Comment se débarrasser de trojan?

Résolu
cls03 Messages postés 10 Statut Membre -  
 Utilisateur anonyme -
Bonjour,

comment je peux faire pour me séparer du virus trojan?
merci de m'aider

A voir également:

50 réponses

cls03
 
j'ai fait une restauration système car j'ai paniquée, j'avais tout perdu
tout est revenu

et maintenant? je fais quoi?
0
bobmarley54 Messages postés 44 Statut Membre
 
relax il ne faut pas paniquer , prendre son temps est ma cmé ! ( sans jeux de mot hein :) )
0
Utilisateur anonyme
 
0
cls03
 
http://www.cijoint.fr/cjlink.php?file=cj201110/cijN7wsAS6.txt

http://www.cijoint.fr/cjlink.php?file=cj201110/cij6YGCiBO.txt
0
Utilisateur anonyme
 
bon ok on reprend d'ici

desinstalle la suite Fighters / et / ou / spamfighter (ca vaut rien)

refais ca :

https://forums.commentcamarche.net/forum/affich-23342171-comment-se-debarrasser-de-trojan?full#7

¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
cls03
 
ComboFix 11-10-09.01 - Céline 09/10/2011 22:27:09.1.2 - x86
Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2046.804 [GMT 2:00]
Lancé depuis: c:\users\Céline\Documents\celine.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Un nouveau point de restauration a été créé
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-09-09 au 2011-10-09 ))))))))))))))))))))))))))))))))))))
.
.
2011-10-09 20:40 . 2011-10-09 20:40 -------- d-----w- c:\users\Céline\AppData\Local\temp
2011-10-09 20:40 . 2011-10-09 20:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-09 20:40 . 2011-10-09 20:40 -------- d-----w- c:\users\CLINE~2\AppData\Local\temp
2011-10-09 20:23 . 2011-10-09 20:23 -------- d-----w- C:\celine
2011-10-08 20:32 . 2011-10-08 21:03 -------- d-----w- c:\programdata\clp
2011-10-08 20:32 . 2011-10-08 20:32 -------- d-----w- c:\programdata\Common Toolkit Suite
2011-10-08 20:32 . 2011-10-08 20:32 -------- d-----w- c:\program files\Common Files\Common Toolkit Suite
2011-10-08 20:31 . 2011-10-09 19:20 -------- dc-h--w- c:\programdata\~0
2011-10-08 20:31 . 2011-10-09 19:20 -------- d-----w- c:\programdata\Fighters
2011-10-08 20:31 . 2011-10-09 19:19 -------- d-----w- c:\users\Céline\AppData\Roaming\Fighters
2011-10-08 20:31 . 2011-10-08 20:31 -------- d-----w- c:\users\Céline\AppData\Local\PackageAware
2011-10-07 17:58 . 2011-10-07 18:57 -------- d-----w- C:\Kill'em
2011-10-07 17:49 . 2011-09-12 23:14 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7A20FA6D-D708-4443-ABFB-88BF1004724E}\mpengine.dll
2011-10-06 19:19 . 2006-06-19 11:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2011-10-06 19:19 . 2006-05-25 13:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2011-10-06 19:19 . 2005-08-25 23:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2011-10-06 19:19 . 2002-03-05 23:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2011-10-06 19:19 . 2003-02-02 18:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2011-10-05 17:47 . 2011-10-05 17:47 -------- d-----w- c:\windows\Sun
2011-10-04 19:45 . 2011-10-04 19:48 -------- d-----w- c:\users\Céline\AppData\Local\AirportMania2
2011-10-01 22:07 . 2011-10-01 22:07 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-01 21:58 . 2011-10-02 08:49 -------- dc----w- c:\windows\system32\DRVSTORE
2011-10-01 21:58 . 2011-10-01 21:58 -------- d-----w- c:\program files\Lavasoft
2011-10-01 21:58 . 2011-10-02 08:49 -------- d-----w- c:\programdata\Lavasoft
2011-10-01 20:29 . 2011-10-01 22:28 -------- d-----w- c:\programdata\AVAST Software
2011-10-01 20:29 . 2011-10-01 20:29 -------- d-----w- c:\program files\AVAST Software
2011-10-01 19:57 . 2011-10-01 19:57 -------- d-----w- c:\users\Céline\AppData\Roaming\Avira
2011-09-29 20:25 . 2011-09-29 20:26 -------- d-----w- c:\program files\Bistro Boulevard
2011-09-29 19:42 . 2011-09-29 19:42 -------- d-----w- c:\program files\Airport Mania 2 - Wild Trips
2011-09-17 20:51 . 2011-09-17 20:51 -------- d-----w- c:\program files\Games
2011-09-17 12:08 . 2011-09-17 12:24 -------- d-----w- c:\programdata\CropBusters
2011-09-15 19:33 . 2011-09-15 19:33 -------- d-----w- c:\users\Céline\AppData\Roaming\Clockwork Pixels
2011-09-14 19:17 . 2011-09-14 19:17 -------- d-----w- c:\program files\Common Files\Adobe
2011-09-13 20:50 . 2011-08-10 12:14 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-28 19:34 . 2011-05-16 19:08 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-30 19:13 . 2009-09-19 14:22 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-08-30 19:13 . 2009-09-12 21:26 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-23 11:04 . 2011-08-09 19:41 916480 ----a-w- c:\windows\system32\wininet.dll
2011-07-23 11:00 . 2011-08-09 19:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-07-23 10:59 . 2011-08-09 19:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-07-23 10:59 . 2011-08-09 19:41 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-07-23 10:59 . 2011-08-09 19:41 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-07-23 10:03 . 2011-08-09 19:41 385024 ----a-w- c:\windows\system32\html.iec
2011-07-23 09:27 . 2011-08-09 19:41 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-07-23 09:25 . 2011-08-09 19:41 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-06 19:01 . 2011-05-10 20:27 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
[code]<pre>
c:\program files\Acer Arcade Deluxe\Play Movie\PMVService .exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
c:\program files\Intel\Intel Matrix Storage Manager\iaanotif .exe
c:\program files\Launch Manager\QtZgAcer .exe
c:\program files\Synaptics\SynTP\SynTPEnh .exe
c:\windows\SetSpkDefault .exe
</pre>/code
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour"="" [N/A]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-04 4702208]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056]
"eRecoveryService"="" [N/A]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-06-26 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-26 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-26 81920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-8-14 535336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 AMService;AMService;c:\windows\TEMP\cydbva\setup.exe run [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-02-08 179712]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-09-13 717296]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-02 13560]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-29 136360]
S3 AVFSFilter;AVFSFilter;c:\windows\system32\DRIVERS\avfsfilter.sys [x]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-04-19 43008]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://fr.fr.acer.yahoo.com
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Céline\AppData\Roaming\Mozilla\Firefox\Profiles\u93rnm68.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.orange.fr/
FF - prefs.js: keyword.URL - hxxp://www.searcheo.fr/france?search&q=
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-09 22:40
Windows 6.0.6002 Service Pack 2 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2011-10-09 22:43:32
ComboFix-quarantined-files.txt 2011-10-09 20:43
.
Avant-CF: 44 446 126 080 octets libres
Après-CF: 44 429 434 880 octets libres
.
- - End Of File - - 6ACB84A5D38D90ADA176A47FBA8334CB
0
Utilisateur anonyme
 
que contient ceci ?

c:\programdata\clp

==================================


__________________________________________________
=>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
=>il est fort déconseillé de le transposer sur un autre ordinateur !<=
----------------------------------------------------------------------------


Toujours avec toutes les protections désactivées, fais ceci :

▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

----------------------------------------------------------
KillAll::

Folder::
c:\windows\TEMP\cydbva
c:\program files\Lavasoft

RenV::
c:\program files\Acer Arcade Deluxe\Play Movie\PMVService .exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
c:\program files\Intel\Intel Matrix Storage Manager\iaanotif .exe
c:\program files\Launch Manager\QtZgAcer .exe
c:\program files\Synaptics\SynTP\SynTPEnh .exe
c:\windows\SetSpkDefault .exe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour"=-
"eRecoveryService"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000

Driver::
AMService
Lavasoft Kernexplorer

Firefox::
FF - prefs.js: keyword.URL - hxxp://www.searcheo.fr/france?search&q=

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]


