Autorun.inf

Fermé
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 - 13 mars 2011 à 17:08
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 - 13 mars 2011 à 23:08
Bonjour,
autorun.inf c'est un virus ou pas ?? j'ais trop de fichier comme ca dans mon pc ??
c'est ses un virus comment le supprimer ??

aider moi svp merci !



29 réponses

AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 21:12
0
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
13 mars 2011 à 21:12
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 21:39
0
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
13 mars 2011 à 21:43
Bien.
Refais OTL comme tu as déjà fait, avec les options demandées.
On va finaliser ;)
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 21:45
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
13 mars 2011 à 21:48
c est ad-remover ça. J'ai demandé un nouveau OTL.

ça:

▶ Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

▶ Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
(Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

▶ Lance OTL
▶ Sous Peronnalisation, copie-colle ce qu'il y a dans le cadre ci-dessous :
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%temp%\.exe /s
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
/md5start
explorer.exe
winlogon.exe
wininit.exe
/md5stop
CREATERESTOREPOINT
nslookup www.google.fr /c 

▶ Clique sur le bouton Analyse.
▶ Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer les rapports.
Donnes le liens pjjoint ici ensuite pour pouvoir être consultés.
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 21:49
oki je le refait
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 22:01
\/\/\/\/\/\/\/\/\/\/voila \/\/\/\/\/\/\/\/\/\/\/
OTL logfile created on: 13/03/2011 21:49:32 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\am1.cr\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

959,00 Mb Total Physical Memory | 198,00 Mb Available Physical Memory | 21,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 57,00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0f:\pagefile.sys 1000 1001 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 15,04 Gb Total Space | 0,75 Gb Free Space | 5,01% Space Free | Partition Type: NTFS
Drive D: | 10,16 Gb Total Space | 0,39 Gb Free Space | 3,89% Space Free | Partition Type: NTFS
Drive E: | 7,19 Gb Total Space | 2,54 Gb Free Space | 35,33% Space Free | Partition Type: NTFS
Drive F: | 8,13 Gb Total Space | 3,00 Gb Free Space | 36,95% Space Free | Partition Type: NTFS
Drive G: | 12,05 Gb Total Space | 10,48 Gb Free Space | 86,96% Space Free | Partition Type: NTFS
Drive H: | 21,96 Gb Total Space | 6,07 Gb Free Space | 27,66% Space Free | Partition Type: NTFS
Drive J: | 4,24 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive L: | 3,73 Gb Total Space | 0,19 Gb Free Space | 5,11% Space Free | Partition Type: FAT32

Computer Name: AM1CR-PC | User Name: am1.cr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========/color

PRC - [2011/03/13 20:42:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
PRC - [2011/02/23 16:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/01/07 23:48:12 | 000,108,080 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
PRC - [2010/10/03 12:02:08 | 000,176,128 | ---- | M] (FaceMoi) -- C:\Facemoi\facemoi.exe
PRC - [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/04/14 07:43:42 | 000,604,704 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE


[color=#E56717]========== Modules (SafeList) ==========/color

MOD - [2011/03/13 20:42:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
MOD - [2011/02/23 16:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


[color=#E56717]========== Win32 Services (SafeList) ==========/color

SRV - [2011/02/23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/02/23 16:04:17 | 000,121,000 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2011/01/07 23:48:18 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
SRV - [2011/01/07 23:46:06 | 000,271,408 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2011/01/05 19:30:36 | 000,352,304 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010/12/20 21:25:49 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/10/15 19:42:14 | 000,326,704 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


[color=#E56717]========== Driver Services (SafeList) ==========/color

DRV - [2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\aswNdis.sys -- (aswNdis)
DRV - [2010/09/22 20:19:02 | 000,037,376 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HssDrv.sys -- (HssDrv)
DRV - [2010/09/22 20:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2009/07/14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 23:02:53 | 000,044,032 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fetnd6.sys -- (FETNDIS)
DRV - [2009/07/13 23:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2009/06/18 19:45:02 | 004,172,832 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVAC.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)


[color=#E56717]========== Standard Registry (SafeList) ==========/color


[color=#E56717]========== Internet Explorer ==========/color

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = https://www.msn.com/fr-fr?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E4 93 40 95 86 9F CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========/color

FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbar.com/...{searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://mp3tubetoolbar.com/..."
FF - prefs.js..keyword.URL: "http://mp3tubetoolbar.com/?prt=undefined02ff&clid=&subid=&Keywords="


FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/13 16:36:43 | 000,000,000 | ---D | M]

[2011/01/07 11:43:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Extensions
[2011/02/05 14:18:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions
[2011/02/05 14:15:37 | 000,000,000 | ---D | M] (Billeo) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}
[2011/02/05 14:13:29 | 000,000,000 | ---D | M] (Temp Installer) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions\{77868449-f49d-d6ec-3145-e651161b1ff8}
[2011/02/05 14:18:05 | 000,000,000 | ---D | M] (KwiClick) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions\vinceturk@gmail.com
File not found (No name found) --
[2011/03/13 16:36:43 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2010/12/13 13:01:43 | 000,000,000 | ---D | M] (ResultBar) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
[2010/12/12 22:52:45 | 000,000,000 | ---D | M] (Skype extension) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
[2010/12/13 13:16:38 | 000,000,000 | ---D | M] (MP3Tube Toolbar) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\MP3TUBETOOLBAR@MP3TUBETOOLBAR.COM
[2011/01/08 18:29:12 | 000,000,000 | ---D | M] (Feedback) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM

O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Facemoi] c:\Facemoi\facemoi.exe (FaceMoi)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [Facemoi] C:\Facemoi\facemoi.exe (FaceMoi)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - F:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - G:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - H:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:16 | 000,000,000 | RHSD | M] - L:\Autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========/color

[2011/03/13 21:15:56 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Remover
[2011/03/13 20:41:27 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
[2011/03/13 20:09:14 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
[2011/03/13 19:05:47 | 000,000,000 | ---D | C] -- C:\UsbFix
[2011/03/13 18:45:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
[2011/03/13 16:38:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2011/03/13 16:38:20 | 000,301,528 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011/03/13 16:38:20 | 000,019,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011/03/13 16:37:58 | 000,101,976 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2011/03/13 16:37:28 | 000,192,728 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2011/03/13 16:37:28 | 000,025,432 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011/03/13 16:37:27 | 000,371,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/03/13 16:37:27 | 000,049,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011/03/13 16:37:25 | 000,053,592 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011/03/13 16:36:39 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2011/03/13 16:36:37 | 000,040,648 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/03/13 16:36:36 | 000,190,016 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/03/13 16:34:04 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\avast!+Internet+Security+6.0.1000+-+Final
[2011/03/13 11:18:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{EAB8046D-5662-40EB-80EF-4B903FE407E8}
[2011/03/12 21:03:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\a la foire
[2011/03/12 20:34:33 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\Peugeot 308 RCZ
[2011/03/12 11:24:50 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3827BE5-AE6F-425F-8B92-07E2C04760D4}
[2011/03/11 22:30:11 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6100EFA6-F4B9-4CB0-B2A3-503711673EC7}
[2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\WinRAR
[2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/03/11 15:41:57 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/03/11 14:17:59 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\WMTools Downloaded Files
[2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\Program Files\Magical Jelly Bean
[2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
[2011/03/11 13:18:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW
[2011/03/11 12:59:06 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker 2.6
[2011/03/11 12:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/03/11 11:51:02 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
[2011/03/11 10:00:05 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{CC828378-C1ED-447D-8AFD-65439449997A}
[2011/03/10 13:46:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E2881344-786A-4EA4-BF58-E371FC8D2B61}
[2011/03/09 08:44:15 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2011/03/09 08:44:15 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/03/09 08:44:14 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011/03/09 08:44:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011/03/09 08:32:58 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{0052845C-12F4-41E9-81BC-E36B5AFFAE23}
[2011/03/06 11:21:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6316F92C-F87F-4158-B751-4969D31340D7}
[2011/03/05 18:01:29 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\fbml
[2011/03/05 10:57:13 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{FFA278B1-0BB9-45E7-A2C6-DA54B636464C}
[2011/03/04 21:25:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BBFC780D-A032-4868-BB32-70DCC4E8576D}
[2011/03/04 08:45:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{C5363477-5639-49A4-B967-D6B008F9AE06}
[2011/03/03 23:36:39 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\am1
[2011/03/03 20:02:22 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{AAF85E9B-5C84-4F32-87CC-C8DAC0F6169C}
[2011/02/25 18:09:45 | 000,028,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mdimon.dll
[2011/02/25 18:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/02/25 18:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011/02/25 18:07:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011/02/25 13:52:55 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{680F6100-4C84-4636-9300-1FCBB26909BD}
[2011/02/18 21:12:07 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Real
[2011/02/18 17:30:15 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV
[2011/02/18 15:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2011/02/18 15:24:41 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/02/18 13:24:09 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Skype
[2011/02/18 13:07:51 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E4A4C0F8-B08F-46C6-8C4A-8C537B92508B}
[2011/02/17 21:43:12 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BF71FD3B-9499-4A1B-B937-B83B8D34E6F7}
[2011/02/17 19:44:15 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E730C43B-B4B1-4126-8D93-921F1748FD87}
[2011/02/15 01:10:43 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{D1C98C22-A525-439E-AD2A-75D43FE3FD2E}
[2011/02/14 13:02:00 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{A814B55B-3810-448F-BF3D-57F658C3982B}
[2011/02/12 21:13:36 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{1FF3C6B9-90ED-4CCB-ABEE-37A678203AE5}
[2011/02/12 00:32:21 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\jeux
[2011/02/11 23:29:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
[2011/02/11 23:20:24 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3197D5E-D469-4B0C-8882-C21732FC5A04}
[2011/02/11 23:13:34 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
[2011/02/11 22:53:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Documents\EA Games
[2011/02/11 22:44:05 | 000,442,368 | R--- | C] (On2.com) -- C:\Windows\System32\vp6vfw.dll
[2011/02/11 22:41:18 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2011/02/11 22:40:27 | 000,000,000 | ---D | C] -- C:\ATI
[2011/02/11 22:38:48 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{5A91C618-A81D-414F-A1B9-99AE9B9D2254}
[2011/02/11 22:02:40 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{4447881A-8E37-4C15-AE01-BB0A1EC048C8}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========/color

