De plus en plus de processus actifs
Résolu/Fermé
San
-
13 déc. 2010 à 23:51
San.lei Messages postés 99 Date d'inscription mercredi 15 décembre 2010 Statut Membre Dernière intervention 8 septembre 2024 - 20 déc. 2010 à 21:57
San.lei Messages postés 99 Date d'inscription mercredi 15 décembre 2010 Statut Membre Dernière intervention 8 septembre 2024 - 20 déc. 2010 à 21:57
A voir également:
- De plus en plus de processus actifs
- Processus hôte windows (rundll32) ✓ - Forum Windows
- Pourquoi je ne vois plus actif il y a ✓ - Forum Facebook
- Impossible d'obtenir le verrou de dpkg (/var/lib/dpkg/lock-frontend). il est possible qu'un autre processus l'utilise. ✓ - Forum Ubuntu
- Différence actif et en ligne messenger ✓ - Forum Facebook
- Modifier priorité processus windows 10 permanent - Forum Programmation
109 réponses
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 21:19
17 déc. 2010 à 21:19
supprime le et lance combo
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 21:33
17 déc. 2010 à 21:33
Je l'ai viré "manuellement", ce "etrust antivirus" qui ne figurait pas dans la liste des programmes.
Lancement de combofix : même message d'erreur : "supprimer CA antivirus" que je ne trouve pas.
Lancement de combofix : même message d'erreur : "supprimer CA antivirus" que je ne trouve pas.
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 21:37
17 déc. 2010 à 21:37
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 21:40
17 déc. 2010 à 21:40
Le mode sans échec ne fonctionne pas, avec ou sans prise en charge du réseau.
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 21:57
17 déc. 2010 à 21:57
pourtant il est bien desinstallé
est ce juste un message d'avertissement ou cela bloque t il l'execution de combo ?
est ce juste un message d'avertissement ou cela bloque t il l'execution de combo ?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 22:02
17 déc. 2010 à 22:02
Ca bloque l'exécution de combo.
Je viens de redémarrer le PC au cas où mais aucun changement.
Je viens de redémarrer le PC au cas où mais aucun changement.
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 22:04
17 déc. 2010 à 22:04
Télécharge SEAF ( de C__XX ) sur ton bureau :
ici http://www.teamxscript.org/SEAFTelechargement.html
* Double clique sur "SEAF.exe" ( clique droit et "Exécuter en tant qu'administrateur" pour Vista / 7 ) pour lancer l'outil.
* Dans l'encardré blanc " Entrez ci dessous...." copie/colle ceci :
etrust
* Au niveau des " options des fichiers ", fait les réglages suivant :
> A "Calculer le checksum" , choisis : MD5
> Coche la case devant " Info. supplémentaire ".
> Coche la case devant " Afficher les ADS "
* Au niveau des " options du registre " :
> coche " chercher également dans le registre "
( ne touche à aucun autre réglage )
* Clique sur " Lancer la recherche " et laisse travailler l'outil ...
( cela peut-être plus ou moins long suivant les cas ).
--> Une fois terminé, une fenêtre avec un log .txt va s'afficher. Enregistre ce rapport de façon à le retrouver facilement ( sur le bureau par exemple ). Sinon il sera en outre sauvegardé à la racine de ton disque dur ( ici > C:\SEAFLog.txt )
ici http://www.teamxscript.org/SEAFTelechargement.html
* Double clique sur "SEAF.exe" ( clique droit et "Exécuter en tant qu'administrateur" pour Vista / 7 ) pour lancer l'outil.
* Dans l'encardré blanc " Entrez ci dessous...." copie/colle ceci :
etrust
* Au niveau des " options des fichiers ", fait les réglages suivant :
> A "Calculer le checksum" , choisis : MD5
> Coche la case devant " Info. supplémentaire ".
> Coche la case devant " Afficher les ADS "
* Au niveau des " options du registre " :
> coche " chercher également dans le registre "
( ne touche à aucun autre réglage )
* Clique sur " Lancer la recherche " et laisse travailler l'outil ...
( cela peut-être plus ou moins long suivant les cas ).
--> Une fois terminé, une fenêtre avec un log .txt va s'afficher. Enregistre ce rapport de façon à le retrouver facilement ( sur le bureau par exemple ). Sinon il sera en outre sauvegardé à la racine de ton disque dur ( ici > C:\SEAFLog.txt )
aloes
Messages postés
6075
Date d'inscription
lundi 21 mai 2007
Statut
Membre
Dernière intervention
25 février 2017
778
17 déc. 2010 à 22:04
17 déc. 2010 à 22:04
Rebonjur les deux,
Je ne fais que de passer.
Pour San.lei : tapes dans la recherche WIndows juste CA, tu dois avoir quelque chose, regardes aussi dans base de registre.
Bonne continuation.
aloes
Je ne fais que de passer.
Pour San.lei : tapes dans la recherche WIndows juste CA, tu dois avoir quelque chose, regardes aussi dans base de registre.
Bonne continuation.
aloes
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
Modifié par San.lei le 17/12/2010 à 22:15
Modifié par San.lei le 17/12/2010 à 22:15
Bonjour Aloes
Je viens de refaire la recherche, je l'ai trouvé.
Je ne sais pas où se trouve la base de registre (ou alors je ne sais pas que ça s'appelle comme ça).
Moment de grâce, le rapport est enregistré.
Je vire CA manuellement ?
Je viens de refaire la recherche, je l'ai trouvé.
Je ne sais pas où se trouve la base de registre (ou alors je ne sais pas que ça s'appelle comme ça).
Moment de grâce, le rapport est enregistré.
Je vire CA manuellement ?
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 22:25
17 déc. 2010 à 22:25
poste le rapport stp
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
Modifié par San.lei le 17/12/2010 à 22:31
Modifié par San.lei le 17/12/2010 à 22:31
Et voilà :
1. ========================= SEAF 1.0.1.0 - C_XX
2.
3. Commencé à: 22:09:07 le 17/12/2010
4.
5. Valeur(s) recherchée(s):
6. etrust
7.
8. Légende: TC => Date de création, TM => Date de modification, DA => Dernier accès
9.
10. (!) --- Calcul du Hash "MD5"
11. (!) --- Informations supplémentaires
12. (!) --- Affichage des ADS
13. (!) --- Recherche registre
14.
15. ====== Fichier(s) ======
16.
17. Aucun fichier trouvé
18.
19.
20. ====== Entrée(s) du registre ======
21.
22.
23. [HKLM\Software\Classes\Installer\Products\3EE01C033BFEA7B4C9CD0597C0B22500\SourceList]
24. "LastUsedSource"="n;1;D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_EXPAND_SZ)
25.
26. [HKLM\Software\Classes\Installer\Products\3EE01C033BFEA7B4C9CD0597C0B22500\SourceList\Net]
27. "1"="D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_EXPAND_SZ)
28.
29. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}]
30. "$Function"="WintrustCertificateTrust" (REG_SZ)
31.
32. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{189A3842-3041-11D1-85E1-00C04FC295EE}]
33. "$Function"="WintrustCertificateTrust" (REG_SZ)
34.
35. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{31D1ADC1-D329-11D1-8ED8-0080C76516C6}]
36. "$Function"="WintrustCertificateTrust" (REG_SZ)
37.
38. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{5555C2CD-17FB-11D1-85C4-00C04FC295EE}]
39. "$Function"="WintrustCertificateTrust" (REG_SZ)
40.
41. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}]
42. "$Function"="HTTPSCertificateTrust" (REG_SZ)
43.
44. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{573E31F8-DDBA-11D0-8CCB-00C04FC295EE}]
45. "$Function"="WintrustCertificateTrust" (REG_SZ)
46.
47. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{64B9D180-8DA2-11CF-8736-00AA00A485EB}]
48. "$Function"="WintrustCertificateTrust" (REG_SZ)
49.
50. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{7801EBD0-CF4B-11D0-851F-0060979387EA}]
51. "$Function"="WintrustCertificateTrust" (REG_SZ)
52.
53. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{C6B2E8D0-E005-11CF-A134-00C04FD7BF43}]
54. "$Function"="WintrustCertificateTrust" (REG_SZ)
55.
56. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{D41E4F1D-A407-11D1-8BC9-00C04FA30A41}]
57. "$Function"="WintrustCertificateTrust" (REG_SZ)
58.
59. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{D41E4F1F-A407-11D1-8BC9-00C04FA30A41}]
60. "$Function"="WintrustCertificateTrust" (REG_SZ)
61.
62. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{E6F795B1-F738-11D0-A72F-00A0C903B83D}]
63. "$Function"="WintrustCertificateTrust" (REG_SZ)
64.
65. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{E6F795B2-F738-11D0-A72F-00A0C903B83D}]
66. "$Function"="WintrustCertificateTrust" (REG_SZ)
67.
68. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}]
69. "$Function"="WintrustCertificateTrust" (REG_SZ)
70.
71. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{FC451C16-AC75-11D1-B4B8-00C04FB66EA0}]
72. "$Function"="GenericChainCertificateTrust" (REG_SZ)
73.
74. [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3EE01C033BFEA7B4C9CD0597C0B22500\InstallProperties]
75. "InstallSource"="D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_SZ)
76.
77. [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}]
78. "InstallSource"="D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_SZ)
79.
80. [HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
81. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
82.
83. [HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
84. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
85.
86. [HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
87. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
88.
89. [HKLM\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
90. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
91.
92. [HKLM\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
93. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
94.
95. [HKLM\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
96. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
97.
98. [HKLM\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
99. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
100.
101. [HKLM\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
102. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
103.
104. [HKLM\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
105. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
106.
107. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
108. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
109.
110. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
111. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
112.
113. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
114. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
115.
116. [HKU\S-1-5-21-3219242564-3313283440-2393574426-1007\Software\Microsoft\Search Assistant\ACMru\5603]
117. "002"="etrust" (REG_SZ)
118.
119. =========================
120.
121. Fin à: 22:11:42 le 17/12/2010
122. 284843 Éléments analysés
123.
124. =========================
125. E.O.F
1. ========================= SEAF 1.0.1.0 - C_XX
2.
3. Commencé à: 22:09:07 le 17/12/2010
4.
5. Valeur(s) recherchée(s):
6. etrust
7.
8. Légende: TC => Date de création, TM => Date de modification, DA => Dernier accès
9.
10. (!) --- Calcul du Hash "MD5"
11. (!) --- Informations supplémentaires
12. (!) --- Affichage des ADS
13. (!) --- Recherche registre
14.
15. ====== Fichier(s) ======
16.
17. Aucun fichier trouvé
18.
19.
20. ====== Entrée(s) du registre ======
21.
22.
23. [HKLM\Software\Classes\Installer\Products\3EE01C033BFEA7B4C9CD0597C0B22500\SourceList]
24. "LastUsedSource"="n;1;D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_EXPAND_SZ)
25.
26. [HKLM\Software\Classes\Installer\Products\3EE01C033BFEA7B4C9CD0597C0B22500\SourceList\Net]
27. "1"="D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_EXPAND_SZ)
28.
29. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}]
30. "$Function"="WintrustCertificateTrust" (REG_SZ)
31.
32. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{189A3842-3041-11D1-85E1-00C04FC295EE}]
33. "$Function"="WintrustCertificateTrust" (REG_SZ)
34.
35. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{31D1ADC1-D329-11D1-8ED8-0080C76516C6}]
36. "$Function"="WintrustCertificateTrust" (REG_SZ)
37.
38. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{5555C2CD-17FB-11D1-85C4-00C04FC295EE}]
39. "$Function"="WintrustCertificateTrust" (REG_SZ)
40.
41. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}]
42. "$Function"="HTTPSCertificateTrust" (REG_SZ)
43.
44. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{573E31F8-DDBA-11D0-8CCB-00C04FC295EE}]
45. "$Function"="WintrustCertificateTrust" (REG_SZ)
46.
47. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{64B9D180-8DA2-11CF-8736-00AA00A485EB}]
48. "$Function"="WintrustCertificateTrust" (REG_SZ)
49.
50. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{7801EBD0-CF4B-11D0-851F-0060979387EA}]
51. "$Function"="WintrustCertificateTrust" (REG_SZ)
52.
53. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{C6B2E8D0-E005-11CF-A134-00C04FD7BF43}]
54. "$Function"="WintrustCertificateTrust" (REG_SZ)
55.
56. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{D41E4F1D-A407-11D1-8BC9-00C04FA30A41}]
57. "$Function"="WintrustCertificateTrust" (REG_SZ)
58.
59. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{D41E4F1F-A407-11D1-8BC9-00C04FA30A41}]
60. "$Function"="WintrustCertificateTrust" (REG_SZ)
61.
62. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{E6F795B1-F738-11D0-A72F-00A0C903B83D}]
63. "$Function"="WintrustCertificateTrust" (REG_SZ)
64.
65. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{E6F795B2-F738-11D0-A72F-00A0C903B83D}]
66. "$Function"="WintrustCertificateTrust" (REG_SZ)
67.
68. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}]
69. "$Function"="WintrustCertificateTrust" (REG_SZ)
70.
71. [HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{FC451C16-AC75-11D1-B4B8-00C04FB66EA0}]
72. "$Function"="GenericChainCertificateTrust" (REG_SZ)
73.
74. [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3EE01C033BFEA7B4C9CD0597C0B22500\InstallProperties]
75. "InstallSource"="D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_SZ)
76.
77. [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}]
78. "InstallSource"="D:\Tools\eTrust Antivirus\License\Lang\fr\" (REG_SZ)
79.
80. [HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
81. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
82.
83. [HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
84. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
85.
86. [HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
87. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
88.
89. [HKLM\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
90. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
91.
92. [HKLM\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
93. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
94.
95. [HKLM\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
96. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
97.
98. [HKLM\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
99. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
100.
101. [HKLM\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
102. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
103.
104. [HKLM\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
105. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
106.
107. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
108. "C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner" (REG_SZ)
109.
110. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
111. "C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor" (REG_SZ)
112.
113. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
114. "C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"="C:\Program Files\CA\eTrust Antivirus\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server" (REG_SZ)
115.
116. [HKU\S-1-5-21-3219242564-3313283440-2393574426-1007\Software\Microsoft\Search Assistant\ACMru\5603]
117. "002"="etrust" (REG_SZ)
118.
119. =========================
120.
121. Fin à: 22:11:42 le 17/12/2010
122. 284843 Éléments analysés
123.
124. =========================
125. E.O.F
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 22:33
17 déc. 2010 à 22:33
1)
? Télécharge OTM (OldTimer) sur ton Bureau :
http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
? Double-clique sur OTM.exe afin de le lancer.
? Copie (Ctrl+C) le texte suivant ci-dessous :
:files
C:\Program Files\CA\
:commands
[emptytemp]
[start explorer]
[reboot]
? Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
? Clique maintenant sur le bouton MoveIt! puis ferme OTM
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
? Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
*Le nom du rapport correspond au moment de sa création : date_heure.log
_________________
2)
Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
___________
3)
retente combofix
? Télécharge OTM (OldTimer) sur ton Bureau :
http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
? Double-clique sur OTM.exe afin de le lancer.
