Mon PC rame
Résolu
evilshin
Messages postés
169
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
je pense que mon ordinateur est infecté par un virus et j'aimerais savoir comment faire.
lorsque je le démarre au bout de 5 minutes il plante meme si je ne fait rien et le disque dur continue de charger sans cesse...
merci d'avance
--
je pense que mon ordinateur est infecté par un virus et j'aimerais savoir comment faire.
lorsque je le démarre au bout de 5 minutes il plante meme si je ne fait rien et le disque dur continue de charger sans cesse...
merci d'avance
--
A voir également:
- Mon PC rame
- Pc qui rame - Guide
- Reinitialiser pc - Guide
- Test performance pc - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Plus de son sur mon pc - Guide
28 réponses
salut :
Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent
▶ Télécharge List'em et enregistre le sur ton bureau
Il ne necessite pas d'installation
▶double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan
▶laisse travailler l'outil
le rapport va s'afficher , une fois le scan fini
▶colle le contenu dans ta prochaine réponse
Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent
▶ Télécharge List'em et enregistre le sur ton bureau
Il ne necessite pas d'installation
▶double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan
▶laisse travailler l'outil
le rapport va s'afficher , une fois le scan fini
▶colle le contenu dans ta prochaine réponse
List'em by g3n-h@ckm@n 1.0.2.0
16/08/2009 15:24:45,73
Microsoft Windows XP [version 5.1.2600]
Infections possibles :
====================
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
"C:\WINDOWS\system32\MSINET.oca"
C:\WINDOWS\System32\SET41.tmp
C:\WINDOWS\System32\SET45.tmp
C:\WINDOWS\System32\SET4D.tmp
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
¤¤¤¤¤¤¤¤¤¤ Windows\Prefetch :
C:\WINDOWS\Prefetch\ALAUNCH.EXE-145B15F4.pf
C:\WINDOWS\Prefetch\ALCMTR.EXE-01A7139B.pf
C:\WINDOWS\Prefetch\ALG.EXE-275708CF.pf
C:\WINDOWS\Prefetch\ASHAVAST.EXE-1EA93A67.pf
C:\WINDOWS\Prefetch\ASHDISP.EXE-204B2541.pf
C:\WINDOWS\Prefetch\ASHMAISV.EXE-072F6A23.pf
C:\WINDOWS\Prefetch\ASHSIMPL.EXE-20AB57BA.pf
C:\WINDOWS\Prefetch\ATL80SP1-KB973923-X86.EXE-0E213871.pf
C:\WINDOWS\Prefetch\AU_.EXE-388AA971.pf
C:\WINDOWS\Prefetch\AVAST.SETUP-295443AF.pf
C:\WINDOWS\Prefetch\AZMIXERSEL.EXE-1A009C4F.pf
C:\WINDOWS\Prefetch\CCLEANER.EXE-09CFC2BC.pf
C:\WINDOWS\Prefetch\CLEANMGR.EXE-31B430FE.pf
C:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf
C:\WINDOWS\Prefetch\CONTROL.EXE-24FBF8B3.pf
C:\WINDOWS\Prefetch\CS 1.6.EXE-06A97CB3.pf
C:\WINDOWS\Prefetch\CS 1.6.EXE-2D3AD6EE.pf
C:\WINDOWS\Prefetch\CTFMON.EXE-05E57A5E.pf
C:\WINDOWS\Prefetch\DATOS.EXE-0A3F44FD.pf
C:\WINDOWS\Prefetch\DATOS.EXE-12738B0F.pf
C:\WINDOWS\Prefetch\DEFRAG.EXE-2858C7E2.pf
C:\WINDOWS\Prefetch\DFRGNTFS.EXE-38C3807C.pf
C:\WINDOWS\Prefetch\DUMPREP.EXE-0AF2BF67.pf
C:\WINDOWS\Prefetch\ERAGENT.EXE-0C495853.pf
C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
C:\WINDOWS\Prefetch\HKCMD.EXE-0F06AE14.pf
C:\WINDOWS\Prefetch\HL.EXE-37F24DD5.pf
C:\WINDOWS\Prefetch\HL.EXE-3AE4385E.pf
C:\WINDOWS\Prefetch\ICARDAGT.EXE-2EF8882C.pf
C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
C:\WINDOWS\Prefetch\IGFXPERS.EXE-19DA7B04.pf
C:\WINDOWS\Prefetch\IGFXSRVC.EXE-1D88F978.pf
C:\WINDOWS\Prefetch\IGFXTRAY.EXE-0A23D403.pf
C:\WINDOWS\Prefetch\INFOCARD.EXE-0146833D.pf
C:\WINDOWS\Prefetch\INSTALL.EXE-1F275C2A.pf
C:\WINDOWS\Prefetch\INSTALL.EXE-3908921A.pf
C:\WINDOWS\Prefetch\JAVA.EXE-32FD225F.pf
C:\WINDOWS\Prefetch\JAVACPL.EXE-19F2F107.pf
C:\WINDOWS\Prefetch\JAVARA.EXE-14B746DF.pf
C:\WINDOWS\Prefetch\JAVASETUP6U15[1].EXE-2EE7300E.pf
C:\WINDOWS\Prefetch\JAVASETUP6U15[1].EXE-310B35B7.pf
C:\WINDOWS\Prefetch\JAVAW.EXE-392A4E93.pf
C:\WINDOWS\Prefetch\JAVAWS.EXE-078C20EA.pf
C:\WINDOWS\Prefetch\JQS.EXE-31B60334.pf
C:\WINDOWS\Prefetch\JRE-6U15-WINDOWS-I586-IFTW.EX-30265955.pf
C:\WINDOWS\Prefetch\JUCHECK.EXE-1E35CB2F.pf
C:\WINDOWS\Prefetch\LAUNCHER.EXE-2242BDB4.pf
C:\WINDOWS\Prefetch\Layout.ini
C:\WINDOWS\Prefetch\LOGON.SCR-24ADF392.pf
C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf
C:\WINDOWS\Prefetch\MISE-A-JOUR-LIVESEARCH.EXE-0DEF2CD4.pf
C:\WINDOWS\Prefetch\MMC.EXE-55643954.pf
C:\WINDOWS\Prefetch\MRT.EXE-161A5291.pf
C:\WINDOWS\Prefetch\MRTSTUB.EXE-2C8FA766.pf
C:\WINDOWS\Prefetch\MSFEEDSSYNC.EXE-05335A39.pf
C:\WINDOWS\Prefetch\MSI1.TMP-0811A6AB.pf
C:\WINDOWS\Prefetch\MSI3.TMP-1D44F61D.pf
C:\WINDOWS\Prefetch\MSI4.TMP-219D4FD9.pf
C:\WINDOWS\Prefetch\MSI7.TMP-05840CEA.pf
C:\WINDOWS\Prefetch\MSIC1.TMP-279A0920.pf
C:\WINDOWS\Prefetch\MSID.TMP-06D29570.pf
C:\WINDOWS\Prefetch\MSIEXEC.EXE-330626DC.pf
C:\WINDOWS\Prefetch\MSMSGS.EXE-0620E8B3.pf
C:\WINDOWS\Prefetch\MSNMSGR.EXE-0EBDBC56.pf
C:\WINDOWS\Prefetch\MSOXMLED.EXE-00789432.pf
C:\WINDOWS\Prefetch\NOTIFICATION-LIVESEARCH.EXE-2F1BD00B.pf
C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf
