Aidez-moi SVP Mon pc est bloqué!!
Résolu/Fermé
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
-
14 janv. 2010 à 14:30
Utilisateur anonyme - 17 janv. 2010 à 17:44
Utilisateur anonyme - 17 janv. 2010 à 17:44
A voir également:
- Aidez-moi SVP Mon pc est bloqué!!
- Mon pc est trop lent et se bloque - Guide
- Test performance pc - Guide
- Reinitialiser pc - Guide
- Mon pc s'allume mais ne démarre pas windows 10 - Guide
- Plus de son sur mon pc - Guide
28 réponses
Utilisateur anonyme
14 janv. 2010 à 17:09
14 janv. 2010 à 17:09
salut :
Télécharge OTL de OLDTimer
▶ enregistre le sur ton Bureau.
▶ Double clic ( pour vista => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.
▶ Coche les 2 cases Lop et Purity
▶ Coche la case devant scan all users
▶ règle-le sur "60 Days"
▶ dans la colonne de gauche , mets tout sur all
ne modifie pas ceci :
"files created whithin" et "files modified whithin"
▶Clic sur Run Scan.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
▶▶ Tu feras la meme chose avec le "Extra.txt".
Télécharge OTL de OLDTimer
▶ enregistre le sur ton Bureau.
▶ Double clic ( pour vista => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.
▶ Coche les 2 cases Lop et Purity
▶ Coche la case devant scan all users
▶ règle-le sur "60 Days"
▶ dans la colonne de gauche , mets tout sur all
ne modifie pas ceci :
"files created whithin" et "files modified whithin"
▶Clic sur Run Scan.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
▶▶ Tu feras la meme chose avec le "Extra.txt".
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
14 janv. 2010 à 17:20
14 janv. 2010 à 17:20
Salut et merci pour ta réponse très claire une lueur d'espoir pour moi voila ce que tu ma demander
http://www.cijoint.fr/cjlink.php?file=cj201001/cijWOMeB1y.txt
http://www.cijoint.fr/cjlink.php?file=cj201001/cijFc6IDAg.txt
encore merci
http://www.cijoint.fr/cjlink.php?file=cj201001/cijWOMeB1y.txt
http://www.cijoint.fr/cjlink.php?file=cj201001/cijFc6IDAg.txt
encore merci
Utilisateur anonyme
14 janv. 2010 à 17:26
14 janv. 2010 à 17:26
Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)
▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..
double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation
coche la case "creer une icone sur le bureau"
une fois terminée , clic sur "terminer" et le programme se lancera seul
choisis la langue puis choisis l'option 1 = Mode Recherche
▶ laisse travailler l'outil
à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.
un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.
▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
tu peux supprimer le rapport catchme.log de ton bureau maintenant.
▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..
double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation
coche la case "creer une icone sur le bureau"
une fois terminée , clic sur "terminer" et le programme se lancera seul
choisis la langue puis choisis l'option 1 = Mode Recherche
▶ laisse travailler l'outil
à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.
un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.
▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
tu peux supprimer le rapport catchme.log de ton bureau maintenant.
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
14 janv. 2010 à 17:46
14 janv. 2010 à 17:46
Comme je suis en mode sans echec administrateur je pense que mon antivirus avast n'est pas actif, j'ai coupé mon pare feu windows quand meme voila ce que tu m'as demandé :
List'em by g3n-h@ckm@n 1.1.8.2
Thx to El Desaparecido.....& CCM team
User : Administrateur (Administrateurs) # BÉCANE
Update on 14/01/2010 by g3n-h@ckm@n ::::: 02:50
Start at: 17:36:35 | 14/01/2010
Contact : g3n-h@ckm@n sur CCM
AMD Athlon(tm) 64 X2 Dual Core Processor 5600+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1368 [VPS 100114-1] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque amovible
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
I:\ -> Disque fixe local | 232,88 Go (122,91 Go free) [Disque dur interne] | NTFS
Z:\ -> Disque fixe local | 298,09 Go (20,14 Go free) [diskdur new] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\csrss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\Explorer.EXE
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
I:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\WINDOWS\system32\ctfmon.exe
I:\Documents and Settings\La Patronne\Mes documents\OTL.exe
I:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
I:\Documents and Settings\La Patronne\Bureau\List_Kill'em\List_Kill'em.exe
I:\WINDOWS\system32\cmd.exe
I:\WINDOWS\system32\wbem\wmiprvse.exe
I:\Documents and Settings\Administrateur\Local Settings\temp\D.tmp\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe REG_SZ I:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
PinnacleDriverCheck REG_SZ I:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
Logitech Hardware Abstraction Layer REG_SZ KHALMNPR.EXE
NvCplDaemon REG_SZ RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz REG_SZ nwiz.exe /install
RTHDCPL REG_SZ RTHDCPL.EXE
SunJavaUpdateSched REG_SZ "I:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
NvMediaCenter REG_SZ RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
avast! REG_SZ I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
UnlockerAssistant REG_SZ "I:\Program Files\Unlocker\UnlockerAssistant.exe" -H
CanonSolutionMenu REG_SZ I:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
CanonMyPrinter REG_SZ I:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
RoxioDragToDisc REG_SZ "I:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
RoxWatchTray REG_SZ "I:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
QuickTime Task REG_SZ "I:\Program Files\QuickTime\qttask.exe" -atboottime
iTunesHelper REG_SZ "I:\Program Files\iTunes\iTunesHelper.exe"
ISUSPM Startup REG_SZ I:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
ISUSScheduler REG_SZ "I:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