? Copie (Ctrl+C) le texte suivant ci-dessous :
:files
C:\Program Files\CA\
:commands
[emptytemp]
[start explorer]
[reboot]
? Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
? Clique maintenant sur le bouton MoveIt! puis ferme OTM
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
? Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
*Le nom du rapport correspond au moment de sa création : date_heure.log
_________________
2)
Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
___________
3)
retente combofix
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 23:08
17 déc. 2010 à 23:08
Etapes 1 à 3 effectuées.
Le rapport Combofix :
ComboFix 10-12-16.05 - Jolujolu 17/12/2010 22:55:59.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.669 [GMT 1:00]
Lancé depuis: c:\documents and settings\Jolujolu\Bureau\ComboFix.exe
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {815D8DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {815EC054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {816FACC4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {8170FDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {822EEC24-FFA4-00FC-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Outdated* {00000000-0000-0000-0000-000000000000}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815395FC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815475C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815513E4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815787A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8158883C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815955DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815B4C14-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815B865C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {816CD7A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {816E8DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {816FC844-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170783C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170D054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170D984-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170FBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81711054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81711DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81713054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171329C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81713DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81714DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171528C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171847C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171B29C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171E3E4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172165C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81721DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172347C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817253DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172583C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81727364-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81727724-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172897C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81728DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817295C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81729BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172BBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172D48C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172EDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173583C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81736DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81737DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173ADDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173B7B4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173C83C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173DBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173DDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81741BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174443C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174860C-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174A054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174B054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174C054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174D704-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174DA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175183C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81751BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817522BC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81752484-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175447C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81754DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175665C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81756BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81756DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81757DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175A65C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175B054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175BBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175C8EC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175CDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175D3E4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175E9F4-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175FBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175FDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81760054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817604CC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81760DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81761594-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81761B64-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817625C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176265C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81762DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81763DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176452C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817655C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81765DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81766DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817679EC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81767DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176844C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817687A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817693DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176A79C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176AA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176AAC4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176ADDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176B65C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176C3B4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176C60C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176CDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176D054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176D47C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176D65C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176EBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176F69C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177147C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817715C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81771DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81772DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817737A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177383C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81773984-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81773DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81774BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81776B64-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177765C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81777BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81778054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81778A2C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81778DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81779054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177D48C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177D83C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177DA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177DBE4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177F47C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177F7A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177FDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817805C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81780DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178135C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178165C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81781914-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178247C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817834AC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81783BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817845C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817849CC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81785A4C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81785BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81789A1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81789DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178A7AC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178B70C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178BA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178BA4C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178C324-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178CB5C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178CB64-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178E494-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178FC0C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179244C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81792A3C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81795894-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179AC0C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179C7A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179DBCC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179E9DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817A07A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817A4DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817ACDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {819C7BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81A1F704-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81A41524-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81A4570C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81D3B054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81DC3CA4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {823A3DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {823D3054-FFA4-00DA-0D24-347CA8A3377C}
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
[i] ADS - WINDOWS: deleted 24 bytes in 1 streams. /i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\GoogleEarthWin.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-11-17 au 2010-12-17 ))))))))))))))))))))))))))))))))))))
.
2010-12-16 19:58 . 2010-12-16 19:58 -------- d-sh--w- c:\documents and settings\Jolujolu\PrivacIE
2010-12-16 19:54 . 2010-12-16 19:54 -------- d-sh--w- c:\documents and settings\Jolujolu\IETldCache
2010-12-16 19:49 . 2010-12-16 19:50 -------- dc-h--w- c:\windows\ie8