------------------------------------------------------------------

▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
▶ Quitte le Bloc Notes

▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt


0
cls03
 
c/programmedata/clp contient ceci
SF_AV-001.bak 09/10/2011 à 8:33
SF_AV-001.lic 09/10/2011 à 20:52

mais je ne sais pas ce que sais
0
cls03
 
j'ai pas compris
je copie et colle sans les espaces entre les lignes?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
 
tel quel sans les lignes exterieures pointillées
0
cls03
 
je ne peux pas faire glisser/déposer
message:
C:/Users/Céline/Desktop/celine.exe
Tentative d'opération non autorisée sur une clé du Registre marquée pour suppression.
0
cls03
 
dès que je veux ouvrir un fichier j'ai ce message.
0
cls03
 
je fais quoi?
0
Utilisateur anonyme
 
redemarre le pc combofix a besoin dun deuxieme redemarrage pour finaliser le nettoyage et bloque le pc :)
0
cls03
 
alors j'ai redémarré, le scan s'est fait et mon pc a redémarré et pas de rapport nul part
je fais quoi?
0
Utilisateur anonyme
 
C:\Combofix.txt non ?
0
cls03
 
non je le trouve nul part
0
Utilisateur anonyme
 
tu as toujours le CFScript que tu as fait avec le texte collé dedans ou pas ?
0
cls03
 
non je ne l'ai plus sur mon bureau
0
cls03
 
après plusieurs tentative j'ai enfin réussi voici le rapport

http://www.cijoint.fr/cjlink.php?file=cj201110/cijHoxvj3k.txt
0
Utilisateur anonyme
 
re

refais un scan OTL stp ?
0
cls03
 
http://www.cijoint.fr/cjlink.php?file=cj201110/cij8gI3WMP.txt

http://www.cijoint.fr/cjlink.php?file=cj201110/cij8qEnVDs.txt
0
Utilisateur anonyme
 
desinstalle mozilla firefox et installe la derniere version

https://www.mozilla.org/fr/firefox/new/

======================================

ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!


si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur OTL.exe pour le lancer.


▶Copie la liste qui se trouve en gras ci-dessous,

▶ colle-la dans la zone sous "Personnalisation" :


:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe

:Services
HSXHWAZL

:OTL
IE - HKU\S-1-5-21-3280417579-4034682547-2729963825-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
FF - prefs.js..extensions.enabledItems: support@predictad.com:1.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.searcheo.fr/france?search&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - prefs.js..keyword.URL: "http://www.searcheo.fr/france?search&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\support@predictad.com: C:\Program Files\AutocompletePro\support@predictad.com
[2009/10/31 16:21:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/10/31 16:25:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/11/09 20:46:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/03/31 12:19:32 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
[2010/05/05 15:02:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/15 22:06:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)

:Files
C:\Users\Céline\AppData\Roaming\Mozilla\Firefox\Profiles\u93rnm68.default\searchplugins\Searcheo.xml
C:\ProgramData\2YTotxV1O.dat
C:\Windows\System32\cC18wDK.com.b
C:\Windows\SetSpkDefault.exe.b
C:\Users\Céline\AppData\Local\slot1.mm1
C:\Users\Céline\AppData\Roaming\iWin
C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe\plugs
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:8DF68137
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:DDF112BD
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:0B352B60
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:EAF954B6
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:EA10407C
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:C0893153
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:5CE65446
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:23834E1E
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:159A493A
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:D8139E6A
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:A0CB43B2
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:8DD20B4A
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:6C75AF4C
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:609CAC7C
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:52641FBE
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:24C072FF
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:0915A718
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:082EF53F
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:EE7AAC75
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:E411AA0D
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:D3A89E47
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:CC4C59B4
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:68B61847
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:59465B40
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:33EA030E
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:2ADF9928
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:22741C1F
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:1316EAD4
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0E67073E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:F9EDCFB0
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DD95E6D9
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D8F9D810
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:B722BCE5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:AFB24B00
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:AE9351E0
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:A1023D41
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:9EE6560D
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:93D985FC
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:908A1B53
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:895A78C5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:3B4DA230
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:2D1AE3BE
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:1CDEDE11
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:CF1334B0
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C72A744C
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:AA0017FD
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:A18121AD
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:97995ED4
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:73461BFA
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:6F0B6A5A
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5080697C
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:3A7527E8
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:32FFF2D1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C611D6C8
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:AECF4772
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:A58B27C9
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:A4AF8D0D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:689AB7E9
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:42A3BDD7
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:3571475C
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:FEF919E6
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F8F070C2
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F81E7082
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F5B51004
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:EF0C5444
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:E732B44B
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:DC0B1070
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:CD9109D4
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C7973317
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:99C301D0
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:8924043A
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:6B7447D4
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:67CF910D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:2E3F04BC
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:26A148EB
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:DE9F4320
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:D2A66480
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:CDCDE97C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:B18C4339
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:AE75CCC8
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:AC73CDCE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:9ACE4E8E
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:966CEAE7
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:953FDC1A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:93B0BB6F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80EA2EA3
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:774A0E14
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:71004506
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:701B92FB
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:5BB7898D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:5AE33054
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:2F1D743F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:2176484C
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:EA7D76BE
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:E1610EDC
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:D93AABC7
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C30487EE
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:AC733A73
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A774141A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:8BE8BFCD
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:6C5EC3CD
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:5CE91C67
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:4E243396
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:4A966CC2
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:3991CD7D
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:1F7A10DD
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:140AD176
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:0E5A5AE9
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:FEEEFFAD
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:E6C6EB3B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:DB77E2C4
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:CA0CE093
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:B4F0E275
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:B285A50E
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:A5241382
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:9BAC4211
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:816255C3
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:7A032A04
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:40EE25BB
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3DF63AD7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3651A580
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:30E0D641
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E45FA8F
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2BFCDF84
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:29629382
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0ADB5110
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:09708CB7
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:F41E22A9
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:EC0279DC
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:EBFB51F1
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:EB333CFC
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:D4D3884D
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:C35B4B19
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A851461E
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A6D6E537
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A4E7D25F
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:53B8C5D2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:52C24010
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:2CE15176
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:19474103
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:193CB03B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0A74923C
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:EF4B1DA9
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:DF5BAC78
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:D51F4BAE
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C6D0ABC3
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:B709343D
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:AED33A42
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:AB3339EF
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:864881BF
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:5A15BCD4
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:523B97A0
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:3CAE2A70
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:16A4620C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:EA1919C7
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E0EBA003
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C0A9B815
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:BC1F7CAE
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:4F7FE589
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:491270B8
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:2DF54B62
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:1181620C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:104A718B
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:0F3F6B1E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:FB08C210
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:FAB64002
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F9E46E4C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E6DFB241
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:DA24A961
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9D5BB34A
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9256664B
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:80BFDE16
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7A3AAF2E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:5C0940F1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:436BE28C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3FD496E1
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E2B84483
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:D01ACC06
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:BF6A2C54
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:B3196E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:B1E64E47
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:B1786630
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:759B7D6F
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6FD36C4B
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6E11933F
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:413E2927
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:386B39C3
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:36FFA2FB
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:3086B95F
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:2F6462DF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:149327FE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:08E5EE32
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:DA18D4E3
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:C946EBB2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:AB82C54F
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A59DD4AD
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:95FC57E0
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:9485E512
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:8BFA0030
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:79875988
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:6423D635
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:4149A170
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:1E17A249
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:041C0562
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:ED51D3ED
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:E5DE9C8F
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:C7F08EA3
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:BF640EE5
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:AE2EA3C2
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A05F750A
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:85A0F6D2
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:71B89F61
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:6247E766
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:5EC637CB
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:512E1728
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:4EF94CF3
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:4C8FA829
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:43860CE8
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:33E12B7A
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:2EB79F01
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:070D9534
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FC70A22A
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:EB4FEEF5
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:BE40C8A2
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A2FF62A6
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:66871744
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3D186293
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:0860D6D6
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:FDCAE7B5
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:E83EE313
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:DF0BC727
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D8D58038
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:CAC06C34
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B9E9A5F9
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A60D0FA6
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A5CD91DF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:98982C88
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:76466F4C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:71112705
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:583FE1DA
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:329BA65B
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:28CDD861
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:0C1258F3
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:008586AE
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:EF5B3572
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:D354012D
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C7857F06
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C3392F75
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C0A504B9
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:A8DFD30C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:99AC3203
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:91A12471
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:4EE95FE7
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:4A906D4A
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:3DB6F365
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:2C399CCA
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:2AE74FF9
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:123A86B5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:11EFE63D
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:0F38F234
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:0C9CD455
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:E3B5F2D1
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:DE875C30
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:DE6EED8B
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:D4BB0AD6
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:C3D26A8A
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:A5584049
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9F50A55A
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:969C0C96
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9491C9C7
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9290C91C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:7ADB695A
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:769BB147
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:66FC2E6F
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:56F368C9
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:5345C8F6
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:217A2324
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:0785072C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:00811B66
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:00258EE7
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:F986CC21
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:F44D3C53
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:DE9AC04F
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:CEF2A14E
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C859F017
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:9FD757A9
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:8B4B9596
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:84E7BFEB
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:751D6870
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:71612023
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:628C9914
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:62525FE7
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:55C54F7C
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:54F7A151
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:4A2862FF
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:370E4EFB
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:33B04540
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:2ABB51D4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:29F0CA7D
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1D6B18F1
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:021496FB
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:EBCF5924
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E774F04D
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E690114B
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D9987109
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:CDB75348
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:CCB49694
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:C76CFF82
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:BE6DC701
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:A26AFC00
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:A01F3A87
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:981456CB
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:92D91D7E
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:64170090
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:56C17A93
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4DDE401B
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4A448DB2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:3B454A5C
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:35A81752
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:17F7AEA3
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:FD444D31
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:F19A4790
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:EB5BDBB0
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D5E0200E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D0668210
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:AC0528D9
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A7B70C4E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:75CC0165
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:627153F1
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:4B244549
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:46A2F27B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:397D67BA
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:38FF076E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:1C201DEB
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:FC60E0F8
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:F3EFA8A8
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:F1F936DF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:EB68CA55
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:E6D148BC
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:E2CFA9CD
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D390A6A7
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ADFAD95A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A6D89509
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A57500CB
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:9D03192E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:94B46CA2
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:8B4C1181
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:65AB2A58
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:5FEFEAEF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:5425B7F5
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:4EE323A4
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:3AD6342E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:35629AE6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2E9900EE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:237E4B91
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:02B823FE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:C67CB31A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:AA0BC725
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:78739EC9
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:67310058
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:53DF4438
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2FBB2B9B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2CDB9CA3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2B856118
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:268BA8AB
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:F3029A65
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EAEE7554
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D9F34335
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D6D084A5
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:CAE3AE67
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:CA99FD89
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BF6C81B2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:B1381B34
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9EB9A9EC
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:88A44CC1
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:87452B14
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:697DDE2B
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:3D6B89CE
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:33384BC0
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:1968990D
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:063969F8
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:F43B7E8F
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:D2593961
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:89C28CF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:852F2262
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:5D10C56A
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:3E200C29
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:2EA99C48
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FC2D0F32
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:EDD903C5
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:C9B27A06
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:BE0BAFE1
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:B0456F0C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9D06FB9C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9331E9D2
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5C4A588B
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:393F7B1E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:27C3CD07
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:169E7AC5
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:160ADF0B
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0F38B460
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:FEB0595A
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:FBE5FDB9
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:A4076A3B
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9AE67195
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:488F7244
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:47A24D4B
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:40BAD1B0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:151760F0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:14A1BBE3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F0762150
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:ED796303
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:D2397415
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:BD8C785E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:B64F7263
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A88BE334
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A6CDBCAC
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:99B20AD0
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:6AF67671
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:57176330
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:36A39835
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:19636FDD
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:13EF4AF6
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D5BF78B4
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D453E38B
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:A441D13F
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:9DB67071
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:8DD36B71
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:75A76CD8
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:4AD2C54D
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F0A06891
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BBF60A29
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:9720EBEF
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:471AD3D0
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:33DB8278
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:F7370879
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:C36B1175
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:2832349A
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:26FBC1F9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:DF3CC840
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:834DD57E
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:7B15F8C8
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:701FCC18
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:122B409D
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:03A039A3
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:C3AD9507
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A4CDE823
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4FA837B4
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:0696EC8E
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:FB647F34
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:F1F85068
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:E6A96BE9
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:BD34FFC5
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:86148D88
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:0D3CE40A
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:F7F6E6CB
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:FDC41D2C
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:1ECED34B
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:E07EA07E
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5197985B
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:1A7E6B73
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:CB0FEE2B
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:124B94C0
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:996104FC
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:4911BB5C
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:8CCDAB14
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:73AFBB96
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:57B2B96C
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:74091520
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:82529191
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:CA8D6B60
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:109734F6