Pinnacle WebUpdater REG_SZ "I:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
DisableRegistryTools REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoCDBurning REG_DWORD 0 (0x0)
HonorAutoRunSetting REG_DWORD 1 (0x1)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} REG_SZ AVG Anti-Spyware 7.5
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
I:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe REG_SZ I:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil
I:\Program Files\Steam\Steam.exe REG_SZ I:\Program Files\Steam\Steam.exe:*:Enabled:Steam Client
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
I:\Program Files\Messenger\msmsgs.exe REG_SZ I:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
I:\Documents and Settings\Le Patron\Mes documents\emule0.47c-xtreme5.4\emule.exe REG_SZ I:\Documents and Settings\Le Patron\Mes documents\emule0.47c-xtreme5.4\emule.exe:*:Enabled:eMule
I:\Program Files\MultiProxy\MProxy.exe REG_SZ I:\Program Files\MultiProxy\MProxy.exe:*:Enabled:MultiProxy personal proxy server
I:\Program Files\Pinnacle\MediaCenter\PSST.exe REG_SZ I:\Program Files\Pinnacle\MediaCenter\PSST.exe:LocalSubNet:Disabled:PSST.exe
I:\Program Files\IP Anonymizer\IP Anonymizer.exe REG_SZ I:\Program Files\IP Anonymizer\IP Anonymizer.exe:*:Enabled:IP Anonymizer
I:\Documents and Settings\Le Patron\Mes documents\del-bor\VLC\vlc.exe REG_SZ I:\Documents and Settings\Le Patron\Mes documents\del-bor\VLC\vlc.exe:*:Enabled:VLC media player
I:\Program Files\Bonjour\mDNSResponder.exe REG_SZ I:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
I:\Program Files\iTunes\iTunes.exe REG_SZ I:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
I:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ I:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
I:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ I:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
I:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe REG_SZ I:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe:*:Enabled:Roxio Upnp Service
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
I:\Program Files\MSN Messenger\livecall.exe REG_SZ I:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
I:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ I:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
I:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ I:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5AE58FCF-6F6A-49B2-B064-02492C66E3F4}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{9DF1C00D-8426-4337-972C-DC042D19A916}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{EDFCB7CB-942C-4822-AF14-F0B687409848}
===============
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8D1D0E9A-C799-4D28-9E29-0061D1E66E43}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
==============
BHO :
======
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.fr/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3
SharedAccess : 0x2
wuauserv : 0x2
=========
=======
Drive :
=======
Défragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
233 Go total, 123 Go libre (52%), 19% fragmenté (fragmentation du fichier 38%)
Vous devriez défragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
I:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
I:\Documents and Settings\All Users\Application Data\.zreglib
I:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
I:\Program Files\DAEMON Tools Toolbar
I:\Program Files\Everest Poker
I:\WINDOWS\IFinst27.exe
I:\WINDOWS\mbr.exe
I:\WINDOWS\System32\drivers\etc\hosts.msn
I:\WINDOWS\System32\fjhdyfhsn.bat
I:\WINDOWS\System32\pmsbfn32.dll
I:\WINDOWS\System32\SET3A.tmp
I:\WINDOWS\System32\SET46.tmp
¤¤¤¤¤¤¤¤¤¤ Keys :
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
================
Other infections
================
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 17:37:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID]
"\30 A?E?2?A?E?D?8?F?-?5?6?9?5?-?4?a?6?d?-?9?7?0?9?-?1?4?E?5?1?C?D?1?7?B?1?C?'?"=""
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
==========
Programs
==========
3D Space Tour
Adobe
Ahead
Alcohol Soft
Alienmule
Alwil Software
Apple Software Update
Architecte_3D_Platinium
ArcSoft
AskTBar
AviSynth 2.5
Beausoft
blueshirtstudio
Bonjour
CamStudio
Canon
CanonBJ
CCleaner
Common Files
ConvertMovie 5.0
DAEMON Tools Lite
DAEMON Tools Toolbar
DIFX
DivX
Enigma Software Group
EVEREST Home Edition
Everest Poker
Fichiers communs
Google
Grisoft
hilopoker
InstallShield Installation Information
Internet Explorer
Inventel
IP Anonymizer
iPod
iTunes
iTunes Agent
IVT Corporation
Java
Logitech
LogoManager Pro Suite
Malwarebytes' Anti-Malware
MegauploadToolbar
Messenger
Micro Application
Microsoft
microsoft frontpage
Microsoft Office
Microsoft Office Outlook Connector
Microsoft Silverlight
Microsoft SQL Server Compact Edition
Microsoft Sync Framework
Microsoft.NET
MIKSOFT
MobiMB Mobile Media Browser
Mobius Phone Explorer
MOVAVI
Movie Maker
Mozilla Firefox
mp3DirectCut
MSBuild
MSN
MSN Apps
MSN Gaming Zone
MSN Messenger
MSReports
MSXML 4.0
MSXML 6.0
MultiProxy
Neonumeric
Nero
NetMeeting
Nokia
Online Services
Orange
Outlook Express
Oxygen Software
PC Connectivity Solution
Photo To Sketch
Pinnacle
PSPWare
QuickTime
Realtek
Reference Assemblies
Roxio
SAGEM
Samsung
SereneScreen
Services en ligne
Silver Style Entertainment
SLD Codec Pack
SlySoft
Smart Projects
SmartSound Software
Sonic
Sony Setup
Spybot - Search & Destroy
Steam
Trojan Remover
Uninstall Information
Unlocker
VideoLAN
Wanadoo
Windows Live
Windows Live SkyDrive
Windows Media Connect
Windows Media Connect 2
Windows Media Player
Windows NT
WindowsUpdate
WinImage
WinRAR
winstat
WMV9_VCM
World_Tv_Center
xerox
Zattoo
Zone Labs
============
Lecteur I:
============
2c4d3eb41efeb71d7e1792ef27
Boot.bak
boot.ini
Bootfont.bin
cmdcons
cmldr
ComboFix.txt
Config.Msi
d8d2ef72366252e41d
DBI.EXE
Documents and Settings
