Virus Win32 - Page 3

Résolu
Précédent
  • 1
  • 2
  • 3
  1. Tigzy Messages postés 7983 Statut Contributeur sécurité 582
     
    * Télécharge >> OTL << sur ton bureau.

    * Fait un double-clic sur l'icône d'OTL pour le lancer
    /!\ pour Vista/Seven fais un clic-droit sur l'icône d'OTL et choisis "Exécuter en tant qu'administrateur"

    * Assure toi d'avoir fermé toutes les applications en cours de fonctionnement.

    * Quand la fenêtre d'OTL apparaît, assure toi que dans la section "Rapport" (en haut à droite) la case "rapport minimal" soit cochée.

    * Copie et colle le contenu de cette citation dans la partie inférieure d'OTL "Personnalisation"


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles



    * Cliques sur l'icône "Analyse" (en haut à gauche) .
    * Laisse le scan aller à son terme sans te servir du PC
    * A la fin du scan un ou deux rapports vont s'ouvrir "OTL.Txt" et ( ou ) "Extras.Txt"( dans certains cas).
    * Copie et colle le ou les rapports dans ta réponse stp...
    * Au cas où, tu peux les retrouver dans le dossier C:\OTL ou sur ton bureau en fonction des cas rencontrés

    0
  2. Emilie180
     
    Bonjour,

    Voici le rapport selon OTL :

    OTL logfile created on: 12/05/2011 23:11:55 - Run 2
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\CLEMENT Emilie\Bureau
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

    502,00 Mb Total Physical Memory | 341,00 Mb Available Physical Memory | 68,00% Memory free
    1,00 Gb Paging File | 1,00 Gb Available in Paging File | 69,00% Paging File free
    Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 33,23 Gb Total Space | 5,25 Gb Free Space | 15,79% Space Free | Partition Type: NTFS

    Computer Name: IBM-68B08E7547B | User Name: CLEMENT Emilie | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    [color=#E56717]========== Processes (SafeList) ==========/color

    PRC - C:\Documents and Settings\CLEMENT Emilie\Bureau\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
    PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    PRC - C:\Program Files\Fichiers communs\Goto Software\Vaderetro_mgr.exe (Goto Software)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
    PRC - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe (Sony Corporation.)
    PRC - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe (Sony Corporation)

    [color=#E56717]========== Modules (SafeList) ==========/color

    MOD - C:\Documents and Settings\CLEMENT Emilie\Bureau\OTL.exe (OldTimer Tools)
    MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)

    [color=#E56717]========== Win32 Services (SafeList) ==========/color

    SRV - (PsaSrv) -- File not found
    SRV - (HidServ) -- File not found
    SRV - (AVG Security Toolbar Service) -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
    SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
    SRV - (avgwd) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    SRV - (ose) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
    SRV - (Apple Mobile Device) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    SRV - (odserv) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
    SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
    SRV - (IBM Rapid Restore Ultra Service) -- C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe ()
    SRV - (S24EventMonitor) -- C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
    SRV - (RegSrvc) -- C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)

    [color=#E56717]========== Driver Services (SafeList) ==========/color

    DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
    DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AVGIDSEH) -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
    DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
    DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
    DRV - (Avgrkx86) -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
    DRV - (psadd) -- C:\WINDOWS\system32\drivers\psadd.sys (IBM Corporation)
    DRV - (PAC207) -- C:\WINDOWS\system32\drivers\PFC027.SYS (PixArt Imaging Inc.)
    DRV - (PCASp50) -- C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
    DRV - (ibmfilter) -- C:\WINDOWS\system32\drivers\ibmfilter.sys (IBM)
    DRV - (w22n51) Pilote Intel(R) -- C:\WINDOWS\system32\drivers\w22n51.sys (Intel® Corporation)
    DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
    DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
    DRV - (TPPWR) -- C:\WINDOWS\system32\drivers\TPPWR.SYS (IBM Corp.)
    DRV - (HSFHWICH) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
    DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
    DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
    DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
    DRV - (cdrbsvsd) -- C:\WINDOWS\System32\drivers\cdrbsvsd.sys (B.H.A Corporation)