:commands
[CLEARALLRESTOREPOINTS]
[emptytemp]
[start explorer]
[reboot]



▶ Clique sur "Correction" pour lancer la suppression.


▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
0
cls03
 
je n'arrive pas à poster le rapport
0
cls03
 
c'est un bloc notes
0
cls03
 
je l'ai enregistré et renommé, le voici

http://www.cijoint.fr/cjlink.php?file=cj201110/cijImB0b7w.txt
0
Utilisateur anonyme
 
fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.


▶ Télécharge ici :

Malwarebytes

▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

relance malwarebytes en suivant scrupuleusement ces consignes :

! Déconnecte toi et ferme toutes applications en cours !

▶ Lance Malwarebyte's .

Fais un examen dit "Complet" .

▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !


Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

0
cls03
 
ça fait 2h que j'essaie de scanner avec malwarebytes mais impossible à chaque fois mon ordi se coupe avec un message d'erreur et redémarre.
je fais quoi?
0
Utilisateur anonyme
 
tu peux preciser le message d'erreur ?
0
cls03
 
mon pc s'éteint et j'ai une page fond noir avec écriture bleu qui défile avec des chiffres aussi qui défilent. en gros ça me mets que j'ai un problème et donc de prendre contact avec mon "constructeur"
0
Utilisateur anonyme
 
fond noir avec ecriture bleue ?
0
cls03
 
oui mon écran est tout noir avec des écritures bleues qui défilent
0
Utilisateur anonyme
 
essaie un examen rapide voir
0
cls03
 
ok
0
cls03
 
j'ai fait l'examen rapide et il ne trouve pas de fichiers infectés alors que tout à l'heure il a scanné pendant 1h30 avant de se couper et j'avais déjà 3 fichiers infectés
0
cls03
 
voici enfin le rapport

http://www.cijoint.fr/cjlink.php?file=cj201110/cijLxONP4S.txt
0
Utilisateur anonyme
 
salut quels soucis persistent ?
0
cls03
 
j'ai fait un scan avec mon antivirus avira, voici le rapport

http://www.cijoint.fr/cjlink.php?file=cj201110/cijYudZFBr.txt
0
Utilisateur anonyme
 
▶ Télécharge Reload_TDSSKiller

▶ Lance le

choisis : lancer le nettoyage

l'outil va automatiquement télécharger la derniere version puis

TDSSKiller va s'ouvrir , clique sur "Start Scan"

Si TDSS.tdl2 est détecté l''option delete sera cochée par défaut.
Si TDSS.tdl3 est détecté assure toi que Cure est bien cochée.
Si TDSS.tdl4(\HardDisk0\MBR) est détecté assure toi que Cure est bien cochée.
Si Suspicious file est indiqué, laisse l''option cochée sur Skip
Si Rootkit.Win32.ZAccess.* est détecté règle sur "cure" en haut , et "delete" en bas

