Problème de son + Bug sur urban terror
samlaruelle
Messages postés
33
Statut
Membre
-
hellow? -
hellow? -
Bonjours a tous,
Alors voila, le son ne fonctionne pas toujours, sur urban terror , je lag alors que je ne lagais jamais avant, de + antivir m'as detecté des trojans et que j'ai supprimé mais j'ai peur d'etre encore infecter, pourriez vous m'aidez svp?
Alors voila, le son ne fonctionne pas toujours, sur urban terror , je lag alors que je ne lagais jamais avant, de + antivir m'as detecté des trojans et que j'ai supprimé mais j'ai peur d'etre encore infecter, pourriez vous m'aidez svp?
A voir également:
- Problème de son + Bug sur urban terror
- Bug chromecast - Guide
- Iptv bug ✓ - Forum TV & Vidéo
- Comment faire bug son téléphone - Forum Mobile
- Bug outlook - Guide
- Total bug caf - Guide
31 réponses
Ok merci jlpjlp de m'aider, et j'ai installé un HIPS ou IDS, je ne sais pas, j'ai vu sur malekal que c'etait une sorte de pare-feu, j'ai downloadé dynamic security agent. Le rapport Combofix ci dessous.
j'ai installé un HIPS ou IDS, je ne sais pas, j'ai vu sur malekal que c'etait une sorte de pare-feu, j'ai downloadé dynamic security agent
et si tu vire tout ce que tu vient de dire cela remarche?
et si tu vire tout ce que tu vient de dire cela remarche?
car il faut eviter de melanger les portections!
pour protéger gratos ton ordi
https://www.commentcamarche.net/telecharger/securite/
vacciner son ordi après avoir branché toutes ses clés usb avec usbfix ou flash disinfector ou rav antivirus car beaucoup actuellement transitent par les supports externes :
http://ww25.evosla.com/compteur.php?soft=rav_antivirus
http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
---------
mettre un antivirus
ANTIVIR ou AVG8 ou (AVAST )
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
https://www.avira.com/fr/free-antivirus-windows
-------------
des anti-espions :
MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
WINDOWS DEFENDER ou SPYWARE TERMINATOR ou SPYWARE GUARD
+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
Rq : spybot … sortent de nouvelles versions régulièrement, vérifiez que vous avez la dernière version
--------
un pare feu :
celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO
https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/18128.html
https://www.zonealarm.com/software/free-firewall
-----------
CCLEANER pour effacer les traces de surf
---------
naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
http://www.mozilla-europe.org/fr/products/firefox/
pour protéger gratos ton ordi
https://www.commentcamarche.net/telecharger/securite/
vacciner son ordi après avoir branché toutes ses clés usb avec usbfix ou flash disinfector ou rav antivirus car beaucoup actuellement transitent par les supports externes :
http://ww25.evosla.com/compteur.php?soft=rav_antivirus
http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
---------
mettre un antivirus
ANTIVIR ou AVG8 ou (AVAST )
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
https://www.avira.com/fr/free-antivirus-windows
-------------
des anti-espions :
MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
WINDOWS DEFENDER ou SPYWARE TERMINATOR ou SPYWARE GUARD
+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
Rq : spybot … sortent de nouvelles versions régulièrement, vérifiez que vous avez la dernière version
--------
un pare feu :
celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO
https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/18128.html
https://www.zonealarm.com/software/free-firewall
-----------
CCLEANER pour effacer les traces de surf
---------
naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
http://www.mozilla-europe.org/fr/products/firefox/
Voila le scan Combofix :
ComboFix 09-07-24.01 - Administrateur 25/07/2009 22:52.3.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1015.647 [GMT 2:00]
Running from: c:\documents and settings\Administrateur.TITANIUM.000\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Privatefirewall *disabled* {AF0CFAAE-AAB5-450a-8C74-0DEEB429DF4F}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\145e6c.msi
c:\windows\Installer\2d31e2a.msi
c:\windows\Installer\5972f.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-25 to 2009-07-25 )))))))))))))))))))))))))))))))
.