    [color=#E56717]========== Standard Registry (SafeList) ==========/color

    [color=#E56717]========== Internet Explorer ==========/color

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.fr/ [binary data]
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/05/05 22:35:31 | 000,000,000 | ---D | M]

    O1 HOSTS File: ([2004/08/05 14:00:00 | 000,000,790 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2 - BHO: (ST) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (Microsoft Corporation)
    O2 - BHO: (Babylon Plug In) - {A057A204-BACC-4D26-9E83-2DB586E27190} - C:\Program Files\BabylonXtra\BabylonXtra.dll (Babylon )
    O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
    O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
    O2 - BHO: (MSNToolBandBHO) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll (Microsoft Corporation)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
    O3 - HKLM\..\Toolbar: (Babylon Plug In) - {A057A204-BACC-4D26-9E83-2DB586E27190} - C:\Program Files\BabylonXtra\BabylonXtra.dll (Babylon )
    O3 - HKLM\..\Toolbar: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Babylon Plug In) - {A057A204-BACC-4D26-9E83-2DB586E27190} - C:\Program Files\BabylonXtra\BabylonXtra.dll (Babylon )
    O3 - HKCU\..\Toolbar\WebBrowser: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [Monitor] C:\WINDOWS\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
    O4 - HKLM..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe ()
    O4 - HKLM..\Run: [VRManager] C:\Program Files\Fichiers communs\Goto Software\Vaderetro_mgr.exe (Goto Software)
    O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe (Sony Corporation)
    O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe (Sony Corporation.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
    O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/... (WUWebControl Class)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/... (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4.1/jinstall-141-win.cab (Java Plug-in 1.4.1)
    O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.1.42
    O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Fichiers communs\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
    O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
    O24 - Desktop WallPaper: C:\Documents and Settings\CLEMENT Emilie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\CLEMENT Emilie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/01/17 19:46:13 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O33 - MountPoints2\{2f3c48d8-dd75-11dd-956c-0020e0805a96}\Shell\AutoRun\command - "" = D:\2u.com
    O33 - MountPoints2\{2f3c48d8-dd75-11dd-956c-0020e0805a96}\Shell\explore\Command - "" = D:\2u.com
    O33 - MountPoints2\{2f3c48d8-dd75-11dd-956c-0020e0805a96}\Shell\open\Command - "" = D:\2u.com
    O33 - MountPoints2\{318f9fa4-c21c-11de-9693-0020e0805a96}\Shell\AutoRun\command - "" = D:\SOL/fla.exe
    O33 - MountPoints2\{318f9fa4-c21c-11de-9693-0020e0805a96}\Shell\explore\command - "" = D:\SOL/fla.exe
    O33 - MountPoints2\{318f9fa4-c21c-11de-9693-0020e0805a96}\Shell\open\command - "" = D:\SOL/fla.exe
    O33 - MountPoints2\{33122056-ffe8-11dc-94a3-0020e0805a96}\Shell - "" = AutoRun
    O33 - MountPoints2\{33122056-ffe8-11dc-94a3-0020e0805a96}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
    O33 - MountPoints2\{57891d40-1266-11de-95aa-0020e0805a96}\Shell\AutoRun\command - "" = m9ma.exe
    O33 - MountPoints2\{57891d40-1266-11de-95aa-0020e0805a96}\Shell\explore\Command - "" = m9ma.exe
    O33 - MountPoints2\{57891d40-1266-11de-95aa-0020e0805a96}\Shell\open\Command - "" = m9ma.exe
    O33 - MountPoints2\{8399faf4-0437-11de-9590-0020e0805a96}\Shell\AutoRun\command - "" = iqe68o.bat
    O33 - MountPoints2\{8399faf4-0437-11de-9590-0020e0805a96}\Shell\explore\Command - "" = iqe68o.bat
    O33 - MountPoints2\{8399faf4-0437-11de-9590-0020e0805a96}\Shell\open\Command - "" = iqe68o.bat
    O33 - MountPoints2\{93b1a62e-06ad-11df-970b-0012f02a036f}\Shell\AutoRun\command - "" = D:\SLATKO/torta.exe
    O33 - MountPoints2\{93b1a62e-06ad-11df-970b-0012f02a036f}\Shell\explore\command - "" = D:\SLATKO/torta.exe
    O33 - MountPoints2\{93b1a62e-06ad-11df-970b-0012f02a036f}\Shell\open\command - "" = D:\SLATKO/torta.exe
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: HidServ - File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    [color=#E56717]========== Files/Folders - Created Within 30 Days ==========/color