une fois qu'il a terminé , redemarre s'il te le demande pour finir de nettoyer

sinon , ferme tdssKiller et le rapport s'affichera sur le bureau

▶ Copie/Colle son contenu dans ta prochaine réponse.
0
cls03
 
22:26:30.0852 5688 TDSS rootkit removing tool 2.6.9.0 Oct 14 2011 11:33:24
22:26:31.0018 5688 ============================================================
22:26:31.0018 5688 Current date / time: 2011/10/14 22:26:31.0018
22:26:31.0018 5688 SystemInfo:
22:26:31.0018 5688
22:26:31.0018 5688 OS Version: 6.0.6002 ServicePack: 2.0
22:26:31.0018 5688 Product type: Workstation
22:26:31.0018 5688 ComputerName: PC-DE-CÉLINE
22:26:31.0019 5688 UserName: Céline
22:26:31.0019 5688 Windows directory: C:\Windows
22:26:31.0019 5688 System windows directory: C:\Windows
22:26:31.0019 5688 Processor architecture: Intel x86
22:26:31.0019 5688 Number of processors: 2
22:26:31.0019 5688 Page size: 0x1000
22:26:31.0019 5688 Boot type: Normal boot
22:26:31.0019 5688 ============================================================
22:26:33.0940 5688 Initialize success
22:26:41.0852 5928 ============================================================
22:26:41.0852 5928 Scan started
22:26:41.0852 5928 Mode: Manual;
22:26:41.0852 5928 ============================================================
22:26:43.0720 5928 61883 (585e64bb6dfbc0a2f1f0b554ded012df) C:\Windows\system32\DRIVERS\61883.sys
22:26:43.0727 5928 61883 - ok
22:26:44.0004 5928 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
22:26:44.0007 5928 ACPI - ok
22:26:44.0313 5928 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
22:26:44.0337 5928 adp94xx - ok
22:26:44.0494 5928 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
22:26:44.0515 5928 adpahci - ok
22:26:44.0667 5928 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
22:26:44.0675 5928 adpu160m - ok
22:26:44.0880 5928 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
22:26:44.0950 5928 adpu320 - ok
22:26:45.0239 5928 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
22:26:45.0255 5928 AFD - ok
22:26:45.0385 5928 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
22:26:45.0393 5928 agp440 - ok
22:26:45.0565 5928 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
22:26:45.0575 5928 aic78xx - ok
22:26:45.0701 5928 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
22:26:45.0706 5928 aliide - ok
22:26:45.0895 5928 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
22:26:45.0905 5928 amdagp - ok
22:26:46.0066 5928 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
22:26:46.0105 5928 amdide - ok
22:26:46.0282 5928 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
22:26:46.0289 5928 AmdK7 - ok
22:26:46.0394 5928 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
22:26:46.0401 5928 AmdK8 - ok
22:26:46.0896 5928 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
22:26:46.0906 5928 arc - ok
22:26:47.0244 5928 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
22:26:47.0255 5928 arcsas - ok
22:26:47.0447 5928 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
22:26:47.0991 5928 AsyncMac - ok
22:26:48.0683 5928 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
22:26:49.0015 5928 atapi - ok
22:26:50.0114 5928 Avc (f4b56425a00beb32f5fa6603ff7b0ea2) C:\Windows\system32\DRIVERS\avc.sys
22:26:50.0123 5928 Avc - ok
22:26:51.0718 5928 AVFSFilter - ok
22:26:51.0891 5928 avgio (f1d43170fdd7399ee17ea32d4f868b0c) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
22:26:51.0972 5928 avgio - ok
22:26:52.0377 5928 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
22:26:52.0406 5928 avgntflt - ok
22:26:52.0796 5928 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
22:26:52.0850 5928 avipbb - ok
22:26:53.0152 5928 b57nd60x (0b92ccf7bfcbe2b33838434f2f50cb61) C:\Windows\system32\DRIVERS\b57nd60x.sys
22:26:53.0323 5928 b57nd60x - ok
22:26:53.0741 5928 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
22:26:54.0088 5928 Beep - ok
22:26:54.0344 5928 blbdrive - ok
22:26:54.0472 5928 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
22:26:54.0550 5928 bowser - ok
22:26:54.0712 5928 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
22:26:54.0716 5928 BrFiltLo - ok
22:26:54.0883 5928 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
22:26:54.0985 5928 BrFiltUp - ok
22:26:55.0129 5928 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
22:26:55.0165 5928 Brserid - ok
22:26:55.0294 5928 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
22:26:55.0342 5928 BrSerWdm - ok
22:26:55.0390 5928 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
22:26:55.0394 5928 BrUsbMdm - ok
22:26:55.0420 5928 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
22:26:55.0475 5928 BrUsbSer - ok
22:26:55.0597 5928 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
22:26:55.0605 5928 BTHMODEM - ok
22:26:55.0631 5928 catchme - ok
22:26:55.0685 5928 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
22:26:55.0719 5928 cdfs - ok
22:26:55.0779 5928 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
22:26:55.0826 5928 cdrom - ok
22:26:55.0890 5928 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
22:26:55.0927 5928 circlass - ok
22:26:55.0990 5928 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
22:26:56.0116 5928 CLFS - ok
22:26:56.0656 5928 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
22:26:56.0662 5928 CmBatt - ok
22:26:56.0722 5928 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
22:26:56.0727 5928 cmdide - ok
22:26:56.0776 5928 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
22:26:56.0820 5928 Compbatt - ok
22:26:56.0839 5928 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
22:26:56.0850 5928 crcdisk - ok
22:26:56.0883 5928 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
22:26:56.0899 5928 Crusoe - ok
22:26:57.0101 5928 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
22:26:57.0108 5928 DfsC - ok
22:26:57.0367 5928 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
22:26:57.0531 5928 disk - ok
22:26:57.0784 5928 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys
22:26:57.0894 5928 DKbFltr - ok
22:26:58.0112 5928 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
22:26:58.0116 5928 drmkaud - ok
22:26:58.0289 5928 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
22:26:58.0310 5928 DXGKrnl - ok
22:26:58.0479 5928 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
22:26:58.0599 5928 E1G60 - ok
22:26:58.0783 5928 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
22:26:58.0844 5928 Ecache - ok
22:27:00.0196 5928 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
22:27:00.0214 5928 elxstor - ok
22:27:01.0148 5928 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
22:27:01.0159 5928 exfat - ok
22:27:01.0285 5928 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
22:27:01.0300 5928 fastfat - ok
22:27:01.0385 5928 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
22:27:01.0441 5928 fdc - ok
22:27:01.0546 5928 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
22:27:01.0633 5928 FileInfo - ok
22:27:01.0699 5928 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
22:27:01.0745 5928 Filetrace - ok
22:27:01.0772 5928 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
22:27:01.0828 5928 flpydisk - ok
22:27:01.0891 5928 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
22:27:02.0041 5928 FltMgr - ok
22:27:02.0604 5928 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
22:27:02.0668 5928 Fs_Rec - ok
22:27:02.0780 5928 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
22:27:02.0865 5928 gagp30kx - ok
22:27:03.0068 5928 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
22:27:03.0104 5928 HdAudAddService - ok
22:27:03.0152 5928 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:27:03.0160 5928 HDAudBus - ok
22:27:03.0191 5928 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
22:27:03.0199 5928 HidBth - ok
22:27:03.0242 5928 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
22:27:03.0255 5928 HidIr - ok
22:27:03.0298 5928 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
22:27:03.0345 5928 HidUsb - ok
22:27:03.0387 5928 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
22:27:03.0398 5928 HpCISSs - ok
22:27:03.0448 5928 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
22:27:03.0462 5928 HSFHWAZL - ok
22:27:03.0515 5928 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
22:27:03.0680 5928 HSF_DPV - ok
22:27:03.0734 5928 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
22:27:03.0822 5928 HTTP - ok
22:27:03.0884 5928 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
22:27:03.0890 5928 i2omp - ok
22:27:03.0980 5928 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
22:27:03.0992 5928 i8042prt - ok
22:27:04.0089 5928 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\drivers\iastor.sys
22:27:04.0092 5928 iaStor - ok
22:27:04.0113 5928 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
22:27:04.0126 5928 iaStorV - ok
22:27:04.0160 5928 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
22:27:04.0171 5928 iirsp - ok
22:27:04.0253 5928 int15 (9d64201c9e5ac8d1f088762ba00ff3ab) C:\Acer\Empowering Technology\eRecovery\int15.sys
22:27:04.0259 5928 int15 - ok
22:27:04.0419 5928 IntcAzAudAddService (9f5898ebd3bbe82eadf2efa595f02a72) C:\Windows\system32\drivers\RTKVHDA.sys
22:27:04.0580 5928 IntcAzAudAddService - ok
22:27:04.0787 5928 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
22:27:04.0810 5928 intelide - ok
22:27:04.0910 5928 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
22:27:04.0911 5928 intelppm - ok
22:27:05.0053 5928 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:27:05.0079 5928 IpFilterDriver - ok
22:27:05.0203 5928 IpInIp - ok
22:27:05.0271 5928 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