[2011/03/13 21:36:45 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/13 21:33:03 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/13 21:27:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/13 21:27:16 | 753,836,032 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/13 21:26:04 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/13 21:26:04 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/13 21:15:57 | 000,001,801 | ---- | M] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
[2011/03/13 21:03:03 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001UA.job
[2011/03/13 20:42:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
[2011/03/13 20:32:42 | 000,000,000 | ---- | M] () -- C:\Windows\System32\cd.dat
[2011/03/13 20:11:04 | 335,085,774 | ---- | M] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
[2011/03/13 19:18:26 | 000,000,758 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/03/13 18:45:54 | 000,000,690 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2011/03/13 18:45:54 | 000,000,685 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2011/03/13 18:45:54 | 000,000,682 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2011/03/13 17:18:00 | 000,002,406 | ---- | M] () -- C:\Users\am1.cr\Desktop\Google Chrome.lnk
[2011/03/13 17:03:01 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001Core.job
[2011/03/13 16:38:21 | 000,001,998 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2011/03/13 16:37:25 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011/03/13 11:15:24 | 000,357,480 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/12 22:36:40 | 000,003,270 | ---- | M] () -- C:\Users\am1.cr\Desktop\flashcode.gif
[2011/03/12 14:00:32 | 000,694,766 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011/03/12 14:00:32 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/03/12 14:00:32 | 000,127,478 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011/03/12 14:00:32 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/03/11 16:14:52 | 000,000,760 | ---- | M] () -- C:\Users\am1.cr\~anis logi 1.DDF
[2011/03/11 13:57:31 | 000,064,492 | ---- | M] () -- C:\Users\am1.cr\Desktop\am1.jpg
[2011/03/11 13:44:59 | 000,198,890 | ---- | M] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
[2011/03/11 13:42:46 | 000,005,120 | ---- | M] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/11 12:54:41 | 000,002,246 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/02/25 18:09:49 | 000,000,382 | ---- | M] () -- C:\Windows\ODBC.INI
[2011/02/25 14:50:12 | 000,001,248 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2011/02/23 16:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/02/23 16:04:17 | 000,190,016 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2011/02/18 15:25:30 | 000,001,068 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========/color