C:\WINDOWS\Prefetch\PHOTOFILTRE.EXE-2E6C8CE5.pf
C:\WINDOWS\Prefetch\READER_SL.EXE-2D713FFC.pf
C:\WINDOWS\Prefetch\REALSCHED.EXE-388D7C2D.pf
C:\WINDOWS\Prefetch\REGEDIT.EXE-2AE3423E.pf
C:\WINDOWS\Prefetch\REGSVR32.EXE-396DEA2C.pf
C:\WINDOWS\Prefetch\RSTRUI.EXE-05C31B56.pf
C:\WINDOWS\Prefetch\RTHDCPL.EXE-005A6E31.pf
C:\WINDOWS\Prefetch\RTKBTMNT.EXE-30304B86.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C500167.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C98A3C8.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-419F288A.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4AA62846.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4EE39BB6.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-5B413BD0.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6030FCDA.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-650D9C14.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E8D4657.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-7020A1C1.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-753F1DF3.pf
C:\WINDOWS\Prefetch\SILVERLIGHT.3.0.EXE-2C133C9F.pf
C:\WINDOWS\Prefetch\SPUPDSVC.EXE-07BA1E73.pf
C:\WINDOWS\Prefetch\SYNTPENH.EXE-2B70B91C.pf
C:\WINDOWS\Prefetch\TASKMGR.EXE-06144C13.pf
C:\WINDOWS\Prefetch\UNINSTALL.EXE-05C7F050.pf
C:\WINDOWS\Prefetch\UNINSTALL.EXE-2CEDE765.pf
C:\WINDOWS\Prefetch\UNREGMP2.EXE-0CFB0619.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0029A0A0.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-02AB5AD9.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-05E8F498.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-07AE39BE.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0805A8D6.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-08A48A3C.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0976907F.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0B5892F2.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0CF7BDD2.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0E1798C8.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0FAD1899.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-21262E50.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-23F9B380.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-24E178AD.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-27188450.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-2CFB58A0.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-3150CA14.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-3163B7C4.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-37836919.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-38569992.pf
C:\WINDOWS\Prefetch\UPDATE_8FF3.EXE-31B03306.pf
C:\WINDOWS\Prefetch\USERINIT.EXE-0743FDA9.pf
C:\WINDOWS\Prefetch\VERCLSID.EXE-28F52AD2.pf
C:\WINDOWS\Prefetch\VIRTUALDJ.EXE-1598C65E.pf
C:\WINDOWS\Prefetch\VLC.EXE-02F29DFD.pf
C:\WINDOWS\Prefetch\WINDOWS-KB890830-V2.13.EXE-1DEA93FD.pf
C:\WINDOWS\Prefetch\WLCOMM.EXE-2F4516F1.pf
C:\WINDOWS\Prefetch\WMIAPSRV.EXE-02740A4B.pf
C:\WINDOWS\Prefetch\WMIPRVSE.EXE-0D449B4F.pf
C:\WINDOWS\Prefetch\WMPLAYER.EXE-1ACCF80A.pf
C:\WINDOWS\Prefetch\WOW-3.2.0-FRFR-DOWNLOADER.EXE-0573DF32.pf
C:\WINDOWS\Prefetch\WOW.EXE-2292A7C2.pf
C:\WINDOWS\Prefetch\WSCNTFY.EXE-0B14C27D.pf
C:\WINDOWS\Prefetch\WUAUCLT.EXE-1360D60A.pf
C:\WINDOWS\Prefetch\ZEROX.EXE-1E76C166.pf
C:\WINDOWS\Prefetch\ZEROX.EXE-21D4518A.pf
C:\WINDOWS\Prefetch\ZEROX.EXE-26AB0778.pf
--------EOF------------
16/08/2009 15:24:45,73
Microsoft Windows XP [version 5.1.2600]
Infections possibles :
====================
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
"C:\WINDOWS\system32\MSINET.oca"
C:\WINDOWS\System32\SET41.tmp
C:\WINDOWS\System32\SET45.tmp
C:\WINDOWS\System32\SET4D.tmp
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
¤¤¤¤¤¤¤¤¤¤ Windows\Prefetch :
C:\WINDOWS\Prefetch\ALAUNCH.EXE-145B15F4.pf
C:\WINDOWS\Prefetch\ALCMTR.EXE-01A7139B.pf
C:\WINDOWS\Prefetch\ALG.EXE-275708CF.pf
C:\WINDOWS\Prefetch\ASHAVAST.EXE-1EA93A67.pf
C:\WINDOWS\Prefetch\ASHDISP.EXE-204B2541.pf
C:\WINDOWS\Prefetch\ASHMAISV.EXE-072F6A23.pf
C:\WINDOWS\Prefetch\ASHSIMPL.EXE-20AB57BA.pf
C:\WINDOWS\Prefetch\ATL80SP1-KB973923-X86.EXE-0E213871.pf
C:\WINDOWS\Prefetch\AU_.EXE-388AA971.pf
C:\WINDOWS\Prefetch\AVAST.SETUP-295443AF.pf
C:\WINDOWS\Prefetch\AZMIXERSEL.EXE-1A009C4F.pf
C:\WINDOWS\Prefetch\CCLEANER.EXE-09CFC2BC.pf
C:\WINDOWS\Prefetch\CLEANMGR.EXE-31B430FE.pf
C:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf
C:\WINDOWS\Prefetch\CONTROL.EXE-24FBF8B3.pf
C:\WINDOWS\Prefetch\CS 1.6.EXE-06A97CB3.pf
C:\WINDOWS\Prefetch\CS 1.6.EXE-2D3AD6EE.pf
C:\WINDOWS\Prefetch\CTFMON.EXE-05E57A5E.pf
C:\WINDOWS\Prefetch\DATOS.EXE-0A3F44FD.pf
C:\WINDOWS\Prefetch\DATOS.EXE-12738B0F.pf
C:\WINDOWS\Prefetch\DEFRAG.EXE-2858C7E2.pf
C:\WINDOWS\Prefetch\DFRGNTFS.EXE-38C3807C.pf
C:\WINDOWS\Prefetch\DUMPREP.EXE-0AF2BF67.pf
C:\WINDOWS\Prefetch\ERAGENT.EXE-0C495853.pf