22:27:05.0279 5928 IPMIDRV - ok
22:27:05.0340 5928 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
22:27:05.0349 5928 IPNAT - ok
22:27:05.0397 5928 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
22:27:05.0401 5928 IRENUM - ok
22:27:05.0457 5928 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
22:27:05.0470 5928 isapnp - ok
22:27:05.0565 5928 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
22:27:05.0567 5928 iScsiPrt - ok
22:27:05.0604 5928 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
22:27:05.0677 5928 iteatapi - ok
22:27:05.0713 5928 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
22:27:05.0719 5928 iteraid - ok
22:27:05.0763 5928 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
22:27:05.0771 5928 kbdclass - ok
22:27:05.0833 5928 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
22:27:05.0838 5928 kbdhid - ok
22:27:05.0888 5928 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
22:27:05.0965 5928 KSecDD - ok
22:27:06.0285 5928 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
22:27:06.0293 5928 lltdio - ok
22:27:06.0461 5928 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
22:27:06.0469 5928 LSI_FC - ok
22:27:06.0525 5928 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
22:27:06.0533 5928 LSI_SAS - ok
22:27:06.0583 5928 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
22:27:06.0591 5928 LSI_SCSI - ok
22:27:06.0645 5928 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
22:27:06.0655 5928 luafv - ok
22:27:06.0706 5928 MBAMSwissArmy - ok
22:27:06.0789 5928 mdmxsdk - ok
22:27:06.0881 5928 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
22:27:06.0888 5928 megasas - ok
22:27:06.0966 5928 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
22:27:06.0967 5928 Modem - ok
22:27:07.0027 5928 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
22:27:07.0028 5928 monitor - ok
22:27:07.0098 5928 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
22:27:07.0110 5928 mouclass - ok
22:27:07.0139 5928 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
22:27:07.0144 5928 mouhid - ok
22:27:07.0201 5928 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
22:27:07.0255 5928 MountMgr - ok
22:27:07.0316 5928 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
22:27:07.0340 5928 mpio - ok
22:27:07.0383 5928 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
22:27:07.0417 5928 mpsdrv - ok
22:27:07.0478 5928 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
22:27:07.0493 5928 Mraid35x - ok
22:27:07.0570 5928 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
22:27:07.0587 5928 MRxDAV - ok
22:27:07.0640 5928 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:27:07.0650 5928 mrxsmb - ok
22:27:07.0701 5928 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:27:07.0728 5928 mrxsmb10 - ok
22:27:07.0745 5928 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:27:07.0775 5928 mrxsmb20 - ok
22:27:07.0805 5928 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
22:27:07.0814 5928 msahci - ok
22:27:07.0848 5928 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
22:27:07.0857 5928 msdsm - ok
22:27:07.0962 5928 MSDV (343291a4dfd7c923c3f71f550830ec1c) C:\Windows\system32\DRIVERS\msdv.sys
22:27:07.0968 5928 MSDV - ok
22:27:08.0024 5928 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
22:27:08.0029 5928 Msfs - ok
22:27:08.0094 5928 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
22:27:08.0120 5928 msisadrv - ok
22:27:08.0174 5928 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
22:27:08.0216 5928 MSKSSRV - ok
22:27:08.0272 5928 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
22:27:08.0290 5928 MSPCLOCK - ok
22:27:08.0324 5928 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
22:27:08.0373 5928 MSPQM - ok
22:27:08.0419 5928 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
22:27:08.0556 5928 MsRPC - ok
22:27:08.0607 5928 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
22:27:08.0608 5928 mssmbios - ok
22:27:08.0646 5928 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
22:27:08.0651 5928 MSTEE - ok
22:27:08.0679 5928 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
22:27:08.0686 5928 Mup - ok
22:27:08.0744 5928 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
22:27:08.0753 5928 NativeWifiP - ok
22:27:08.0798 5928 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
22:27:08.0803 5928 NDIS - ok
22:27:08.0847 5928 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
22:27:08.0852 5928 NdisTapi - ok
22:27:08.0921 5928 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
22:27:08.0926 5928 Ndisuio - ok
22:27:08.0978 5928 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:27:08.0987 5928 NdisWan - ok
22:27:09.0019 5928 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
22:27:09.0066 5928 NDProxy - ok
22:27:09.0145 5928 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
22:27:09.0203 5928 NetBIOS - ok
22:27:09.0257 5928 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
22:27:09.0273 5928 netbt - ok
22:27:09.0440 5928 NETw4v32 (1d73499a6664b4da05d750ff83fdb274) C:\Windows\system32\DRIVERS\NETw4v32.sys
22:27:09.0639 5928 NETw4v32 - ok
22:27:10.0013 5928 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
22:27:10.0038 5928 nfrd960 - ok
22:27:10.0151 5928 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
22:27:10.0157 5928 Npfs - ok
22:27:10.0208 5928 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
22:27:10.0217 5928 nsiproxy - ok
22:27:10.0341 5928 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
22:27:10.0429 5928 Ntfs - ok
22:27:10.0472 5928 NTIDrvr (7f1c1f78d709c4a54cbb46ede7e0b48d) C:\Windows\system32\DRIVERS\NTIDrvr.sys
22:27:10.0476 5928 NTIDrvr - ok
22:27:10.0513 5928 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
22:27:10.0536 5928 ntrigdigi - ok
22:27:10.0578 5928 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
22:27:10.0583 5928 Null - ok
22:27:10.0799 5928 nvlddmkm (8e5e17b69830d7cc4691a8e564870c46) C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:27:11.0004 5928 nvlddmkm - ok
22:27:11.0106 5928 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
22:27:11.0189 5928 nvraid - ok
22:27:11.0225 5928 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
22:27:11.0261 5928 nvstor - ok
22:27:11.0309 5928 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
22:27:11.0365 5928 nv_agp - ok
22:27:11.0383 5928 NwlnkFlt - ok
22:27:11.0403 5928 NwlnkFwd - ok
22:27:11.0475 5928 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
22:27:11.0476 5928 ohci1394 - ok
22:27:11.0562 5928 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
22:27:11.0578 5928 Parport - ok
22:27:11.0626 5928 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
22:27:11.0651 5928 partmgr - ok
22:27:11.0677 5928 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
22:27:11.0681 5928 Parvdm - ok
22:27:11.0729 5928 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
22:27:11.0745 5928 pci - ok
22:27:11.0776 5928 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
22:27:11.0781 5928 pciide - ok
22:27:11.0817 5928 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
22:27:11.0829 5928 pcmcia - ok
22:27:11.0917 5928 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
22:27:12.0021 5928 PEAUTH - ok
22:27:12.0106 5928 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
22:27:12.0115 5928 PptpMiniport - ok
22:27:12.0160 5928 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
22:27:12.0168 5928 Processor - ok
22:27:12.0234 5928 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
22:27:12.0236 5928 PSched - ok
22:27:12.0278 5928 PSDFilter (e801d5cc24e1cf18fa87d24d7074b876) C:\Windows\system32\DRIVERS\psdfilter.sys
22:27:12.0286 5928 PSDFilter - ok
22:27:12.0331 5928 PSDNServ (24b5e3429f7f0e779fc2e6e36a0a5f73) C:\Windows\system32\drivers\PSDNServ.sys
22:27:12.0336 5928 PSDNServ - ok
22:27:12.0375 5928 psdvdisk (01cbfd08c0e8a6106bb26fcda297154e) C:\Windows\system32\drivers\psdvdisk.sys
22:27:12.0409 5928 psdvdisk - ok
22:27:12.0477 5928 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
22:27:12.0538 5928 ql2300 - ok
22:27:12.0573 5928 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
22:27:12.0585 5928 ql40xx - ok
22:27:12.0640 5928 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
22:27:12.0652 5928 QWAVEdrv - ok
22:27:12.0704 5928 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
22:27:12.0709 5928 RasAcd - ok
22:27:12.0765 5928 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:27:12.0774 5928 Rasl2tp - ok
22:27:12.0819 5928 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
22:27:12.0825 5928 RasPppoe - ok
22:27:12.0897 5928 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
22:27:12.0907 5928 RasSstp - ok
22:27:12.0992 5928 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
22:27:13.0014 5928 rdbss - ok
22:27:13.0067 5928 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:27:13.0071 5928 RDPCDD - ok
22:27:13.0562 5928 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
22:27:13.0597 5928 rdpdr - ok
22:27:14.0092 5928 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
22:27:14.0097 5928 RDPENCDD - ok
22:27:14.0599 5928 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
22:27:14.0614 5928 RDPWD - ok
22:27:15.0318 5928 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
22:27:15.0325 5928 rimmptsk - ok
22:27:15.0358 5928 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
22:27:15.0367 5928 rimsptsk - ok
22:27:15.0397 5928 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
22:27:15.0405 5928 rismxdp - ok
22:27:15.0458 5928 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
22:27:15.0468 5928 rspndr - ok
