Probleme virus et autre,
Résolu/Fermé
A voir également:
- Probleme virus et autre,
- Youtu.be virus - Accueil - Guide virus
- Svchost.exe virus - Guide
- Faux message virus ordinateur - Accueil - Arnaque
- Tinyurl.com virus - Forum Virus
- Virus mcafee - Accueil - Piratage
77 réponses
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
11 oct. 2008 à 17:26
11 oct. 2008 à 17:26
"pouvez vous me dire comment suprimer no spam !!!!!"
---> Attends avant d'attaquer le pavé alors.
---> Attends avant d'attaquer le pavé alors.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
11 oct. 2008 à 18:08
11 oct. 2008 à 18:08
C'est toi qui a installé No-Spam ?
oui c'est moi il y a quelque temps, il est introuvable dans ajout et supprim programmes et pas faisable dans program files !!
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
11 oct. 2008 à 18:26
11 oct. 2008 à 18:26
"et pas faisable dans program files"
---> C'est à dire ?
---> C'est à dire ?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
je ne prétens pas le suprimmer de progran files mais comme je ne le trouve pas dans ajout supp etc... j'ai essayé et il me met un message d'inaccéssibilitée
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
11 oct. 2008 à 18:32
11 oct. 2008 à 18:32
Tu ne peux pas supprimer le dossier suivant :
C:\Program Files\StofWare\
C:\Program Files\StofWare\
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
11 oct. 2008 à 18:38
11 oct. 2008 à 18:38
---> Télécharge OTMoveIt2 à partir du lien ci-dessous :
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
---> Enregistre le fichier sur le Bureau.
---> Double-clique sur le fichier OTMoveIt2.exe pour lancer l'outil.
Assure-toi que la case Unregister Dll's and Ocx's soit bien cochée.
---> Copie l'intégralité du texte ci-dessous et colle-le dans la fenêtre intitulée Paste List Of Files/Folders to Move.
C:\Program Files\StofWare\
---> Clique sur MoveIt! pour lancer la suppression.
Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit.
Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
---> Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
---> Enregistre le fichier sur le Bureau.
---> Double-clique sur le fichier OTMoveIt2.exe pour lancer l'outil.
Assure-toi que la case Unregister Dll's and Ocx's soit bien cochée.
---> Copie l'intégralité du texte ci-dessous et colle-le dans la fenêtre intitulée Paste List Of Files/Folders to Move.
C:\Program Files\StofWare\
---> Clique sur MoveIt! pour lancer la suppression.
Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit.
Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
---> Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles.
C:\Program Files\StofWare\NoSpam\temp moved successfully.
C:\Program Files\StofWare\NoSpam moved successfully.
C:\Program Files\StofWare moved successfully.
File/Folder not found.
File/Folder not found.
File/Folder not found.
File/Folder ---> Clique sur MoveIt! pour lancer la suppression. not found.
File/Folder Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit. not found.
File/Folder not found.
File/Folder Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES. not found.
File/Folder not found.
File/Folder ---> Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles. not found.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10112008_184032
C:\Program Files\StofWare\NoSpam moved successfully.
C:\Program Files\StofWare moved successfully.
File/Folder not found.
File/Folder not found.
File/Folder not found.
File/Folder ---> Clique sur MoveIt! pour lancer la suppression. not found.
File/Folder Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit. not found.
File/Folder not found.
File/Folder Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES. not found.
File/Folder not found.
File/Folder ---> Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles. not found.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10112008_184032
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
11 oct. 2008 à 18:44
11 oct. 2008 à 18:44
Pourquoi tu mets mes indications dans OTMoveIt2 ? LOL
Le dossier a été déplacé, refais la procédure disponible ici :
http://www.commentcamarche.net/forum/affich 8811526 probleme virus et autre?page=3#57
Le dossier a été déplacé, refais la procédure disponible ici :
http://www.commentcamarche.net/forum/affich 8811526 probleme virus et autre?page=3#57
[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\HP_Propriétaire\*.msnfix: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\OtMoveIt2.exe: trouvé !
C:\Program Files\*.msnfix: trouvé !
C:\WINDOWS\*.msnfix: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\HP_Propriétaire\Bureau\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\HP_Propriétaire\*.msnfix: ERREUR DE SUPPRESSION !!
C:\Program Files\*.msnfix: ERREUR DE SUPPRESSION !!
C:\WINDOWS\*.msnfix: ERREUR DE SUPPRESSION !!
C:\_OtMoveIt: supprimé !
-->- Recherche:
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\HP_Propriétaire\*.msnfix: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\OtMoveIt2.exe: trouvé !
C:\Program Files\*.msnfix: trouvé !
C:\WINDOWS\*.msnfix: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\HP_Propriétaire\Bureau\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\HP_Propriétaire\*.msnfix: ERREUR DE SUPPRESSION !!
C:\Program Files\*.msnfix: ERREUR DE SUPPRESSION !!
C:\WINDOWS\*.msnfix: ERREUR DE SUPPRESSION !!
C:\_OtMoveIt: supprimé !
ComboFix 08-10-10.09 - HP_Propriétaire 2008-10-11 22:00:47.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.569 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\HP_Propriétaire\Bureau\combofix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Laurent\new.txt
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-11 au 2008-10-11 ))))))))))))))))))))))))))))))))))))
.