C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
C:\WINDOWS\Prefetch\HKCMD.EXE-0F06AE14.pf
C:\WINDOWS\Prefetch\HL.EXE-37F24DD5.pf
C:\WINDOWS\Prefetch\HL.EXE-3AE4385E.pf
C:\WINDOWS\Prefetch\ICARDAGT.EXE-2EF8882C.pf
C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
C:\WINDOWS\Prefetch\IGFXPERS.EXE-19DA7B04.pf
C:\WINDOWS\Prefetch\IGFXSRVC.EXE-1D88F978.pf
C:\WINDOWS\Prefetch\IGFXTRAY.EXE-0A23D403.pf
C:\WINDOWS\Prefetch\INFOCARD.EXE-0146833D.pf
C:\WINDOWS\Prefetch\INSTALL.EXE-1F275C2A.pf
C:\WINDOWS\Prefetch\INSTALL.EXE-3908921A.pf
C:\WINDOWS\Prefetch\JAVA.EXE-32FD225F.pf
C:\WINDOWS\Prefetch\JAVACPL.EXE-19F2F107.pf
C:\WINDOWS\Prefetch\JAVARA.EXE-14B746DF.pf
C:\WINDOWS\Prefetch\JAVASETUP6U15[1].EXE-2EE7300E.pf
C:\WINDOWS\Prefetch\JAVASETUP6U15[1].EXE-310B35B7.pf
C:\WINDOWS\Prefetch\JAVAW.EXE-392A4E93.pf
C:\WINDOWS\Prefetch\JAVAWS.EXE-078C20EA.pf
C:\WINDOWS\Prefetch\JQS.EXE-31B60334.pf
C:\WINDOWS\Prefetch\JRE-6U15-WINDOWS-I586-IFTW.EX-30265955.pf
C:\WINDOWS\Prefetch\JUCHECK.EXE-1E35CB2F.pf
C:\WINDOWS\Prefetch\LAUNCHER.EXE-2242BDB4.pf
C:\WINDOWS\Prefetch\Layout.ini
C:\WINDOWS\Prefetch\LOGON.SCR-24ADF392.pf
C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf
C:\WINDOWS\Prefetch\MISE-A-JOUR-LIVESEARCH.EXE-0DEF2CD4.pf
C:\WINDOWS\Prefetch\MMC.EXE-55643954.pf
C:\WINDOWS\Prefetch\MRT.EXE-161A5291.pf
C:\WINDOWS\Prefetch\MRTSTUB.EXE-2C8FA766.pf
C:\WINDOWS\Prefetch\MSFEEDSSYNC.EXE-05335A39.pf
C:\WINDOWS\Prefetch\MSI1.TMP-0811A6AB.pf
C:\WINDOWS\Prefetch\MSI3.TMP-1D44F61D.pf
C:\WINDOWS\Prefetch\MSI4.TMP-219D4FD9.pf
C:\WINDOWS\Prefetch\MSI7.TMP-05840CEA.pf
C:\WINDOWS\Prefetch\MSIC1.TMP-279A0920.pf
C:\WINDOWS\Prefetch\MSID.TMP-06D29570.pf
C:\WINDOWS\Prefetch\MSIEXEC.EXE-330626DC.pf
C:\WINDOWS\Prefetch\MSMSGS.EXE-0620E8B3.pf
C:\WINDOWS\Prefetch\MSNMSGR.EXE-0EBDBC56.pf
C:\WINDOWS\Prefetch\MSOXMLED.EXE-00789432.pf
C:\WINDOWS\Prefetch\NOTIFICATION-LIVESEARCH.EXE-2F1BD00B.pf
C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf
C:\WINDOWS\Prefetch\PHOTOFILTRE.EXE-2E6C8CE5.pf
C:\WINDOWS\Prefetch\READER_SL.EXE-2D713FFC.pf
C:\WINDOWS\Prefetch\REALSCHED.EXE-388D7C2D.pf
C:\WINDOWS\Prefetch\REGEDIT.EXE-2AE3423E.pf
C:\WINDOWS\Prefetch\REGSVR32.EXE-396DEA2C.pf
C:\WINDOWS\Prefetch\RSTRUI.EXE-05C31B56.pf
C:\WINDOWS\Prefetch\RTHDCPL.EXE-005A6E31.pf
C:\WINDOWS\Prefetch\RTKBTMNT.EXE-30304B86.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C500167.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C98A3C8.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-419F288A.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4AA62846.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4EE39BB6.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-5B413BD0.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6030FCDA.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-650D9C14.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E8D4657.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-7020A1C1.pf
C:\WINDOWS\Prefetch\RUNDLL32.EXE-753F1DF3.pf
C:\WINDOWS\Prefetch\SILVERLIGHT.3.0.EXE-2C133C9F.pf
C:\WINDOWS\Prefetch\SPUPDSVC.EXE-07BA1E73.pf
C:\WINDOWS\Prefetch\SYNTPENH.EXE-2B70B91C.pf
C:\WINDOWS\Prefetch\TASKMGR.EXE-06144C13.pf
C:\WINDOWS\Prefetch\UNINSTALL.EXE-05C7F050.pf
C:\WINDOWS\Prefetch\UNINSTALL.EXE-2CEDE765.pf
C:\WINDOWS\Prefetch\UNREGMP2.EXE-0CFB0619.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0029A0A0.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-02AB5AD9.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-05E8F498.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-07AE39BE.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0805A8D6.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-08A48A3C.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0976907F.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0B5892F2.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0CF7BDD2.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0E1798C8.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-0FAD1899.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-21262E50.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-23F9B380.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-24E178AD.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-27188450.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-2CFB58A0.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-3150CA14.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-3163B7C4.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-37836919.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-38569992.pf
C:\WINDOWS\Prefetch\UPDATE_8FF3.EXE-31B03306.pf
C:\WINDOWS\Prefetch\USERINIT.EXE-0743FDA9.pf
C:\WINDOWS\Prefetch\VERCLSID.EXE-28F52AD2.pf
C:\WINDOWS\Prefetch\VIRTUALDJ.EXE-1598C65E.pf
C:\WINDOWS\Prefetch\VLC.EXE-02F29DFD.pf
C:\WINDOWS\Prefetch\WINDOWS-KB890830-V2.13.EXE-1DEA93FD.pf
C:\WINDOWS\Prefetch\WLCOMM.EXE-2F4516F1.pf