22:27:15.0512 5928 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
22:27:15.0542 5928 sbp2port - ok
22:27:15.0623 5928 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
22:27:15.0635 5928 sdbus - ok
22:27:15.0830 5928 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:27:15.0837 5928 secdrv - ok
22:27:16.0386 5928 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
22:27:16.0393 5928 Serenum - ok
22:27:17.0155 5928 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
22:27:17.0167 5928 Serial - ok
22:27:18.0042 5928 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
22:27:18.0051 5928 sermouse - ok
22:27:18.0492 5928 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
22:27:18.0498 5928 sffdisk - ok
22:27:18.0772 5928 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
22:27:18.0779 5928 sffp_mmc - ok
22:27:19.0261 5928 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:27:19.0267 5928 sffp_sd - ok
22:27:20.0609 5928 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
22:27:20.0616 5928 sfloppy - ok
22:27:20.0931 5928 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
22:27:20.0943 5928 sisagp - ok
22:27:21.0068 5928 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
22:27:21.0076 5928 SiSRaid2 - ok
22:27:21.0701 5928 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
22:27:21.0712 5928 SiSRaid4 - ok
22:27:21.0972 5928 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
22:27:21.0982 5928 Smb - ok
22:27:22.0940 5928 SNP2UVC (1c550748f896e53b7b0fe7717845132b) C:\Windows\system32\DRIVERS\snp2uvc.sys
22:27:23.0507 5928 SNP2UVC - ok
22:27:24.0266 5928 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
22:27:24.0306 5928 spldr - ok
22:27:25.0800 5928 sptd (71e276f6d189413266ea22171806597b) C:\Windows\system32\Drivers\sptd.sys
22:27:25.0800 5928 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
22:27:25.0804 5928 sptd ( LockedFile.Multi.Generic ) - warning
22:27:25.0804 5928 sptd - detected LockedFile.Multi.Generic (1)
22:27:26.0809 5928 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
22:27:28.0200 5928 srv - ok
22:27:28.0889 5928 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
22:27:28.0902 5928 srv2 - ok
22:27:29.0870 5928 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
22:27:29.0883 5928 srvnet - ok
22:27:30.0022 5928 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
22:27:30.0029 5928 ssmdrv - ok
22:27:30.0748 5928 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
22:27:30.0757 5928 swenum - ok
22:27:31.0291 5928 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
22:27:31.0301 5928 Symc8xx - ok
22:27:31.0593 5928 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
22:27:31.0601 5928 Sym_hi - ok
22:27:32.0637 5928 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
22:27:32.0647 5928 Sym_u3 - ok
22:27:33.0606 5928 SynTP (5d6e865780aae258aba1a1484782cfec) C:\Windows\system32\DRIVERS\SynTP.sys
22:27:33.0622 5928 SynTP - ok
22:27:35.0361 5928 Tcpip (2756186e287139310997090797e0182b) C:\Windows\system32\drivers\tcpip.sys
22:27:35.0501 5928 Tcpip - ok
22:27:36.0573 5928 Tcpip6 (2756186e287139310997090797e0182b) C:\Windows\system32\DRIVERS\tcpip.sys
22:27:36.0586 5928 Tcpip6 - ok
22:27:37.0810 5928 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
22:27:37.0818 5928 tcpipreg - ok
22:27:38.0016 5928 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
22:27:38.0022 5928 TDPIPE - ok
22:27:38.0803 5928 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
22:27:39.0153 5928 TDTCP - ok
22:27:40.0164 5928 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
22:27:40.0174 5928 tdx - ok
22:27:41.0050 5928 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
22:27:41.0061 5928 TermDD - ok
22:27:42.0029 5928 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:27:42.0098 5928 tssecsrv - ok
22:27:42.0326 5928 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
22:27:42.0332 5928 tunmp - ok
22:27:42.0910 5928 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
22:27:42.0918 5928 tunnel - ok
22:27:43.0215 5928 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
22:27:43.0286 5928 uagp35 - ok
22:27:44.0269 5928 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
22:27:44.0525 5928 udfs - ok
22:27:45.0141 5928 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
22:27:45.0152 5928 uliagpkx - ok
22:27:45.0918 5928 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
22:27:45.0933 5928 uliahci - ok
22:27:46.0806 5928 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
22:27:46.0830 5928 UlSata - ok
22:27:47.0354 5928 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
22:27:47.0367 5928 ulsata2 - ok
22:27:48.0060 5928 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
22:27:48.0069 5928 umbus - ok
22:27:48.0646 5928 usbbus (8ef48ff1c23b1ce6f96d09a45959eb20) C:\Windows\system32\DRIVERS\lgusbbus.sys
22:27:48.0653 5928 usbbus - ok
22:27:49.0090 5928 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
22:27:49.0100 5928 usbccgp - ok
22:27:50.0036 5928 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
22:27:50.0052 5928 usbcir - ok
22:27:50.0349 5928 UsbDiag (a0e24c5c2d0cff04bbd3753a72fae80b) C:\Windows\system32\DRIVERS\lgusbdiag.sys
22:27:50.0587 5928 UsbDiag - ok
22:27:51.0546 5928 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
22:27:51.0555 5928 usbehci - ok
22:27:51.0880 5928 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
22:27:51.0895 5928 usbhub - ok
22:27:52.0182 5928 USBModem (cc09a1132b1f6a8362107cc134e90d0b) C:\Windows\system32\DRIVERS\lgusbmodem.sys
22:27:52.0190 5928 USBModem - ok
22:27:52.0308 5928 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
22:27:52.0315 5928 usbohci - ok
22:27:52.0430 5928 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
22:27:52.0437 5928 usbprint - ok
22:27:52.0643 5928 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
22:27:52.0651 5928 usbscan - ok
22:27:52.0818 5928 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:27:52.0828 5928 USBSTOR - ok
22:27:53.0025 5928 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
22:27:53.0032 5928 usbuhci - ok
22:27:53.0185 5928 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
22:27:53.0193 5928 vga - ok
22:27:53.0348 5928 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
22:27:53.0359 5928 VgaSave - ok
22:27:53.0518 5928 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
22:27:53.0559 5928 viaagp - ok
22:27:53.0731 5928 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
22:27:53.0741 5928 ViaC7 - ok
22:27:53.0944 5928 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
22:27:53.0953 5928 viaide - ok
22:27:54.0002 5928 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
22:27:54.0014 5928 volmgr - ok
22:27:54.0065 5928 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
22:27:54.0121 5928 volmgrx - ok
22:27:54.0184 5928 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
22:27:54.0204 5928 volsnap - ok
22:27:54.0312 5928 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
22:27:54.0325 5928 vsmraid - ok
22:27:54.0420 5928 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
22:27:54.0427 5928 WacomPen - ok
22:27:54.0481 5928 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:27:54.0492 5928 Wanarp - ok
22:27:54.0572 5928 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:27:54.0575 5928 Wanarpv6 - ok
22:27:54.0629 5928 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
22:27:54.0638 5928 Wd - ok
22:27:54.0711 5928 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
22:27:54.0740 5928 Wdf01000 - ok
22:27:54.0829 5928 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
22:27:54.0866 5928 winachsf - ok
22:27:54.0912 5928 winbondcir (3fa87d56769838aac82fafc3e78fc732) C:\Windows\system32\DRIVERS\winbondcir.sys
22:27:54.0922 5928 winbondcir - ok
22:27:55.0033 5928 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:27:55.0038 5928 WmiAcpi - ok
22:27:55.0124 5928 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
22:27:55.0130 5928 WpdUsb - ok
22:27:55.0182 5928 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
22:27:55.0187 5928 ws2ifsl - ok
22:27:55.0256 5928 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:27:55.0264 5928 WUDFRd - ok
22:27:55.0388 5928 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} (8098180b3f6c430a4e60333bc036f936) C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl
22:27:55.0391 5928 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} - ok
22:27:55.0431 5928 MBR (0x1B8) (e1d1d586ac841525e8c087b729eeb6a0) \Device\Harddisk0\DR0
22:27:55.0433 5928 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - infected
22:27:55.0433 5928 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
22:27:55.0451 5928 Boot (0x1200) (0afa126cc3c0fc8856dea4d31b80a5f0) \Device\Harddisk0\DR0\Partition0
22:27:55.0452 5928 \Device\Harddisk0\DR0\Partition0 - ok
22:27:55.0472 5928 Boot (0x1200) (95a5101931566967ac8fdcb2c0621581) \Device\Harddisk0\DR0\Partition1
22:27:55.0474 5928 \Device\Harddisk0\DR0\Partition1 - ok
22:27:55.0475 5928 ============================================================
22:27:55.0475 5928 Scan finished
22:27:55.0475 5928 ============================================================
22:27:55.0498 4240 Detected object count: 2
22:27:55.0498 4240 Actual detected object count: 2
22:30:15.0312 4240 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:30:15.0313 4240 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
22:30:17.0817 4240 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - will be cured on reboot
22:30:17.0822 4240 \Device\Harddisk0\DR0 - ok
22:30:17.0824 4240 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Cure
22:30:22.0593 5592 Deinitialize success
0
Utilisateur anonyme
 