2010-12-16 19:40 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-12-16 19:34 . 2010-11-06 00:21 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-16 19:34 . 2010-11-06 00:21 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-16 19:34 . 2010-11-06 00:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-16 08:54 . 2010-12-16 08:54 -------- d-----w- C:\_OTM
2010-12-16 08:17 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 20:07 . 2010-12-15 21:10 -------- d-----w- C:\Kill'em
2010-12-15 20:05 . 2010-12-15 21:19 -------- d-----w- c:\program files\List_Kill'em
2010-12-15 19:11 . 2010-12-16 20:36 -------- d-----w- c:\program files\ZHPDiag
2010-12-14 20:58 . 2010-12-14 20:58 -------- d-----w- c:\program files\Ad-Remover
2010-12-13 22:24 . 2010-09-06 09:26 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-12-13 20:09 . 2010-12-13 20:09 -------- d-----w- c:\documents and settings\Jolujolu\Application Data\Malwarebytes
2010-12-13 20:08 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-13 20:08 . 2010-12-13 20:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-12-13 20:08 . 2010-12-13 20:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-13 20:08 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-13 19:37 . 2010-12-13 19:37 -------- d-----w- c:\documents and settings\Jolujolu\Application Data\zzajvYrXuNZNLFWUqakqmy
2010-12-13 18:42 . 2010-12-13 18:42 -------- d-----w- c:\program files\Trend Micro
2010-12-13 18:24 . 2010-12-13 18:24 -------- d-----w- c:\documents and settings\Jolujolu\Application Data\OdWGnqLnrGDlyYYzIUwQvT
2010-12-12 10:36 . 2010-12-13 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson
2010-12-12 10:36 . 2010-12-13 19:43 -------- d-----w- c:\program files\Sony Ericsson
2010-12-12 09:12 . 2010-12-12 09:12 -------- d-----w- c:\documents and settings\Jolujolu\Local Settings\Application Data\Real
2010-12-12 09:12 . 2010-12-12 09:12 11776 ----a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2010-12-12 09:12 . 2010-12-12 09:12 -------- d-----w- c:\program files\Fichiers communs\xing shared
2010-12-12 09:11 . 2010-12-12 09:11 151776 ----a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2010-12-12 09:11 . 2010-12-12 09:11 100352 ----a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
2010-12-11 17:03 . 2010-12-11 17:04 84621672 ----a-w- c:\program files\Fichiers communs\Windows Live\.cache\wlc27.tmp
2010-11-18 18:12 . 2010-11-18 18:12 86016 -c----w- c:\windows\system32\dllcache\isign32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-17 21:40 . 2004-10-25 09:23 13440 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-16 19:36 . 2008-12-22 20:43 86576 ----a-w- c:\documents and settings\Jolujolu\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2010-12-16 19:36 . 2008-12-22 20:43 392728 ----a-w- c:\documents and settings\Jolujolu\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
2010-12-16 19:36 . 2008-12-22 20:43 132672 ----a-w- c:\documents and settings\Jolujolu\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2010-12-12 09:11 . 2004-10-25 10:21 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-12 09:11 . 2004-10-25 10:21 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-11-18 18:12 . 2002-03-11 07:57 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:21 . 2004-02-06 16:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2002-03-11 07:39 43520 ------w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2002-03-11 07:39 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-10-25 11:24 385024 ------w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2002-03-11 07:40 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:14 . 2002-03-11 07:39 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:07 . 2002-03-11 07:40 1853440 ----a-w- c:\windows\system32\win32k.sys
2010-10-25 21:57 . 2007-05-18 21:25 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-09-05 12:27 . 2010-09-05 12:11 134946144 ----a-w- c:\program files\OOo_3.2.1_Win_x86_install_fr.exe
2010-08-30 15:04 . 2010-08-30 15:04 3149696 ----a-w- c:\program files\MaConfig_4_2_1_1.exe
2010-08-19 19:43 . 2010-08-19 19:43 336280 ----a-w- c:\program files\rootsupd.exe
2010-08-19 19:40 . 2010-08-19 19:40 909176 ----a-w- c:\program files\WGAPluginInstall(2).exe
2010-07-14 18:11 . 2010-07-14 18:11 318904 ----a-w- c:\program files\WindowsMedia-Firefox-Plugin.exe
2010-06-09 16:24 . 2010-06-09 16:19 20330720 ----a-w- c:\program files\TomTomHOME2winlatest.exe
2010-05-25 20:00 . 2010-05-25 19:59 21292528 ----a-w- c:\program files\RealPlayerSPGold_fr.exe
2010-05-21 19:15 . 2010-05-21 19:15 563040 ----a-w- c:\program files\googleupdatesetup.exe
2010-05-14 17:38 . 2010-05-14 17:05 25045388 ----a-w- c:\program files\MediaCoder-0.7.3.4666.exe
2010-05-14 15:45 . 2010-05-14 15:45 9918872 ----a-w- c:\program files\WMEncoder.exe
2010-05-14 15:02 . 2010-05-14 15:02 909176 ----a-w- c:\program files\WGAPluginInstall.exe
2010-05-14 14:02 . 2010-05-14 14:00 25860576 ----a-w- c:\program files\k-lite-mega-codec-pack_k-lite_mega_codec_pack_5.9.0_anglais_35535.exe
2010-03-12 22:00 . 2010-03-12 21:59 8149640 ----a-w- c:\program files\Firefox Setup 3.5.8.exe
2010-02-21 20:27 . 2010-02-21 20:24 74121968 -c--a-w- c:\program files\a2FreeSetup.exe
2009-10-30 09:53 . 2006-09-20 16:32 4301928 ----a-w- c:\program files\Shockwave_Installer_Slim.exe
2009-09-04 19:53 . 2009-09-04 19:53 308160 ------w- c:\program files\avast_home_setup.exe
2009-07-04 18:43 . 2009-07-04 18:43 2228534 ------w- c:\program files\audacity-win-1.2.6.exe
2009-07-01 21:28 . 2006-09-19 20:05 21935408 ------w- c:\program files\QuickTimeInstaller.exe
2009-06-12 19:52 . 2006-01-17 19:49 840679 -c----w- c:\program files\7z432.exe
2009-06-07 18:20 . 2009-06-07 18:17 27100264 ------w- c:\program files\PowerPointViewer.exe
2009-05-23 21:26 . 2009-05-23 21:26 2477416 ------w- c:\program files\poiedit_poiedit_5.1.0_francais_35736.exe
2009-03-05 20:15 . 2009-03-05 20:14 4152168 ------w- c:\program files\SetupAnyDVD6522.exe
2009-02-17 19:04 . 2009-02-17 19:04 1842024 ------w- c:\program files\Installation_WLMessenger2009.exe
2008-12-11 21:10 . 2008-12-11 21:10 3909833 ------w- c:\program files\Setup_FreeVideoConverter.exe
2008-12-11 11:45 . 2008-12-11 11:45 6108728 ------w- c:\program files\picasaweb-current-setup.exe
2008-11-29 20:48 . 2008-11-29 20:48 3279829 ------w- c:\program files\GBonSetup.exe
2008-10-27 20:49 . 2006-09-24 17:26 1851544 ------w- c:\program files\install_flash_player.exe
2008-09-27 18:01 . 2008-09-27 18:00 4479080 ------w- c:\program files\SweetImSetup.exe
2008-07-18 17:36 . 2007-12-16 19:22 2402832 ------w- c:\program files\WLinstaller.exe
2008-07-09 19:56 . 2008-07-09 19:54 19153264 ------w- c:\program files\aaw2008.exe
2008-04-16 21:48 . 2008-04-16 21:40 24578952 ------w- c:\program files\AdbeRdr812_fr_FR.exe
2008-04-16 21:44 . 2008-04-16 21:44 359656 ------w- c:\program files\msicuu2.exe
2007-07-27 18:10 . 2007-07-27 18:09 2720456 ------w- c:\program files\ccsetup141.exe
2007-07-27 16:27 . 2007-07-27 16:27 1060536 ------w- c:\program files\setup690.exe
2007-06-01 21:37 . 2007-06-01 21:32 14584221 ------w- c:\program files\klcodec310f.exe
2007-04-22 16:16 . 2007-04-22 16:15 2714784 ------w- c:\program files\ccsetup139.exe
2007-04-18 19:19 . 2007-04-18 19:18 13256032 ------w- c:\program files\PDFCreator-0_9_3_GPLGhostscript.exe
2007-03-30 19:47 . 2007-03-30 19:47 814547 ------w- c:\program files\RegSupreme_setup.exe
2007-03-21 20:45 . 2007-03-21 20:45 633344 ------w- c:\program files\bibexp_tutorial.exe
2007-03-21 20:37 . 2007-03-21 20:37 3185664 ------w- c:\program files\bxp3.exe
2007-03-16 21:13 . 2007-03-16 21:12 2683984 ------w- c:\program files\ccsetup137.exe
2007-03-11 11:16 . 2007-03-11 11:14 29816881 ------w- c:\program files\gkati_radwxp.exe
2007-03-02 17:40 . 2007-03-02 17:35 2369536 -c----w- c:\program files\MSCariocaSetup-fra.msi
2007-02-18 20:38 . 2007-02-18 20:37 2833783 ------w- c:\program files\MAC_399F.exe
2006-09-26 19:49 . 2005-12-30 21:37 7218088 -c----w- c:\program files\psa30se_fr_fr.exe
2006-09-26 19:48 . 2005-12-30 21:37 762512 -c----w- c:\program files\ytb612_efgsip.exe
2006-09-24 15:35 . 2006-09-24 15:36 700120 -c----w- c:\program files\flashplayer7installer.exe
2006-09-23 22:02 . 2006-09-23 21:57 182920 -c----w- c:\program files\uninstall_flash_player.exe
2006-09-19 20:28 . 2006-09-19 20:21 7050552 -c----w- c:\program files\psa30se_en_us.exe
2006-09-19 19:58 . 2006-09-19 19:55 14075456 -c----w- c:\program files\RealPlayer10-5GOLD_fr.exe
2006-09-19 19:46 . 2006-09-19 19:46 12814336 -c----w- c:\program files\mp10setup.exe
2006-09-19 19:32 . 2006-09-19 19:32 16277288 -c----w- c:\program files\Install_Messenger.exe
2006-08-15 14:11 . 2006-08-15 14:01 286633 -c----w- c:\program files\igo_fr.exe
2006-08-15 14:07 . 2006-08-15 14:08 804864 -c----w- c:\program files\igowin.exe
2006-05-05 19:06 . 2006-05-05 19:03 48376504 -c----w- c:\program files\flstudio608_install.exe
2006-01-28 21:19 . 2006-01-28 21:18 2888451 -c----w- c:\program files\gw-4.09-win.exe
2006-01-18 22:02 . 2006-01-18 21:59 9394376 -c----w- c:\program files\Install_MSN_Messenger.EXE
2005-12-11 20:40 . 2005-12-11 20:33 1601668 ------w- c:\program files\pf-setup.exe
2005-10-15 14:51 . 2005-10-15 14:50 5995533 -c----w- c:\program files\SetupBDE5.exe
2005-10-10 19:17 . 2005-10-10 19:16 2855080 -c----w- c:\program files\aawsepersonal.exe
2005-04-04 16:51 . 2005-04-04 16:48 1953480 -c----w- c:\program files\PPVIEWER.EXE
2005-03-21 17:31 . 2005-03-21 17:27 18258164 -c----w- c:\program files\D3_1_1.exe
2004-08-19 14:10 . 2007-01-12 20:43 133120 ------w- c:\program files\sndrec32.exe
2004-08-19 14:10 . 2007-01-05 22:00 347648 ------w- c:\program files\mspaint.exe
2000-06-15 15:50 . 2001-07-06 13:40 1384448 ------w- c:\program files\MSVBVM60.dll
2006-01-22 19:06 1172472 --sha-r- c:\windows\windir\svchost.exe
2006-04-12 13:57 1172472 --sha-r- c:\windows\windir\system.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-10-27 16384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dit"="Dit.exe" [2004-04-02 86016]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jolujolu^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.0.lnk]
path=c:\documents and settings\Jolujolu\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.0.lnk
backup=c:\windows\pss\OpenOffice.org 2.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-16 09:45 63712 ------w- c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 00:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2004-02-25 16:15 454656 ------w- c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2004-02-25 16:06 212992 ------w- c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2004-07-26 17:14 1867776 ------w- c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2008-05-06 08:42 202088 ------w- c:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-11-03 08:59 204288 ------w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\e-on software\\Vue 6 PLE RenderCow\\Infinite RenderCow.eon"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [04/09/2009 21:00 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/09/2009 21:00 17744]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [18/03/2009 01:03 92008]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/10/2004 10:23 13440]
R3 fbxusb;FreeBox USB Network Adapter;c:\windows\system32\drivers\fbxusb.sys [16/12/2004 12:11 18848]
R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;c:\windows\system32\drivers\PhTVTune.sys [04/03/2004 12:25 24704]
R3 UKBFLT;UKBFLT;c:\windows\system32\drivers\UKBFLT.sys [15/12/2004 11:24 11672]
S1 ATMhelpr;ATMhelpr; [x]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;"c:\program files\Avira\AntiVir Desktop\sched.exe" --> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21/05/2010 20:15 136176]
S2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe --> c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [?]