2009-07-25 09:15 . 2009-07-25 09:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Privacyware
2009-07-25 09:15 . 2009-07-25 09:15 -------- d-----w- c:\program files\Privacyware
2009-07-24 20:59 . 2009-07-24 21:01 -------- dc-h--w- c:\windows\ie8
2009-07-24 20:25 . 2009-07-24 20:38 -------- dc----w- C:\UsbFix
2009-07-24 20:07 . 2009-07-24 20:07 -------- dc----w- C:\rsit
2009-07-24 13:09 . 2009-07-24 13:09 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\NeroDCTemplates
2009-07-23 19:05 . 2009-07-23 19:06 55328 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-23 14:29 . 2009-07-23 14:59 152576 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-22 10:05 . 2009-07-25 07:01 -------- d-----w- c:\program files\Panda Security
2009-07-22 08:26 . 2009-07-22 08:26 -------- d-----w- c:\program files\ESET
2009-07-21 22:40 . 2009-07-21 22:40 -------- d-----w- c:\windows\system32\wbem\Repository
2009-07-19 08:43 . 2009-07-20 00:46 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\Netlog
2009-07-17 19:35 . 2009-07-17 19:35 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\Temp
2009-07-17 05:59 . 2009-07-23 17:16 -------- d-----w- c:\program files\Navilog1
2009-07-17 04:52 . 2009-07-24 14:37 -------- dc----w- C:\FindyKill
2009-07-10 16:59 . 2009-07-10 16:59 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-07-10 16:59 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-10 16:59 . 2009-07-10 16:59 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-10 15:17 . 2009-07-25 03:48 -------- d-----w- c:\program files\SpywareBlaster
2009-07-08 15:43 . 2009-07-08 15:57 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\DoctorWeb
2009-07-07 23:03 . 2009-07-24 20:07 -------- d-----w- c:\program files\trend micro
2009-07-07 12:52 . 2009-07-23 21:04 -------- dc----w- C:\Bases
2009-07-07 12:51 . 2009-07-23 21:10 -------- dc----w- C:\Kaspersky
2009-07-07 12:09 . 2009-07-07 12:09 23218 ----a-w- c:\windows\system32\ipsec6.zip
2009-07-06 18:19 . 2009-07-06 18:19 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-07-06 18:17 . 2009-07-10 18:16 -------- d-----w- c:\windows\ERUNT
2009-07-06 18:17 . 2009-07-06 18:32 -------- dc----w- C:\Backups
2009-07-06 16:53 . 2009-07-25 03:49 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-06 16:52 . 2009-07-06 16:52 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\AVG8
2009-07-06 16:51 . 2009-07-14 16:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-06 16:01 . 2009-07-06 16:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Simply Super Software
2009-07-05 09:45 . 2007-05-17 15:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2009-07-05 09:45 . 2004-02-22 08:11 719872 ----a-w- c:\windows\system32\devil.dll
2009-07-05 09:44 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-05 09:44 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2009-07-05 09:36 . 2009-07-05 09:36 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\FMZilla
2009-07-05 09:36 . 2009-07-25 02:28 -------- d-----w- c:\program files\Free Music Zilla
2009-07-04 19:11 . 2009-07-04 19:11 2330880 ----a-w- c:\windows\system32\TUKernel.exe
2009-07-03 14:18 . 2009-07-03 14:18 -------- d--h--w- c:\windows\PIF
2009-07-03 11:04 . 2009-07-03 11:04 -------- d-----w- c:\program files\eChanblard
2009-07-03 05:08 . 2009-07-09 18:09 -------- d-----w- c:\program files\Download Direct
2009-07-03 03:52 . 2009-07-03 03:52 198064 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-03 03:52 . 2009-07-03 03:55 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\IDM
2009-07-03 03:44 . 2009-07-03 03:44 -------- d-----w- c:\program files\Free Download Manager
2009-07-03 03:44 . 2009-07-03 05:46 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\DMCache
2009-07-03 03:44 . 2009-07-03 03:44 -------- dc----w- c:\program files\BoontyGames
2009-07-03 03:38 . 2009-07-03 03:44 -------- d-----w- c:\program files\ID
2009-07-03 03:23 . 2009-07-03 03:38 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\IDM(2)
2009-07-02 16:26 . 2009-07-02 16:26 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Megaupload
2009-07-01 13:26 . 2009-07-01 13:26 -------- d-----w- c:\program files\Fichiers communs\NSV
2009-07-01 01:22 . 2009-07-01 01:22 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\GlarySoft
2009-06-30 18:22 . 2009-06-30 18:39 -------- d-----w- c:\program files\UrbanTerror
2009-06-27 09:44 . 1998-11-17 11:44 328704 ----a-w- c:\windows\IsUn0407.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-25 19:26 . 2009-02-15 21:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-07-25 17:58 . 2009-01-29 19:52 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TrackMania
2009-07-25 00:27 . 2009-01-16 20:37 -------- d-----w- c:\program files\a-squared Free
2009-07-24 13:22 . 2008-12-15 20:32 1 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-23 19:06 . 2009-07-23 19:05 1724 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-23 15:01 . 2008-12-15 20:12 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-22 17:35 . 2008-12-23 08:31 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\dvdcss