found.000
Kill'em
List'em.txt
Nouveau dossier
NTDETECT.COM
ntldr
O2C
pagefile.sys
Program Files
Qoobox
RECYCLER
sqmdata00.sqm
sqmdata01.sqm
sqmdata02.sqm
sqmdata03.sqm
sqmdata04.sqm
sqmdata05.sqm
sqmdata06.sqm
sqmdata07.sqm
sqmdata08.sqm
sqmdata09.sqm
sqmdata10.sqm
sqmdata11.sqm
sqmdata12.sqm
sqmdata13.sqm
sqmdata14.sqm
sqmdata15.sqm
sqmdata16.sqm
sqmdata17.sqm
sqmdata18.sqm
sqmdata19.sqm
sqmnoopt00.sqm
sqmnoopt01.sqm
sqmnoopt02.sqm
sqmnoopt03.sqm
sqmnoopt04.sqm
sqmnoopt05.sqm
sqmnoopt06.sqm
sqmnoopt07.sqm
sqmnoopt08.sqm
sqmnoopt09.sqm
sqmnoopt10.sqm
sqmnoopt11.sqm
sqmnoopt12.sqm
sqmnoopt13.sqm
sqmnoopt14.sqm
sqmnoopt15.sqm
sqmnoopt16.sqm
sqmnoopt17.sqm
sqmnoopt18.sqm
sqmnoopt19.sqm
System Volume Information
WINDOWS
¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials
I:\Documents and Settings\Le Patron\Mes documents\del-bor\Sapin De Noel 3D Ecran De Veille\Sapin De Noel 3D Ecran De Veille\Serial.txt
I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Serial Sony Vegas 8 0 Pro.txt
I:\Program Files\Architecte_3D_Platinium\Textures\CustomTextures\Matériaux supplémentaires Punch\Marbre-granite\Patchy Grey Granite.PTI
I:\Program Files\Architecte_3D_Platinium\Textures\CustomTextures\Matériaux supplémentaires Punch\Marbre-granite\Patchy Grey Granite.PTX
I:\Documents and Settings\Le Patron\Mes documents\del-bor\Marine Aquarium Time 1.1\Marine Aquarium 2\core Keygen.exe
I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Videospin Keygen.zip
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
List'em by g3n-h@ckm@n 1.1.8.2
Thx to El Desaparecido.....& CCM team
User : Administrateur (Administrateurs) # BÉCANE
Update on 14/01/2010 by g3n-h@ckm@n ::::: 02:50
Start at: 17:36:35 | 14/01/2010
Contact : g3n-h@ckm@n sur CCM
AMD Athlon(tm) 64 X2 Dual Core Processor 5600+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1368 [VPS 100114-1] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque amovible
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
I:\ -> Disque fixe local | 232,88 Go (122,91 Go free) [Disque dur interne] | NTFS
Z:\ -> Disque fixe local | 298,09 Go (20,14 Go free) [diskdur new] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\csrss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\Explorer.EXE
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
I:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\WINDOWS\system32\ctfmon.exe
I:\Documents and Settings\La Patronne\Mes documents\OTL.exe
I:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
I:\Documents and Settings\La Patronne\Bureau\List_Kill'em\List_Kill'em.exe
I:\WINDOWS\system32\cmd.exe
I:\WINDOWS\system32\wbem\wmiprvse.exe
I:\Documents and Settings\Administrateur\Local Settings\temp\D.tmp\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe REG_SZ I:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
PinnacleDriverCheck REG_SZ I:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
Logitech Hardware Abstraction Layer REG_SZ KHALMNPR.EXE
NvCplDaemon REG_SZ RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz REG_SZ nwiz.exe /install
RTHDCPL REG_SZ RTHDCPL.EXE
SunJavaUpdateSched REG_SZ "I:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
NvMediaCenter REG_SZ RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
avast! REG_SZ I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
UnlockerAssistant REG_SZ "I:\Program Files\Unlocker\UnlockerAssistant.exe" -H
CanonSolutionMenu REG_SZ I:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
CanonMyPrinter REG_SZ I:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
RoxioDragToDisc REG_SZ "I:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
RoxWatchTray REG_SZ "I:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
QuickTime Task REG_SZ "I:\Program Files\QuickTime\qttask.exe" -atboottime
iTunesHelper REG_SZ "I:\Program Files\iTunes\iTunesHelper.exe"
ISUSPM Startup REG_SZ I:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
ISUSScheduler REG_SZ "I:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
Pinnacle WebUpdater REG_SZ "I:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
DisableRegistryTools REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoCDBurning REG_DWORD 0 (0x0)
HonorAutoRunSetting REG_DWORD 1 (0x1)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} REG_SZ AVG Anti-Spyware 7.5
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
I:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe REG_SZ I:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil
I:\Program Files\Steam\Steam.exe REG_SZ I:\Program Files\Steam\Steam.exe:*:Enabled:Steam Client
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
I:\Program Files\Messenger\msmsgs.exe REG_SZ I:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
I:\Documents and Settings\Le Patron\Mes documents\emule0.47c-xtreme5.4\emule.exe REG_SZ I:\Documents and Settings\Le Patron\Mes documents\emule0.47c-xtreme5.4\emule.exe:*:Enabled:eMule
I:\Program Files\MultiProxy\MProxy.exe REG_SZ I:\Program Files\MultiProxy\MProxy.exe:*:Enabled:MultiProxy personal proxy server
I:\Program Files\Pinnacle\MediaCenter\PSST.exe REG_SZ I:\Program Files\Pinnacle\MediaCenter\PSST.exe:LocalSubNet:Disabled:PSST.exe
I:\Program Files\IP Anonymizer\IP Anonymizer.exe REG_SZ I:\Program Files\IP Anonymizer\IP Anonymizer.exe:*:Enabled:IP Anonymizer
I:\Documents and Settings\Le Patron\Mes documents\del-bor\VLC\vlc.exe REG_SZ I:\Documents and Settings\Le Patron\Mes documents\del-bor\VLC\vlc.exe:*:Enabled:VLC media player
I:\Program Files\Bonjour\mDNSResponder.exe REG_SZ I:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
I:\Program Files\iTunes\iTunes.exe REG_SZ I:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
I:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ I:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
I:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ I:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
I:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe REG_SZ I:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe:*:Enabled:Roxio Upnp Service
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
I:\Program Files\MSN Messenger\livecall.exe REG_SZ I:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
I:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ I:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
I:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ I:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ I:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5AE58FCF-6F6A-49B2-B064-02492C66E3F4}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{9DF1C00D-8426-4337-972C-DC042D19A916}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{EDFCB7CB-942C-4822-AF14-F0B687409848}
===============
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8D1D0E9A-C799-4D28-9E29-0061D1E66E43}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
==============
BHO :
======
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.fr/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3
SharedAccess : 0x2
wuauserv : 0x2
=========
=======
Drive :
=======
Défragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
233 Go total, 123 Go libre (52%), 19% fragmenté (fragmentation du fichier 38%)
Vous devriez défragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
I:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
I:\Documents and Settings\All Users\Application Data\.zreglib
I:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
I:\Program Files\DAEMON Tools Toolbar
I:\Program Files\Everest Poker
I:\WINDOWS\IFinst27.exe
I:\WINDOWS\mbr.exe
I:\WINDOWS\System32\drivers\etc\hosts.msn
I:\WINDOWS\System32\fjhdyfhsn.bat
I:\WINDOWS\System32\pmsbfn32.dll
I:\WINDOWS\System32\SET3A.tmp
I:\WINDOWS\System32\SET46.tmp
¤¤¤¤¤¤¤¤¤¤ Keys :
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
================
Other infections
================
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 17:37:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:57,9a,0f,1a,96,ae,f3,67,04,07,90,1c,f1,2a,a0,46,6b,01,e1,f8,45,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:c7,aa,c2,43,ab,7b,0c,28,02,55,0a,03,ca,5d,91,da,b8,25,a1,6c,69,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID]
"\30 A?E?2?A?E?D?8?F?-?5?6?9?5?-?4?a?6?d?-?9?7?0?9?-?1?4?E?5?1?C?D?1?7?B?1?C?'?"=""
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
==========
Programs
==========
3D Space Tour
Adobe
Ahead
Alcohol Soft
Alienmule
Alwil Software
Apple Software Update
Architecte_3D_Platinium
ArcSoft
AskTBar
AviSynth 2.5
Beausoft
blueshirtstudio
Bonjour
CamStudio
Canon
CanonBJ
CCleaner
Common Files
ConvertMovie 5.0
DAEMON Tools Lite
DAEMON Tools Toolbar
DIFX
DivX
Enigma Software Group
EVEREST Home Edition
Everest Poker
Fichiers communs
Grisoft
hilopoker
InstallShield Installation Information
Internet Explorer
Inventel
IP Anonymizer
iPod
iTunes
iTunes Agent
IVT Corporation
Java
Logitech
LogoManager Pro Suite
Malwarebytes' Anti-Malware
MegauploadToolbar
Messenger
Micro Application
Microsoft
microsoft frontpage
Microsoft Office
Microsoft Office Outlook Connector
Microsoft Silverlight
Microsoft SQL Server Compact Edition
Microsoft Sync Framework
Microsoft.NET
MIKSOFT
MobiMB Mobile Media Browser
Mobius Phone Explorer
MOVAVI
Movie Maker
Mozilla Firefox
mp3DirectCut
MSBuild
MSN
MSN Apps
MSN Gaming Zone
MSN Messenger
MSReports
MSXML 4.0
MSXML 6.0
MultiProxy
Neonumeric
Nero
NetMeeting
Nokia
Online Services
Orange
Outlook Express
Oxygen Software
PC Connectivity Solution
Photo To Sketch
Pinnacle
PSPWare
QuickTime
Realtek
Reference Assemblies
Roxio
SAGEM
Samsung
SereneScreen
Services en ligne
Silver Style Entertainment
SLD Codec Pack
SlySoft
Smart Projects
SmartSound Software
Sonic
Sony Setup
Spybot - Search & Destroy
Steam
Trojan Remover
Uninstall Information
Unlocker
VideoLAN
Wanadoo
Windows Live
Windows Live SkyDrive
Windows Media Connect
Windows Media Connect 2
Windows Media Player
Windows NT
WindowsUpdate
WinImage
WinRAR
winstat
WMV9_VCM
World_Tv_Center
xerox
Zattoo
Zone Labs
============
Lecteur I:
============
2c4d3eb41efeb71d7e1792ef27
Boot.bak
boot.ini
Bootfont.bin
cmdcons
cmldr
ComboFix.txt
Config.Msi
d8d2ef72366252e41d
DBI.EXE
Documents and Settings
found.000
Kill'em
List'em.txt
Nouveau dossier
NTDETECT.COM
ntldr
O2C
pagefile.sys
Program Files
Qoobox
RECYCLER
sqmdata00.sqm
sqmdata01.sqm
sqmdata02.sqm
sqmdata03.sqm
sqmdata04.sqm
sqmdata05.sqm
sqmdata06.sqm
sqmdata07.sqm
sqmdata08.sqm
sqmdata09.sqm
sqmdata10.sqm
sqmdata11.sqm
sqmdata12.sqm
sqmdata13.sqm
sqmdata14.sqm
sqmdata15.sqm
sqmdata16.sqm
sqmdata17.sqm
sqmdata18.sqm
sqmdata19.sqm
sqmnoopt00.sqm
sqmnoopt01.sqm
sqmnoopt02.sqm
sqmnoopt03.sqm
sqmnoopt04.sqm
sqmnoopt05.sqm
sqmnoopt06.sqm
sqmnoopt07.sqm
sqmnoopt08.sqm
sqmnoopt09.sqm
sqmnoopt10.sqm
sqmnoopt11.sqm
sqmnoopt12.sqm
sqmnoopt13.sqm
sqmnoopt14.sqm
sqmnoopt15.sqm
sqmnoopt16.sqm
sqmnoopt17.sqm
sqmnoopt18.sqm
sqmnoopt19.sqm
System Volume Information
WINDOWS
¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials
I:\Documents and Settings\Le Patron\Mes documents\del-bor\Sapin De Noel 3D Ecran De Veille\Sapin De Noel 3D Ecran De Veille\Serial.txt
I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Serial Sony Vegas 8 0 Pro.txt
I:\Program Files\Architecte_3D_Platinium\Textures\CustomTextures\Matériaux supplémentaires Punch\Marbre-granite\Patchy Grey Granite.PTI
I:\Program Files\Architecte_3D_Platinium\Textures\CustomTextures\Matériaux supplémentaires Punch\Marbre-granite\Patchy Grey Granite.PTX
I:\Documents and Settings\Le Patron\Mes documents\del-bor\Marine Aquarium Time 1.1\Marine Aquarium 2\core Keygen.exe
I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Videospin Keygen.zip
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Utilisateur anonyme
14 janv. 2010 à 18:54
14 janv. 2010 à 18:54
▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'option 2 = Mode Suppression
laisse travailler l'outil.