    [2011/05/12 23:04:21 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\CLEMENT Emilie\Bureau\OTL.exe
    [2011/05/11 17:47:45 | 002,461,194 | ---- | C] (Nicolas Coolman ) -- C:\Documents and Settings\CLEMENT Emilie\Bureau\ZHPDiag2.exe
    [2011/05/10 11:59:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\CLEMENT Emilie\Bureau\tdsskiller
    [2011/05/06 23:20:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP
    [2011/05/06 22:40:58 | 000,000,000 | ---D | C] -- C:\Program Files\ZHPDiag
    [2011/05/06 19:58:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\eMule
    [2011/05/06 13:45:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\CLEMENT Emilie\Recent
    [2011/05/05 22:42:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\CLEMENT Emilie\Application Data\AVG10
    [2011/05/05 22:37:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
    [2011/05/05 22:36:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AVG 2011
    [2011/05/05 22:30:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
    [2011/05/05 22:30:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
    [2011/05/04 17:41:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
    [2011/05/01 14:21:34 | 001,407,280 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\CLEMENT Emilie\Bureau\TDSSKiller.exe
    [2011/04/28 19:10:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2011/04/22 21:31:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\CLEMENT Emilie\Bureau\RK_Quarantine (ne pas toucher!!)
    [2011/04/20 19:15:56 | 000,000,000 | ---D | C] -- C:\rsit
    [2011/04/20 00:45:42 | 000,000,000 | ---D | C] -- C:\Navilog1
    [2011/04/19 22:23:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\CLEMENT Emilie\Application Data\Malwarebytes
    [2011/04/19 22:22:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2011/04/19 21:51:54 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
    [2011/04/19 20:39:15 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2011/04/19 15:00:52 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
    [2011/04/16 15:35:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\CLEMENT Emilie\Application Data\RegistryKeys
    [6 C:\Documents and Settings\CLEMENT Emilie\Mes documents\*.tmp files -> C:\Documents and Settings\CLEMENT Emilie\Mes documents\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\Documents and Settings\CLEMENT Emilie\Bureau\*.tmp files -> C:\Documents and Settings\CLEMENT Emilie\Bureau\*.tmp -> ]