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Program Files\Avira
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-11 19:24 . 2008-10-11 19:24 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 19:24 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-11 19:24 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-11 19:18 . 2008-10-11 19:18 2,189,864 --a------ C:\Program Files\mbam-setup.exe
2008-10-11 18:48 . 2008-10-11 18:48 <REP> d-------- C:\Program Files\CCleaner
2008-10-11 18:47 . 2008-10-11 18:47 2,934,168 --a------ C:\Program Files\ccsetup212.exe
2008-10-11 15:55 . 2008-10-11 15:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-11 15:54 . 2008-10-11 15:54 2,344,429 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 15:42 . 2008-10-11 19:20 <REP> d-------- C:\Program Files\Unlocker
2008-10-05 15:42 . 2008-10-05 15:42 243,204 --------- C:\Program Files\unlocker1.8.7.exe
2008-10-05 15:39 . 2008-10-11 18:02 <REP> d-------- C:\Program Files\Trend Micro
2008-10-02 21:42 . 2008-10-02 21:42 335,112 --a------ C:\Program Files\Setup.exe
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\LocalLow
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Program Files\TVUPlayer
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 5,126,750 --a------ C:\Program Files\TVUPlayer.zip
2008-09-27 21:30 . 2008-09-27 21:43 <REP> d-------- C:\Program Files\TVAnts
2008-09-27 21:30 . 2008-09-27 21:42 2,889,336 --a------ C:\Program Files\TvantsSetup.EXE
2008-09-27 21:27 . 2008-09-27 21:53 <REP> d-------- C:\Program Files\SopCast
2008-09-27 21:24 . 2008-09-27 21:24 3,168,382 --a------ C:\Program Files\SopCast.zip
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-16 13:22 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-16 13:15 . 2008-09-16 13:15 <REP> d-------- C:\WINDOWS\EHome
2008-09-12 20:31 . 2008-09-13 16:01 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\skypePM
2008-09-12 20:23 . 2008-09-13 17:23 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\Skype
2008-09-12 20:20 . 2008-09-13 16:00 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
2008-09-12 20:20 . 2008-09-12 20:20 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-09-12 20:17 . 2008-09-17 08:26 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-09-12 20:12 . 2008-09-12 20:12 22,458,664 --a------ C:\Program Files\skypesetup.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 19:54 --------- d-----w C:\Program Files\Wanadoo
2008-10-11 14:31 --------- d-----w C:\Program Files\CFWebAdvancedU
2008-10-11 13:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-10-10 07:15 10,070 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
2008-10-06 02:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-01 00:22 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-08 16:07 20,134 ----a-w C:\WINDOWS\system32\akeugwc.exe
2008-09-02 15:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 13:47 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-08-20 13:46 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-20 13:43 357,936 ----a-w C:\Program Files\RealPlayer11GOLD_fr.exe
2008-08-19 14:26 --------- d-----w C:\Documents and Settings\Laurent\Application Data\Shareaza
2008-08-19 14:21 --------- d-----w C:\Program Files\Shareaza
2008-08-19 14:21 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Shareaza
2008-08-19 14:19 5,265,101 ----a-w C:\Program Files\shareaza_2.3.1.0_win32.exe
2008-08-19 13:53 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-19 13:51 14,156,170 ----a-w C:\Program Files\klcodec414f.exe
2008-08-11 17:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\IM
2008-08-11 09:59 --------- d-----w C:\Program Files\IncrediMail
2008-08-11 09:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-16 15:17 72,406 ----a-w C:\WINDOWS\system32\qqmeeic.exe
2008-04-28 10:43 1,616,896 ----a-w C:\Program Files\Relax zen.pps
2008-04-03 18:49 199,168 ----a-w C:\Program Files\Office 2007 Service Pack 1 Changes_all.xls
2008-01-30 19:45 19,004,560 ----a-w C:\Program Files\setupfre.exe
2008-01-30 19:38 22,845,992 ----a-w C:\Program Files\AdbeRdr80_fr_FR.exe
2007-12-21 09:07 18,164,640 ----a-w C:\Program Files\aaw2007.exe
2007-11-15 03:56 525,920 ----a-w C:\Program Files\music_fr.exe
2007-10-25 00:49 4,162,920 ----a-w C:\Program Files\sweetimsetup.exe
2007-10-24 14:58 2,628,296 ----a-w C:\Program Files\ccsetup201.exe
2007-10-24 14:46 19,271,412 ----a-w C:\Program Files\scribus-1.3.3.9-win32-install.exe
2007-10-18 12:58 1,622,584 ----a-w C:\Program Files\CuteWriter.exe
2007-10-16 08:31 7,218,088 ----a-w C:\Program Files\psa30se_fr_fr.exe
2007-10-07 15:49 3,851,578 ----a-w C:\Program Files\dvmpegv6.exe
2007-10-07 15:17 18,502,160 ------w C:\Program Files\te4xp_trial_4.3.1.222_setup_fr.exe
2007-10-07 15:06 20,227,576 ----a-w C:\Program Files\te4xp_retail_4.3.1.222_setup_fr.exe
2007-10-07 14:54 11,981,422 ------w C:\Program Files\gordian.knot.codec.pack.1.9.setup.exe
2007-10-07 14:37 1,052,120 ------w C:\Program Files\mjpegcodecv3.2.4.zip
2007-10-07 14:25 43 ----a-w C:\Program Files\i_view32.ini
2007-10-07 14:24 1,156,096 ----a-w C:\Program Files\iview400_setup.exe
2007-10-07 14:23 72,388 ----a-w C:\Program Files\french400.exe
2007-09-21 15:21 6,373,796 ----a-w C:\Program Files\Install Marco Polo Anglais 4.exe