S3 CA_LIC_CLNT;Client de licence CA;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe --> c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [?]
S3 CA_LIC_SRVR;Serveur de licence CA;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe --> c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [?]
S3 jbridgep;jbridgep;\??\c:\docume~1\Jolujolu\LOCALS~1\Temp\jbridgep.sys --> c:\docume~1\Jolujolu\LOCALS~1\Temp\jbridgep.sys [?]
S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [23/05/2009 08:45 14336]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [23/05/2009 08:45 17408]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [25/10/2004 12:24 129535]
.
Contenu du dossier 'Tâches planifiées'
2010-10-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
2010-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-21 19:15]
2010-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-21 19:15]
2010-12-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3219242564-3313283440-2393574426-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
2010-12-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3219242564-3313283440-2393574426-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost;*.local
IE: &Recherche AOL Toolbar
IE: &Winamp Toolbar Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{90EAE591-7E7E-434a-8E28-ECFD00071806} - c:\program files\PokerStars.FR\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\Jolujolu\Application Data\Mozilla\Firefox\Profiles\w1pfxpf0.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?mkt=fr-FR&form=MIAWB1&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: Exif Viewer: exif_viewer@mozilla.doslash.org - %profile%\extensions\exif_viewer@mozilla.doslash.org
FF - Ext: FxIF: {11483926-db67-4190-91b1-ef20fcec5f33} - %profile%\extensions\{11483926-db67-4190-91b1-ef20fcec5f33}
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-PCMService - c:\program files\Home Cinema\PowerCinema\PCMService.exe
MSConfigStartUp-TkBellExe - c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-17 23:00
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-3219242564-3313283440-2393574426-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(524)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2010-12-17 23:03:47
ComboFix-quarantined-files.txt 2010-12-17 22:03
Avant-CF: 25 524 686 848 octets libres
Après-CF: 25 462 358 016 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
- - End Of File - - 0245D253AF0E806883B5A0A570E668FD
Le rapport Combofix :
ComboFix 10-12-16.05 - Jolujolu 17/12/2010 22:55:59.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.669 [GMT 1:00]
Lancé depuis: c:\documents and settings\Jolujolu\Bureau\ComboFix.exe
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {815D8DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {815EC054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {816FACC4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {8170FDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Disabled/Updated* {822EEC24-FFA4-00FC-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Outdated* {00000000-0000-0000-0000-000000000000}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815395FC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815475C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815513E4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815787A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8158883C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815955DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815B4C14-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {815B865C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {816CD7A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {816E8DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {816FC844-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170783C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170D054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170D984-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8170FBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81711054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81711DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81713054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171329C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81713DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81714DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171528C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171847C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171B29C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8171E3E4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172165C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81721DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172347C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817253DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172583C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81727364-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81727724-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172897C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81728DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817295C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81729BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172BBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172D48C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8172EDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173583C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81736DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81737DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173ADDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173B7B4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173C83C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173DBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8173DDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81741BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174443C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174860C-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174A054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174B054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174C054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174D704-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8174DA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175183C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81751BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817522BC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81752484-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175447C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81754DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175665C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81756BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81756DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81757DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175A65C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175B054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175BBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175C8EC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175CDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175D3E4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175E9F4-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175FBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8175FDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81760054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817604CC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81760DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81761594-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81761B64-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817625C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176265C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81762DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81763DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176452C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817655C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81765DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81766DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817679EC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81767DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176844C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817687A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817693DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176A79C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176AA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176AAC4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176ADDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176B65C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176C3B4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176C60C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176CDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176D054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176D47C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176D65C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176EBFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8176F69C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177147C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817715C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81771DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81772DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817737A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177383C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81773984-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81773DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81774BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81776B64-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177765C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81777BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81778054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81778A2C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81778DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81779054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177BDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177D48C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177D83C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177DA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177DBE4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177F47C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177F7A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8177FDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817805C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81780DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178135C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178165C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81781914-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178247C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817834AC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81783BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817845C4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817849CC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81785A4C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81785BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81789A1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81789DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178A7AC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178B70C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178BA1C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178BA4C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178C324-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178CB5C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178CB64-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178E494-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8178FC0C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179244C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81792A3C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81795894-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179AC0C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179C7A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179DBCC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {8179E9DC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817A07A4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817A4DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {817ACDDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {819C7BFC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81A1F704-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81A41524-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81A4570C-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81D3B054-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {81DC3CA4-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {823A3DDC-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {823D3054-FFA4-00DA-0D24-347CA8A3377C}
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
[i] ADS - WINDOWS: deleted 24 bytes in 1 streams. /i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\GoogleEarthWin.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-11-17 au 2010-12-17 ))))))))))))))))))))))))))))))))))))
.