en fin de scan un rapport s'ouvre
▶ colle le contenu dans ta reponse
mais cette fois-ci :
▶ choisis l'option 2 = Mode Suppression
laisse travailler l'outil.
en fin de scan un rapport s'ouvre
▶ colle le contenu dans ta reponse
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
14 janv. 2010 à 19:16
14 janv. 2010 à 19:16
Kill'em by g3n-h@ckm@n 1.1.8.2
User : Administrateur (Administrateurs) # BÉCANE
Update on 14/01/2010 by g3n-h@ckm@n ::::: 02:50
Start at: 19:10:40 | 14/01/2010
Contact : g3n-h@ckm@n sur CCM
AMD Athlon(tm) 64 X2 Dual Core Processor 5600+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1368 [VPS 100114-1] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque amovible
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
I:\ -> Disque fixe local | 232,88 Go (122,91 Go free) [Disque dur interne] | NTFS
Z:\ -> Disque fixe local | 298,09 Go (20,14 Go free) [diskdur new] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\csrss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\Explorer.EXE
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
I:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\WINDOWS\system32\ctfmon.exe
I:\Documents and Settings\La Patronne\Bureau\List_Kill'em\List_Kill'em.exe
I:\WINDOWS\system32\cmd.exe
I:\WINDOWS\system32\wbem\wmiprvse.exe
I:\Documents and Settings\Administrateur\Local Settings\temp\10.tmp\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
"I:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}"
"I:\Documents and Settings\All Users\Application Data\.zreglib"
I:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
"I:\Program Files\DAEMON Tools Toolbar"
"I:\Program Files\Everest Poker"
"I:\WINDOWS\IFinst27.exe"
"I:\WINDOWS\mbr.exe"
"I:\WINDOWS\System32\drivers\etc\hosts.msn"
"I:\WINDOWS\System32\fjhdyfhsn.bat"
"I:\WINDOWS\System32\pmsbfn32.dll"
I:\WINDOWS\System32\SET3A.tmp
I:\WINDOWS\System32\SET46.tmp
¤¤¤¤¤¤¤¤¤¤ Files/folders deleted :
Quarantine :
.zreglib.Kill'em
DAEMON Tools Toolbar.Kill'em
Everest Poker.Kill'em
fjhdyfhsn.bat.Kill'em
hosts.msn.Kill'em
IFinst27.exe.Kill'em
MBR.exe.Kill'em
pmsbfn32.dll.Kill'em
QTSBandwidthCache.Kill'em
SET3A.tmp.Kill'em
SET46.tmp.Kill'em
{3276BE95_AF08_429F_A64F_CA64CB79BCF6}.Kill'em
==============
host file OK !
==============
========
Registry
========
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe
============
Disk Cleaned
============
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
User : Administrateur (Administrateurs) # BÉCANE
Update on 14/01/2010 by g3n-h@ckm@n ::::: 02:50
Start at: 19:10:40 | 14/01/2010
Contact : g3n-h@ckm@n sur CCM
AMD Athlon(tm) 64 X2 Dual Core Processor 5600+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1368 [VPS 100114-1] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque amovible
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
I:\ -> Disque fixe local | 232,88 Go (122,91 Go free) [Disque dur interne] | NTFS
Z:\ -> Disque fixe local | 298,09 Go (20,14 Go free) [diskdur new] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\csrss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\Explorer.EXE
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
I:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\WINDOWS\system32\ctfmon.exe
I:\Documents and Settings\La Patronne\Bureau\List_Kill'em\List_Kill'em.exe
I:\WINDOWS\system32\cmd.exe
I:\WINDOWS\system32\wbem\wmiprvse.exe
I:\Documents and Settings\Administrateur\Local Settings\temp\10.tmp\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
"I:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}"
"I:\Documents and Settings\All Users\Application Data\.zreglib"
I:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
"I:\Program Files\DAEMON Tools Toolbar"
"I:\Program Files\Everest Poker"
"I:\WINDOWS\IFinst27.exe"
"I:\WINDOWS\mbr.exe"
"I:\WINDOWS\System32\drivers\etc\hosts.msn"
"I:\WINDOWS\System32\fjhdyfhsn.bat"
"I:\WINDOWS\System32\pmsbfn32.dll"
I:\WINDOWS\System32\SET3A.tmp
I:\WINDOWS\System32\SET46.tmp
¤¤¤¤¤¤¤¤¤¤ Files/folders deleted :
Quarantine :
.zreglib.Kill'em
DAEMON Tools Toolbar.Kill'em
Everest Poker.Kill'em
fjhdyfhsn.bat.Kill'em
hosts.msn.Kill'em
IFinst27.exe.Kill'em
MBR.exe.Kill'em
pmsbfn32.dll.Kill'em
QTSBandwidthCache.Kill'em
SET3A.tmp.Kill'em
SET46.tmp.Kill'em
{3276BE95_AF08_429F_A64F_CA64CB79BCF6}.Kill'em
==============
host file OK !