2009-07-21 22:27 . 2009-05-26 19:59 -------- d-----w- c:\program files\ma-config.com
2009-07-19 23:47 . 2009-03-18 06:10 -------- d-----w- c:\program files\Royal-Yugi Online
2009-07-19 23:44 . 2009-07-05 01:52 9 ----a-w- c:\program files\Royal-Yugi Online__x3_asse_x3__.txt
2009-07-16 19:06 . 2008-11-06 06:59 -------- d-----w- c:\program files\Windows Live Favorites
2009-07-13 23:00 . 2009-01-12 17:44 3775176 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-13 11:36 . 2008-12-29 13:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2008-12-29 13:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-11 09:49 . 2009-05-27 14:13 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-07-10 20:52 . 2009-02-04 17:51 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\teamspeak2
2009-07-10 20:46 . 2009-05-24 06:51 -------- d-----w- c:\program files\Winamp
2009-07-10 18:18 . 2009-05-28 16:23 85173752 -c--a-w- C:\Sauv.reg
2009-07-10 17:07 . 2009-06-01 06:52 -------- d-----w- c:\program files\eMule
2009-07-09 21:22 . 2008-12-15 20:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-06 16:51 . 2009-01-16 20:08 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-07-02 16:22 . 2008-10-25 14:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-01 23:27 . 2009-05-19 15:27 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\SUPERAntiSpyware.com
2009-07-01 23:27 . 2009-05-19 15:27 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-01 21:10 . 2009-05-27 14:12 -------- d-sh--w- c:\documents and settings\All Users.WINDOWS\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-28 11:09 . 2009-01-15 19:54 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\gtk-2.0
2009-06-16 14:40 . 2004-08-04 00:54 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:40 . 2001-08-24 14:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 01:32 . 2009-06-15 01:21 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\TeamViewer
2009-06-15 01:21 . 2009-06-15 01:21 -------- d-----w- c:\program files\TeamViewer
2009-06-13 17:42 . 2009-03-24 16:28 -------- d-----w- c:\program files\ServerMania
2009-06-13 17:19 . 2009-06-13 17:19 -------- d-----w- c:\program files\TeamSpeak 3
2009-06-09 18:45 . 2009-06-09 18:45 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Logitech
2009-06-09 04:53 . 2009-06-09 04:53 -------- d-----w- c:\program files\Common Files
2009-06-09 04:51 . 2009-04-20 09:29 -------- d-----w- c:\program files\Fichiers communs\logishrd
2009-06-09 04:45 . 2008-10-25 14:24 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2009-06-09 04:25 . 2001-08-24 14:00 71248 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-09 04:25 . 2001-08-24 14:00 458230 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-05 19:40 . 2008-12-17 20:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ma-config.com
2009-06-04 07:31 . 2009-05-27 14:08 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Desktopicon
2009-06-03 19:10 . 2004-08-04 00:54 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-01 15:22 . 2009-06-01 15:22 -------- d-----w- c:\program files\Avira
2009-06-01 15:22 . 2009-06-01 14:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira
2009-06-01 14:50 . 2009-06-01 14:50 -------- d-----w- c:\program files\RarZilla Free Unrar
2009-05-30 00:35 . 2009-05-30 00:35 -------- d-----w- c:\program files\Logitech
2009-05-30 00:25 . 2009-04-07 21:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
2009-05-27 14:13 . 2009-05-27 14:13 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\TuneUp Software
2009-05-27 14:13 . 2009-05-27 14:13 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TuneUp Software
2009-05-27 13:25 . 2009-05-27 13:25 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Uniblue
2009-05-27 13:25 . 2009-05-27 13:25 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-05-27 13:22 . 2008-12-16 17:01 18424 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 15:44 . 2009-04-11 06:34 152576 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-13 05:04 . 2004-08-04 00:54 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:33 . 2004-08-04 00:54 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-04 15:22 . 2008-12-15 11:55 5075968 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-04-30 11:31 . 2008-12-15 11:55 17881088 ----a-w- c:\windows\RTHDCPL.EXE
2009-07-20 11:50 . 2008-10-26 17:56 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-07-13 414992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-23 148888]
"Dynamic Security Agent"="c:\program files\Privacyware\Dynamic Security Agent\DSA.exe" [2007-11-22 2376968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Fichiers communs\logishrd\WUApp32.exe" [2008-12-17 443664]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
Rappels du Calendrier Microsoft Works.lnk - c:\program files\MSWorks\Calendrier\WKCALREM.EXE [1998-8-11 68368]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrateur.TITANIUM.000^Menu Démarrer^Programmes^Démarrage^Free Music Zilla.lnk]
path=c:\documents and settings\Administrateur.TITANIUM.000\Menu Démarrer\Programmes\Démarrage\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrateur.TITANIUM.000^Menu Démarrer^Programmes^Démarrage^Logitech . Enregistrement du produit.lnk]