2010-12-16 19:58 . 2010-12-16 19:58 -------- d-sh--w- c:\documents and settings\Jolujolu\PrivacIE
2010-12-16 19:54 . 2010-12-16 19:54 -------- d-sh--w- c:\documents and settings\Jolujolu\IETldCache
2010-12-16 19:49 . 2010-12-16 19:50 -------- dc-h--w- c:\windows\ie8
2010-12-16 19:40 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-12-16 19:34 . 2010-11-06 00:21 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-16 19:34 . 2010-11-06 00:21 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-16 19:34 . 2010-11-06 00:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-16 08:54 . 2010-12-16 08:54 -------- d-----w- C:\_OTM
2010-12-16 08:17 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 20:07 . 2010-12-15 21:10 -------- d-----w- C:\Kill'em
2010-12-15 20:05 . 2010-12-15 21:19 -------- d-----w- c:\program files\List_Kill'em
2010-12-15 19:11 . 2010-12-16 20:36 -------- d-----w- c:\program files\ZHPDiag
2010-12-14 20:58 . 2010-12-14 20:58 -------- d-----w- c:\program files\Ad-Remover
2010-12-13 22:24 . 2010-09-06 09:26 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-12-13 20:09 . 2010-12-13 20:09 -------- d-----w- c:\documents and settings\Jolujolu\Application Data\Malwarebytes
2010-12-13 20:08 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-13 20:08 . 2010-12-13 20:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-12-13 20:08 . 2010-12-13 20:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-13 20:08 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-13 19:37 . 2010-12-13 19:37 -------- d-----w- c:\documents and settings\Jolujolu\Application Data\zzajvYrXuNZNLFWUqakqmy
2010-12-13 18:42 . 2010-12-13 18:42 -------- d-----w- c:\program files\Trend Micro
2010-12-13 18:24 . 2010-12-13 18:24 -------- d-----w- c:\documents and settings\Jolujolu\Application Data\OdWGnqLnrGDlyYYzIUwQvT
2010-12-12 10:36 . 2010-12-13 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson
2010-12-12 10:36 . 2010-12-13 19:43 -------- d-----w- c:\program files\Sony Ericsson
2010-12-12 09:12 . 2010-12-12 09:12 -------- d-----w- c:\documents and settings\Jolujolu\Local Settings\Application Data\Real
2010-12-12 09:12 . 2010-12-12 09:12 11776 ----a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2010-12-12 09:12 . 2010-12-12 09:12 -------- d-----w- c:\program files\Fichiers communs\xing shared
2010-12-12 09:11 . 2010-12-12 09:11 151776 ----a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2010-12-12 09:11 . 2010-12-12 09:11 100352 ----a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
2010-12-11 17:03 . 2010-12-11 17:04 84621672 ----a-w- c:\program files\Fichiers communs\Windows Live\.cache\wlc27.tmp
2010-11-18 18:12 . 2010-11-18 18:12 86016 -c----w- c:\windows\system32\dllcache\isign32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-17 21:40 . 2004-10-25 09:23 13440 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-16 19:36 . 2008-12-22 20:43 86576 ----a-w- c:\documents and settings\Jolujolu\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2010-12-16 19:36 . 2008-12-22 20:43 392728 ----a-w- c:\documents and settings\Jolujolu\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
2010-12-16 19:36 . 2008-12-22 20:43 132672 ----a-w- c:\documents and settings\Jolujolu\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2010-12-12 09:11 . 2004-10-25 10:21 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-12 09:11 . 2004-10-25 10:21 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-11-18 18:12 . 2002-03-11 07:57 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:21 . 2004-02-06 16:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2002-03-11 07:39 43520 ------w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2002-03-11 07:39 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-10-25 11:24 385024 ------w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2002-03-11 07:40 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:14 . 2002-03-11 07:39 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:07 . 2002-03-11 07:40 1853440 ----a-w- c:\windows\system32\win32k.sys
2010-10-25 21:57 . 2007-05-18 21:25 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-09-05 12:27 . 2010-09-05 12:11 134946144 ----a-w- c:\program files\OOo_3.2.1_Win_x86_install_fr.exe
2010-08-30 15:04 . 2010-08-30 15:04 3149696 ----a-w- c:\program files\MaConfig_4_2_1_1.exe
2010-08-19 19:43 . 2010-08-19 19:43 336280 ----a-w- c:\program files\rootsupd.exe
2010-08-19 19:40 . 2010-08-19 19:40 909176 ----a-w- c:\program files\WGAPluginInstall(2).exe
2010-07-14 18:11 . 2010-07-14 18:11 318904 ----a-w- c:\program files\WindowsMedia-Firefox-Plugin.exe
2010-06-09 16:24 . 2010-06-09 16:19 20330720 ----a-w- c:\program files\TomTomHOME2winlatest.exe
2010-05-25 20:00 . 2010-05-25 19:59 21292528 ----a-w- c:\program files\RealPlayerSPGold_fr.exe
2010-05-21 19:15 . 2010-05-21 19:15 563040 ----a-w- c:\program files\googleupdatesetup.exe
2010-05-14 17:38 . 2010-05-14 17:05 25045388 ----a-w- c:\program files\MediaCoder-0.7.3.4666.exe
2010-05-14 15:45 . 2010-05-14 15:45 9918872 ----a-w- c:\program files\WMEncoder.exe
2010-05-14 15:02 . 2010-05-14 15:02 909176 ----a-w- c:\program files\WGAPluginInstall.exe
2010-05-14 14:02 . 2010-05-14 14:00 25860576 ----a-w- c:\program files\k-lite-mega-codec-pack_k-lite_mega_codec_pack_5.9.0_anglais_35535.exe
2010-03-12 22:00 . 2010-03-12 21:59 8149640 ----a-w- c:\program files\Firefox Setup 3.5.8.exe
2010-02-21 20:27 . 2010-02-21 20:24 74121968 -c--a-w- c:\program files\a2FreeSetup.exe
2009-10-30 09:53 . 2006-09-20 16:32 4301928 ----a-w- c:\program files\Shockwave_Installer_Slim.exe
2009-09-04 19:53 . 2009-09-04 19:53 308160 ------w- c:\program files\avast_home_setup.exe
2009-07-04 18:43 . 2009-07-04 18:43 2228534 ------w- c:\program files\audacity-win-1.2.6.exe
2009-07-01 21:28 . 2006-09-19 20:05 21935408 ------w- c:\program files\QuickTimeInstaller.exe
2009-06-12 19:52 . 2006-01-17 19:49 840679 -c----w- c:\program files\7z432.exe
2009-06-07 18:20 . 2009-06-07 18:17 27100264 ------w- c:\program files\PowerPointViewer.exe
2009-05-23 21:26 . 2009-05-23 21:26 2477416 ------w- c:\program files\poiedit_poiedit_5.1.0_francais_35736.exe
2009-03-05 20:15 . 2009-03-05 20:14 4152168 ------w- c:\program files\SetupAnyDVD6522.exe
2009-02-17 19:04 . 2009-02-17 19:04 1842024 ------w- c:\program files\Installation_WLMessenger2009.exe
2008-12-11 21:10 . 2008-12-11 21:10 3909833 ------w- c:\program files\Setup_FreeVideoConverter.exe
2008-12-11 11:45 . 2008-12-11 11:45 6108728 ------w- c:\program files\picasaweb-current-setup.exe
2008-11-29 20:48 . 2008-11-29 20:48 3279829 ------w- c:\program files\GBonSetup.exe
2008-10-27 20:49 . 2006-09-24 17:26 1851544 ------w- c:\program files\install_flash_player.exe
2008-09-27 18:01 . 2008-09-27 18:00 4479080 ------w- c:\program files\SweetImSetup.exe
2008-07-18 17:36 . 2007-12-16 19:22 2402832 ------w- c:\program files\WLinstaller.exe
2008-07-09 19:56 . 2008-07-09 19:54 19153264 ------w- c:\program files\aaw2008.exe
2008-04-16 21:48 . 2008-04-16 21:40 24578952 ------w- c:\program files\AdbeRdr812_fr_FR.exe
2008-04-16 21:44 . 2008-04-16 21:44 359656 ------w- c:\program files\msicuu2.exe
2007-07-27 18:10 . 2007-07-27 18:09 2720456 ------w- c:\program files\ccsetup141.exe
2007-07-27 16:27 . 2007-07-27 16:27 1060536 ------w- c:\program files\setup690.exe
2007-06-01 21:37 . 2007-06-01 21:32 14584221 ------w- c:\program files\klcodec310f.exe
2007-04-22 16:16 . 2007-04-22 16:15 2714784 ------w- c:\program files\ccsetup139.exe
2007-04-18 19:19 . 2007-04-18 19:18 13256032 ------w- c:\program files\PDFCreator-0_9_3_GPLGhostscript.exe
2007-03-30 19:47 . 2007-03-30 19:47 814547 ------w- c:\program files\RegSupreme_setup.exe
2007-03-21 20:45 . 2007-03-21 20:45 633344 ------w- c:\program files\bibexp_tutorial.exe
2007-03-21 20:37 . 2007-03-21 20:37 3185664 ------w- c:\program files\bxp3.exe
2007-03-16 21:13 . 2007-03-16 21:12 2683984 ------w- c:\program files\ccsetup137.exe
2007-03-11 11:16 . 2007-03-11 11:14 29816881 ------w- c:\program files\gkati_radwxp.exe
2007-03-02 17:40 . 2007-03-02 17:35 2369536 -c----w- c:\program files\MSCariocaSetup-fra.msi