C:\WINDOWS\Prefetch\WMIAPSRV.EXE-02740A4B.pf
C:\WINDOWS\Prefetch\WMIPRVSE.EXE-0D449B4F.pf
C:\WINDOWS\Prefetch\WMPLAYER.EXE-1ACCF80A.pf
C:\WINDOWS\Prefetch\WOW-3.2.0-FRFR-DOWNLOADER.EXE-0573DF32.pf
C:\WINDOWS\Prefetch\WOW.EXE-2292A7C2.pf
C:\WINDOWS\Prefetch\WSCNTFY.EXE-0B14C27D.pf
C:\WINDOWS\Prefetch\WUAUCLT.EXE-1360D60A.pf
C:\WINDOWS\Prefetch\ZEROX.EXE-1E76C166.pf
C:\WINDOWS\Prefetch\ZEROX.EXE-21D4518A.pf
C:\WINDOWS\Prefetch\ZEROX.EXE-26AB0778.pf
--------EOF------------
Télécharge OTL de OLDTimer
▶ enregistre le sur ton Bureau.
▶ Double clic sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous Customs Scans/Fixes :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:files
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\System32\SET41.tmp
C:\WINDOWS\System32\SET45.tmp
C:\WINDOWS\System32\SET4D.tmp
:commands
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur RunFix pour lancer la suppression.
▶ Poste le rapport.
▶ enregistre le sur ton Bureau.
▶ Double clic sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous Customs Scans/Fixes :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:files
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\System32\SET41.tmp
C:\WINDOWS\System32\SET45.tmp
C:\WINDOWS\System32\SET4D.tmp
:commands
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur RunFix pour lancer la suppression.
▶ Poste le rapport.
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== FILES ==========
C:\WINDOWS\system32\MSINET.oca moved successfully.
C:\WINDOWS\System32\SET41.tmp moved successfully.
C:\WINDOWS\System32\SET45.tmp moved successfully.
C:\WINDOWS\System32\SET4D.tmp moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Loïc
->Temp folder emptied: 49302104 bytes
->Temporary Internet Files folder emptied: 6765411 bytes
->Java cache emptied: 14274752 bytes
->Google Chrome cache emptied: 6074566 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Propriétaire
%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 3072 bytes
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4ec.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 2517821 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 75,44 mb
OTL by OldTimer - Version 3.0.10.7 log created on 08162009_180412
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4ec.dat not found!
Registry entries deleted on Reboot...
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4ec.dat not found!
Registry entries deleted on Reboot...
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== FILES ==========
C:\WINDOWS\system32\MSINET.oca moved successfully.
C:\WINDOWS\System32\SET41.tmp moved successfully.
C:\WINDOWS\System32\SET45.tmp moved successfully.
C:\WINDOWS\System32\SET4D.tmp moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Loïc
->Temp folder emptied: 49302104 bytes
->Temporary Internet Files folder emptied: 6765411 bytes
->Java cache emptied: 14274752 bytes
->Google Chrome cache emptied: 6074566 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Propriétaire
%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 3072 bytes
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4ec.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 2517821 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 75,44 mb
OTL by OldTimer - Version 3.0.10.7 log created on 08162009_180412
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4ec.dat not found!
Registry entries deleted on Reboot...
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4ec.dat not found!
Registry entries deleted on Reboot...
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
▶ Double clic sur OTL.exe pour le lancer.
▶ Coche les 2 cases Lop et Purity
▶ Coche la case devant scan all users
▶ règle-le sur "60 Days"
▶Clic sur Run Scan.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
Tu feras la meme chose avec le "Extra.txt".
▶ Coche les 2 cases Lop et Purity
▶ Coche la case devant scan all users
▶ règle-le sur "60 Days"
▶Clic sur Run Scan.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
Tu feras la meme chose avec le "Extra.txt".
OTL:
http://www.cijoint.fr/cjlink.php?file=cj200908/cijwURCM0Q.txt
EXTRA:
http://www.cijoint.fr/cjlink.php?file=cj200908/cijNza0Sck.txt
http://www.cijoint.fr/cjlink.php?file=cj200908/cijwURCM0Q.txt
EXTRA:
http://www.cijoint.fr/cjlink.php?file=cj200908/cijNza0Sck.txt
▶ Télécharge et install UsbFix par Chiquitine29
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
▶ Double clic sur le raccourci UsbFix présent sur ton bureau .
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
▶ Laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra.
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
▶ Double clic sur le raccourci UsbFix présent sur ton bureau .
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
▶ Laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra.