2007-08-27 14:18 880,280 ----a-w C:\Program Files\Google_Updater.exe
2007-08-26 13:37 7,943,248 ----a-w C:\Program Files\CFP_Setup_English_2.4.18.184.exe
2007-07-30 12:08 21,093,584 ----a-w C:\Program Files\webinst.exe
2007-07-30 11:43 20,579,112 ----a-w C:\Program Files\mny07trl.exe
2007-07-30 11:16 5,548 ----a-w C:\Documents and Settings\Laurent\ufzzyb.exe
2007-07-30 11:10 5,548 ----a-w C:\Documents and Settings\Laurent\rjmdoi.exe
2007-07-30 11:03 5,548 ----a-w C:\Documents and Settings\Laurent\ucijdk.exe
2007-07-30 10:56 5,548 ----a-w C:\Documents and Settings\Laurent\tjkqil.exe
2007-07-30 10:50 5,548 ----a-w C:\Documents and Settings\Laurent\mwtznp.exe
2007-07-30 10:43 5,548 ----a-w C:\Documents and Settings\Laurent\roukhk.exe
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\Laurent\yeozdp.exe
2007-07-30 10:23 5,548 ----a-w C:\Documents and Settings\Laurent\oolqqh.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\Laurent\uzneyg.exe
2007-07-30 10:10 5,547 ----a-w C:\Documents and Settings\Laurent\fixgsm.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\Laurent\wzdrtk.exe
2007-07-30 09:56 5,548 ----a-w C:\Documents and Settings\Laurent\euhazs.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\Laurent\kuhtys.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\Laurent\iajavt.exe
2007-07-30 09:30 5,548 ----a-w C:\Documents and Settings\Laurent\rihjfm.exe
2007-07-30 09:16 5,548 ----a-w C:\Documents and Settings\Laurent\vghyeo.exe
2007-07-30 09:10 5,548 ----a-w C:\Documents and Settings\Laurent\gpqsfb.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\Laurent\utsywu.exe
2007-07-30 09:02 5,548 ----a-w C:\Documents and Settings\Laurent\mwqggi.exe
2007-07-04 14:30 12,819,266 ----a-w C:\Program Files\klcodec325f.exe
2007-06-16 12:31 25,839,688 ----a-w C:\Program Files\wmp11-windowsxp-x86-fr-fr.exe
2007-05-31 17:02 14,072,008 ----a-w C:\Program Files\installexperiencepack.exe
2007-05-22 17:32 228,352 ----a-w C:\Program Files\orange exe impots.exe
2007-05-20 18:56 5,576,280 ----a-w C:\Program Files\MsgPlusLive-420 messenger live.exe
2007-04-30 12:05 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-04-25 08:53 1,615 ----a-w C:\Program Files\changesfr.txt
2007-02-23 18:36 476,776 ----a-w C:\Program Files\incredimail_install.exe
2007-02-06 09:53 1,005,632 ----a-w C:\Program Files\messenger.MSNFix
2007-02-01 12:30 9,258,851 ----a-w C:\Program Files\gestionnaire_internethd.exe
2007-02-01 05:41 3,132,036 ----a-w C:\Program Files\orangedesktopsearch.exe
2007-01-14 20:25 545,960 ----a-w C:\Program Files\comite.exe
2007-10-07 14:57 56 --sh--r C:\WINDOWS\system32\48A91A5E46.sys
2007-10-07 14:57 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 122880]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Orange Desktop Search"="C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe" [2007-01-17 4938016]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-03-08 20480]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"EPSON Stylus DX4200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-08 98304]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-20 185896]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\J‚r“me\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - C:\Documents and Settings\HP_Propri‚taire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-04-09 152616]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-03-08 450560]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DVMA"= dvicmau.dll
"msacm.dvmpega"= dvacmau.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
--a------ 2004-10-14 17:55 32768 C:\PROGRA~1\Wanadoo\GestMAJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--a------ 2004-08-23 15:49 20480 C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 468768]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-04-03 C:\WINDOWS\Tasks\Restauration du système.job
- C:\WINDOWS\system32\Restore\rstrui.exe [2008-04-14 04:34]
2008-10-11 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Workflow - E:\install\Workflow.exe
HKLM-Run-PCDrProfiler - (no file)
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://mystart.incredimail.com/french/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Window Title =
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.hp.com/go/mypcchoice
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
R1 -: HKCU-SearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 -: { - C:\Program Files\Messenger\msmsgs.exe
O9 -: {C:\Program Files\Messenger\msmsgs.exe - -
O15 -: Trusted Zone: *.canalplay.com
O15 -: Trusted Zone: *.canalplusactive.com
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-11 22:06:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-11 22:07:17
ComboFix-quarantined-files.txt 2008-10-11 20:07:11
Avant-CF: 134 679 523 328 octets libres
Après-CF: 135,247,355,904 octets libres
298 --- E O F --- 2008-09-17 01:00:48
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.569 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\HP_Propriétaire\Bureau\combofix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Laurent\new.txt
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-11 au 2008-10-11 ))))))))))))))))))))))))))))))))))))
.