2007-02-18 20:38 . 2007-02-18 20:37 2833783 ------w- c:\program files\MAC_399F.exe
2006-09-26 19:49 . 2005-12-30 21:37 7218088 -c----w- c:\program files\psa30se_fr_fr.exe
2006-09-26 19:48 . 2005-12-30 21:37 762512 -c----w- c:\program files\ytb612_efgsip.exe
2006-09-24 15:35 . 2006-09-24 15:36 700120 -c----w- c:\program files\flashplayer7installer.exe
2006-09-23 22:02 . 2006-09-23 21:57 182920 -c----w- c:\program files\uninstall_flash_player.exe
2006-09-19 20:28 . 2006-09-19 20:21 7050552 -c----w- c:\program files\psa30se_en_us.exe
2006-09-19 19:58 . 2006-09-19 19:55 14075456 -c----w- c:\program files\RealPlayer10-5GOLD_fr.exe
2006-09-19 19:46 . 2006-09-19 19:46 12814336 -c----w- c:\program files\mp10setup.exe
2006-09-19 19:32 . 2006-09-19 19:32 16277288 -c----w- c:\program files\Install_Messenger.exe
2006-08-15 14:11 . 2006-08-15 14:01 286633 -c----w- c:\program files\igo_fr.exe
2006-08-15 14:07 . 2006-08-15 14:08 804864 -c----w- c:\program files\igowin.exe
2006-05-05 19:06 . 2006-05-05 19:03 48376504 -c----w- c:\program files\flstudio608_install.exe
2006-01-28 21:19 . 2006-01-28 21:18 2888451 -c----w- c:\program files\gw-4.09-win.exe
2006-01-18 22:02 . 2006-01-18 21:59 9394376 -c----w- c:\program files\Install_MSN_Messenger.EXE
2005-12-11 20:40 . 2005-12-11 20:33 1601668 ------w- c:\program files\pf-setup.exe
2005-10-15 14:51 . 2005-10-15 14:50 5995533 -c----w- c:\program files\SetupBDE5.exe
2005-10-10 19:17 . 2005-10-10 19:16 2855080 -c----w- c:\program files\aawsepersonal.exe
2005-04-04 16:51 . 2005-04-04 16:48 1953480 -c----w- c:\program files\PPVIEWER.EXE
2005-03-21 17:31 . 2005-03-21 17:27 18258164 -c----w- c:\program files\D3_1_1.exe
2004-08-19 14:10 . 2007-01-12 20:43 133120 ------w- c:\program files\sndrec32.exe
2004-08-19 14:10 . 2007-01-05 22:00 347648 ------w- c:\program files\mspaint.exe
2000-06-15 15:50 . 2001-07-06 13:40 1384448 ------w- c:\program files\MSVBVM60.dll
2006-01-22 19:06 1172472 --sha-r- c:\windows\windir\svchost.exe
2006-04-12 13:57 1172472 --sha-r- c:\windows\windir\system.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-10-27 16384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dit"="Dit.exe" [2004-04-02 86016]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jolujolu^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.0.lnk]
path=c:\documents and settings\Jolujolu\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.0.lnk
backup=c:\windows\pss\OpenOffice.org 2.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-16 09:45 63712 ------w- c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 00:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2004-02-25 16:15 454656 ------w- c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2004-02-25 16:06 212992 ------w- c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2004-07-26 17:14 1867776 ------w- c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2008-05-06 08:42 202088 ------w- c:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-11-03 08:59 204288 ------w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\e-on software\\Vue 6 PLE RenderCow\\Infinite RenderCow.eon"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [04/09/2009 21:00 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/09/2009 21:00 17744]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [18/03/2009 01:03 92008]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/10/2004 10:23 13440]
R3 fbxusb;FreeBox USB Network Adapter;c:\windows\system32\drivers\fbxusb.sys [16/12/2004 12:11 18848]
R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;c:\windows\system32\drivers\PhTVTune.sys [04/03/2004 12:25 24704]
R3 UKBFLT;UKBFLT;c:\windows\system32\drivers\UKBFLT.sys [15/12/2004 11:24 11672]
S1 ATMhelpr;ATMhelpr; [x]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;"c:\program files\Avira\AntiVir Desktop\sched.exe" --> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21/05/2010 20:15 136176]
S2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe --> c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [?]
S3 CA_LIC_CLNT;Client de licence CA;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe --> c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [?]
S3 CA_LIC_SRVR;Serveur de licence CA;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe --> c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [?]
S3 jbridgep;jbridgep;\??\c:\docume~1\Jolujolu\LOCALS~1\Temp\jbridgep.sys --> c:\docume~1\Jolujolu\LOCALS~1\Temp\jbridgep.sys [?]
S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [23/05/2009 08:45 14336]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [23/05/2009 08:45 17408]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [25/10/2004 12:24 129535]
.
Contenu du dossier 'Tâches planifiées'
2010-10-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
2010-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-21 19:15]
2010-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-21 19:15]
2010-12-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3219242564-3313283440-2393574426-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
2010-12-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3219242564-3313283440-2393574426-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost;*.local
IE: &Recherche AOL Toolbar
IE: &Winamp Toolbar Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{90EAE591-7E7E-434a-8E28-ECFD00071806} - c:\program files\PokerStars.FR\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\Jolujolu\Application Data\Mozilla\Firefox\Profiles\w1pfxpf0.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?mkt=fr-FR&form=MIAWB1&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: Exif Viewer: exif_viewer@mozilla.doslash.org - %profile%\extensions\exif_viewer@mozilla.doslash.org
FF - Ext: FxIF: {11483926-db67-4190-91b1-ef20fcec5f33} - %profile%\extensions\{11483926-db67-4190-91b1-ef20fcec5f33}
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-PCMService - c:\program files\Home Cinema\PowerCinema\PCMService.exe
MSConfigStartUp-TkBellExe - c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-17 23:00
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-3219242564-3313283440-2393574426-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(524)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2010-12-17 23:03:47
ComboFix-quarantined-files.txt 2010-12-17 22:03
Avant-CF: 25 524 686 848 octets libres
Après-CF: 25 462 358 016 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
- - End Of File - - 0245D253AF0E806883B5A0A570E668FD
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 23:21
17 déc. 2010 à 23:21
Une question supplémentaire : j'ai désinstallé Spybot.
Quel antispyware me conseilles-tu ?
Quel antispyware me conseilles-tu ?
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 23:26
17 déc. 2010 à 23:26
MalwareByte's Anti-Malware
____________
en attendant on patine un peu sur ton sujet
ceci à une sale gue.le, il y a quoi dedans
c:\documents and settings\Jolujolu\Application Data\zzajvYrXuNZNLFWUq
c:\documents and settings\Jolujolu\Application Data\OdWGnqLnrGDlyYYzIUwQvT
_____________
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier :
c:\windows\windir\system.exe
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Copie le lien de Virus Total dans ta réponse.
Si tu ne trouves pas le fichier alors
Affiche tous les fichiers et dossiers :
Pour cela :
Clique sur démarrer/panneau de configuration/option des dossiers/affichage
Cocher afficher les dossiers cachés
Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher masquer les extensions dont le type est connu
Puis fais «appliquer» pour valider les changements.
Et OK
____________
en attendant on patine un peu sur ton sujet
ceci à une sale gue.le, il y a quoi dedans
c:\documents and settings\Jolujolu\Application Data\zzajvYrXuNZNLFWUq
c:\documents and settings\Jolujolu\Application Data\OdWGnqLnrGDlyYYzIUwQvT
_____________
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier :
c:\windows\windir\system.exe
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Copie le lien de Virus Total dans ta réponse.