==============
========
Registry
========
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe
============
Disk Cleaned
============
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
14 janv. 2010 à 21:23
14 janv. 2010 à 21:23
toujours le meme probleme bloqué au demarrage barre des taches bloquée aucun chargement ctr alt supp inactif bref la grosse galere
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
14 janv. 2010 à 22:20
14 janv. 2010 à 22:20
http://www.cijoint.fr/cjlink.php?file=cj201001/cijTW41KJF.txt *
voila par contre il ma pas sortir le deuxieme rapport
voila par contre il ma pas sortir le deuxieme rapport
Utilisateur anonyme
14 janv. 2010 à 22:49
14 janv. 2010 à 22:49
▶ Double clic sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous Customs Scans/Fixes :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-1757981266-839522115-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} file:///G:/1394driver/setup.exe ()
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
@Alternate Data Stream - 121 bytes -> I:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 110 bytes -> I:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=-
"ISUSScheduler"=-
"iTunesHelper"=-
"nwiz"=-
"QuickTime Task"=-
"RoxioDragToDisc"=-
"RoxWatchTray"=-
"RTHDCPL"=-
:files
I:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
:commands
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur RunFix pour lancer la suppression.
▶ Poste le rapport.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous Customs Scans/Fixes :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-1757981266-839522115-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} file:///G:/1394driver/setup.exe ()
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
@Alternate Data Stream - 121 bytes -> I:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 110 bytes -> I:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=-
"ISUSScheduler"=-
"iTunesHelper"=-
"nwiz"=-
"QuickTime Task"=-
"RoxioDragToDisc"=-
"RoxWatchTray"=-
"RTHDCPL"=-
:files
I:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
:commands
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur RunFix pour lancer la suppression.
▶ Poste le rapport.
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
15 janv. 2010 à 00:47
15 janv. 2010 à 00:47
All processes killed
========== PROCESSES ==========
Process explorer.exe killed successfully!
Process iexplore.exe killed successfully!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools not found.
Registry value HKEY_USERS\S-1-5-21-1757981266-839522115-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives not found.
Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
File DBE-93DF-4017-8BB3-F1C300C0EC51} file:///G:/1394driver/setup.exe not found.
Starting removal of ActiveX control {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
File I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\bwfile-8876480\ not found.
Invalid CLSID key: I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
File I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll not found.
Unable to delete ADS I:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9 .
Unable to delete ADS I:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 .
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSScheduler not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxioDragToDisc not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxWatchTray not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RTHDCPL not found.
========== FILES ==========
File\Folder I:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 987285 bytes
->FireFox cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: La Patronne
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: Le Patron
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
Je pense que c'est celui la car je c pas trop ou il s'enregistre le rapport donc je l'ai fais deux fois merci encore :
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,00 mb
OTL by OldTimer - Version 3.1.24.0 log created on 01152010_004110
========== PROCESSES ==========
Process explorer.exe killed successfully!
Process iexplore.exe killed successfully!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools not found.
Registry value HKEY_USERS\S-1-5-21-1757981266-839522115-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives not found.
Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
File DBE-93DF-4017-8BB3-F1C300C0EC51} file:///G:/1394driver/setup.exe not found.
Starting removal of ActiveX control {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
File I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\bwfile-8876480\ not found.
Invalid CLSID key: I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
File I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll not found.
Unable to delete ADS I:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9 .
Unable to delete ADS I:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 .
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSScheduler not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxioDragToDisc not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxWatchTray not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RTHDCPL not found.
========== FILES ==========
File\Folder I:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 987285 bytes
->FireFox cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: La Patronne
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: Le Patron
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
Je pense que c'est celui la car je c pas trop ou il s'enregistre le rapport donc je l'ai fais deux fois merci encore :
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,00 mb
OTL by OldTimer - Version 3.1.24.0 log created on 01152010_004110
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
15 janv. 2010 à 00:49
15 janv. 2010 à 00:49
All processes killed
========== PROCESSES ==========
Process explorer.exe killed successfully!
Process iexplore.exe killed successfully!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1757981266-839522115-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
I:\WINDOWS\Downloaded Program Files\DivXPlugin.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
I:\WINDOWS\Downloaded Program Files\jinstall-6u2.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
I:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
File DBE-93DF-4017-8BB3-F1C300C0EC51} file:///G:/1394driver/setup.exe not found.
Starting removal of ActiveX control {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\bwfile-8876480\ deleted successfully.
Invalid CLSID key: I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
File I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll not found.
ADS I:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9 deleted successfully.
ADS I:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSScheduler deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxioDragToDisc deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxWatchTray deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RTHDCPL deleted successfully.
========== FILES ==========
I:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 3280703 bytes
->Temporary Internet Files folder emptied: 8230186 bytes
->FireFox cache emptied: 2904350 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: La Patronne
->Temp folder emptied: 1011 bytes
->Temporary Internet Files folder emptied: 3241321 bytes
->Java cache emptied: 9554635 bytes
->FireFox cache emptied: 102469616 bytes
User: Le Patron
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->Java cache emptied: 48026 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 112094 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
Enfait par rapport a l'heure c'est plutot celui ci voila desole merci :
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 16337343 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32768 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 190745 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 140,00 mb
OTL by OldTimer - Version 3.1.24.0 log created on 01152010_000321
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== PROCESSES ==========
Process explorer.exe killed successfully!