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Program Files\Avira
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-11 19:24 . 2008-10-11 19:24 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 19:24 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-11 19:24 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-11 19:18 . 2008-10-11 19:18 2,189,864 --a------ C:\Program Files\mbam-setup.exe
2008-10-11 18:48 . 2008-10-11 18:48 <REP> d-------- C:\Program Files\CCleaner
2008-10-11 18:47 . 2008-10-11 18:47 2,934,168 --a------ C:\Program Files\ccsetup212.exe
2008-10-11 15:55 . 2008-10-11 15:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-11 15:54 . 2008-10-11 15:54 2,344,429 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 15:42 . 2008-10-11 19:20 <REP> d-------- C:\Program Files\Unlocker
2008-10-05 15:42 . 2008-10-05 15:42 243,204 --------- C:\Program Files\unlocker1.8.7.exe
2008-10-05 15:39 . 2008-10-11 18:02 <REP> d-------- C:\Program Files\Trend Micro
2008-10-02 21:42 . 2008-10-02 21:42 335,112 --a------ C:\Program Files\Setup.exe
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\LocalLow
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Program Files\TVUPlayer
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 5,126,750 --a------ C:\Program Files\TVUPlayer.zip
2008-09-27 21:30 . 2008-09-27 21:43 <REP> d-------- C:\Program Files\TVAnts
2008-09-27 21:30 . 2008-09-27 21:42 2,889,336 --a------ C:\Program Files\TvantsSetup.EXE
2008-09-27 21:27 . 2008-09-27 21:53 <REP> d-------- C:\Program Files\SopCast
2008-09-27 21:24 . 2008-09-27 21:24 3,168,382 --a------ C:\Program Files\SopCast.zip
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-16 13:22 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-16 13:15 . 2008-09-16 13:15 <REP> d-------- C:\WINDOWS\EHome
2008-09-12 20:31 . 2008-09-13 16:01 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\skypePM
2008-09-12 20:23 . 2008-09-13 17:23 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\Skype
2008-09-12 20:20 . 2008-09-13 16:00 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
2008-09-12 20:20 . 2008-09-12 20:20 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-09-12 20:17 . 2008-09-17 08:26 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-09-12 20:12 . 2008-09-12 20:12 22,458,664 --a------ C:\Program Files\skypesetup.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 19:54 --------- d-----w C:\Program Files\Wanadoo
2008-10-11 14:31 --------- d-----w C:\Program Files\CFWebAdvancedU
2008-10-11 13:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-10-10 07:15 10,070 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
2008-10-06 02:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-01 00:22 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-08 16:07 20,134 ----a-w C:\WINDOWS\system32\akeugwc.exe
2008-09-02 15:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 13:47 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-08-20 13:46 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-20 13:43 357,936 ----a-w C:\Program Files\RealPlayer11GOLD_fr.exe
2008-08-19 14:26 --------- d-----w C:\Documents and Settings\Laurent\Application Data\Shareaza
2008-08-19 14:21 --------- d-----w C:\Program Files\Shareaza
2008-08-19 14:21 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Shareaza
2008-08-19 14:19 5,265,101 ----a-w C:\Program Files\shareaza_2.3.1.0_win32.exe
2008-08-19 13:53 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-19 13:51 14,156,170 ----a-w C:\Program Files\klcodec414f.exe
2008-08-11 17:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\IM
2008-08-11 09:59 --------- d-----w C:\Program Files\IncrediMail
2008-08-11 09:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-16 15:17 72,406 ----a-w C:\WINDOWS\system32\qqmeeic.exe
2008-04-28 10:43 1,616,896 ----a-w C:\Program Files\Relax zen.pps
2008-04-03 18:49 199,168 ----a-w C:\Program Files\Office 2007 Service Pack 1 Changes_all.xls
2008-01-30 19:45 19,004,560 ----a-w C:\Program Files\setupfre.exe
2008-01-30 19:38 22,845,992 ----a-w C:\Program Files\AdbeRdr80_fr_FR.exe
2007-12-21 09:07 18,164,640 ----a-w C:\Program Files\aaw2007.exe
2007-11-15 03:56 525,920 ----a-w C:\Program Files\music_fr.exe
2007-10-25 00:49 4,162,920 ----a-w C:\Program Files\sweetimsetup.exe
2007-10-24 14:58 2,628,296 ----a-w C:\Program Files\ccsetup201.exe
2007-10-24 14:46 19,271,412 ----a-w C:\Program Files\scribus-1.3.3.9-win32-install.exe
2007-10-18 12:58 1,622,584 ----a-w C:\Program Files\CuteWriter.exe
2007-10-16 08:31 7,218,088 ----a-w C:\Program Files\psa30se_fr_fr.exe
2007-10-07 15:49 3,851,578 ----a-w C:\Program Files\dvmpegv6.exe
2007-10-07 15:17 18,502,160 ------w C:\Program Files\te4xp_trial_4.3.1.222_setup_fr.exe
2007-10-07 15:06 20,227,576 ----a-w C:\Program Files\te4xp_retail_4.3.1.222_setup_fr.exe
2007-10-07 14:54 11,981,422 ------w C:\Program Files\gordian.knot.codec.pack.1.9.setup.exe
2007-10-07 14:37 1,052,120 ------w C:\Program Files\mjpegcodecv3.2.4.zip
2007-10-07 14:25 43 ----a-w C:\Program Files\i_view32.ini
2007-10-07 14:24 1,156,096 ----a-w C:\Program Files\iview400_setup.exe