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
############################## | UsbFix V6.018 |
User : Loïc (Administrateurs) # ACER-2141B46CA9
Update on 16/08/09 by Chiquitine29 & C_XX
Start at: 22:42:25 | 16/08/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 090815-0] 4.8.1335 [ Enabled | Updated ]
AV : McAfee VirusScan [ Enabled | Updated ]
FW : McAfee Personal Firewall[ Enabled ]
C:\ -> Disque fixe local # 144,17 Go (96,89 Go free) [ACER] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Fichiers # Dossiers infectieux |
################## | Suspect ! ... | https://www.virustotal.com/gui/ |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\G
Shell\AutoRun\command =G:\autorun.exe
HKCU\..\..\Explorer\MountPoints2\{134b79a2-3d4a-11de-8de8-00234e49ae17}
Shell\AutoRun\command =D:\ivcvknr.bat
Shell\explore\Command =D:\ivcvknr.bat
Shell\open\Command =D:\ivcvknr.bat
HKCU\..\..\Explorer\MountPoints2\{23e3f619-defc-11dd-84ac-00234e49ae17}
Shell\AutoRun\command =2a.exe
Shell\open\Command =2a.exe
HKCU\..\..\Explorer\MountPoints2\{7b5f3528-0c2c-11de-8d3f-00234e49ae17}
Shell\AutoRun\command =F:\.pspware\PSPWareLauncher.exe
HKCU\..\..\Explorer\MountPoints2\{d652a56a-e5f7-11dd-84e4-00234e49ae17}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
HKCU\..\..\Explorer\MountPoints2\{e3614ba2-f061-11dd-8cdb-00234e49ae17}
Shell\AutoRun\command =E:\SETUP.EXE
Shell\configure\command =E:\SETUP.EXE
Shell\install\command =E:\SETUP.EXE
################## | Cracks / Keygens / Serials |
"C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\2_CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe"
16/02/2009 22:05 |Size : 240954926 |Crc32 : 6789b71f |Md5 : fe218ca71667000e4b7b688f1d2726ea
"C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\AutoUpdator.exe"
15/04/2006 14:12 |Size : 307200 |Crc32 : 9140376c |Md5 : 43bb068d0b313801d30d28c0b2b7bf0d
User : Loïc (Administrateurs) # ACER-2141B46CA9
Update on 16/08/09 by Chiquitine29 & C_XX
Start at: 22:42:25 | 16/08/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 090815-0] 4.8.1335 [ Enabled | Updated ]
AV : McAfee VirusScan [ Enabled | Updated ]
FW : McAfee Personal Firewall[ Enabled ]
C:\ -> Disque fixe local # 144,17 Go (96,89 Go free) [ACER] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Fichiers # Dossiers infectieux |
################## | Suspect ! ... | https://www.virustotal.com/gui/ |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\G
Shell\AutoRun\command =G:\autorun.exe
HKCU\..\..\Explorer\MountPoints2\{134b79a2-3d4a-11de-8de8-00234e49ae17}
Shell\AutoRun\command =D:\ivcvknr.bat
Shell\explore\Command =D:\ivcvknr.bat
Shell\open\Command =D:\ivcvknr.bat
HKCU\..\..\Explorer\MountPoints2\{23e3f619-defc-11dd-84ac-00234e49ae17}
Shell\AutoRun\command =2a.exe
Shell\open\Command =2a.exe
HKCU\..\..\Explorer\MountPoints2\{7b5f3528-0c2c-11de-8d3f-00234e49ae17}
Shell\AutoRun\command =F:\.pspware\PSPWareLauncher.exe
HKCU\..\..\Explorer\MountPoints2\{d652a56a-e5f7-11dd-84e4-00234e49ae17}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
HKCU\..\..\Explorer\MountPoints2\{e3614ba2-f061-11dd-8cdb-00234e49ae17}
Shell\AutoRun\command =E:\SETUP.EXE
Shell\configure\command =E:\SETUP.EXE
Shell\install\command =E:\SETUP.EXE
################## | Cracks / Keygens / Serials |
"C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\2_CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe"
16/02/2009 22:05 |Size : 240954926 |Crc32 : 6789b71f |Md5 : fe218ca71667000e4b7b688f1d2726ea
"C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\AutoUpdator.exe"
15/04/2006 14:12 |Size : 307200 |Crc32 : 9140376c |Md5 : 43bb068d0b313801d30d28c0b2b7bf0d
supprime ceci source d infection
C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\2_CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe"
16/02/2009 22:05 |Size : 240954926 |Crc32 : 6789b71f |Md5 : fe218ca71667000e4b7b688f1d2726ea
"C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\AutoUpdator.exe"
15/04/2006 14:12 |Size : 307200 |Crc32 : 9140376c |Md5 : 43bb068d0b313801d30d28c0b2b7bf0d
ensuite :
▶ (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir
▶ Double clic (clic droit "en tant qu'administrateur" pour Vista)sur le raccourci UsbFix présent sur ton bureau
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]
▶ Ton bureau disparaitra et le pc redémarrera .
▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\2_CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe"
16/02/2009 22:05 |Size : 240954926 |Crc32 : 6789b71f |Md5 : fe218ca71667000e4b7b688f1d2726ea
"C:\Documents and Settings\Lo‹c\Bureau\css Crack Installer\AutoUpdator.exe"
15/04/2006 14:12 |Size : 307200 |Crc32 : 9140376c |Md5 : 43bb068d0b313801d30d28c0b2b7bf0d
ensuite :
▶ (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir
▶ Double clic (clic droit "en tant qu'administrateur" pour Vista)sur le raccourci UsbFix présent sur ton bureau
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]
▶ Ton bureau disparaitra et le pc redémarrera .
▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
############################## | UsbFix V6.018 |
User : Loïc (Administrateurs) # ACER-2141B46CA9
Update on 16/08/09 by Chiquitine29 & C_XX
Start at: 23:05:30 | 16/08/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 090815-0] 4.8.1335 [ Enabled | Updated ]
AV : McAfee VirusScan [ Enabled | Updated ]
FW : McAfee Personal Firewall[ Enabled ]
C:\ -> Disque fixe local # 144,17 Go (95,89 Go free) [ACER] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | Fichiers # Dossiers infectieux |
################## | Autres |
################## | Suspect ! ... | https://www.virustotal.com/gui/ |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{134b79a2-3d4a-11de-8de8-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{23e3f619-defc-11dd-84ac-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{7b5f3528-0c2c-11de-8d3f-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{d652a56a-e5f7-11dd-84e4-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{e3614ba2-f061-11dd-8cdb-00234e49ae17}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[19/08/2008 13:14|--a--c---|0] -> C:\AUTOEXEC.BAT
[07/01/2009 19:17|-rahsc---|216] -> C:\boot.ini
[14/04/2008 08:00|-rahsc---|4952] -> C:\Bootfont.bin
[07/03/2009 16:41|--a--c---|3187] -> C:\cleannavi.txt
[19/08/2008 13:14|--a--c---|0] -> C:\CONFIG.SYS
[07/03/2009 16:31|--a--c---|3055] -> C:\fixnavi.txt
[?|?|?] -> C:\hiberfil.sys
[19/08/2008 13:14|-rahsc---|0] -> C:\IO.SYS
[16/08/2009 12:20|--a--c---|638] -> C:\JavaRa.log
[16/08/2009 15:27|--a--c---|6370] -> C:\List'em.txt
[19/08/2008 13:14|-rahsc---|0] -> C:\MSDOS.SYS
[14/04/2008 08:00|-rahs----|47564] -> C:\NTDETECT.COM
[14/04/2008 08:00|-rahs----|252240] -> C:\ntldr
[29/02/2004 17:44|--a--c---|52576] -> C:\orange.bmp
[?|?|?] -> C:\pagefile.sys
[19/08/2008 13:34|--a--c---|542] -> C:\RHDSetup.log
[16/08/2009 23:08|--a--c---|3378] -> C:\UsbFix.txt
################## | Cracks / Keygens / Serials |
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\2_CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe"
16/02/2009 22:05 |Size : 240954926 |Crc32 : 6789b71f |Md5 : fe218ca71667000e4b7b688f1d2726ea
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\AutoUpdator.exe"
15/04/2006 14:12 |Size : 307200 |Crc32 : 9140376c |Md5 : 43bb068d0b313801d30d28c0b2b7bf0d
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\CSS_Patch_v17_04-04-2007-DZ.exe"
16/02/2009 18:46 |Size : 9906342 |Crc32 : c406f408 |Md5 : 09d9f0cc028dba681862d9d50add16d9
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\cstrike.exe"
24/01/2006 18:50 |Size : 40960 |Crc32 : eced64ae |Md5 : d987a2b1b4d826a33a22c2be3ca1aecd
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\hl2.exe"
26/08/2006 14:01 |Size : 106496 |Crc32 : aa99fc97 |Md5 : 7c271bbd974c760f516f1c9f9b61e0f2
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\Language.exe"
08/11/2005 19:28 |Size : 409600 |Crc32 : 9471632f |Md5 : 33e261f127a0798adeb8348d137f27c6
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\srcds.exe"
26/08/2006 14:02 |Size : 151552 |Crc32 : 5bb9ac58 |Md5 : 1df721b7fc4e37464b9afdfbdb13c676
################## | ! Fin du rapport # UsbFix V6.018 ! |
User : Loïc (Administrateurs) # ACER-2141B46CA9
Update on 16/08/09 by Chiquitine29 & C_XX
Start at: 23:05:30 | 16/08/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 090815-0] 4.8.1335 [ Enabled | Updated ]
AV : McAfee VirusScan [ Enabled | Updated ]
FW : McAfee Personal Firewall[ Enabled ]
C:\ -> Disque fixe local # 144,17 Go (95,89 Go free) [ACER] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | Fichiers # Dossiers infectieux |
################## | Autres |
################## | Suspect ! ... | https://www.virustotal.com/gui/ |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{134b79a2-3d4a-11de-8de8-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{23e3f619-defc-11dd-84ac-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{7b5f3528-0c2c-11de-8d3f-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{d652a56a-e5f7-11dd-84e4-00234e49ae17}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{e3614ba2-f061-11dd-8cdb-00234e49ae17}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[19/08/2008 13:14|--a--c---|0] -> C:\AUTOEXEC.BAT
[07/01/2009 19:17|-rahsc---|216] -> C:\boot.ini
[14/04/2008 08:00|-rahsc---|4952] -> C:\Bootfont.bin
[07/03/2009 16:41|--a--c---|3187] -> C:\cleannavi.txt
[19/08/2008 13:14|--a--c---|0] -> C:\CONFIG.SYS
[07/03/2009 16:31|--a--c---|3055] -> C:\fixnavi.txt
[?|?|?] -> C:\hiberfil.sys
[19/08/2008 13:14|-rahsc---|0] -> C:\IO.SYS
[16/08/2009 12:20|--a--c---|638] -> C:\JavaRa.log
[16/08/2009 15:27|--a--c---|6370] -> C:\List'em.txt
[19/08/2008 13:14|-rahsc---|0] -> C:\MSDOS.SYS
[14/04/2008 08:00|-rahs----|47564] -> C:\NTDETECT.COM
[14/04/2008 08:00|-rahs----|252240] -> C:\ntldr
[29/02/2004 17:44|--a--c---|52576] -> C:\orange.bmp
[?|?|?] -> C:\pagefile.sys
[19/08/2008 13:34|--a--c---|542] -> C:\RHDSetup.log
[16/08/2009 23:08|--a--c---|3378] -> C:\UsbFix.txt
################## | Cracks / Keygens / Serials |
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\2_CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe"
16/02/2009 22:05 |Size : 240954926 |Crc32 : 6789b71f |Md5 : fe218ca71667000e4b7b688f1d2726ea
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\AutoUpdator.exe"
15/04/2006 14:12 |Size : 307200 |Crc32 : 9140376c |Md5 : 43bb068d0b313801d30d28c0b2b7bf0d
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\CSS_Patch_v17_04-04-2007-DZ.exe"
16/02/2009 18:46 |Size : 9906342 |Crc32 : c406f408 |Md5 : 09d9f0cc028dba681862d9d50add16d9
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\cstrike.exe"
24/01/2006 18:50 |Size : 40960 |Crc32 : eced64ae |Md5 : d987a2b1b4d826a33a22c2be3ca1aecd
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\hl2.exe"
26/08/2006 14:01 |Size : 106496 |Crc32 : aa99fc97 |Md5 : 7c271bbd974c760f516f1c9f9b61e0f2
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\Language.exe"
08/11/2005 19:28 |Size : 409600 |Crc32 : 9471632f |Md5 : 33e261f127a0798adeb8348d137f27c6
"C:\Documents and Settings\Lo‹c\Mes documents\css Crack Installer\srcds.exe"
26/08/2006 14:02 |Size : 151552 |Crc32 : 5bb9ac58 |Md5 : 1df721b7fc4e37464b9afdfbdb13c676
################## | ! Fin du rapport # UsbFix V6.018 ! |
bien maintenant refais un OTL en cochant les trois cases comme precedemment et en mettant tout sur "all" colonne de gauche
OTL Extras logfile created on: 17/08/2009 07:53:26 - Run 3
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Loïc\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
1011,88 Mb Total Physical Memory | 811,74 Mb Available Physical Memory | 80,22% Memory free
2,37 Gb Paging File | 2,30 Gb Available in Paging File | 97,08% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144,17 Gb Total Space | 96,89 Gb Free Space | 67,21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ACER-2141B46CA9
Current User Name: Loïc
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Standard
[color=#E56717]========== Extra Registry (All) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\WINDOWS\System32\shell32.DLL (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\WINDOWS\system32\ieframe.DLL (Microsoft Corporation)
.js [@ = JSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-4198042028-3245414257-3734608709-1006\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
[color=#E56717]========== Authorized Applications List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine -- ()
"C:\Program Files\1701 A.D. Demo\1701_Demo.exe" = C:\Program Files\1701 A.D. Demo\1701_Demo.exe:*:Enabled:1701 A.D. Demo -- File not found
"C:\Documents and Settings\Loïc\Local Settings\Temp\RarSFX0\hl.exe" = C:\Documents and Settings\Loïc\Local Settings\Temp\RarSFX0\hl.exe:*:Enabled:Half-Life Launcher -- File not found
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-frFR-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-frFR-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Program Files\World of Warcraft\WoW-3.2.0-frFR-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{059C042E-796A-4ACC-A81A-ECC2010BB78C}" = Windows Live Messenger