Si tu ne trouves pas le fichier alors
Affiche tous les fichiers et dossiers :
Pour cela :
Clique sur démarrer/panneau de configuration/option des dossiers/affichage
Cocher afficher les dossiers cachés
Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher masquer les extensions dont le type est connu
Puis fais «appliquer» pour valider les changements.
Et OK
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 23:36
17 déc. 2010 à 23:36
Dans chacun des 2 dossiers, il y a un autre dossier portant le même nom et à l'intérieur un autre dossier nommé 0.0.0.0
La même chose pour les deux.
Le rapport de virustotal :
AhnLab-V3 2010.12.17.05 2010.12.17 -
AntiVir 7.11.0.83 2010.12.17 -
Antiy-AVL 2.0.3.7 2010.12.17 -
Avast 4.8.1351.0 2010.12.17 -
Avast5 5.0.677.0 2010.12.17 -
AVG 9.0.0.851 2010.12.17 -
BitDefender 7.2 2010.12.17 -
CAT-QuickHeal 11.00 2010.12.17 -
ClamAV 0.96.4.0 2010.12.17 -
Command 5.2.11.5 2010.12.17 -
Comodo 7099 2010.12.17 -
DrWeb 5.0.2.03300 2010.12.17 -
Emsisoft 5.1.0.1 2010.12.17 -
eSafe 7.0.17.0 2010.12.16 -
eTrust-Vet 36.1.8048 2010.12.17 -
F-Prot 4.6.2.117 2010.12.16 -
F-Secure 9.0.16160.0 2010.12.17 -
Fortinet 4.2.254.0 2010.12.17 -
GData 21 2010.12.17 -
Ikarus T3.1.1.90.0 2010.12.17 -
Jiangmin 13.0.900 2010.12.17 -
K7AntiVirus 9.73.3277 2010.12.17 -
Kaspersky 7.0.0.125 2010.12.17 -
McAfee 5.400.0.1158 2010.12.17 -
McAfee-GW-Edition 2010.1C 2010.12.17 -
Microsoft 1.6402 2010.12.17 -
NOD32 5712 2010.12.17 -
Norman 6.06.12 2010.12.17 -
nProtect 2010-12-17.01 2010.12.17 -
Panda 10.0.2.7 2010.12.17 -
PCTools 7.0.3.5 2010.12.17 -
Prevx 3.0 2010.12.17 -
Rising 22.78.04.00 2010.12.17 -
Sophos 4.60.0 2010.12.17 -
SUPERAntiSpyware 4.40.0.1006 2010.12.17 -
Symantec 20101.3.0.103 2010.12.17 -
TheHacker 6.7.0.1.101 2010.12.15 -
TrendMicro 9.120.0.1004 2010.12.17 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.17 -
VBA32 3.12.14.2 2010.12.17 -
VIPRE 7695 2010.12.17 -
ViRobot 2010.12.17.4206 2010.12.17 -
VirusBuster 13.6.100.0 2010.12.17 -
Additional information
Show all
MD5 : 8fee9a2354b3646a94daedb08b731dda
SHA1 : 08b19b463f2158e9eac698a4d384dbef73f493c1
SHA256: 67cd14659393f976e920c7bda6ed66b4198997d6756c1ce199d90aae870d8508
La même chose pour les deux.
Le rapport de virustotal :
AhnLab-V3 2010.12.17.05 2010.12.17 -
AntiVir 7.11.0.83 2010.12.17 -
Antiy-AVL 2.0.3.7 2010.12.17 -
Avast 4.8.1351.0 2010.12.17 -
Avast5 5.0.677.0 2010.12.17 -
AVG 9.0.0.851 2010.12.17 -
BitDefender 7.2 2010.12.17 -
CAT-QuickHeal 11.00 2010.12.17 -
ClamAV 0.96.4.0 2010.12.17 -
Command 5.2.11.5 2010.12.17 -
Comodo 7099 2010.12.17 -
DrWeb 5.0.2.03300 2010.12.17 -
Emsisoft 5.1.0.1 2010.12.17 -
eSafe 7.0.17.0 2010.12.16 -
eTrust-Vet 36.1.8048 2010.12.17 -
F-Prot 4.6.2.117 2010.12.16 -
F-Secure 9.0.16160.0 2010.12.17 -
Fortinet 4.2.254.0 2010.12.17 -
GData 21 2010.12.17 -
Ikarus T3.1.1.90.0 2010.12.17 -
Jiangmin 13.0.900 2010.12.17 -
K7AntiVirus 9.73.3277 2010.12.17 -
Kaspersky 7.0.0.125 2010.12.17 -
McAfee 5.400.0.1158 2010.12.17 -
McAfee-GW-Edition 2010.1C 2010.12.17 -
Microsoft 1.6402 2010.12.17 -
NOD32 5712 2010.12.17 -
Norman 6.06.12 2010.12.17 -
nProtect 2010-12-17.01 2010.12.17 -
Panda 10.0.2.7 2010.12.17 -
PCTools 7.0.3.5 2010.12.17 -
Prevx 3.0 2010.12.17 -
Rising 22.78.04.00 2010.12.17 -
Sophos 4.60.0 2010.12.17 -
SUPERAntiSpyware 4.40.0.1006 2010.12.17 -
Symantec 20101.3.0.103 2010.12.17 -
TheHacker 6.7.0.1.101 2010.12.15 -
TrendMicro 9.120.0.1004 2010.12.17 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.17 -
VBA32 3.12.14.2 2010.12.17 -
VIPRE 7695 2010.12.17 -
ViRobot 2010.12.17.4206 2010.12.17 -
VirusBuster 13.6.100.0 2010.12.17 -
Additional information
Show all
MD5 : 8fee9a2354b3646a94daedb08b731dda
SHA1 : 08b19b463f2158e9eac698a4d384dbef73f493c1
SHA256: 67cd14659393f976e920c7bda6ed66b4198997d6756c1ce199d90aae870d8508
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 23:37
17 déc. 2010 à 23:37
tu peux me faire un imprim ecran pour voir
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 23:39
17 déc. 2010 à 23:39
Comment je peux faire pour te montrer l'arborescence ?
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 23:43
17 déc. 2010 à 23:43
C'est bon j'ai trouvé mais pour joindre le fichier ?
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 23:43
17 déc. 2010 à 23:43
ouvre ce dossier
utilise la touche imprim ecran (en haut à droit)
ouvre paint
coller
enregistre
puis ci joint
utilise la touche imprim ecran (en haut à droit)
ouvre paint
coller
enregistre
puis ci joint
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
Modifié par San.lei le 17/12/2010 à 23:51
Modifié par San.lei le 17/12/2010 à 23:51
Désolée, j'aurais du y penser......
http://www.cijoint.fr/cjlink.php?file=cj201012/cijhjT43Bn.jpg
http://www.cijoint.fr/cjlink.php?file=cj201012/cij6WAFtkL.jpg
http://www.cijoint.fr/cjlink.php?file=cj201012/cijhjT43Bn.jpg
http://www.cijoint.fr/cjlink.php?file=cj201012/cij6WAFtkL.jpg
moment de grace
Messages postés
29042
Date d'inscription
samedi 6 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
18 juillet 2013
2 274
17 déc. 2010 à 23:57
17 déc. 2010 à 23:57
il y a rien dans ce dossier nommé 0.0.0.0 ?
San.lei
Messages postés
99
Date d'inscription
mercredi 15 décembre 2010
Statut
Membre
Dernière intervention
8 septembre 2024
1
17 déc. 2010 à 23:59
17 déc. 2010 à 23:59
Rien du tout.
C'est d'ailleurs la première fois que je vois ces dossiers.
C'est d'ailleurs la première fois que je vois ces dossiers.