backup=c:\windows\pss\Logitech . Enregistrement du produit.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrateur.TITANIUM.000^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Fenêtre d'état Canon LBP-810.LNK]
backup=c:\windows\pss\Fenêtre d'état Canon LBP-810.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"LightScribe Control Panel"=c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
"CAPON"=c:\windows\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_05\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\Steam\\SteamApps\\asseforlife\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\asseforlife\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\TmUnitedForever\\TmForever.exe"=
"c:\\Program Files\\TmUnitedForever\\Serveur\\TrackmaniaServer.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\TmUnitedForever\\TmForeverLauncher.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Royal-Yugi Online\\RYO.exe"=
"c:\\Program Files\\UrbanTerror\\ioUrbanTerror.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Kaspersky\\kavupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"22088:TCP"= 22088:TCP:BitComet 22088 TCP
"22088:UDP"= 22088:UDP:BitComet 22088 UDP
"2351:TCP"= 2351:TCP:tmu 1
"3451:TCP"= 3451:TCP:tmu 2
"2351:UDP"= 2351:UDP:tmu 3
"3451:UDP"= 3451:UDP:tmu 4
"2350:TCP"= 2350:TCP:tm1
"2350:UDP"= 2350:UDP:tm2
"3450:TCP"= 3450:TCP:tm3
"3450:UDP"= 3450:UDP:tm4
"135:TCP"= 135:TCP:DCOM(135)
R1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys [22/11/2007 19:41 87304]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [01/06/2009 17:22 108289]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [29/12/2008 15:11 211216]
R2 PFNet;Privacyware network service;c:\program files\Privacyware\Dynamic Security Agent\pfsvc.exe [22/11/2007 19:42 349448]
R2 RapidPort;RapidPort;c:\windows\system32\drivers\CAPLPTN.SYS [24/05/2009 08:42 22912]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [10/07/2009 18:59 604416]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [29/12/2008 15:11 19096]
S2 gupdate1c98fb4bd28432c;Service Google Update (gupdate1c98fb4bd28432c);c:\program files\Google\Update\GoogleUpdate.exe [15/02/2009 23:31 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [14/05/2009 15:16 1684736]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);c:\windows\system32\drivers\s716bus.sys [23/12/2008 15:33 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;c:\windows\system32\drivers\s716mdfl.sys [02/03/2009 16:46 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;c:\windows\system32\drivers\s716mdm.sys [02/03/2009 16:46 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s716mgmt.sys [13/03/2009 09:48 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);c:\windows\system32\drivers\s716nd5.sys [13/03/2009 14:25 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;c:\windows\system32\drivers\s716obex.sys [13/03/2009 09:48 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);c:\windows\system32\drivers\s716unic.sys [13/03/2009 14:24 98952]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-07-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-15 23:11]
2009-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 21:31]
2009-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 21:31]
2009-07-25 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:42]
2009-07-25 c:\windows\Tasks\Malwarebytes' Scheduled Update for Administrateur.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-12-29 11:36]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-{66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
mWindow Title =
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Mozilla\Firefox\Profiles\xbponqkb.default\
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npornap.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-25 22:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1715567821-764733703-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,8f,e3,dd,26,84,ec,41,9c,c2,44,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,8f,e3,dd,26,84,ec,41,9c,c2,44,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\pfproc.dll
- - - - - - - > 'lsass.exe'(660)
c:\windows\system32\pfproc.dll
.
Completion time: 2009-07-25 22:58
ComboFix-quarantined-files.txt 2009-07-25 20:58
Pre-Run: 16 016 965 632 octets libres
Post-Run: 15 987 138 560 octets libres
Current=4 Default=4 Failed=1 LastKnownGood=3 Sets=1,2,3,4
336 --- E O F --- 2009-07-16 19:43
ComboFix 09-07-24.01 - Administrateur 25/07/2009 22:52.3.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1015.647 [GMT 2:00]
Running from: c:\documents and settings\Administrateur.TITANIUM.000\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Privatefirewall *disabled* {AF0CFAAE-AAB5-450a-8C74-0DEEB429DF4F}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\145e6c.msi
c:\windows\Installer\2d31e2a.msi
c:\windows\Installer\5972f.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-25 to 2009-07-25 )))))))))))))))))))))))))))))))
.