    [color=#E56717]========== Files - Modified Within 30 Days ==========/color

    [2036/02/07 11:58:16 | 000,090,112 | R--- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\VTS_01_0.IFO
    [2036/02/07 11:58:15 | 000,012,288 | R--- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\VIDEO_TS.IFO
    [2011/05/12 23:04:54 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\CLEMENT Emilie\Bureau\OTL.exe
    [2011/05/12 22:54:10 | 000,001,054 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2011/05/12 22:24:03 | 000,001,184 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-388442084-983558461-4008141643-1005UA.job
    [2011/05/12 22:15:57 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2011/05/12 22:14:11 | 000,001,050 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2011/05/12 22:14:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2011/05/12 22:14:02 | 526,897,152 | -HS- | M] () -- C:\hiberfil.sys
    [2011/05/12 19:24:12 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-388442084-983558461-4008141643-1005Core.job
    [2011/05/12 19:18:07 | 000,142,166 | ---- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\renouvellement assu santé.pdf
    [2011/05/11 22:31:02 | 000,047,616 | ---- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/05/11 20:22:13 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2011/05/11 18:16:01 | 000,000,000 | ---- | M] () -- C:\PhysicalDisk0_MBR.bin
    [2011/05/11 18:12:14 | 000,000,684 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\MBRCheck.lnk
    [2011/05/11 18:12:12 | 000,000,672 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
    [2011/05/11 18:12:08 | 000,000,677 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
    [2011/05/11 17:54:46 | 002,461,194 | ---- | M] (Nicolas Coolman ) -- C:\Documents and Settings\CLEMENT Emilie\Bureau\ZHPDiag2.exe
    [2011/05/11 17:31:00 | 114,720,170 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2011/05/10 12:00:01 | 001,407,280 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\CLEMENT Emilie\Bureau\TDSSKiller.exe
    [2011/05/10 11:57:24 | 001,280,815 | ---- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\tdsskiller.zip
    [2011/05/06 19:59:16 | 000,000,663 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\eMule.lnk
    [2011/05/01 13:22:38 | 000,109,867 | ---- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Mes documents\ZHPDiagdernier
    [2011/04/19 12:40:15 | 000,001,719 | ---- | M] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\iframe-form-descargas.asp
    [2011/04/18 20:21:31 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2011/04/15 16:47:47 | 000,274,968 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011/04/15 15:43:17 | 000,513,736 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
    [2011/04/15 15:43:17 | 000,444,362 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2011/04/15 15:43:17 | 000,085,842 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
    [2011/04/15 15:43:17 | 000,072,238 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [6 C:\Documents and Settings\CLEMENT Emilie\Mes documents\*.tmp files -> C:\Documents and Settings\CLEMENT Emilie\Mes documents\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\Documents and Settings\CLEMENT Emilie\Bureau\*.tmp files -> C:\Documents and Settings\CLEMENT Emilie\Bureau\*.tmp -> ]

    [color=#E56717]========== Files Created - No Company Name ==========/color

    [2011/05/12 19:18:05 | 000,142,166 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\renouvellement assu santé.pdf
    [2011/05/11 18:16:01 | 000,000,000 | ---- | C] () -- C:\PhysicalDisk0_MBR.bin
    [2011/05/11 18:12:12 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
    [2011/05/11 18:12:08 | 000,000,677 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
    [2011/05/11 17:31:00 | 114,720,170 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2011/05/10 11:58:21 | 001,280,815 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\tdsskiller.zip
    [2011/05/06 23:20:58 | 000,000,684 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\MBRCheck.lnk
    [2011/05/06 19:59:16 | 000,000,663 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\eMule.lnk
    [2011/05/01 13:22:38 | 000,109,867 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Mes documents\ZHPDiagdernier
    [2011/04/19 12:40:22 | 000,001,719 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Bureau\iframe-form-descargas.asp
    [2011/04/18 20:21:31 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
    [2011/03/10 11:26:15 | 000,000,518 | ---- | C] () -- C:\WINDOWS\System32\SP207.INI
    [2011/03/10 09:36:51 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
    [2011/03/02 08:16:01 | 000,000,284 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Application Data\ViewerApp.dat
    [2010/01/29 20:41:23 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
    [2008/12/29 01:48:32 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
    [2008/10/30 02:08:13 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
    [2008/05/14 20:21:52 | 000,441,705 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll
    [2008/01/28 05:20:40 | 000,047,616 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/01/21 19:59:01 | 000,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2008/01/17 22:27:40 | 000,000,137 | ---- | C] () -- C:\Documents and Settings\CLEMENT Emilie\Local Settings\Application Data\fusioncache.dat
    [2008/01/17 19:12:10 | 000,002,500 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2008/01/17 18:52:15 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2008/01/17 18:51:00 | 000,184,320 | ---- | C] () -- C:\WINDOWS\TPBATHLP.EXE
    [2008/01/17 18:45:52 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
    [2008/01/17 18:45:02 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
    [2008/01/17 18:45:02 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
    [2008/01/17 18:39:02 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\psasrv.exe
    [2008/01/17 18:32:03 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
    [2008/01/17 18:32:03 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
    [2008/01/17 18:32:03 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
    [2008/01/17 18:32:02 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
    [2008/01/17 18:32:02 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
    [2008/01/17 18:32:02 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
    [2008/01/17 18:30:35 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2008/01/17 18:21:40 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\TpShocks.exe
    [2004/12/16 12:41:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
    [2004/12/16 12:41:58 | 000,019,853 | ---- | C] () -- C:\WINDOWS\ibmprc.ini
    [2004/11/09 02:12:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2004/10/02 11:12:56 | 000,045,124 | ---- | C] () -- C:\WINDOWS\System32\LsaWrApi.dll
    [2004/10/02 11:05:18 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\D8021Xps.dll
    [2004/09/18 02:18:28 | 000,000,903 | ---- | C] () -- C:\WINDOWS\orun32.ini
    [2004/09/18 02:11:27 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2004/09/18 02:02:38 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2004/09/18 01:57:28 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2004/09/18 01:56:42 | 000,274,968 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2004/01/09 15:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
    [2003/11/13 12:12:00 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\tp4uires.dll
    [2003/11/13 12:12:00 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\tp4unins.exe
    [2003/11/13 12:12:00 | 000,005,600 | ---- | C] () -- C:\WINDOWS\System32\tp4table.dat
    [2003/10/16 15:57:06 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
    [2003/10/16 15:57:04 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
    [2002/01/22 00:48:12 | 000,106,496 | ---- | C] () -- C:\WINDOWS\desktopset.exe
    [2001/08/23 16:26:08 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
    [2001/08/23 16:24:30 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
    [1980/01/01 09:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [1980/01/01 09:00:00 | 000,513,736 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
    [1980/01/01 09:00:00 | 000,444,362 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [1980/01/01 09:00:00 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
    [1980/01/01 09:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [1980/01/01 09:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [1980/01/01 09:00:00 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
    [1980/01/01 09:00:00 | 000,085,842 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
    [1980/01/01 09:00:00 | 000,072,238 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [1980/01/01 09:00:00 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ibmpmsvc.exe
    [1980/01/01 09:00:00 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\tpinspm.dll
    [1980/01/01 09:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [1980/01/01 09:00:00 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
    [1980/01/01 09:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [1980/01/01 09:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [1980/01/01 09:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [1980/01/01 09:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

