successfully.
C:\WINDOWS\system32\o4Patch.exe moved successfully.
C:\WINDOWS\system32\IEDFix.exe moved successfully.
C:\WINDOWS\system32\IEDFix.C.exe moved successfully.
C:\WINDOWS\system32\Agent.OMZ.Fix.exe moved successfully.
C:\WINDOWS\system32\404Fix.exe moved successfully.
C:\WINDOWS\system32\WS2Fix.exe moved successfully.
C:\WINDOWS\system32\VCCLSID.exe moved successfully.
C:\WINDOWS\system32\swxcacls.exe moved successfully.
C:\WINDOWS\system32\swsc.exe moved successfully.
C:\WINDOWS\system32\SrchSTS.exe moved successfully.
C:\WINDOWS\system32\dumphive.exe moved successfully.
C:\WINDOWS\system32\swreg.exe moved successfully.
C:\WINDOWS\system32\Process.exe moved successfully.
File/Folder C:\WINDOWS\system32\Process.exe not found.
C:\rapport.txt moved successfully.
C:\TB.txt moved successfully.
C:\ToolBar SD\Backup-TB\Reg moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1\Temp moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\Cookies moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1 moved successfully.
C:\ToolBar SD\Backup-TB moved successfully.
C:\ToolBar SD moved successfully.
C:\crote.txt moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\\ deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\HZH3JB0O\affich-12338688-malwarebytes-chaud-chaud-chaud[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1e0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05082009_100001
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 10:09
8 mai 2009 à 10:09
j'ai un bip d'erreur pas moyen de fermer OTMoveilt3
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 10:30
8 mai 2009 à 10:30
en fait il fallait patienter le programe m'a demander chose faite au demarage j'ai eu seulement une fenetre qui me demander d'accepter que le programe de OTMovelt3 s'ouvre sur le bureau rien d'autre j'ai accepter et suite a cela un log est apparu je pense qu'il est un peu different du premier a lors je le joins
========== FILES ==========
C:\UsbFix.txt moved successfully.
C:\UsbFix\Tools moved successfully.
C:\UsbFix moved successfully.
C:\WINDOWS\system32\VACFix.exe moved successfully.
C:\WINDOWS\system32\o4Patch.exe moved successfully.
C:\WINDOWS\system32\IEDFix.exe moved successfully.
C:\WINDOWS\system32\IEDFix.C.exe moved successfully.
C:\WINDOWS\system32\Agent.OMZ.Fix.exe moved successfully.
C:\WINDOWS\system32\404Fix.exe moved successfully.
C:\WINDOWS\system32\WS2Fix.exe moved successfully.
C:\WINDOWS\system32\VCCLSID.exe moved successfully.
C:\WINDOWS\system32\swxcacls.exe moved successfully.
C:\WINDOWS\system32\swsc.exe moved successfully.
C:\WINDOWS\system32\SrchSTS.exe moved successfully.
C:\WINDOWS\system32\dumphive.exe moved successfully.
C:\WINDOWS\system32\swreg.exe moved successfully.
C:\WINDOWS\system32\Process.exe moved successfully.
File/Folder C:\WINDOWS\system32\Process.exe not found.
C:\rapport.txt moved successfully.
C:\TB.txt moved successfully.
C:\ToolBar SD\Backup-TB\Reg moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1\Temp moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\Cookies moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1 moved successfully.
C:\ToolBar SD\Backup-TB moved successfully.
C:\ToolBar SD moved successfully.
C:\crote.txt moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\\ deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\HZH3JB0O\affich-12338688-malwarebytes-chaud-chaud-chaud[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1e0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05082009_100001
Files moved on Reboot...
File C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\HZH3JB0O\affich-12338688-malwarebytes-chaud-chaud-chaud[1].htm not found!
C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_1e0.dat not found!
ui me demander d'accepter que le programe de OTMovelt3 s'ouvre sur le bureau rien d'autre j'ai accepter et suite a cela un log est apparu je pense qu'il est un peu different du premier a lors je le joins
========== FILES ==========
C:\UsbFix.txt moved successfully.
C:\UsbFix\Tools moved successfully.
C:\UsbFix moved successfully.
C:\WINDOWS\system32\VACFix.exe moved successfully.
C:\WINDOWS\system32\o4Patch.exe moved successfully.
C:\WINDOWS\system32\IEDFix.exe moved successfully.
C:\WINDOWS\system32\IEDFix.C.exe moved successfully.
C:\WINDOWS\system32\Agent.OMZ.Fix.exe moved successfully.
C:\WINDOWS\system32\404Fix.exe moved successfully.
C:\WINDOWS\system32\WS2Fix.exe moved successfully.
C:\WINDOWS\system32\VCCLSID.exe moved successfully.
C:\WINDOWS\system32\swxcacls.exe moved successfully.
C:\WINDOWS\system32\swsc.exe moved successfully.
C:\WINDOWS\system32\SrchSTS.exe moved successfully.
C:\WINDOWS\system32\dumphive.exe moved successfully.
C:\WINDOWS\system32\swreg.exe moved successfully.
C:\WINDOWS\system32\Process.exe moved successfully.
File/Folder C:\WINDOWS\system32\Process.exe not found.