2009-07-25 09:15 . 2009-07-25 09:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Privacyware
2009-07-25 09:15 . 2009-07-25 09:15 -------- d-----w- c:\program files\Privacyware
2009-07-24 20:59 . 2009-07-24 21:01 -------- dc-h--w- c:\windows\ie8
2009-07-24 20:25 . 2009-07-24 20:38 -------- dc----w- C:\UsbFix
2009-07-24 20:07 . 2009-07-24 20:07 -------- dc----w- C:\rsit
2009-07-24 13:09 . 2009-07-24 13:09 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\NeroDCTemplates
2009-07-23 19:05 . 2009-07-23 19:06 55328 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-23 14:29 . 2009-07-23 14:59 152576 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-22 10:05 . 2009-07-25 07:01 -------- d-----w- c:\program files\Panda Security
2009-07-22 08:26 . 2009-07-22 08:26 -------- d-----w- c:\program files\ESET
2009-07-21 22:40 . 2009-07-21 22:40 -------- d-----w- c:\windows\system32\wbem\Repository
2009-07-19 08:43 . 2009-07-20 00:46 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\Netlog
2009-07-17 19:35 . 2009-07-17 19:35 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\Temp
2009-07-17 05:59 . 2009-07-23 17:16 -------- d-----w- c:\program files\Navilog1
2009-07-17 04:52 . 2009-07-24 14:37 -------- dc----w- C:\FindyKill
2009-07-10 16:59 . 2009-07-10 16:59 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-07-10 16:59 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-10 16:59 . 2009-07-10 16:59 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-10 15:17 . 2009-07-25 03:48 -------- d-----w- c:\program files\SpywareBlaster
2009-07-08 15:43 . 2009-07-08 15:57 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\DoctorWeb
2009-07-07 23:03 . 2009-07-24 20:07 -------- d-----w- c:\program files\trend micro
2009-07-07 12:52 . 2009-07-23 21:04 -------- dc----w- C:\Bases
2009-07-07 12:51 . 2009-07-23 21:10 -------- dc----w- C:\Kaspersky
2009-07-07 12:09 . 2009-07-07 12:09 23218 ----a-w- c:\windows\system32\ipsec6.zip
2009-07-06 18:19 . 2009-07-06 18:19 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-07-06 18:17 . 2009-07-10 18:16 -------- d-----w- c:\windows\ERUNT
2009-07-06 18:17 . 2009-07-06 18:32 -------- dc----w- C:\Backups
2009-07-06 16:53 . 2009-07-25 03:49 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-06 16:52 . 2009-07-06 16:52 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\AVG8
2009-07-06 16:51 . 2009-07-14 16:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-06 16:01 . 2009-07-06 16:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Simply Super Software
2009-07-05 09:45 . 2007-05-17 15:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2009-07-05 09:45 . 2004-02-22 08:11 719872 ----a-w- c:\windows\system32\devil.dll
2009-07-05 09:44 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-05 09:44 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2009-07-05 09:36 . 2009-07-05 09:36 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\FMZilla
2009-07-05 09:36 . 2009-07-25 02:28 -------- d-----w- c:\program files\Free Music Zilla
2009-07-04 19:11 . 2009-07-04 19:11 2330880 ----a-w- c:\windows\system32\TUKernel.exe
2009-07-03 14:18 . 2009-07-03 14:18 -------- d--h--w- c:\windows\PIF
2009-07-03 11:04 . 2009-07-03 11:04 -------- d-----w- c:\program files\eChanblard
2009-07-03 05:08 . 2009-07-09 18:09 -------- d-----w- c:\program files\Download Direct
2009-07-03 03:52 . 2009-07-03 03:52 198064 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-03 03:52 . 2009-07-03 03:55 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\IDM
2009-07-03 03:44 . 2009-07-03 03:44 -------- d-----w- c:\program files\Free Download Manager
2009-07-03 03:44 . 2009-07-03 05:46 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\DMCache
2009-07-03 03:44 . 2009-07-03 03:44 -------- dc----w- c:\program files\BoontyGames
2009-07-03 03:38 . 2009-07-03 03:44 -------- d-----w- c:\program files\ID
2009-07-03 03:23 . 2009-07-03 03:38 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\IDM(2)
2009-07-02 16:26 . 2009-07-02 16:26 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Megaupload
2009-07-01 13:26 . 2009-07-01 13:26 -------- d-----w- c:\program files\Fichiers communs\NSV
2009-07-01 01:22 . 2009-07-01 01:22 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\GlarySoft
2009-06-30 18:22 . 2009-06-30 18:39 -------- d-----w- c:\program files\UrbanTerror
2009-06-27 09:44 . 1998-11-17 11:44 328704 ----a-w- c:\windows\IsUn0407.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-25 19:26 . 2009-02-15 21:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-07-25 17:58 . 2009-01-29 19:52 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TrackMania
2009-07-25 00:27 . 2009-01-16 20:37 -------- d-----w- c:\program files\a-squared Free
2009-07-24 13:22 . 2008-12-15 20:32 1 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-23 19:06 . 2009-07-23 19:05 1724 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-23 15:01 . 2008-12-15 20:12 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-22 17:35 . 2008-12-23 08:31 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\dvdcss
2009-07-21 22:27 . 2009-05-26 19:59 -------- d-----w- c:\program files\ma-config.com
2009-07-19 23:47 . 2009-03-18 06:10 -------- d-----w- c:\program files\Royal-Yugi Online
2009-07-19 23:44 . 2009-07-05 01:52 9 ----a-w- c:\program files\Royal-Yugi Online__x3_asse_x3__.txt