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{27DC856A-0916-4988-8198-8714DDD3183D}" = AGEIA PhysX v7.05.17
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros for Acer Driver v7.6.0.224_Foxconn Installation Program
"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{428102E6-8A39-48B9-8389-847F5A44A600}" = MSXML 4.0
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{54BB0384-1C33-488F-A95B-877E480D3EDC}" = MSXML 4.0
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{67D0313C-4F15-437D-9A2D-C1564088A26A}" = Windows Live Sync
"{6901DD22-527A-41EF-9059-E81FEDE9E494}" = Windows Presentation Foundation Language Pack (FRA)
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}" = Microsoft Works
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7370DF47-B4F9-4279-BFC3-3F09919F720D}" = Installation Windows Live
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}" = Windows Live Call
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-040C-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (French) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-040C-0000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{A0353900-21A2-42CF-B973-883500A027F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
"{90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{A0353900-21A2-42CF-B973-883500A027F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-040C-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2007
"{90120000-001A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{A0353900-21A2-42CF-B973-883500A027F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{5A2F65A4-808F-4A1E-973E-92E17824982D}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
"{90120000-0044-040C-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{EC50B538-CBE1-42E6-B7FE-87AA540AADFB}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A8DB611A-D80E-450D-85F6-3ACDD164BE31}" = Pro Evolution Soccer 2009
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B168C59D-5FCF-4EEC-B464-BFA7A8266150}" = Windows Communication Foundation Language Pack - FRA
"{B84C141C-9A13-44BE-9A69-301D7B11D836}" = Windows Workflow Foundation FR Language Pack
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}" = Assistant de connexion Windows Live
"{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}" = Microsoft .NET Framework 3.0 French Language Pack
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F196AC50-7C95-42E1-9947-BDAB18BF3C8C}" = Microsoft .NET Framework 2.0 Language Pack - FRA
"{F7952CA2-A925-4CA1-A934-A46E8EC9CA18}" = Acer Crystal Eye Webcam
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"avast!" = avast! Antivirus
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CursorXP" = CursorXP
"Dofus 1.27.0" = Dofus 1.27.0
"eMule" = eMule
"Google Desktop" = Google Desktop
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 2.0 Language Pack - FRA" = Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft .NET Framework 3.0 French Language Pack" = Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoFiltre" = PhotoFiltre
"PowerISO" = PowerISO
"PROPLUS" = Microsoft Office Professional Plus 2007
"Ramboost XP_is1" = RamBoost XP 4.0.6
"RealPlayer 6.0" = RealPlayer
"skyrocktbar" = Skyrock Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"UsbFix" = UsbFix
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VLC media player" = VLC media player 0.9.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Lecteur Windows Media 11
"WinLiveSuite_Wave3" = Installation Windows Live
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wow Cartographe" = Wow Cartographe 1.08b
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
[HKEY_USERS\S-1-5-21-4198042028-3245414257-3734608709-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Live Search" = Notification Live Search
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
[ Antivirus Events ]
Error - 16/08/2009 08:37:58 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 09:17:34 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 09:28:45 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 11:59:10 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 12:07:28 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 12:21:27 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 15:37:40 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 17:56:23 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 18:05:01 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 18:14:08 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
[ Application Events ]
Error - 17/08/2009 00:06:27 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (2432) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:06:27 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (2432) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:06:42 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (3696) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:06:42 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (3696) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:06:52 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (3696) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:06:52 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (3696) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:07:18 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (2132) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:07:18 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (2132) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:07:28 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (2132) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:07:28 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (2132) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
[ System Events ]
Error - 17/08/2009 01:42:25 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:29 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:34 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:38 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:42 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:46 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:50 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:53:05 | Computer Name = ACER-2141B46CA9 | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1084" lors de la mise en route du service EventSystem
avec les arguments "" pour démarrer le serveur : {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 17/08/2009 01:54:04 | Computer Name = ACER-2141B46CA9 | Source = Service Control Manager | ID = 7000
Description = Le service McAfee Services n'a pas pu démarrer en raison de l'erreur :
%%3
Error - 17/08/2009 01:54:04 | Computer Name = ACER-2141B46CA9 | Source = Service Control Manager | ID = 7026
Description = Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se
charger : Aavmker4 aswSP Fips intelppm SCDEmu
< End of report >
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Loïc\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
1011,88 Mb Total Physical Memory | 811,74 Mb Available Physical Memory | 80,22% Memory free
2,37 Gb Paging File | 2,30 Gb Available in Paging File | 97,08% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144,17 Gb Total Space | 96,89 Gb Free Space | 67,21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ACER-2141B46CA9
Current User Name: Loïc
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Standard
[color=#E56717]========== Extra Registry (All) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\WINDOWS\System32\shell32.DLL (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\WINDOWS\system32\ieframe.DLL (Microsoft Corporation)
.js [@ = JSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-4198042028-3245414257-3734608709-1006\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
[color=#E56717]========== Authorized Applications List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine -- ()