    [color=#E56717]========== Custom Scans ==========/color

    [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >/color

    [color=#A23BEC]< MD5 for: AGP440.SYS >/color
    [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
    [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
    [2010/08/28 04:55:43 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
    [2010/08/28 04:55:43 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
    [2008/04/14 04:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
    [2008/04/14 04:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
    [2004/08/04 08:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

    [color=#A23BEC]< MD5 for: ATAPI.SYS >/color
    [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
    [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
    [2010/08/28 04:55:43 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
    [2010/08/28 04:55:43 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
    [2008/04/14 04:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
    [2008/04/14 04:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
    [2004/08/04 07:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

    [color=#A23BEC]< MD5 for: EVENTLOG.DLL >/color
    [2004/08/05 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=21E83876A6287F15538EF187D286FE11 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
    [2008/04/14 12:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
    [2008/04/14 12:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\eventlog.dll

    [color=#A23BEC]< MD5 for: NETLOGON.DLL >/color
    [2008/04/14 12:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
    [2008/04/14 12:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\netlogon.dll
    [2009/02/07 04:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
    [2009/02/07 04:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
    [2004/08/05 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=FAF07FDCDE76000621A28D19F8E2E8EB -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

    [color=#A23BEC]< MD5 for: SCECLI.DLL >/color
    [2008/04/14 12:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
    [2008/04/14 12:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\scecli.dll
    [2004/08/05 14:00:00 | 000,186,368 | ---- | M] (Microsoft Corporation) MD5=DEC0397F35D027874804EC72979D03CC -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

    [color=#A23BEC]< %systemroot%\*. /mp /s >/color

    [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >/color
    [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

    [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >/color

    [color=#E56717]========== Alternate Data Streams ==========/color

    @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

    < End of report >
    0
  3. Tigzy Messages postés 7983 Statut Contributeur sécurité 582
     
    Je voit pas de problème particulier dans OTL..
    Tu as d'autres soucis?
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. Emilie180
     
    Je crois que tu as résolu mon seul problème : le blocage de l'installation d'AVG.

    Pour être sûr que mon PC est "clean", un message est apparu un jour de l'anti-virus disant qu'il avait détecté 2 adresses IP pour mon PC.

    Enfin, quelques problèmes de connexion internet qui sont résolus en utilisant un autre WIFI.

    Je ne vois rien d'autre.

    J'en profite pour te remercier d'avoir désinfecté mon PC. MERCI

    ps : si tu as le temps, j'aimerais bien savoir ce que c'était et comment j'ai pu le choper (pour éviter que ça se renouvelle ...)
    0
  6. Tigzy Messages postés 7983 Statut Contributeur sécurité 582
     
    En infection il y avait pas grand chose, un adware navipromo.
    Il faut faire attention surtout aux logiciels gratuit comme LivePlayer ou d'autres.

    * Télécharge DELFix de Xplode
    * Lance le.
    * A l'invite, tape 2 (suppression)
    * Un rapport va s'ouvrir à la fin, colle le dans la réponse

    ----------

    Tu peux lire ce sujet sur les logiciels recommandés, et les attitudes responsables sur le web
    Et celui ci, sur les logiciels gratuits à éviter

    ------

    Tu peux garder Malwarebytes pour un scan de temps à autres

    -----

    Pense à marquer le fil comme résolu

    0
  7. Emilie180
     
    Merci pour ces conseils.

    Dernier petit point, le scan delfix.exe est corrompu (message apparu au lancement du logiciel sur mon PC) . y a t-il un autre lien que je puisse utiliser ?
    0
    1. Tigzy Messages postés 7983 Statut Contributeur sécurité 582
       
      Tu as essayé de le rétélécharger? le lien est le seul qui existe
      0
  8. Emilie180
     
    C'est fait :

    # DelFix v7.8 - Rapport créé le 13/05/2011 à 19:16
    # Mis à jour le 02/05/11 à 18h par Xplode
    # Système d'exploitation : Microsoft Windows XP (32 bits) [version 5.1.2600] Service Pack 3
    # Nom d'utilisateur : CLEMENT Emilie - IBM-68B08E7547B (Administrateur)
    # Exécuté depuis : C:\Documents and Settings\CLEMENT Emilie\Bureau\delfix.exe
    # Option [Suppression]

    ~~~~~~ Dossier(s) ~~~~~~

    Supprimé : C:\32788R22FWJFW
    Supprimé : C:\Navilog1
    Supprimé : C:\RSIT
    Supprimé : C:\Program Files\ZHPDiag
    Supprimé : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP

    ~~~~~~ Fichier(s) ~~~~~~

    Supprimé : C:\PhysicalDisk0_MBR.bin
    Supprimé : C:\TDSSKiller.2.5.0.0_10.05.2011_12.00.41_log.txt
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Bureau\MBRCheck_05.11.11_19.15.25.txt
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Bureau\OTL.exe
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Bureau\OTL.Txt
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Bureau\TDSSKiller.exe
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Bureau\tdsskiller.zip
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Bureau\ZHPDiag2.exe
    Supprimé : C:\Documents and Settings\All Users\Bureau\MBRCheck.lnk
    Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
    Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
    Supprimé : C:\Documents and Settings\CLEMENT Emilie\Mes documents\Downloads\tdsskiller.zip

    ~~~~~~ Registre ~~~~~~

    Clé Supprimée : HKLM\Software\OldTimer Tools
    Clé Supprimée : HKLM\Software\TrendMicro\Hijackthis
    Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

    ~~~~~~ Autre ~~~~~~

    -> Prefetch vidé

    ########## EOF - "C:\DelFixSuppr.txt" - [1824 octets] ##########
    0
    1. Tigzy Messages postés 7983 Statut Contributeur sécurité 582
       
      ok, c'est bon.
      revient me voir si tu as encore des problème :)
      0
Précédent
  • 1
  • 2
  • 3