2009-07-16 19:06 . 2008-11-06 06:59 -------- d-----w- c:\program files\Windows Live Favorites
2009-07-13 23:00 . 2009-01-12 17:44 3775176 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-13 11:36 . 2008-12-29 13:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2008-12-29 13:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-11 09:49 . 2009-05-27 14:13 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-07-10 20:52 . 2009-02-04 17:51 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\teamspeak2
2009-07-10 20:46 . 2009-05-24 06:51 -------- d-----w- c:\program files\Winamp
2009-07-10 18:18 . 2009-05-28 16:23 85173752 -c--a-w- C:\Sauv.reg
2009-07-10 17:07 . 2009-06-01 06:52 -------- d-----w- c:\program files\eMule
2009-07-09 21:22 . 2008-12-15 20:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-06 16:51 . 2009-01-16 20:08 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-07-02 16:22 . 2008-10-25 14:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-01 23:27 . 2009-05-19 15:27 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\SUPERAntiSpyware.com
2009-07-01 23:27 . 2009-05-19 15:27 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-01 21:10 . 2009-05-27 14:12 -------- d-sh--w- c:\documents and settings\All Users.WINDOWS\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-28 11:09 . 2009-01-15 19:54 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\gtk-2.0
2009-06-16 14:40 . 2004-08-04 00:54 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:40 . 2001-08-24 14:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 01:32 . 2009-06-15 01:21 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\TeamViewer
2009-06-15 01:21 . 2009-06-15 01:21 -------- d-----w- c:\program files\TeamViewer
2009-06-13 17:42 . 2009-03-24 16:28 -------- d-----w- c:\program files\ServerMania
2009-06-13 17:19 . 2009-06-13 17:19 -------- d-----w- c:\program files\TeamSpeak 3
2009-06-09 18:45 . 2009-06-09 18:45 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Logitech
2009-06-09 04:53 . 2009-06-09 04:53 -------- d-----w- c:\program files\Common Files
2009-06-09 04:51 . 2009-04-20 09:29 -------- d-----w- c:\program files\Fichiers communs\logishrd
2009-06-09 04:45 . 2008-10-25 14:24 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2009-06-09 04:25 . 2001-08-24 14:00 71248 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-09 04:25 . 2001-08-24 14:00 458230 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-05 19:40 . 2008-12-17 20:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ma-config.com
2009-06-04 07:31 . 2009-05-27 14:08 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Desktopicon
2009-06-03 19:10 . 2004-08-04 00:54 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-01 15:22 . 2009-06-01 15:22 -------- d-----w- c:\program files\Avira
2009-06-01 15:22 . 2009-06-01 14:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira
2009-06-01 14:50 . 2009-06-01 14:50 -------- d-----w- c:\program files\RarZilla Free Unrar
2009-05-30 00:35 . 2009-05-30 00:35 -------- d-----w- c:\program files\Logitech
2009-05-30 00:25 . 2009-04-07 21:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
2009-05-27 14:13 . 2009-05-27 14:13 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\TuneUp Software
2009-05-27 14:13 . 2009-05-27 14:13 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TuneUp Software
2009-05-27 13:25 . 2009-05-27 13:25 -------- d-----w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Uniblue
2009-05-27 13:25 . 2009-05-27 13:25 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-05-27 13:22 . 2008-12-16 17:01 18424 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 15:44 . 2009-04-11 06:34 152576 ----a-w- c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-13 05:04 . 2004-08-04 00:54 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:33 . 2004-08-04 00:54 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-04 15:22 . 2008-12-15 11:55 5075968 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-04-30 11:31 . 2008-12-15 11:55 17881088 ----a-w- c:\windows\RTHDCPL.EXE
2009-07-20 11:50 . 2008-10-26 17:56 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-07-13 414992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-23 148888]
"Dynamic Security Agent"="c:\program files\Privacyware\Dynamic Security Agent\DSA.exe" [2007-11-22 2376968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Fichiers communs\logishrd\WUApp32.exe" [2008-12-17 443664]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
Rappels du Calendrier Microsoft Works.lnk - c:\program files\MSWorks\Calendrier\WKCALREM.EXE [1998-8-11 68368]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrateur.TITANIUM.000^Menu Démarrer^Programmes^Démarrage^Free Music Zilla.lnk]
path=c:\documents and settings\Administrateur.TITANIUM.000\Menu Démarrer\Programmes\Démarrage\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrateur.TITANIUM.000^Menu Démarrer^Programmes^Démarrage^Logitech . Enregistrement du produit.lnk]
backup=c:\windows\pss\Logitech . Enregistrement du produit.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrateur.TITANIUM.000^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Fenêtre d'état Canon LBP-810.LNK]
backup=c:\windows\pss\Fenêtre d'état Canon LBP-810.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"LightScribe Control Panel"=c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