"C:\Program Files\1701 A.D. Demo\1701_Demo.exe" = C:\Program Files\1701 A.D. Demo\1701_Demo.exe:*:Enabled:1701 A.D. Demo -- File not found
"C:\Documents and Settings\Loïc\Local Settings\Temp\RarSFX0\hl.exe" = C:\Documents and Settings\Loïc\Local Settings\Temp\RarSFX0\hl.exe:*:Enabled:Half-Life Launcher -- File not found
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-frFR-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-frFR-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Program Files\World of Warcraft\WoW-3.2.0-frFR-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{059C042E-796A-4ACC-A81A-ECC2010BB78C}" = Windows Live Messenger
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{27DC856A-0916-4988-8198-8714DDD3183D}" = AGEIA PhysX v7.05.17
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros for Acer Driver v7.6.0.224_Foxconn Installation Program
"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{428102E6-8A39-48B9-8389-847F5A44A600}" = MSXML 4.0
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{54BB0384-1C33-488F-A95B-877E480D3EDC}" = MSXML 4.0
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{67D0313C-4F15-437D-9A2D-C1564088A26A}" = Windows Live Sync
"{6901DD22-527A-41EF-9059-E81FEDE9E494}" = Windows Presentation Foundation Language Pack (FRA)
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}" = Microsoft Works
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7370DF47-B4F9-4279-BFC3-3F09919F720D}" = Installation Windows Live
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}" = Windows Live Call
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-040C-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (French) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-040C-0000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{A0353900-21A2-42CF-B973-883500A027F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
"{90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{A0353900-21A2-42CF-B973-883500A027F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-040C-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2007
"{90120000-001A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{A0353900-21A2-42CF-B973-883500A027F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{5A2F65A4-808F-4A1E-973E-92E17824982D}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
"{90120000-0044-040C-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{EC50B538-CBE1-42E6-B7FE-87AA540AADFB}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A8DB611A-D80E-450D-85F6-3ACDD164BE31}" = Pro Evolution Soccer 2009
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B168C59D-5FCF-4EEC-B464-BFA7A8266150}" = Windows Communication Foundation Language Pack - FRA
"{B84C141C-9A13-44BE-9A69-301D7B11D836}" = Windows Workflow Foundation FR Language Pack
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}" = Assistant de connexion Windows Live
"{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}" = Microsoft .NET Framework 3.0 French Language Pack
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F196AC50-7C95-42E1-9947-BDAB18BF3C8C}" = Microsoft .NET Framework 2.0 Language Pack - FRA
"{F7952CA2-A925-4CA1-A934-A46E8EC9CA18}" = Acer Crystal Eye Webcam
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"avast!" = avast! Antivirus
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CursorXP" = CursorXP
"Dofus 1.27.0" = Dofus 1.27.0
"eMule" = eMule
"Google Desktop" = Google Desktop
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 2.0 Language Pack - FRA" = Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft .NET Framework 3.0 French Language Pack" = Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoFiltre" = PhotoFiltre
"PowerISO" = PowerISO
"PROPLUS" = Microsoft Office Professional Plus 2007
"Ramboost XP_is1" = RamBoost XP 4.0.6
"RealPlayer 6.0" = RealPlayer
"skyrocktbar" = Skyrock Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"UsbFix" = UsbFix
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VLC media player" = VLC media player 0.9.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Lecteur Windows Media 11
"WinLiveSuite_Wave3" = Installation Windows Live
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wow Cartographe" = Wow Cartographe 1.08b
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
[HKEY_USERS\S-1-5-21-4198042028-3245414257-3734608709-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Live Search" = Notification Live Search
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
[ Antivirus Events ]
Error - 16/08/2009 08:37:58 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 09:17:34 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 09:28:45 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 11:59:10 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 12:07:28 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 12:21:27 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 15:37:40 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 17:56:23 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 18:05:01 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
Error - 16/08/2009 18:14:08 | Computer Name = ACER-2141B46CA9 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Fichiers communs\Real\Plugins\ravemgr.dll failed, 0000001E.
[ Application Events ]
Error - 17/08/2009 00:06:27 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (2432) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:06:27 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (2432) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:06:42 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (3696) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:06:42 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (3696) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:06:52 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (3696) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:06:52 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (3696) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:07:18 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (2132) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:07:18 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (2132) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 17/08/2009 00:07:28 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 489
Description = wuauclt (2132) Une tentative d'ouverture du fichier "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
pour accès en lecture seule a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).
Error - 17/08/2009 00:07:28 | Computer Name = ACER-2141B46CA9 | Source = ESENT | ID = 455
Description = wuaueng.dll (2132) SUS20ClientDataStore: L'erreur -1032 (0xfffffbf8)
s'est produite lors de l'ouverture du fichier journal C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
[ System Events ]
Error - 17/08/2009 01:42:25 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:29 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:34 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:38 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:42 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:46 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:42:50 | Computer Name = ACER-2141B46CA9 | Source = Disk | ID = 262151
Description = Le périphérique \Device\Harddisk0\D comporte un bloc défectueux.
Error - 17/08/2009 01:53:05 | Computer Name = ACER-2141B46CA9 | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1084" lors de la mise en route du service EventSystem
avec les arguments "" pour démarrer le serveur : {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 17/08/2009 01:54:04 | Computer Name = ACER-2141B46CA9 | Source = Service Control Manager | ID = 7000
Description = Le service McAfee Services n'a pas pu démarrer en raison de l'erreur :
%%3
Error - 17/08/2009 01:54:04 | Computer Name = ACER-2141B46CA9 | Source = Service Control Manager | ID = 7026
Description = Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se
charger : Aavmker4 aswSP Fips intelppm SCDEmu
< End of report >