2007-10-07 14:23 72,388 ----a-w C:\Program Files\french400.exe
2007-09-21 15:21 6,373,796 ----a-w C:\Program Files\Install Marco Polo Anglais 4.exe
2007-08-27 14:18 880,280 ----a-w C:\Program Files\Google_Updater.exe
2007-08-26 13:37 7,943,248 ----a-w C:\Program Files\CFP_Setup_English_2.4.18.184.exe
2007-07-30 12:08 21,093,584 ----a-w C:\Program Files\webinst.exe
2007-07-30 11:43 20,579,112 ----a-w C:\Program Files\mny07trl.exe
2007-07-30 11:16 5,548 ----a-w C:\Documents and Settings\Laurent\ufzzyb.exe
2007-07-30 11:10 5,548 ----a-w C:\Documents and Settings\Laurent\rjmdoi.exe
2007-07-30 11:03 5,548 ----a-w C:\Documents and Settings\Laurent\ucijdk.exe
2007-07-30 10:56 5,548 ----a-w C:\Documents and Settings\Laurent\tjkqil.exe
2007-07-30 10:50 5,548 ----a-w C:\Documents and Settings\Laurent\mwtznp.exe
2007-07-30 10:43 5,548 ----a-w C:\Documents and Settings\Laurent\roukhk.exe
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\Laurent\yeozdp.exe
2007-07-30 10:23 5,548 ----a-w C:\Documents and Settings\Laurent\oolqqh.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\Laurent\uzneyg.exe
2007-07-30 10:10 5,547 ----a-w C:\Documents and Settings\Laurent\fixgsm.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\Laurent\wzdrtk.exe
2007-07-30 09:56 5,548 ----a-w C:\Documents and Settings\Laurent\euhazs.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\Laurent\kuhtys.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\Laurent\iajavt.exe
2007-07-30 09:30 5,548 ----a-w C:\Documents and Settings\Laurent\rihjfm.exe
2007-07-30 09:16 5,548 ----a-w C:\Documents and Settings\Laurent\vghyeo.exe
2007-07-30 09:10 5,548 ----a-w C:\Documents and Settings\Laurent\gpqsfb.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\Laurent\utsywu.exe
2007-07-30 09:02 5,548 ----a-w C:\Documents and Settings\Laurent\mwqggi.exe
2007-07-04 14:30 12,819,266 ----a-w C:\Program Files\klcodec325f.exe
2007-06-16 12:31 25,839,688 ----a-w C:\Program Files\wmp11-windowsxp-x86-fr-fr.exe
2007-05-31 17:02 14,072,008 ----a-w C:\Program Files\installexperiencepack.exe
2007-05-22 17:32 228,352 ----a-w C:\Program Files\orange exe impots.exe
2007-05-20 18:56 5,576,280 ----a-w C:\Program Files\MsgPlusLive-420 messenger live.exe
2007-04-30 12:05 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-04-25 08:53 1,615 ----a-w C:\Program Files\changesfr.txt
2007-02-23 18:36 476,776 ----a-w C:\Program Files\incredimail_install.exe
2007-02-06 09:53 1,005,632 ----a-w C:\Program Files\messenger.MSNFix
2007-02-01 12:30 9,258,851 ----a-w C:\Program Files\gestionnaire_internethd.exe
2007-02-01 05:41 3,132,036 ----a-w C:\Program Files\orangedesktopsearch.exe
2007-01-14 20:25 545,960 ----a-w C:\Program Files\comite.exe
2007-10-07 14:57 56 --sh--r C:\WINDOWS\system32\48A91A5E46.sys
2007-10-07 14:57 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 122880]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Orange Desktop Search"="C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe" [2007-01-17 4938016]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-03-08 20480]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"EPSON Stylus DX4200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-08 98304]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-20 185896]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\J‚r“me\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - C:\Documents and Settings\HP_Propri‚taire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-04-09 152616]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-03-08 450560]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DVMA"= dvicmau.dll
"msacm.dvmpega"= dvacmau.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
--a------ 2004-10-14 17:55 32768 C:\PROGRA~1\Wanadoo\GestMAJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--a------ 2004-08-23 15:49 20480 C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 468768]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-04-03 C:\WINDOWS\Tasks\Restauration du système.job
- C:\WINDOWS\system32\Restore\rstrui.exe [2008-04-14 04:34]
2008-10-11 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Workflow - E:\install\Workflow.exe
HKLM-Run-PCDrProfiler - (no file)
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://mystart.incredimail.com/french/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Window Title =
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.hp.com/go/mypcchoice
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
R1 -: HKCU-SearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 -: { - C:\Program Files\Messenger\msmsgs.exe
O9 -: {C:\Program Files\Messenger\msmsgs.exe - -
O15 -: Trusted Zone: *.canalplay.com
O15 -: Trusted Zone: *.canalplusactive.com
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-11 22:06:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-11 22:07:17
ComboFix-quarantined-files.txt 2008-10-11 20:07:11
Avant-CF: 134 679 523 328 octets libres
Après-CF: 135,247,355,904 octets libres
298 --- E O F --- 2008-09-17 01:00:48
ComboFix 08-10-11.01 - HP_Propriétaire 2008-10-11 22:57:19.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.600 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\HP_Propriétaire\Bureau\combofix.exe