[2011/03/13 21:15:57 | 000,001,801 | ---- | C] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
[2011/03/13 20:32:42 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
[2011/03/13 20:10:05 | 335,085,774 | ---- | C] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
[2011/03/13 19:18:26 | 000,000,758 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/03/13 18:45:54 | 000,000,690 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2011/03/13 18:45:54 | 000,000,685 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2011/03/13 18:45:54 | 000,000,682 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2011/03/13 16:38:21 | 000,001,998 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2011/03/12 22:36:42 | 000,003,270 | ---- | C] () -- C:\Users\am1.cr\Desktop\flashcode.gif
[2011/03/11 16:14:22 | 000,000,760 | ---- | C] () -- C:\Users\am1.cr\~anis logi 1.DDF
[2011/03/11 16:04:19 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\age of empie 2.bat
[2011/03/11 15:47:17 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\am1.bat
[2011/03/11 13:57:29 | 000,064,492 | ---- | C] () -- C:\Users\am1.cr\Desktop\am1.jpg
[2011/03/11 13:45:07 | 000,198,890 | ---- | C] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
[2011/03/11 12:59:06 | 000,002,495 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
[2011/03/11 12:54:41 | 000,002,246 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/03/11 12:28:25 | 000,001,054 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/11 12:28:23 | 000,001,050 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/09 20:18:20 | 000,005,120 | ---- | C] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/06 13:14:41 | 000,070,746 | ---- | C] () -- C:\Users\am1.cr\Desktop\Img00025.jpg
[2011/02/25 18:09:49 | 000,000,382 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/02/18 15:25:30 | 000,001,068 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2011/01/22 17:03:58 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2010/12/20 15:13:23 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll
[2009/07/14 09:39:49 | 000,694,766 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2009/07/14 09:39:49 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2009/07/14 09:39:49 | 000,127,478 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2009/07/14 09:39:49 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 000,357,480 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,606,992 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,103,370 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/14 07:43:32 | 000,154,144 | ---- | C] () -- C:\Windows\System32\RTLCPAPI.dll
[2003/04/01 10:58:02 | 000,005,260 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI

< End of report >
0
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
13 mars 2011 à 22:13
ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."

sur OTL.exe pour le lancer.


▶ Copie/colle les lignes suivantes en gras et place les dans la zone "personnalisation" :


:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe

:Services
AnchorFree

:OTL
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbar.com/{searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://mp3tubetoolbar.com/"
FF - prefs.js..keyword.URL: "http://mp3tubetoolbar.com/?prt=undefined02ff&clid=&subid=&Keywords="

:Files
D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Windows\System32\drivers\HssDrv.sys

:commands
[emptytemp]
[start explorer]
[reboot]



▶ Clique sur « Correction » et laisse l'outil travailler. L'ordinateur redémarre.

▶ Copie/colle la totalité du rapport dans ta prochaine réponse.

Après redémarrage :

▶ Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton bureau.

▶ ▶ Miroir 1 si inaccessible
▶ ▶ Miroir 2 si inaccessible

▶ ▶ /!\ Utilisateur de Vista et Windows 7 : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu'Administrateur »

▶ Double clique sur le fichier téléchargé pour lancer le processus d'installation.
▶ Dans l'onglet "mise à jour", clique sur le bouton Recherche de mise à jour
▶ si le pare-feu demande l'autorisation de se connecter pour Malwarebytes, accepte
Une fois la mise à jour terminée
▶ rends-toi dans l'onglet Recherche
▶ Sélectionne Exécuter un examen complet
▶ Clique sur Rechercher
▶ ▶ Le scan démarre.
▶ A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
▶ Clique sur Ok pour poursuivre.
▶ Si des malwares ont été détectés, cliques sur Afficher les résultats
▶ Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection . Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
▶ Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse. Copie/colle le ici (ctrl+a pour tout sélectionner, ctrl+c pour copier, ctrl+v pour coller)

▶ ▶ Il se peut que MBAM ait besoin de redémarrer le pc pour finaliser la suppression, donc pas de panique, redémarre ton pc !!!
▶ Une fois le PC redémarré, rends toi dans l'onglet rapport/log
▶ Tu clique dessus pour l'afficher, une fois affiché
▶ Copie/colle le ici (ctrl+a pour tout sélectionner, ctrl+c pour copier, ctrl+v pour coller)

Si tu as besoin d'aide regarde ce tutoriel :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