ca doit deja aller mieux là...
0
cls03
 
j'ai refais un scan avec avira, voici le rapport



Avira AntiVir Personal
Date de création du fichier de rapport : samedi 15 octobre 2011 21:28

La recherche porte sur 3395449 souches de virus.

Le programme fonctionne en version intégrale illimitée.
Les services en ligne sont disponibles.

Détenteur de la licence : Avira AntiVir Personal - Free Antivirus
Numéro de série : 0000149996-ADJIE-0000001
Plateforme : Windows Vista
Version de Windows : (Service Pack 2) [6.0.6002]
Mode Boot : Démarré normalement
Identifiant : SYSTEM
Nom de l'ordinateur : PC-DE-CÉLINE

Informations de version :
BUILD.DAT : 10.2.0.150 35935 Bytes 26/07/2011 11:07:00
AVSCAN.EXE : 10.3.0.7 484008 Bytes 30/08/2011 19:13:22
AVSCAN.DLL : 10.0.5.0 56680 Bytes 30/08/2011 19:13:22
LUKE.DLL : 10.3.0.5 45416 Bytes 30/08/2011 19:13:32
LUKERES.DLL : 10.0.0.0 13672 Bytes 17/08/2010 12:39:11
AVSCPLR.DLL : 10.3.0.7 119656 Bytes 30/08/2011 19:13:36
AVREG.DLL : 10.3.0.9 88833 Bytes 30/08/2011 19:13:36
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 20:35:33
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 21:18:00
VBASE002.VDF : 7.11.3.0 1950720 Bytes 09/02/2011 19:16:39
VBASE003.VDF : 7.11.5.225 1980416 Bytes 07/04/2011 20:04:33
VBASE004.VDF : 7.11.8.178 2354176 Bytes 31/05/2011 20:58:27
VBASE005.VDF : 7.11.10.251 1788416 Bytes 07/07/2011 19:31:02
VBASE006.VDF : 7.11.13.60 6411776 Bytes 16/08/2011 18:10:55
VBASE007.VDF : 7.11.15.106 2389504 Bytes 05/10/2011 16:01:28
VBASE008.VDF : 7.11.15.107 2048 Bytes 05/10/2011 16:01:28
VBASE009.VDF : 7.11.15.108 2048 Bytes 05/10/2011 16:01:29
VBASE010.VDF : 7.11.15.109 2048 Bytes 05/10/2011 16:01:29
VBASE011.VDF : 7.11.15.110 2048 Bytes 05/10/2011 16:01:29
VBASE012.VDF : 7.11.15.111 2048 Bytes 05/10/2011 16:01:29
VBASE013.VDF : 7.11.15.144 161792 Bytes 07/10/2011 18:53:48
VBASE014.VDF : 7.11.15.177 130048 Bytes 10/10/2011 19:09:12
VBASE015.VDF : 7.11.15.213 113664 Bytes 11/10/2011 19:09:13
VBASE016.VDF : 7.11.16.1 163328 Bytes 14/10/2011 20:23:13
VBASE017.VDF : 7.11.16.2 2048 Bytes 14/10/2011 20:23:14
VBASE018.VDF : 7.11.16.3 2048 Bytes 14/10/2011 20:23:14
VBASE019.VDF : 7.11.16.4 2048 Bytes 14/10/2011 20:23:14
VBASE020.VDF : 7.11.16.5 2048 Bytes 14/10/2011 20:23:14
VBASE021.VDF : 7.11.16.6 2048 Bytes 14/10/2011 20:23:14
VBASE022.VDF : 7.11.16.7 2048 Bytes 14/10/2011 20:23:14
VBASE023.VDF : 7.11.16.8 2048 Bytes 14/10/2011 20:23:14
VBASE024.VDF : 7.11.16.9 2048 Bytes 14/10/2011 20:23:14
VBASE025.VDF : 7.11.16.10 2048 Bytes 14/10/2011 20:23:14
VBASE026.VDF : 7.11.16.11 2048 Bytes 14/10/2011 20:23:14
VBASE027.VDF : 7.11.16.12 2048 Bytes 14/10/2011 20:23:14
VBASE028.VDF : 7.11.16.13 2048 Bytes 14/10/2011 20:23:15
VBASE029.VDF : 7.11.16.14 2048 Bytes 14/10/2011 20:23:15
VBASE030.VDF : 7.11.16.15 2048 Bytes 14/10/2011 20:23:15
VBASE031.VDF : 7.11.16.18 15360 Bytes 14/10/2011 20:23:15
Version du moteur : 8.2.6.84
AEVDF.DLL : 8.1.2.1 106868 Bytes 01/08/2010 19:30:53
AESCRIPT.DLL : 8.1.3.81 467322 Bytes 05/10/2011 16:01:44
AESCN.DLL : 8.1.7.2 127349 Bytes 25/11/2010 19:54:18
AESBX.DLL : 8.2.1.34 323957 Bytes 05/06/2011 09:09:48
AERDL.DLL : 8.1.9.15 639348 Bytes 11/09/2011 18:59:39
AEPACK.DLL : 8.2.10.11 684408 Bytes 24/09/2011 18:54:56
AEOFFICE.DLL : 8.1.2.15 201083 Bytes 17/09/2011 11:36:39
AEHEUR.DLL : 8.1.2.180 3748217 Bytes 12/10/2011 19:09:22
AEHELP.DLL : 8.1.17.7 254327 Bytes 30/07/2011 07:24:49
AEGEN.DLL : 8.1.5.9 401780 Bytes 27/08/2011 19:26:59
AEEMU.DLL : 8.1.3.0 393589 Bytes 25/11/2010 19:54:15
AECORE.DLL : 8.1.23.0 196983 Bytes 27/08/2011 19:26:58
AEBB.DLL : 8.1.1.0 53618 Bytes 24/04/2010 19:19:30
AVWINLL.DLL : 10.0.0.0 19304 Bytes 17/08/2010 12:38:56
AVPREF.DLL : 10.0.3.2 44904 Bytes 30/08/2011 19:13:22
AVREP.DLL : 10.0.0.10 174120 Bytes 19/05/2011 19:19:36
AVARKT.DLL : 10.0.26.1 255336 Bytes 30/08/2011 19:13:17
AVEVTLOG.DLL : 10.0.0.9 203112 Bytes 30/08/2011 19:13:19
SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/06/2010 14:28:02
AVSMTP.DLL : 10.0.0.17 63848 Bytes 17/08/2010 12:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 17/06/2010 14:28:01
RCIMAGE.DLL : 10.0.0.35 2589544 Bytes 30/08/2011 19:13:08
RCTEXT.DLL : 10.0.64.0 100712 Bytes 30/08/2011 19:13:09

Configuration pour la recherche actuelle :
Nom de la tâche...............................: Contrôle intégral du système
Fichier de configuration......................: C:\program files\avira\antivir desktop\sysscan.avp
Documentation.................................: par défaut
Action principale.............................: interactif
Action secondaire.............................: ignorer
Recherche sur les secteurs d'amorçage maître..: marche
Recherche sur les secteurs d'amorçage.........: marche
Secteurs d'amorçage...........................: C:, D:,
Recherche dans les programmes actifs..........: marche
Programmes en cours étendus...................: marche
Recherche en cours sur l'enregistrement.......: marche
Recherche de Rootkits.........................: marche
Contrôle d'intégrité de fichiers système......: arrêt
Fichier mode de recherche.....................: Tous les fichiers
Recherche sur les archives....................: marche
Limiter la profondeur de récursivité..........: 20
Archive Smart Extensions......................: marche
Heuristique de macrovirus.....................: marche
Heuristique fichier...........................: avancé
Catégories de dangers divergentes.............: +APPL,+GAME,+JOKE,+PCK,+SPR,

Début de la recherche : samedi 15 octobre 2011 21:28

La recherche d'objets cachés commence.