Commutateurs utilisés :: C:\Documents and Settings\HP_Propriétaire\Bureau\cfscript.txt
* Un nouveau point de restauration a été créé
FILE ::
C:\Documents and Settings\Laurent\euhazs.exe
C:\Documents and Settings\Laurent\fixgsm.exe
C:\Documents and Settings\Laurent\gpqsfb.exe
C:\Documents and Settings\Laurent\iajavt.exe
C:\Documents and Settings\Laurent\kuhtys.exe
C:\Documents and Settings\Laurent\mwqggi.exe
C:\Documents and Settings\Laurent\mwtznp.exe
C:\Documents and Settings\Laurent\oolqqh.exe
C:\Documents and Settings\Laurent\rihjfm.exe
C:\Documents and Settings\Laurent\rjmdoi.exe
C:\Documents and Settings\Laurent\roukhk.exe
C:\Documents and Settings\Laurent\tjkqil.exe
C:\Documents and Settings\Laurent\ucijdk.exe
C:\Documents and Settings\Laurent\ufzzyb.exe
C:\Documents and Settings\Laurent\utsywu.exe
C:\Documents and Settings\Laurent\uzneyg.exe
C:\Documents and Settings\Laurent\vghyeo.exe
C:\Documents and Settings\Laurent\wzdrtk.exe
C:\Documents and Settings\Laurent\yeozdp.exe
C:\Program Files\comite.exe
C:\Program Files\messenger.MSNFix
C:\Program Files\MsgPlusLive-420 messenger live.exe
C:\Program Files\orange exe impots.exe
C:\WINDOWS\system32\akeugwc.exe
C:\WINDOWS\system32\qqmeeic.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Laurent\euhazs.exe
C:\Documents and Settings\Laurent\fixgsm.exe
C:\Documents and Settings\Laurent\gpqsfb.exe
C:\Documents and Settings\Laurent\iajavt.exe
C:\Documents and Settings\Laurent\kuhtys.exe
C:\Documents and Settings\Laurent\mwqggi.exe
C:\Documents and Settings\Laurent\mwtznp.exe
C:\Documents and Settings\Laurent\oolqqh.exe
C:\Documents and Settings\Laurent\rihjfm.exe
C:\Documents and Settings\Laurent\rjmdoi.exe
C:\Documents and Settings\Laurent\roukhk.exe
C:\Documents and Settings\Laurent\tjkqil.exe
C:\Documents and Settings\Laurent\ucijdk.exe
C:\Documents and Settings\Laurent\ufzzyb.exe
C:\Documents and Settings\Laurent\utsywu.exe
C:\Documents and Settings\Laurent\uzneyg.exe
C:\Documents and Settings\Laurent\vghyeo.exe
C:\Documents and Settings\Laurent\wzdrtk.exe
C:\Documents and Settings\Laurent\yeozdp.exe
C:\Program Files\comite.exe
C:\Program Files\messenger.MSNFix
C:\Program Files\MsgPlusLive-420 messenger live.exe
C:\Program Files\orange exe impots.exe
C:\WINDOWS\system32\akeugwc.exe
C:\WINDOWS\system32\qqmeeic.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-11 au 2008-10-11 ))))))))))))))))))))))))))))))))))))
.
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Program Files\Avira
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-11 19:24 . 2008-10-11 19:24 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 19:24 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-11 19:24 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-11 19:18 . 2008-10-11 19:18 2,189,864 --a------ C:\Program Files\mbam-setup.exe
2008-10-11 18:48 . 2008-10-11 18:48 <REP> d-------- C:\Program Files\CCleaner
2008-10-11 18:47 . 2008-10-11 18:47 2,934,168 --a------ C:\Program Files\ccsetup212.exe
2008-10-11 15:55 . 2008-10-11 15:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-11 15:54 . 2008-10-11 15:54 2,344,429 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 15:42 . 2008-10-11 19:20 <REP> d-------- C:\Program Files\Unlocker
2008-10-05 15:42 . 2008-10-05 15:42 243,204 --------- C:\Program Files\unlocker1.8.7.exe
2008-10-05 15:39 . 2008-10-11 18:02 <REP> d-------- C:\Program Files\Trend Micro
2008-10-02 21:42 . 2008-10-02 21:42 335,112 --a------ C:\Program Files\Setup.exe
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\LocalLow
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Program Files\TVUPlayer
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 5,126,750 --a------ C:\Program Files\TVUPlayer.zip
2008-09-27 21:30 . 2008-09-27 21:43 <REP> d-------- C:\Program Files\TVAnts
2008-09-27 21:30 . 2008-09-27 21:42 2,889,336 --a------ C:\Program Files\TvantsSetup.EXE
2008-09-27 21:27 . 2008-09-27 21:53 <REP> d-------- C:\Program Files\SopCast
2008-09-27 21:24 . 2008-09-27 21:24 3,168,382 --a------ C:\Program Files\SopCast.zip
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-16 13:22 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-16 13:15 . 2008-09-16 13:15 <REP> d-------- C:\WINDOWS\EHome
2008-09-12 20:31 . 2008-09-13 16:01 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\skypePM
2008-09-12 20:23 . 2008-09-13 17:23 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\Skype
2008-09-12 20:20 . 2008-09-13 16:00 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
2008-09-12 20:20 . 2008-09-12 20:20 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-09-12 20:17 . 2008-09-17 08:26 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-09-12 20:12 . 2008-09-12 20:12 22,458,664 --a------ C:\Program Files\skypesetup.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 21:04 --------- d-----w C:\Program Files\Wanadoo
2008-10-11 14:31 --------- d-----w C:\Program Files\CFWebAdvancedU
2008-10-11 13:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-10-10 07:15 10,070 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