"CAPON"=c:\windows\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_05\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\Steam\\SteamApps\\asseforlife\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\asseforlife\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\TmUnitedForever\\TmForever.exe"=
"c:\\Program Files\\TmUnitedForever\\Serveur\\TrackmaniaServer.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\TmUnitedForever\\TmForeverLauncher.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Royal-Yugi Online\\RYO.exe"=
"c:\\Program Files\\UrbanTerror\\ioUrbanTerror.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Kaspersky\\kavupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"22088:TCP"= 22088:TCP:BitComet 22088 TCP
"22088:UDP"= 22088:UDP:BitComet 22088 UDP
"2351:TCP"= 2351:TCP:tmu 1
"3451:TCP"= 3451:TCP:tmu 2
"2351:UDP"= 2351:UDP:tmu 3
"3451:UDP"= 3451:UDP:tmu 4
"2350:TCP"= 2350:TCP:tm1
"2350:UDP"= 2350:UDP:tm2
"3450:TCP"= 3450:TCP:tm3
"3450:UDP"= 3450:UDP:tm4
"135:TCP"= 135:TCP:DCOM(135)
R1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys [22/11/2007 19:41 87304]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [01/06/2009 17:22 108289]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [29/12/2008 15:11 211216]
R2 PFNet;Privacyware network service;c:\program files\Privacyware\Dynamic Security Agent\pfsvc.exe [22/11/2007 19:42 349448]
R2 RapidPort;RapidPort;c:\windows\system32\drivers\CAPLPTN.SYS [24/05/2009 08:42 22912]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [10/07/2009 18:59 604416]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [29/12/2008 15:11 19096]
S2 gupdate1c98fb4bd28432c;Service Google Update (gupdate1c98fb4bd28432c);c:\program files\Google\Update\GoogleUpdate.exe [15/02/2009 23:31 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [14/05/2009 15:16 1684736]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);c:\windows\system32\drivers\s716bus.sys [23/12/2008 15:33 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;c:\windows\system32\drivers\s716mdfl.sys [02/03/2009 16:46 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;c:\windows\system32\drivers\s716mdm.sys [02/03/2009 16:46 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s716mgmt.sys [13/03/2009 09:48 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);c:\windows\system32\drivers\s716nd5.sys [13/03/2009 14:25 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;c:\windows\system32\drivers\s716obex.sys [13/03/2009 09:48 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);c:\windows\system32\drivers\s716unic.sys [13/03/2009 14:24 98952]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-07-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-15 23:11]
2009-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 21:31]
2009-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 21:31]
2009-07-25 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:42]
2009-07-25 c:\windows\Tasks\Malwarebytes' Scheduled Update for Administrateur.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-12-29 11:36]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-{66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
mWindow Title =
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Administrateur.TITANIUM.000\Application Data\Mozilla\Firefox\Profiles\xbponqkb.default\
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npornap.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-25 22:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1715567821-764733703-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,8f,e3,dd,26,84,ec,41,9c,c2,44,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,8f,e3,dd,26,84,ec,41,9c,c2,44,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\pfproc.dll
- - - - - - - > 'lsass.exe'(660)
c:\windows\system32\pfproc.dll
.
Completion time: 2009-07-25 22:58
ComboFix-quarantined-files.txt 2009-07-25 20:58
Pre-Run: 16 016 965 632 octets libres
Post-Run: 15 987 138 560 octets libres
Current=4 Default=4 Failed=1 LastKnownGood=3 Sets=1,2,3,4
336 --- E O F --- 2009-07-16 19:43
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Pour le IDS, tu pens qu'il vaudrait mieux le virer pour laisser le teatimer de spybot?
Car j'ai antivir en resident + mbam en resident + a-squarred et spybot en scans occasionnels +ccleaner et cleanup pour le nettoyage regulier, je passe toujours ccleaner et tune up avant de jouer a Urban terror, je ferme' toutes mes autres apllications et ca lag pas trop mais ces derniers ca bug, même sur des serveur a faible ping et a faible nombre de personne (4/5)..
Car j'ai antivir en resident + mbam en resident + a-squarred et spybot en scans occasionnels +ccleaner et cleanup pour le nettoyage regulier, je passe toujours ccleaner et tune up avant de jouer a Urban terror, je ferme' toutes mes autres apllications et ca lag pas trop mais ces derniers ca bug, même sur des serveur a faible ping et a faible nombre de personne (4/5)..
J'ai retesté Urban terror, j'ai nettoyé avant avec ccleaner, tune up + clean up, j'ai laissé que d'allumué urban terror mais il bug encore. avant ca ne lagait quasiment jamais :/
Mettre a jour java:
https://javara.fr.malavida.com/
Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.
si cela ne fonctionne pas
https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80
tu peux désinstaller les vieilles versions.