Je reviens demain soir. @+ bonne nuit.
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 22:21
bon nuit je vais faire tout ca
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 23:02
voila
OTL logfile created on: 13/03/2011 22:50:42 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\am1.cr\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

959,00 Mb Total Physical Memory | 213,00 Mb Available Physical Memory | 22,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 54,00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0f:\pagefile.sys 1000 1001 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 15,04 Gb Total Space | 0,99 Gb Free Space | 6,55% Space Free | Partition Type: NTFS
Drive D: | 10,16 Gb Total Space | 0,39 Gb Free Space | 3,89% Space Free | Partition Type: NTFS
Drive E: | 7,19 Gb Total Space | 2,54 Gb Free Space | 35,33% Space Free | Partition Type: NTFS
Drive F: | 8,13 Gb Total Space | 3,00 Gb Free Space | 36,95% Space Free | Partition Type: NTFS
Drive G: | 12,05 Gb Total Space | 10,48 Gb Free Space | 86,96% Space Free | Partition Type: NTFS
Drive H: | 21,96 Gb Total Space | 6,07 Gb Free Space | 27,66% Space Free | Partition Type: NTFS
Drive J: | 4,24 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive L: | 3,73 Gb Total Space | 0,19 Gb Free Space | 5,11% Space Free | Partition Type: FAT32

Computer Name: AM1CR-PC | User Name: am1.cr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2011/02/23 16:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/01/07 23:48:12 | 000,108,080 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
PRC - [2010/10/03 12:02:08 | 000,176,128 | ---- | M] (FaceMoi) -- C:\Facemoi\facemoi.exe
PRC - [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/04/14 07:43:42 | 000,604,704 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2011/02/23 16:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009/07/14 02:15:20 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\fdProxy.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found [Auto | Running] -- -- (HssSrv)
SRV - [2011/02/23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/02/23 16:04:17 | 000,121,000 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2011/01/07 23:48:18 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
SRV - [2011/01/07 23:46:06 | 000,271,408 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2010/12/20 21:25:49 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/10/15 19:42:14 | 000,326,704 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Running] -- -- (HssDrv)
DRV - [2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\aswNdis.sys -- (aswNdis)
DRV - [2010/09/22 20:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2009/07/14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 23:02:53 | 000,044,032 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fetnd6.sys -- (FETNDIS)
DRV - [2009/07/13 23:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2009/06/18 19:45:02 | 004,172,832 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVAC.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = https://www.msn.com/fr-fr?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E4 93 40 95 86 9F CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbar.com/...{searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://mp3tubetoolbar.com/..."


FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/13 16:36:43 | 000,000,000 | ---D | M]

[2011/01/07 11:43:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Extensions
[2011/02/05 14:18:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions
[2011/02/05 14:15:37 | 000,000,000 | ---D | M] (Billeo) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}
[2011/02/05 14:13:29 | 000,000,000 | ---D | M] (Temp Installer) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions\{77868449-f49d-d6ec-3145-e651161b1ff8}
[2011/02/05 14:18:05 | 000,000,000 | ---D | M] (KwiClick) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions\vinceturk@gmail.com
File not found (No name found) --
[2011/03/13 16:36:43 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
[2010/12/12 22:52:45 | 000,000,000 | ---D | M] (Skype extension) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
[2010/12/13 13:16:38 | 000,000,000 | ---D | M] (MP3Tube Toolbar) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\MP3TUBETOOLBAR@MP3TUBETOOLBAR.COM
[2011/01/08 18:29:12 | 000,000,000 | ---D | M] (Feedback) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM

O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Facemoi] c:\Facemoi\facemoi.exe (FaceMoi)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [Facemoi] C:\Facemoi\facemoi.exe (FaceMoi)
O4 - HKLM..\RunOnce: [OTL] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - F:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - G:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - H:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/03/13 20:09:16 | 000,000,000 | RHSD | M] - L:\Autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2011/03/13 22:23:33 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/03/13 21:15:56 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Remover
[2011/03/13 20:09:14 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
[2011/03/13 19:05:47 | 000,000,000 | ---D | C] -- C:\UsbFix
[2011/03/13 18:45:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
[2011/03/13 16:38:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2011/03/13 16:38:20 | 000,301,528 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011/03/13 16:38:20 | 000,019,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011/03/13 16:37:58 | 000,101,976 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2011/03/13 16:37:28 | 000,192,728 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2011/03/13 16:37:28 | 000,025,432 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011/03/13 16:37:27 | 000,371,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/03/13 16:37:27 | 000,049,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011/03/13 16:37:25 | 000,053,592 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011/03/13 16:36:39 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2011/03/13 16:36:37 | 000,040,648 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/03/13 16:36:36 | 000,190,016 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/03/13 16:34:04 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\avast!+Internet+Security+6.0.1000+-+Final
[2011/03/13 11:18:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{EAB8046D-5662-40EB-80EF-4B903FE407E8}
[2011/03/12 21:03:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\a la foire
[2011/03/12 20:34:33 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\Peugeot 308 RCZ
[2011/03/12 11:24:50 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3827BE5-AE6F-425F-8B92-07E2C04760D4}
[2011/03/11 22:30:11 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6100EFA6-F4B9-4CB0-B2A3-503711673EC7}
[2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\WinRAR
[2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/03/11 15:41:57 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/03/11 14:17:59 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\WMTools Downloaded Files
[2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\Program Files\Magical Jelly Bean
[2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
[2011/03/11 13:18:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW
[2011/03/11 12:59:06 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker 2.6
[2011/03/11 12:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/03/11 11:51:02 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
[2011/03/11 10:00:05 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{CC828378-C1ED-447D-8AFD-65439449997A}
[2011/03/10 13:46:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E2881344-786A-4EA4-BF58-E371FC8D2B61}
[2011/03/09 08:44:15 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2011/03/09 08:44:15 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/03/09 08:44:14 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011/03/09 08:44:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011/03/09 08:32:58 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{0052845C-12F4-41E9-81BC-E36B5AFFAE23}
[2011/03/06 11:21:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6316F92C-F87F-4158-B751-4969D31340D7}
[2011/03/05 18:01:29 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\fbml
[2011/03/05 10:57:13 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{FFA278B1-0BB9-45E7-A2C6-DA54B636464C}
[2011/03/04 21:25:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BBFC780D-A032-4868-BB32-70DCC4E8576D}
[2011/03/04 08:45:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{C5363477-5639-49A4-B967-D6B008F9AE06}
[2011/03/03 23:36:39 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\am1
[2011/03/03 20:02:22 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{AAF85E9B-5C84-4F32-87CC-C8DAC0F6169C}
[2011/02/25 18:09:45 | 000,028,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mdimon.dll
[2011/02/25 18:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/02/25 18:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011/02/25 18:07:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011/02/25 13:52:55 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{680F6100-4C84-4636-9300-1FCBB26909BD}
[2011/02/18 21:12:07 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Real
[2011/02/18 17:30:15 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV
[2011/02/18 15:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2011/02/18 15:24:41 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/02/18 13:24:09 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Skype
[2011/02/18 13:07:51 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E4A4C0F8-B08F-46C6-8C4A-8C537B92508B}
[2011/02/17 21:43:12 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BF71FD3B-9499-4A1B-B937-B83B8D34E6F7}
[2011/02/17 19:44:15 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E730C43B-B4B1-4126-8D93-921F1748FD87}
[2011/02/15 01:10:43 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{D1C98C22-A525-439E-AD2A-75D43FE3FD2E}
[2011/02/14 13:02:00 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{A814B55B-3810-448F-BF3D-57F658C3982B}
[2011/02/12 21:13:36 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{1FF3C6B9-90ED-4CCB-ABEE-37A678203AE5}
[2011/02/12 00:32:21 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\jeux
[2011/02/11 23:29:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
[2011/02/11 23:20:24 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3197D5E-D469-4B0C-8882-C21732FC5A04}