2008-10-06 02:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-01 00:22 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-02 15:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 13:47 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-08-20 13:46 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-20 13:43 357,936 ----a-w C:\Program Files\RealPlayer11GOLD_fr.exe
2008-08-19 14:26 --------- d-----w C:\Documents and Settings\Laurent\Application Data\Shareaza
2008-08-19 14:21 --------- d-----w C:\Program Files\Shareaza
2008-08-19 14:21 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Shareaza
2008-08-19 14:19 5,265,101 ----a-w C:\Program Files\shareaza_2.3.1.0_win32.exe
2008-08-19 13:53 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-19 13:51 14,156,170 ----a-w C:\Program Files\klcodec414f.exe
2008-08-11 17:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\IM
2008-08-11 09:59 --------- d-----w C:\Program Files\IncrediMail
2008-08-11 09:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-04-28 10:43 1,616,896 ----a-w C:\Program Files\Relax zen.pps
2008-04-03 18:49 199,168 ----a-w C:\Program Files\Office 2007 Service Pack 1 Changes_all.xls
2008-01-30 19:45 19,004,560 ----a-w C:\Program Files\setupfre.exe
2008-01-30 19:38 22,845,992 ----a-w C:\Program Files\AdbeRdr80_fr_FR.exe
2007-12-21 09:07 18,164,640 ----a-w C:\Program Files\aaw2007.exe
2007-11-15 03:56 525,920 ----a-w C:\Program Files\music_fr.exe
2007-10-25 00:49 4,162,920 ----a-w C:\Program Files\sweetimsetup.exe
2007-10-24 14:58 2,628,296 ----a-w C:\Program Files\ccsetup201.exe
2007-10-24 14:46 19,271,412 ----a-w C:\Program Files\scribus-1.3.3.9-win32-install.exe
2007-10-18 12:58 1,622,584 ----a-w C:\Program Files\CuteWriter.exe
2007-10-16 08:31 7,218,088 ----a-w C:\Program Files\psa30se_fr_fr.exe
2007-10-07 15:49 3,851,578 ----a-w C:\Program Files\dvmpegv6.exe
2007-10-07 15:17 18,502,160 ------w C:\Program Files\te4xp_trial_4.3.1.222_setup_fr.exe
2007-10-07 15:06 20,227,576 ----a-w C:\Program Files\te4xp_retail_4.3.1.222_setup_fr.exe
2007-10-07 14:54 11,981,422 ------w C:\Program Files\gordian.knot.codec.pack.1.9.setup.exe
2007-10-07 14:37 1,052,120 ------w C:\Program Files\mjpegcodecv3.2.4.zip
2007-10-07 14:25 43 ----a-w C:\Program Files\i_view32.ini
2007-10-07 14:24 1,156,096 ----a-w C:\Program Files\iview400_setup.exe
2007-10-07 14:23 72,388 ----a-w C:\Program Files\french400.exe
2007-09-21 15:21 6,373,796 ----a-w C:\Program Files\Install Marco Polo Anglais 4.exe
2007-08-27 14:18 880,280 ----a-w C:\Program Files\Google_Updater.exe
2007-08-26 13:37 7,943,248 ----a-w C:\Program Files\CFP_Setup_English_2.4.18.184.exe
2007-07-30 12:08 21,093,584 ----a-w C:\Program Files\webinst.exe
2007-07-30 11:43 20,579,112 ----a-w C:\Program Files\mny07trl.exe
2007-07-04 14:30 12,819,266 ----a-w C:\Program Files\klcodec325f.exe
2007-06-16 12:31 25,839,688 ----a-w C:\Program Files\wmp11-windowsxp-x86-fr-fr.exe
2007-05-31 17:02 14,072,008 ----a-w C:\Program Files\installexperiencepack.exe
2007-04-30 12:05 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-04-25 08:53 1,615 ----a-w C:\Program Files\changesfr.txt
2007-02-23 18:36 476,776 ----a-w C:\Program Files\incredimail_install.exe
2007-02-01 12:30 9,258,851 ----a-w C:\Program Files\gestionnaire_internethd.exe
2007-02-01 05:41 3,132,036 ----a-w C:\Program Files\orangedesktopsearch.exe
2007-10-07 14:57 56 --sh--r C:\WINDOWS\system32\48A91A5E46.sys
2007-10-07 14:57 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 122880]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Orange Desktop Search"="C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe" [2007-01-17 4938016]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-03-08 20480]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"EPSON Stylus DX4200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-08 98304]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\J‚r“me\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - C:\Documents and Settings\HP_Propri‚taire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-04-09 152616]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-03-08 450560]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DVMA"= dvicmau.dll
"msacm.dvmpega"= dvacmau.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
--a------ 2004-10-14 17:55 32768 C:\PROGRA~1\Wanadoo\GestMAJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--a------ 2004-08-23 15:49 20480 C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 468768]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
.
Contenu du dossier 'Tâches planifiées'
2008-04-03 C:\WINDOWS\Tasks\Restauration du système.job
- C:\WINDOWS\system32\Restore\rstrui.exe [2008-04-14 04:34]
2008-10-11 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-11 23:01:36
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\FTRTSVC.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\IncrediMail\bin\ImApp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\system32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\system32\searchprotocolhost.exe
C:\WINDOWS\system32\searchfilterhost.exe
.
**************************************************************************
.