Process iexplore.exe killed successfully!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1757981266-839522115-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
I:\WINDOWS\Downloaded Program Files\DivXPlugin.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
I:\WINDOWS\Downloaded Program Files\jinstall-6u2.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
I:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
File DBE-93DF-4017-8BB3-F1C300C0EC51} file:///G:/1394driver/setup.exe not found.
Starting removal of ActiveX control {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B91AEDBE-93DF-4017-8BB3-F1C300C0EC51}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\bwfile-8876480\ deleted successfully.
Invalid CLSID key: I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
File I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll not found.
ADS I:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9 deleted successfully.
ADS I:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSScheduler deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxioDragToDisc deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RoxWatchTray deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RTHDCPL deleted successfully.
========== FILES ==========
I:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 3280703 bytes
->Temporary Internet Files folder emptied: 8230186 bytes
->FireFox cache emptied: 2904350 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: La Patronne
->Temp folder emptied: 1011 bytes
->Temporary Internet Files folder emptied: 3241321 bytes
->Java cache emptied: 9554635 bytes
->FireFox cache emptied: 102469616 bytes
User: Le Patron
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->Java cache emptied: 48026 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 112094 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
Enfait par rapport a l'heure c'est plutot celui ci voila desole merci :
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 16337343 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32768 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 190745 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 140,00 mb
OTL by OldTimer - Version 3.1.24.0 log created on 01152010_000321
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
15 janv. 2010 à 01:10
15 janv. 2010 à 01:10
J'ai fais un peu n'importe quoi je pense que c'est plutot le deuxieme rapport le bon voila merci désolé!
Utilisateur anonyme
15 janv. 2010 à 12:03
15 janv. 2010 à 12:03
hello
▶ Télécharge et install UsbFix
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
▶ Double clic sur le raccourci UsbFix présent sur ton bureau .
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
▶ Laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra.
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
▶ Télécharge et install UsbFix
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
▶ Double clic sur le raccourci UsbFix présent sur ton bureau .
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
▶ Laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra.
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
15 janv. 2010 à 13:39
15 janv. 2010 à 13:39
############################## | UsbFix V6.073 |
User : Administrateur (Administrateurs) # BÉCANE
Update on 09/01/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:27:42 | 15/01/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
AMD Athlon(tm) 64 X2 Dual Core Processor 5600+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1368 [VPS 100115-0] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque amovible
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
I:\ -> Disque fixe local # 232,88 Go (124,04 Go free) [Disque dur interne] # NTFS
J:\ -> Disque amovible # 3,72 Go (1,7 Go free) [USB DISK] # FAT32
Z:\ -> Disque fixe local # 298,09 Go (20,14 Go free) [diskdur new] # NTFS
############################## | Processus actifs |
I:\WINDOWS\System32\smss.exe 424
I:\WINDOWS\system32\csrss.exe 476
I:\WINDOWS\system32\winlogon.exe 500
I:\WINDOWS\system32\services.exe 564
I:\WINDOWS\system32\lsass.exe 576
I:\WINDOWS\system32\svchost.exe 716
I:\WINDOWS\system32\svchost.exe 792
I:\WINDOWS\system32\svchost.exe 908
I:\WINDOWS\system32\svchost.exe 928
I:\WINDOWS\system32\svchost.exe 996
I:\WINDOWS\Explorer.EXE 1216
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe 1248
I:\Program Files\Internet Explorer\IEXPLORE.EXE 2008
I:\WINDOWS\system32\ctfmon.exe 2028
I:\WINDOWS\system32\wbem\wmiprvse.exe 624
################## | Elements infectieux |
################## | Registre |
################## | Mountpoints2 |
################## | Cracks > Keygens > Serials |
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2 Marine Aquarium Time (le plus belle ecran de veille 3D) + Goldfish + serials + keygens.zip"
-> Contain : 2_Marine Aquarium Time (le plus belle ‚cran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .exe
"I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Videospin Keygen.zip"
-> Contain : ForexStartGuide.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Goldfish Aquarium\eatlga09key.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium 2\MAquarium-V2.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium 2\core Keygen.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium Time 1.1\MAT-V1-1.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium Time 1.1\eatmat11key.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Goldfish Aquarium\GoldfishAquarium-V1.exe
"I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Sony.Vegas.Pro.8.FR.Avec.Keygen.By.Logicix.[eMule-Box.com].rar"
-> contain : Sony.Vegas.Pro.8.FR.Avec.Keygen.By.Logicix\vegaspro80c_fra.exe
################## | ! Fin du rapport # UsbFix V6.073 ! |
User : Administrateur (Administrateurs) # BÉCANE
Update on 09/01/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:27:42 | 15/01/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
AMD Athlon(tm) 64 X2 Dual Core Processor 5600+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1368 [VPS 100115-0] 4.8.1368 [ Enabled | Updated ]
C:\ -> Disque amovible
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
I:\ -> Disque fixe local # 232,88 Go (124,04 Go free) [Disque dur interne] # NTFS
J:\ -> Disque amovible # 3,72 Go (1,7 Go free) [USB DISK] # FAT32
Z:\ -> Disque fixe local # 298,09 Go (20,14 Go free) [diskdur new] # NTFS
############################## | Processus actifs |
I:\WINDOWS\System32\smss.exe 424
I:\WINDOWS\system32\csrss.exe 476
I:\WINDOWS\system32\winlogon.exe 500
I:\WINDOWS\system32\services.exe 564
I:\WINDOWS\system32\lsass.exe 576
I:\WINDOWS\system32\svchost.exe 716
I:\WINDOWS\system32\svchost.exe 792
I:\WINDOWS\system32\svchost.exe 908
I:\WINDOWS\system32\svchost.exe 928
I:\WINDOWS\system32\svchost.exe 996
I:\WINDOWS\Explorer.EXE 1216
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe 1248
I:\Program Files\Internet Explorer\IEXPLORE.EXE 2008
I:\WINDOWS\system32\ctfmon.exe 2028
I:\WINDOWS\system32\wbem\wmiprvse.exe 624
################## | Elements infectieux |
################## | Registre |
################## | Mountpoints2 |
################## | Cracks > Keygens > Serials |