[2011/02/11 23:13:34 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2011/03/13 22:33:03 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/13 22:29:50 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/13 22:29:50 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/13 22:03:02 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001UA.job
[2011/03/13 21:36:45 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/13 21:27:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/13 21:27:16 | 753,836,032 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/13 21:15:57 | 000,001,801 | ---- | M] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
[2011/03/13 20:32:42 | 000,000,000 | ---- | M] () -- C:\Windows\System32\cd.dat
[2011/03/13 20:11:04 | 335,085,774 | ---- | M] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
[2011/03/13 19:18:26 | 000,000,758 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/03/13 18:45:54 | 000,000,690 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2011/03/13 18:45:54 | 000,000,685 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2011/03/13 18:45:54 | 000,000,682 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2011/03/13 17:18:00 | 000,002,406 | ---- | M] () -- C:\Users\am1.cr\Desktop\Google Chrome.lnk
[2011/03/13 17:03:01 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001Core.job
[2011/03/13 16:38:21 | 000,001,998 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2011/03/13 16:37:25 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011/03/13 11:15:24 | 000,357,480 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/12 22:36:40 | 000,003,270 | ---- | M] () -- C:\Users\am1.cr\Desktop\flashcode.gif
[2011/03/12 14:00:32 | 000,694,766 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011/03/12 14:00:32 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/03/12 14:00:32 | 000,127,478 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011/03/12 14:00:32 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/03/11 16:14:52 | 000,000,760 | ---- | M] () -- C:\Users\am1.cr\~anis logi 1.DDF
[2011/03/11 13:57:31 | 000,064,492 | ---- | M] () -- C:\Users\am1.cr\Desktop\am1.jpg
[2011/03/11 13:44:59 | 000,198,890 | ---- | M] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
[2011/03/11 13:42:46 | 000,005,120 | ---- | M] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/11 12:54:41 | 000,002,246 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/02/25 18:09:49 | 000,000,382 | ---- | M] () -- C:\Windows\ODBC.INI
[2011/02/25 14:50:12 | 000,001,248 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2011/02/23 16:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/02/23 16:04:17 | 000,190,016 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2011/02/18 15:25:30 | 000,001,068 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2011/03/13 21:15:57 | 000,001,801 | ---- | C] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
[2011/03/13 20:32:42 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
[2011/03/13 20:10:05 | 335,085,774 | ---- | C] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
[2011/03/13 19:18:26 | 000,000,758 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/03/13 18:45:54 | 000,000,690 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2011/03/13 18:45:54 | 000,000,685 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2011/03/13 18:45:54 | 000,000,682 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2011/03/13 16:38:21 | 000,001,998 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2011/03/12 22:36:42 | 000,003,270 | ---- | C] () -- C:\Users\am1.cr\Desktop\flashcode.gif
[2011/03/11 16:14:22 | 000,000,760 | ---- | C] () -- C:\Users\am1.cr\~anis logi 1.DDF
[2011/03/11 16:04:19 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\age of empie 2.bat
[2011/03/11 15:47:17 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\am1.bat
[2011/03/11 13:57:29 | 000,064,492 | ---- | C] () -- C:\Users\am1.cr\Desktop\am1.jpg
[2011/03/11 13:45:07 | 000,198,890 | ---- | C] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
[2011/03/11 12:54:41 | 000,002,246 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/03/11 12:28:25 | 000,001,054 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/11 12:28:23 | 000,001,050 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/09 20:18:20 | 000,005,120 | ---- | C] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/06 13:14:41 | 000,070,746 | ---- | C] () -- C:\Users\am1.cr\Desktop\Img00025.jpg
[2011/02/25 18:09:49 | 000,000,382 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/02/18 15:25:30 | 000,001,068 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2011/01/22 17:03:58 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2010/12/20 15:13:23 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll
[2009/07/14 09:39:49 | 000,694,766 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2009/07/14 09:39:49 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2009/07/14 09:39:49 | 000,127,478 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2009/07/14 09:39:49 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 000,357,480 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,606,992 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,103,370 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/14 07:43:32 | 000,154,144 | ---- | C] () -- C:\Windows\System32\RTLCPAPI.dll
[2003/04/01 10:58:02 | 000,005,260 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI

< End of report >
0
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
13 mars 2011 à 23:04
ça c est run2
c est le rapport de la correction qu il me fallait :-)
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 23:08
ils arrive
0
L'Extraterrestre Messages postés 11 Date d'inscription lundi 14 février 2011 Statut Membre Dernière intervention 13 mars 2011
13 mars 2011 à 17:11
Bonjour,

Non se n'es pas un viruse autorun,c'est un programme qui fait partie de windons bien à vous.
-2
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
13 mars 2011 à 17:15
0
AM1 G Messages postés 156 Date d'inscription dimanche 13 mars 2011 Statut Membre Dernière intervention 23 janvier 2012 9
13 mars 2011 à 17:21
je le trouve dans tous mes fichier tous !
0