La recherche sur les processus démarrés commence :
Processus de recherche 'mscorsvw.exe' - '33' module(s) sont contrôlés
Processus de recherche 'mcbuilder.exe' - '20' module(s) sont contrôlés
Processus de recherche 'taskeng.exe' - '24' module(s) sont contrôlés
Processus de recherche 'taskeng.exe' - '24' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '30' module(s) sont contrôlés
Processus de recherche 'vssvc.exe' - '49' module(s) sont contrôlés
Processus de recherche 'avscan.exe' - '76' module(s) sont contrôlés
Processus de recherche 'avscan.exe' - '28' module(s) sont contrôlés
Processus de recherche 'avcenter.exe' - '65' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '21' module(s) sont contrôlés
Processus de recherche 'mscorsvw.exe' - '36' module(s) sont contrôlés
Processus de recherche 'taskeng.exe' - '49' module(s) sont contrôlés
Processus de recherche 'unsecapp.exe' - '28' module(s) sont contrôlés
Processus de recherche 'wmiprvse.exe' - '55' module(s) sont contrôlés
Processus de recherche 'unsecapp.exe' - '28' module(s) sont contrôlés
Processus de recherche 'wmiprvse.exe' - '34' module(s) sont contrôlés
Processus de recherche 'capuserv.exe' - '70' module(s) sont contrôlés
Processus de recherche 'eRecoveryService.exe' - '47' module(s) sont contrôlés
Processus de recherche 'SearchIndexer.exe' - '59' module(s) sont contrôlés
Processus de recherche 'WLIDSvcM.exe' - '16' module(s) sont contrôlés
Processus de recherche 'ePowerSvc.exe' - '54' module(s) sont contrôlés
Processus de recherche 'WLIDSVC.EXE' - '69' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '7' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '44' module(s) sont contrôlés
Processus de recherche 'StarWindServiceAE.exe' - '36' module(s) sont contrôlés
Processus de recherche 'RichVideo.exe' - '22' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '42' module(s) sont contrôlés
Processus de recherche 'ERAGENT.EXE' - '31' module(s) sont contrôlés
Processus de recherche 'MobilityService.exe' - '37' module(s) sont contrôlés
Processus de recherche 'LSSrvc.exe' - '20' module(s) sont contrôlés
Processus de recherche 'IAANTMon.exe' - '36' module(s) sont contrôlés
Processus de recherche 'RtkBtMnt.exe' - '29' module(s) sont contrôlés
Processus de recherche 'ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE' - '119' module(s) sont contrôlés
Processus de recherche 'eNet Service.exe' - '51' module(s) sont contrôlés
Processus de recherche 'EPOWER_DMC.EXE' - '52' module(s) sont contrôlés
Processus de recherche 'ENMTRAY.EXE' - '91' module(s) sont contrôlés
Processus de recherche 'ehmsas.exe' - '19' module(s) sont contrôlés
Processus de recherche 'rundll32.exe' - '44' module(s) sont contrôlés
Processus de recherche 'ehtray.exe' - '26' module(s) sont contrôlés
Processus de recherche 'avshadow.exe' - '33' module(s) sont contrôlés
Processus de recherche 'eLockServ.exe' - '42' module(s) sont contrôlés
Processus de recherche 'eDSService.exe' - '31' module(s) sont contrôlés
Processus de recherche 'avguard.exe' - '64' module(s) sont contrôlés
Processus de recherche 'armsvc.exe' - '25' module(s) sont contrôlés
Processus de recherche 'avgnt.exe' - '54' module(s) sont contrôlés
Processus de recherche 'rundll32.exe' - '35' module(s) sont contrôlés
Processus de recherche 'RtHDVCpl.exe' - '50' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '59' module(s) sont contrôlés
Processus de recherche 'sched.exe' - '55' module(s) sont contrôlés
Processus de recherche 'taskeng.exe' - '82' module(s) sont contrôlés
Processus de recherche 'spoolsv.exe' - '86' module(s) sont contrôlés
Processus de recherche 'Explorer.EXE' - '128' module(s) sont contrôlés
Processus de recherche 'Dwm.exe' - '31' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '94' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '81' module(s) sont contrôlés
Processus de recherche 'SLsvc.exe' - '23' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '37' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '152' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '115' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '64' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '48' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '35' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '40' module(s) sont contrôlés
Processus de recherche 'winlogon.exe' - '30' module(s) sont contrôlés
Processus de recherche 'lsm.exe' - '22' module(s) sont contrôlés
Processus de recherche 'lsass.exe' - '60' module(s) sont contrôlés
Processus de recherche 'services.exe' - '33' module(s) sont contrôlés
Processus de recherche 'csrss.exe' - '14' module(s) sont contrôlés
Processus de recherche 'wininit.exe' - '26' module(s) sont contrôlés
Processus de recherche 'csrss.exe' - '14' module(s) sont contrôlés
Processus de recherche 'smss.exe' - '2' module(s) sont contrôlés

La recherche sur les secteurs d'amorçage maître commence :
Secteur d'amorçage maître HD0
[INFO] Aucun virus trouvé !

La recherche sur les secteurs d'amorçage commence :
Secteur d'amorçage 'C:\'
[INFO] Aucun virus trouvé !
Secteur d'amorçage 'D:\'
[INFO] Aucun virus trouvé !

La recherche sur les renvois aux fichiers exécutables (registre) commence :
Le registre a été contrôlé ( '739' fichiers).


La recherche sur les fichiers sélectionnés commence :

Recherche débutant dans 'C:\' <ACER>
C:\BigFishGamesCache\GameManager\GameDB\F5225T1L4\F5225T1L4.zip.001
[AVERTISSEMENT] Impossible de lire le fichier !
C:\Windows\SoftwareDistribution\Download\69bea2bed5a5ee2ff732854dbfa0e304ee96e020
[0] Type d'archive: Portable Executable Resource
--> resource54
[1] Type d'archive: CAB (Microsoft)
--> WriterProdLang.7z
[2] Type d'archive: 7-Zip
--> WriterProdLang.cab
[3] Type d'archive: CAB (Microsoft)
--> writerprodlang.msi
[AVERTISSEMENT] Impossible de lire le fichier !
--> resource86
[1] Type d'archive: CAB (Microsoft)
--> LanguageSelector64.7z
[2] Type d'archive: 7-Zip
--> LanguageSelector64.cab
[3] Type d'archive: CAB (Microsoft)
--> LanguageSelector64.msi
[AVERTISSEMENT] Impossible de lire le fichier !
Recherche débutant dans 'D:\' <DATA>


Fin de la recherche : samedi 15 octobre 2011 22:56
Temps nécessaire: 1:28:05 Heure(s)

La recherche a été effectuée intégralement

32656 Les répertoires ont été contrôlés
490966 Des fichiers ont été contrôlés
0 Des virus ou programmes indésirables ont été trouvés
0 Des fichiers ont été classés comme suspects
0 Des fichiers ont été supprimés
0 Des virus ou programmes indésirables ont été réparés
0 Les fichiers ont été déplacés dans la quarantaine
0 Les fichiers ont été renommés
0 Impossible de scanner des fichiers
490966 Fichiers non infectés
2947 Les archives ont été contrôlées
3 Avertissements
0 Consignes
631158 Des objets ont été contrôlés lors du Rootkitscan
0 Des objets cachés ont été trouvés
0
cls03
 
je fais quoi pour les 3 avertissements?
0
Utilisateur anonyme
 
les avertissement sont normaux

============

https://forums.commentcamarche.net/forum/affich-23342171-comment-se-debarrasser-de-trojan?page=2#66

tu n'as pas repondu à ca
0
cls03
 
c'est cool je n'ai plus ces fenêtres intempestives qui me signalaient que mon pc était infecté.

ça veut dire que tout est Ok? je n'ai plus de virus?
0