_________________________________
Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
/!\ Déconnectes toi et fermes toutes applications en cours
● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
● Double clique sur l'icône Ad-removersituée sur ton bureau
● Au menu principal choisi l'option "A"
● Postes le rapport qui apparait à la fin .
( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
https://javara.fr.malavida.com/
Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.
si cela ne fonctionne pas
https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80
tu peux désinstaller les vieilles versions.
_________________________________
Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
/!\ Déconnectes toi et fermes toutes applications en cours
● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
● Double clique sur l'icône Ad-removersituée sur ton bureau
● Au menu principal choisi l'option "A"
● Postes le rapport qui apparait à la fin .
( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
Le log javara:
JavaRa 1.15 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Sun Jul 26 17:38:38 2009
Found and removed: C:\Program Files\Java\j2re1.4.2_05
Found and removed: C:\Program Files\Java\jre1.6.0_07
Found and removed: C:\Documents and Settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_11
Found and removed: C:\Documents and Settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_12
Found and removed: C:\Documents and Settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_13
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Classes\JavaPlugin.142_05
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_05
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\JavaPlugin.142_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D410205
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
JavaRa 1.15 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Sun Jul 26 17:38:38 2009
Found and removed: C:\Program Files\Java\j2re1.4.2_05
Found and removed: C:\Program Files\Java\jre1.6.0_07
Found and removed: C:\Documents and Settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_11
Found and removed: C:\Documents and Settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_12
Found and removed: C:\Documents and Settings\Administrateur.TITANIUM.000\Application Data\Sun\Java\jre1.6.0_13
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142050}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410205
Found and removed: SOFTWARE\Classes\JavaPlugin.142_05
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_05
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_05
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\JavaPlugin.142_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D410205
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
Et le log ad remover de C_XX:
======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 24/06/2009 à 7:10 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 17:42:14, 26/07/2009 | Mode Normal | Option: SCAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: TITANIUM | Utilisateur actuel: Administrateur
.
Administrateur: Administrateur
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité *Desactive*
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.5.1 *
Nom du profil: xbponqkb.default (Administrateur)
.
(Prefs.js) user_pref("browser.startup.homepage", "www.google.fr");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.1");
(Invalidprefs.js) user_pref("browser.search.defaultenginename", "Ask.com");
(Invalidprefs.js) user_pref("browser.search.selectedEngine", "Ask.com");
(Invalidprefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.5");
.
.
* Internet Explorer Version 8.0.6001.18702 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.google.fr/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
C:\Documents and Settings\Administrateur.TITANIUM.000\.housecall6.6\patch.exe
.
===================================
.
2738 Octet(s) - C:\Ad-Report-CLEAN.log
2115 Octet(s) - C:\Ad-Report-SCAN.log
.
5 Fichier(s) - C:\DOCUME~1\ADMINI~1.000\LOCALS~1\Temp
3 Fichier(s) - C:\WINDOWS\Temp
.
1 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 18:02:31 | 26/07/2009
.
============== E.O.F ==============
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 24/06/2009 à 7:10 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 17:42:14, 26/07/2009 | Mode Normal | Option: SCAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: TITANIUM | Utilisateur actuel: Administrateur
.
Administrateur: Administrateur
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité *Desactive*
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.5.1 *
Nom du profil: xbponqkb.default (Administrateur)
.
(Prefs.js) user_pref("browser.startup.homepage", "www.google.fr");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.1");
(Invalidprefs.js) user_pref("browser.search.defaultenginename", "Ask.com");
(Invalidprefs.js) user_pref("browser.search.selectedEngine", "Ask.com");
(Invalidprefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.5");
.
.
* Internet Explorer Version 8.0.6001.18702 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.google.fr/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
C:\Documents and Settings\Administrateur.TITANIUM.000\.housecall6.6\patch.exe
.
===================================
.
2738 Octet(s) - C:\Ad-Report-CLEAN.log
2115 Octet(s) - C:\Ad-Report-SCAN.log
.
5 Fichier(s) - C:\DOCUME~1\ADMINI~1.000\LOCALS~1\Temp
3 Fichier(s) - C:\WINDOWS\Temp
.
1 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 18:02:31 | 26/07/2009
.
============== E.O.F ==============
.
non rien je me demande si cela ne vient pas d'un nettoyage poussé de tuneup
repare windows puis dis si cela persiste
https://www.commentcamarche.net/informatique/windows/25-verifier-et-reparer-des-fichiers-systeme-avec-windows-10/
repare windows puis dis si cela persiste
https://www.commentcamarche.net/informatique/windows/25-verifier-et-reparer-des-fichiers-systeme-avec-windows-10/