C:\rapport.txt moved successfully.
C:\TB.txt moved successfully.
C:\ToolBar SD\Backup-TB\Reg moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1\Temp moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\LOCALS~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1\Cookies moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1\CHRIST~1 moved successfully.
C:\ToolBar SD\Backup-TB\DOCUME~1 moved successfully.
C:\ToolBar SD\Backup-TB moved successfully.
C:\ToolBar SD moved successfully.
C:\crote.txt moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\\ deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\HZH3JB0O\affich-12338688-malwarebytes-chaud-chaud-chaud[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1e0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05082009_100001
Files moved on Reboot...
File C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\HZH3JB0O\affich-12338688-malwarebytes-chaud-chaud-chaud[1].htm not found!
C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_1e0.dat not found!
ui me demander d'accepter que le programe de OTMovelt3 s'ouvre sur le bureau rien d'autre j'ai accepter et suite a cela un log est apparu je pense qu'il est un peu different du premier a lors je le joins
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 10:38
8 mai 2009 à 10:38
===== Rapport WareOut Removal Tool =====
version 3.0
analyse effectuée le 08/05/2009 à 10:34:40,68
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
C:\autorun.inf trouvé!
C:\autorun.inf suppression impossible
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system32\ ~~~~
~~~~ Recherche d'infections dans C:\Documents and Settings\christelle\Application Data\ ~~~~
~~~~ Recherche d'infections dans C:\Documents and Settings\christelle\Bureau\ ~~~~
~~~~ Recherche de détournement de DNS ~~~~
~~~~ Recherche du Rootkit kd???.exe ~~~~
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
============================================
=================== ROOTKIT ================
============================================
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system32\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system32\drivers\ ~~~~
~~~~ Recherche d'infections dans C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\ ~~~~
~~~~ Recherche d'infections dans C:\Documents and Settings\christelle\Start Menu\Programs\ ~~~~
~~~~ Nettoyage du registre ~~~~
~~~~ Tentative de réparation des entrées suivantes: ~~~~
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"
[HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]
~~~~ Vérification: ~~~~
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
_________________________________
développé par http://pc-system.fr
_________________________________
version 3.0
analyse effectuée le 08/05/2009 à 10:34:40,68
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
C:\autorun.inf trouvé!
C:\autorun.inf suppression impossible
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system32\ ~~~~
~~~~ Recherche d'infections dans C:\Documents and Settings\christelle\Application Data\ ~~~~
~~~~ Recherche d'infections dans C:\Documents and Settings\christelle\Bureau\ ~~~~
~~~~ Recherche de détournement de DNS ~~~~
~~~~ Recherche du Rootkit kd???.exe ~~~~
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
============================================
=================== ROOTKIT ================
============================================
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system32\ ~~~~
~~~~ Recherche d'infections dans C:\WINDOWS\system32\drivers\ ~~~~
~~~~ Recherche d'infections dans C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\ ~~~~
~~~~ Recherche d'infections dans C:\Documents and Settings\christelle\Start Menu\Programs\ ~~~~
~~~~ Nettoyage du registre ~~~~
~~~~ Tentative de réparation des entrées suivantes: ~~~~
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"
[HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]
~~~~ Vérification: ~~~~
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
_________________________________
développé par http://pc-system.fr
_________________________________
Utilisateur anonyme
8 mai 2009 à 10:44
8 mai 2009 à 10:44
ok ,
refais un scan RSIT , post log.txt . Dis moi comment va le pc et on termine .
refais un scan RSIT , post log.txt . Dis moi comment va le pc et on termine .
ketty291
Messages postés
635
Date d'inscription
samedi 1 juillet 2006
Statut
Membre
Dernière intervention
1 août 2019
4
8 mai 2009 à 12:39
8 mai 2009 à 12:39
excusez moi du retard voila LE LOG RSI T l'impression generale a l'air bonne faut voir par la suite bien entendu je vous remercie pour votre aide extraordinaire je vous souhaite un tres bon WEE KEND
Logfile of random's system information tool 1.06 (written by random/random)
Run by christelle at 2009-05-08 12:34:55
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 44 GB (61%) free of 71 GB
Total RAM: 191 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:21, on 08/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\slrundll.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\christelle\Bureau\Nouveau dossier\outils de netoyage\RSIT.exe
C:\Program Files\trend micro\christelle.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{68AB83EC-876E-4379-AF8D-80D168787380}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{78004490-FE29-4827-AB72-85F876FE3B4B}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CS1\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
Logfile of random's system information tool 1.06 (written by random/random)
Run by christelle at 2009-05-08 12:34:55
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 44 GB (61%) free of 71 GB
Total RAM: 191 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:21, on 08/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\slrundll.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\christelle\Bureau\Nouveau dossier\outils de netoyage\RSIT.exe
C:\Program Files\trend micro\christelle.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{68AB83EC-876E-4379-AF8D-80D168787380}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{78004490-FE29-4827-AB72-85F876FE3B4B}: NameServer = 217.20.114.128,85.237.87.165
O17 - HKLM\System\CS1\Services\Tcpip\..\{57A1991D-6326-4EE7-B915-B788A9D2AEF9}: NameServer = 217.20.114.128,85.237.87.165
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe