Probleme connection internet virus
Résolu
Alex251297
Messages postés
68
Date d'inscription
Statut
Membre
Dernière intervention
-
g3n-h@ckm@n Messages postés 13238 Date d'inscription Statut Membre Dernière intervention -
g3n-h@ckm@n Messages postés 13238 Date d'inscription Statut Membre Dernière intervention -
Bonjour,
Je présente mon problème ce matin tout allais bien ma connexion marchais et l'après midi je suis partis chez des gens et en revenant ma connexion a internet ne marchais plus j'étais juste connecté sur skype tout marchais bien mais par sur les navigateurs et jeux en réseau , j'ai donc décidé de redémarrer et la l'icône de connexion internet ne détectais plus rien et était barré d'une croix rouge donc même skype ne marchais plus
Je précise que je suis sur un autre ordinateur mais je peux tout de même télecharger des logiciel vous permetant de m'aider et les transferer sur l'autre PC a l'aide d'une clef USB :)
Je sais que ce n'est pas al catégorie appropriée mais je pense que c'est un virus ou autre donc je poste ici ^^
Merci, Cordialement
Alex251297
Je présente mon problème ce matin tout allais bien ma connexion marchais et l'après midi je suis partis chez des gens et en revenant ma connexion a internet ne marchais plus j'étais juste connecté sur skype tout marchais bien mais par sur les navigateurs et jeux en réseau , j'ai donc décidé de redémarrer et la l'icône de connexion internet ne détectais plus rien et était barré d'une croix rouge donc même skype ne marchais plus
Je précise que je suis sur un autre ordinateur mais je peux tout de même télecharger des logiciel vous permetant de m'aider et les transferer sur l'autre PC a l'aide d'une clef USB :)
Je sais que ce n'est pas al catégorie appropriée mais je pense que c'est un virus ou autre donc je poste ici ^^
Merci, Cordialement
Alex251297
A voir également:
- Probleme connection internet virus
- Gmail connection - Guide
- Virus mcafee - Accueil - Piratage
- Gps sans internet - Guide
- Complete internet repair - Télécharger - Web & Internet
- D'où peut venir un problème de connexion internet sur un ordinateur ? - Guide
52 réponses
envoie , voir ?
Alex251297
Messages postés
68
Date d'inscription
Statut
Membre
Dernière intervention
1
http://www.noelshack.com/2013-20-1368480891-antivir.png
g3n-h@ckm@n
Messages postés
13238
Date d'inscription
Statut
Membre
Dernière intervention
948
?
Alex251297
Messages postés
68
Date d'inscription
Statut
Membre
Dernière intervention
1
zut epic fail
g3n-h@ckm@n
Messages postés
13238
Date d'inscription
Statut
Membre
Dernière intervention
948
lol
Alex251297
Messages postés
68
Date d'inscription
Statut
Membre
Dernière intervention
1
Voila :D pas epic fail ^^ http://www.noelshack.com/2013-20-1368481689-dossier-temp.png
ok
ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous "Personnalisation" :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\xhunter1.sys -- (xhunter1)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\vtany.sys -- (vtany)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
:Files
C:\Program Files\Pando Networks
C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
@Alternate Data Stream - 12 bytes -> C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}
:commands
[CLEARALLRESTOREPOINTS]
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur "Correction" pour lancer la suppression.
▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous "Personnalisation" :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\xhunter1.sys -- (xhunter1)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\vtany.sys -- (vtany)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
:Files
C:\Program Files\Pando Networks
C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
@Alternate Data Stream - 12 bytes -> C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}
:commands
[CLEARALLRESTOREPOINTS]
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur "Correction" pour lancer la suppression.
▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
Sans les processus etc cochés
===========
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Service xhunter1 stopped successfully!
Service xhunter1 deleted successfully!
File C:\Windows\xhunter1.sys not found.
Service XDva401 stopped successfully!
Service XDva401 deleted successfully!
File C:\Windows\system32\XDva401.sys not found.
Service vtany stopped successfully!
Service vtany deleted successfully!
File C:\Windows\vtany.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully.
========== FILES ==========
C:\Program Files\Pando Networks folder moved successfully.
C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 moved successfully.
ADS C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: Alexis
->Temp folder emptied: 3845803 bytes
->Temporary Internet Files folder emptied: 13959051 bytes
->FireFox cache emptied: 105460744 bytes
->Google Chrome cache emptied: 275964239 bytes
->Flash cache emptied: 1748 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8549768 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 389,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 05142013_175546
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
=========
Avec les processus etc cochés
=========
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Error: No service named xhunter1 was found to stop!
Service\Driver key xhunter1 not found.
File C:\Windows\xhunter1.sys not found.
Error: No service named XDva401 was found to stop!
Service\Driver key XDva401 not found.
File C:\Windows\system32\XDva401.sys not found.
Error: No service named vtany was found to stop!
Service\Driver key vtany not found.
File C:\Windows\vtany.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ not found.
========== FILES ==========
File\Folder C:\Program Files\Pando Networks not found.
File\Folder C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 not found.
Unable to delete ADS C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} .
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: Alexis
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 128 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 05142013_180434
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
===========
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Service xhunter1 stopped successfully!
Service xhunter1 deleted successfully!
File C:\Windows\xhunter1.sys not found.
Service XDva401 stopped successfully!
Service XDva401 deleted successfully!
File C:\Windows\system32\XDva401.sys not found.
Service vtany stopped successfully!
Service vtany deleted successfully!
File C:\Windows\vtany.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully.
========== FILES ==========
C:\Program Files\Pando Networks folder moved successfully.
C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 moved successfully.
ADS C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: Alexis
->Temp folder emptied: 3845803 bytes
->Temporary Internet Files folder emptied: 13959051 bytes
->FireFox cache emptied: 105460744 bytes
->Google Chrome cache emptied: 275964239 bytes
->Flash cache emptied: 1748 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8549768 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 389,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 05142013_175546
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
=========
Avec les processus etc cochés
=========
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Error: No service named xhunter1 was found to stop!
Service\Driver key xhunter1 not found.
File C:\Windows\xhunter1.sys not found.
Error: No service named XDva401 was found to stop!
Service\Driver key XDva401 not found.
File C:\Windows\system32\XDva401.sys not found.
Error: No service named vtany was found to stop!
Service\Driver key vtany not found.
File C:\Windows\vtany.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ not found.
========== FILES ==========
File\Folder C:\Program Files\Pando Networks not found.
File\Folder C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 not found.
Unable to delete ADS C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} .
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: Alexis
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 128 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 05142013_180434
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan | g3n-h@ckm@n | Saachaa | 3.0512 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
~ ¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 20:51:31
~ Update on 12/05/2013 | 13.30 by g3n-h@ckm@n
~ Evolution : http://www.security-helpzone.com/forum/Forum-Mises-%C3%A0-jour-Pre-Scan | http://sosvirus.org/viewforum.php?f=229
~ Pre_Script Infos : http://sosvirus.org/viewtopic.php?f=228&t=312 | http://www.security-helpzone.com/forum/Thread-Les-Switches
~ Pre_scan Feedbacks : http://sosvirus.org/viewforum.php?f=233 | http://www.security-helpzone.com/forum/Forum-Feedbacks-Pre-Scan
~ [Alexis (Administrator)] - [ALEXIS-PC]
~ SID = S-1-5-21-562231591-2248875222-1900388517-1000
~ System : Windows 7 Ultimate (32 bits) Ultimate Service Pack 1
~ ProcessorNameString : AMD Athlon(tm) 7550 Dual-Core Processor
~ Identifier : x86 Family 16 Model 2 Stepping 3
~ Mémory RAM = Total (KB) : 3013110 | Free (KB) : 1987280
~ Pagefile = Total (KB) : 6024470 | Free (KB) : 5034340
~ Virtual = Total (KB) : 2097020 | Free (KB) : 1984660
¤¤¤¤¤¤¤¤¤¤ | Boot's scripts
¤¤¤¤¤¤¤¤¤¤ | Drives
c:\ -> [Fixed] | [] | Total : 105140 Mo | Free : 24140 Mo -> NTFS
d:\ -> [CDROM] | [WUSB600N] | Total : 160 Mo | Free : 0 Mo -> CDFS
f:\ -> [Fixed] | [Nouveau nom] | Total : 200000 Mo | Free : 173730 Mo -> NTFS
¤¤¤¤¤¤¤¤¤¤ | Windows Updates
Last(s) détection(s) : 2013-05-11 16:54:29
Last(s) download(s) : 2013-05-10 06:47:07
Last(s) installation(s) : 2013-05-10 08:44:43
¤¤¤¤¤¤¤¤¤¤ | Sessions
~ C:\Windows\system32\config\systemprofile
~ C:\Windows\ServiceProfiles\LocalService
~ C:\Windows\ServiceProfiles\NetworkService
~ C:\Users\Alexis
~ C:\Users\UpdatusUser
New restorepoint created
¤¤¤¤¤¤¤¤¤¤ | stopped Processes
(1164) -- explorer.exe
(1208) -- ctfmon.exe
¤¤¤¤¤¤¤¤¤¤ | Running processes
Boot : Safemode
¤¤¤¤¤¤¤¤¤¤ | Winlogon User : OK !
¤¤¤¤¤¤¤¤¤¤ | Winlogon Machine : OK !
Changed : [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]|[AutoRestartShell] : 1 -> 0
¤¤¤¤¤¤¤¤¤¤ | Associations : OK !
¤
Navigators settings associations are OK !
¤¤¤¤¤¤¤¤¤¤ | Registry
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]|[Hidden] : 2 -> 0
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel]|[AllItemsIconView] : 0 -> 1
¤¤¤¤¤¤¤¤¤¤ | SafeBoot | Control | Repair
Safeboot Keys are O.K
Alternate shell is OK !
¤
Safeboot Minimal Subkeys : O.K !
¤
Safeboot Network Subkeys : O.K !
¤¤¤¤¤¤¤¤¤¤ | IFEO : OK !
¤¤¤¤¤¤¤¤¤¤ | Mountpoints2
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{35ba7147-2f4b-11e2-b245-806e6f6e6963} | AutoRun\command] : D:\start.exe
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{40f1820a-a124-11e2-9b59-0026183337e0} | AutoRun\command] : G:\Autorun.exe
Contenu de D:\Autorun.inf :
[autorun]
OPEN=start.exe
ICON=install.ico
¤¤¤¤¤¤¤¤¤¤ | Windows
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]|[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
Winsrv : OK !
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[AppInit_DLLS] :
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[LoadAppInit_DLLs] : 0
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[Programs] : com exe bat pif cmd
¤¤¤¤¤¤¤¤¤¤ | Security Center : OK !
¤¤¤¤¤¤¤¤¤¤ | Services Corrections
Repaired : [HKLM | Services\Compbatt] : 3 -> 0
Repaired : [HKLM | Services\agp440] : 3 -> 2
Repaired : [HKLM | Services\Bits] : 3 -> 2
Repaired : [HKLM | Services\EapHost] : 3 -> 2
Repaired : [HKLM | Services\SppSvc] : 3 -> 2
Repaired : [HKLM | Services\windefend] : 3 -> 2
Repaired : [HKLM | Services\wudfsvc] : 3 -> 2
Repaired : [HKLM | Services\WerSvc] : 3 -> 2
¤¤¤¤¤¤¤¤¤¤ | Internet Explorer
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Internet Explorer\Main]|[Start Page] : about:blank -> https://www.google.com/?gws_rd=ssl
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Internet Explorer\Main]|[Search Page] : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] : about:blank -> https://www.msn.com/fr-fr/?ocid=iehp
¤
Repaired : [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[ProxyOverride] : *.local;<local> -> *.local
¤¤¤¤¤¤¤¤¤¤ | Hosts
C:\Windows\System32\Drivers\etc\hosts : Cleaned
¤¤¤¤¤¤¤¤¤¤ | Files | Folders | Registry
Moved to quarantine successfully : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Deleted : [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]|[BDAgent] : "C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe"
Will be moved at reboot : 1
Deleted : [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]|[Linksys Wireless Manager] : "C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" /cm /min /lcid 1036
Will be moved at reboot : 1
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] : Microsoft Windows Media Player 12.0
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] : Offline Browsing Pack
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] : 1
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] : 1
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] : Internet Explorer Help
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] : Internet Explorer Setup Tools
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] : Microsoft Windows Media Player
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] : Microsoft Windows Media Player
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] : Address Book 7
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] : Windows Desktop Update
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] : Windows Desktop Update
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] : 1
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] : 1
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] : Dynamic HTML Data Binding
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] : Internet Explorer Core Fonts
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] : HTML Help
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] : Themes Setup
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] : Themes Setup
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{3C3901C5-3455-3E0A-A214-0B093A5070A6}] :
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] : Microsoft Windows Script 5.6
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] : MSN Site Access
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] : Web Platform Customizations
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] : Web Platform Customizations
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}] : .NET Framework
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] : Active Directory Service Interface
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] : DirectDrawEx
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}] : .NET Framework
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}] : Adobe Flash Player 9 ActiveX
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] : %SystemRoot%\system32\msieftp.dll
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] : Google Chrome
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] : Google Chrome
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
Prefetch -> Emptied
Suspect : C:\Users\Alexis\AppData\Roaming\.minecraft\lastlogin
Suspect : 1
Suspect : C:\Users\Alexis\AppData\Roaming\Wireshark\recent
Suspect : C:\Users\Alexis\AppData\Roaming\Wireshark\recent_common
Suspect : 1
Suspect : C:\Users\Alexis\AppData\Roaming\Mumble\mumble.sqlite
Suspect : 1
Suspect : 1
Suspect : 1
Suspect : 1
Suspect : 1
¤¤¤¤¤¤¤¤¤¤ | Hidden files
~ [Windows] : Hidden : 5 | Restored : 5
~ [AppData] : Hidden : 1 | Restored : 1
¤¤¤¤¤¤¤¤¤¤ | Listing Partition(s)
Disk: 0 Size=305G
Pos MBRndx Type/Name Size Active Hide Start Sector Sectors
--- ------ ---------- ---- ------ ---- ------------ ------------
0 0 07-NTFS 100M Yes No 2,048 204,800
1 1 07-NTFS 105G No No 206,848 215,334,912
2 2 07-NTFS 200G No No 215,541,760 409,595,904
¤¤¤¤¤¤¤¤¤¤
[HKLM | Winlogon] | AutoRestartShell : 0 -> 1
End : 21:05:06
Pre_Scan_Protect.exe Stopped successfully !
Other report : C:\Users\Alexis\Desktop\Pre_Diag_13_05_2013_14_41_35.txt
Other report : C:\Users\Alexis\Desktop\Pre_Diag_13_05_2013_21_30_48.txt
Other report : C:\Users\Alexis\Desktop\Pre_Scan_12_05_2013_20_32_56.txt
¤¤¤¤¤¤¤¤¤¤ | Attempt to restart stopped
20:50:05 : ctfmon.exe
20:51:31 : ctfmon.exe
20:51:31 : ctfmon.exe
20:51:31 : ctfmon.exe
20:51:31 : ctfmon.exe
20:52:47 : ctfmon.exe
20:52:47 : ctfmon.exe
20:52:49 : ctfmon.exe
20:52:51 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:23 : ctfmon.exe
20:53:23 : ctfmon.exe
20:53:30 : ctfmon.exe
20:53:30 : ctfmon.exe
20:53:30 : ctfmon.exe
20:56:21 : ctfmon.exe
20:56:24 : ctfmon.exe
20:56:29 : ctfmon.exe
20:56:36 : ctfmon.exe
20:56:36 : ctfmon.exe
20:56:44 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:55 : ctfmon.exe
20:56:55 : ctfmon.exe
20:56:55 : ctfmon.exe
20:56:55 : ctfmon.exe
20:59:52 : ctfmon.exe
20:59:53 : ctfmon.exe
20:59:56 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:05:06 : ctfmon.exe
~ Thx to C_XX , Slyk for their help for the evolution of the tool
¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤ - 609
~ ¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 20:51:31
~ Update on 12/05/2013 | 13.30 by g3n-h@ckm@n
~ Evolution : http://www.security-helpzone.com/forum/Forum-Mises-%C3%A0-jour-Pre-Scan | http://sosvirus.org/viewforum.php?f=229
~ Pre_Script Infos : http://sosvirus.org/viewtopic.php?f=228&t=312 | http://www.security-helpzone.com/forum/Thread-Les-Switches
~ Pre_scan Feedbacks : http://sosvirus.org/viewforum.php?f=233 | http://www.security-helpzone.com/forum/Forum-Feedbacks-Pre-Scan
~ [Alexis (Administrator)] - [ALEXIS-PC]
~ SID = S-1-5-21-562231591-2248875222-1900388517-1000
~ System : Windows 7 Ultimate (32 bits) Ultimate Service Pack 1
~ ProcessorNameString : AMD Athlon(tm) 7550 Dual-Core Processor
~ Identifier : x86 Family 16 Model 2 Stepping 3
~ Mémory RAM = Total (KB) : 3013110 | Free (KB) : 1987280
~ Pagefile = Total (KB) : 6024470 | Free (KB) : 5034340
~ Virtual = Total (KB) : 2097020 | Free (KB) : 1984660
¤¤¤¤¤¤¤¤¤¤ | Boot's scripts
¤¤¤¤¤¤¤¤¤¤ | Drives
c:\ -> [Fixed] | [] | Total : 105140 Mo | Free : 24140 Mo -> NTFS
d:\ -> [CDROM] | [WUSB600N] | Total : 160 Mo | Free : 0 Mo -> CDFS
f:\ -> [Fixed] | [Nouveau nom] | Total : 200000 Mo | Free : 173730 Mo -> NTFS
¤¤¤¤¤¤¤¤¤¤ | Windows Updates
Last(s) détection(s) : 2013-05-11 16:54:29
Last(s) download(s) : 2013-05-10 06:47:07
Last(s) installation(s) : 2013-05-10 08:44:43
¤¤¤¤¤¤¤¤¤¤ | Sessions
~ C:\Windows\system32\config\systemprofile
~ C:\Windows\ServiceProfiles\LocalService
~ C:\Windows\ServiceProfiles\NetworkService
~ C:\Users\Alexis
~ C:\Users\UpdatusUser
New restorepoint created
¤¤¤¤¤¤¤¤¤¤ | stopped Processes
(1164) -- explorer.exe
(1208) -- ctfmon.exe
¤¤¤¤¤¤¤¤¤¤ | Running processes
Boot : Safemode
¤¤¤¤¤¤¤¤¤¤ | Winlogon User : OK !
¤¤¤¤¤¤¤¤¤¤ | Winlogon Machine : OK !
Changed : [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]|[AutoRestartShell] : 1 -> 0
¤¤¤¤¤¤¤¤¤¤ | Associations : OK !
¤
Navigators settings associations are OK !
¤¤¤¤¤¤¤¤¤¤ | Registry
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]|[Hidden] : 2 -> 0
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel]|[AllItemsIconView] : 0 -> 1
¤¤¤¤¤¤¤¤¤¤ | SafeBoot | Control | Repair
Safeboot Keys are O.K
Alternate shell is OK !
¤
Safeboot Minimal Subkeys : O.K !
¤
Safeboot Network Subkeys : O.K !
¤¤¤¤¤¤¤¤¤¤ | IFEO : OK !
¤¤¤¤¤¤¤¤¤¤ | Mountpoints2
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{35ba7147-2f4b-11e2-b245-806e6f6e6963} | AutoRun\command] : D:\start.exe
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{40f1820a-a124-11e2-9b59-0026183337e0} | AutoRun\command] : G:\Autorun.exe
Contenu de D:\Autorun.inf :
[autorun]
OPEN=start.exe
ICON=install.ico
¤¤¤¤¤¤¤¤¤¤ | Windows
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]|[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
Winsrv : OK !
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[AppInit_DLLS] :
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[LoadAppInit_DLLs] : 0
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[Programs] : com exe bat pif cmd
¤¤¤¤¤¤¤¤¤¤ | Security Center : OK !
¤¤¤¤¤¤¤¤¤¤ | Services Corrections
Repaired : [HKLM | Services\Compbatt] : 3 -> 0
Repaired : [HKLM | Services\agp440] : 3 -> 2
Repaired : [HKLM | Services\Bits] : 3 -> 2
Repaired : [HKLM | Services\EapHost] : 3 -> 2
Repaired : [HKLM | Services\SppSvc] : 3 -> 2
Repaired : [HKLM | Services\windefend] : 3 -> 2
Repaired : [HKLM | Services\wudfsvc] : 3 -> 2
Repaired : [HKLM | Services\WerSvc] : 3 -> 2
¤¤¤¤¤¤¤¤¤¤ | Internet Explorer
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Internet Explorer\Main]|[Start Page] : about:blank -> https://www.google.com/?gws_rd=ssl
Repaired : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Internet Explorer\Main]|[Search Page] : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] : about:blank -> https://www.msn.com/fr-fr/?ocid=iehp
¤
Repaired : [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[ProxyOverride] : *.local;<local> -> *.local
¤¤¤¤¤¤¤¤¤¤ | Hosts
C:\Windows\System32\Drivers\etc\hosts : Cleaned
¤¤¤¤¤¤¤¤¤¤ | Files | Folders | Registry
Moved to quarantine successfully : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Deleted : [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]|[BDAgent] : "C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe"
Will be moved at reboot : 1
Deleted : [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]|[Linksys Wireless Manager] : "C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" /cm /min /lcid 1036
Will be moved at reboot : 1
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] : Microsoft Windows Media Player 12.0
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] : Offline Browsing Pack
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] : 1
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] : 1
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] : Internet Explorer Help
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] : Internet Explorer Setup Tools
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] : Microsoft Windows Media Player
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] : Microsoft Windows Media Player
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] : Address Book 7
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] : Windows Desktop Update
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] : Windows Desktop Update
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] : 1
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] : 1
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] : Dynamic HTML Data Binding
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] : Internet Explorer Core Fonts
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] : HTML Help
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] : Themes Setup
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] : Themes Setup
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{3C3901C5-3455-3E0A-A214-0B093A5070A6}] :
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] : Microsoft Windows Script 5.6
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] : MSN Site Access
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] : Web Platform Customizations
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] : Web Platform Customizations
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}] : .NET Framework
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] : Active Directory Service Interface
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] : DirectDrawEx
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}] : .NET Framework
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}] : Adobe Flash Player 9 ActiveX
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] : %SystemRoot%\system32\msieftp.dll
Deleted : [HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] : Google Chrome
Deleted : [HKU\S-1-5-21-562231591-2248875222-1900388517-1000\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] : Google Chrome
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : 1
Will be moved at reboot : C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
Prefetch -> Emptied
Suspect : C:\Users\Alexis\AppData\Roaming\.minecraft\lastlogin
Suspect : 1
Suspect : C:\Users\Alexis\AppData\Roaming\Wireshark\recent
Suspect : C:\Users\Alexis\AppData\Roaming\Wireshark\recent_common
Suspect : 1
Suspect : C:\Users\Alexis\AppData\Roaming\Mumble\mumble.sqlite
Suspect : 1
Suspect : 1
Suspect : 1
Suspect : 1
Suspect : 1
¤¤¤¤¤¤¤¤¤¤ | Hidden files
~ [Windows] : Hidden : 5 | Restored : 5
~ [AppData] : Hidden : 1 | Restored : 1
¤¤¤¤¤¤¤¤¤¤ | Listing Partition(s)
Disk: 0 Size=305G
Pos MBRndx Type/Name Size Active Hide Start Sector Sectors
--- ------ ---------- ---- ------ ---- ------------ ------------
0 0 07-NTFS 100M Yes No 2,048 204,800
1 1 07-NTFS 105G No No 206,848 215,334,912
2 2 07-NTFS 200G No No 215,541,760 409,595,904
¤¤¤¤¤¤¤¤¤¤
[HKLM | Winlogon] | AutoRestartShell : 0 -> 1
End : 21:05:06
Pre_Scan_Protect.exe Stopped successfully !
Other report : C:\Users\Alexis\Desktop\Pre_Diag_13_05_2013_14_41_35.txt
Other report : C:\Users\Alexis\Desktop\Pre_Diag_13_05_2013_21_30_48.txt
Other report : C:\Users\Alexis\Desktop\Pre_Scan_12_05_2013_20_32_56.txt
¤¤¤¤¤¤¤¤¤¤ | Attempt to restart stopped
20:50:05 : ctfmon.exe
20:51:31 : ctfmon.exe
20:51:31 : ctfmon.exe
20:51:31 : ctfmon.exe
20:51:31 : ctfmon.exe
20:52:47 : ctfmon.exe
20:52:47 : ctfmon.exe
20:52:49 : ctfmon.exe
20:52:51 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:21 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:22 : ctfmon.exe
20:53:23 : ctfmon.exe
20:53:23 : ctfmon.exe
20:53:30 : ctfmon.exe
20:53:30 : ctfmon.exe
20:53:30 : ctfmon.exe
20:56:21 : ctfmon.exe
20:56:24 : ctfmon.exe
20:56:29 : ctfmon.exe
20:56:36 : ctfmon.exe
20:56:36 : ctfmon.exe
20:56:44 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:51 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:52 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:53 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:54 : ctfmon.exe
20:56:55 : ctfmon.exe
20:56:55 : ctfmon.exe
20:56:55 : ctfmon.exe
20:56:55 : ctfmon.exe
20:59:52 : ctfmon.exe
20:59:53 : ctfmon.exe
20:59:56 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
20:59:59 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:00 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:01 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:02 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:03 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:04 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:05 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:08 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:10 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:11 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:12 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:13 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:00:14 : ctfmon.exe
21:05:06 : ctfmon.exe
~ Thx to C_XX , Slyk for their help for the evolution of the tool
¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤ - 609