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2 Marine Aquarium Time (le plus belle ecran de veille 3D) + Goldfish + serials + keygens.zip"
-> Contain : 2_Marine Aquarium Time (le plus belle ‚cran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .exe
"I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Videospin Keygen.zip"
-> Contain : ForexStartGuide.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Goldfish Aquarium\eatlga09key.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium 2\MAquarium-V2.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium 2\core Keygen.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium Time 1.1\MAT-V1-1.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Marine Aquarium Time 1.1\eatmat11key.exe
"I:\Documents and Settings\Le Patron\Mes documents\del-bor\Goldfish Aquarium\2_Marine Aquarium Time (le plus belle écran de veille 3D) + Goldfish + serials + keygens by www.Iguanaland.ht.st .rar"
-> contain : Goldfish Aquarium\GoldfishAquarium-V1.exe
"I:\Documents and Settings\Le Patron\Mes documents\Mes fichiers reçus\der incoming\Sony.Vegas.Pro.8.FR.Avec.Keygen.By.Logicix.[eMule-Box.com].rar"
-> contain : Sony.Vegas.Pro.8.FR.Avec.Keygen.By.Logicix\vegaspro80c_fra.exe
################## | ! Fin du rapport # UsbFix V6.073 ! |
Utilisateur anonyme
15 janv. 2010 à 16:56
15 janv. 2010 à 16:56
relance usbfix , option vaccination puis option desinstallation
ensuite :
Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
▶ Télécharge :
Malwarebytes
ou :
Malwarebytes
▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
▶ Potasses le Tuto pour te familiariser avec le prg :
( cela dit, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
▶ Lance Malwarebyte's .
Fais un examen dit "Complet" .
▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
ensuite :
Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
▶ Télécharge :
Malwarebytes
ou :
Malwarebytes
▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
▶ Potasses le Tuto pour te familiariser avec le prg :
( cela dit, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
▶ Lance Malwarebyte's .
Fais un examen dit "Complet" .
▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
15 janv. 2010 à 19:05
15 janv. 2010 à 19:05
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3569
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13
15/01/2010 19:01:03
mbam-log-2010-01-15 (19-01-03).txt
Type de recherche: Examen complet (I:\|J:\|Z:\|)
Eléments examinés: 265124
Temps écoulé: 48 minute(s), 14 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 24
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
I:\System Volume Information\_restore{1435864A-B950-4FDA-968A-EB6D87CB2A32}\RP537\A0215680.sys (Malware.Trace) -> Quarantined and deleted successfully.
I:\System Volume Information\_restore{1435864A-B950-4FDA-968A-EB6D87CB2A32}\RP537\A0216682.sys (Malware.Trace) -> Quarantined and deleted successfully.
I:\Documents and Settings\LocalService\Cookies\bumo.reg (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\bumo.reg (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\esycire._dl (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\esycire._dl (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\ilifati.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\ilifati.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\jababug.inf (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\jababug.inf (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\jiceji._sy (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\jiceji._sy (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\kyba.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\kyba.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\MM2048.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\MM2048.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\MM256.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\MM256.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\polorid.vbs (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\polorid.vbs (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\syssp.exe (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\syssp.exe (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\uwux.exe (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\uwux.exe (Fake.Dropped.Malware) -> Delete on reboot.
Version de la base de données: 3569
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13
15/01/2010 19:01:03
mbam-log-2010-01-15 (19-01-03).txt
Type de recherche: Examen complet (I:\|J:\|Z:\|)
Eléments examinés: 265124
Temps écoulé: 48 minute(s), 14 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 24
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
I:\System Volume Information\_restore{1435864A-B950-4FDA-968A-EB6D87CB2A32}\RP537\A0215680.sys (Malware.Trace) -> Quarantined and deleted successfully.
I:\System Volume Information\_restore{1435864A-B950-4FDA-968A-EB6D87CB2A32}\RP537\A0216682.sys (Malware.Trace) -> Quarantined and deleted successfully.
I:\Documents and Settings\LocalService\Cookies\bumo.reg (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\bumo.reg (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\esycire._dl (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\esycire._dl (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\ilifati.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\ilifati.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\jababug.inf (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\jababug.inf (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\jiceji._sy (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\jiceji._sy (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\kyba.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\kyba.dl (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\MM2048.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\MM2048.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\MM256.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\MM256.dat (Trojan.Agent) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\polorid.vbs (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\polorid.vbs (Malware.Trace) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\syssp.exe (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\syssp.exe (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\LocalService\Cookies\uwux.exe (Fake.Dropped.Malware) -> Delete on reboot.
I:\Documents and Settings\NetworkService\Cookies\uwux.exe (Fake.Dropped.Malware) -> Delete on reboot.
Utilisateur anonyme
15 janv. 2010 à 19:29
15 janv. 2010 à 19:29
execute ceci et dis moi ce qui dit le rapport qui s'ouvre :
http://sd-1.archive-host.com/membres/up/829108531491024/Just_This_File.exe
http://sd-1.archive-host.com/membres/up/829108531491024/Just_This_File.exe
titilancien
Messages postés
35
Date d'inscription
jeudi 14 janvier 2010
Statut
Membre
Dernière intervention
30 janvier 2010
15 janv. 2010 à 19:55
15 janv. 2010 à 19:55
sa me m ouvre un fichier nommé del avec a l'interieur juste ecrit " File :"
Utilisateur anonyme
15 janv. 2010 à 20:02
15 janv. 2010 à 20:02
donc c est bon ils ont ete supprimé
quels soucis reste-t-il ?
quels soucis reste-t-il ?