Heure de fin: 2008-10-11 23:07:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-11 21:07:43
ComboFix2.txt 2008-10-11 20:07:18
Avant-CF: 137 439 821 824 octets libres
Après-CF: 137,418,485,760 octets libres
324 --- E O F --- 2008-09-17 01:00:48
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.600 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\HP_Propriétaire\Bureau\combofix.exe
Commutateurs utilisés :: C:\Documents and Settings\HP_Propriétaire\Bureau\cfscript.txt
* Un nouveau point de restauration a été créé
FILE ::
C:\Documents and Settings\Laurent\euhazs.exe
C:\Documents and Settings\Laurent\fixgsm.exe
C:\Documents and Settings\Laurent\gpqsfb.exe
C:\Documents and Settings\Laurent\iajavt.exe
C:\Documents and Settings\Laurent\kuhtys.exe
C:\Documents and Settings\Laurent\mwqggi.exe
C:\Documents and Settings\Laurent\mwtznp.exe
C:\Documents and Settings\Laurent\oolqqh.exe
C:\Documents and Settings\Laurent\rihjfm.exe
C:\Documents and Settings\Laurent\rjmdoi.exe
C:\Documents and Settings\Laurent\roukhk.exe
C:\Documents and Settings\Laurent\tjkqil.exe
C:\Documents and Settings\Laurent\ucijdk.exe
C:\Documents and Settings\Laurent\ufzzyb.exe
C:\Documents and Settings\Laurent\utsywu.exe
C:\Documents and Settings\Laurent\uzneyg.exe
C:\Documents and Settings\Laurent\vghyeo.exe
C:\Documents and Settings\Laurent\wzdrtk.exe
C:\Documents and Settings\Laurent\yeozdp.exe
C:\Program Files\comite.exe
C:\Program Files\messenger.MSNFix
C:\Program Files\MsgPlusLive-420 messenger live.exe
C:\Program Files\orange exe impots.exe
C:\WINDOWS\system32\akeugwc.exe
C:\WINDOWS\system32\qqmeeic.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Laurent\euhazs.exe
C:\Documents and Settings\Laurent\fixgsm.exe
C:\Documents and Settings\Laurent\gpqsfb.exe
C:\Documents and Settings\Laurent\iajavt.exe
C:\Documents and Settings\Laurent\kuhtys.exe
C:\Documents and Settings\Laurent\mwqggi.exe
C:\Documents and Settings\Laurent\mwtznp.exe
C:\Documents and Settings\Laurent\oolqqh.exe
C:\Documents and Settings\Laurent\rihjfm.exe
C:\Documents and Settings\Laurent\rjmdoi.exe
C:\Documents and Settings\Laurent\roukhk.exe
C:\Documents and Settings\Laurent\tjkqil.exe
C:\Documents and Settings\Laurent\ucijdk.exe
C:\Documents and Settings\Laurent\ufzzyb.exe
C:\Documents and Settings\Laurent\utsywu.exe
C:\Documents and Settings\Laurent\uzneyg.exe
C:\Documents and Settings\Laurent\vghyeo.exe
C:\Documents and Settings\Laurent\wzdrtk.exe
C:\Documents and Settings\Laurent\yeozdp.exe
C:\Program Files\comite.exe
C:\Program Files\messenger.MSNFix
C:\Program Files\MsgPlusLive-420 messenger live.exe
C:\Program Files\orange exe impots.exe
C:\WINDOWS\system32\akeugwc.exe
C:\WINDOWS\system32\qqmeeic.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-11 au 2008-10-11 ))))))))))))))))))))))))))))))))))))
.
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Program Files\Avira
2008-10-11 20:12 . 2008-10-11 20:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-11 19:24 . 2008-10-11 19:24 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 19:24 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-11 19:24 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-11 19:18 . 2008-10-11 19:18 2,189,864 --a------ C:\Program Files\mbam-setup.exe
2008-10-11 18:48 . 2008-10-11 18:48 <REP> d-------- C:\Program Files\CCleaner
2008-10-11 18:47 . 2008-10-11 18:47 2,934,168 --a------ C:\Program Files\ccsetup212.exe
2008-10-11 15:55 . 2008-10-11 15:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-11 15:54 . 2008-10-11 15:54 2,344,429 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-10 23:05 . 2008-10-10 23:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 15:42 . 2008-10-11 19:20 <REP> d-------- C:\Program Files\Unlocker
2008-10-05 15:42 . 2008-10-05 15:42 243,204 --------- C:\Program Files\unlocker1.8.7.exe
2008-10-05 15:39 . 2008-10-11 18:02 <REP> d-------- C:\Program Files\Trend Micro
2008-10-02 21:42 . 2008-10-02 21:42 335,112 --a------ C:\Program Files\Setup.exe
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\LocalLow
2008-09-27 21:46 . 2008-09-27 21:46 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\TVU Networks
2008-09-27 21:45 . 2008-09-27 21:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Program Files\TVUPlayer
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\LocalLow
2008-09-27 21:44 . 2008-09-27 21:44 5,126,750 --a------ C:\Program Files\TVUPlayer.zip
2008-09-27 21:30 . 2008-09-27 21:43 <REP> d-------- C:\Program Files\TVAnts
2008-09-27 21:30 . 2008-09-27 21:42 2,889,336 --a------ C:\Program Files\TvantsSetup.EXE
2008-09-27 21:27 . 2008-09-27 21:53 <REP> d-------- C:\Program Files\SopCast
2008-09-27 21:24 . 2008-09-27 21:24 3,168,382 --a------ C:\Program Files\SopCast.zip
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-16 13:25 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-16 13:22 . 2008-09-16 13:25 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-16 13:15 . 2008-09-16 13:15 <REP> d-------- C:\WINDOWS\EHome
2008-09-12 20:31 . 2008-09-13 16:01 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\skypePM
2008-09-12 20:23 . 2008-09-13 17:23 <REP> d-------- C:\Documents and Settings\Laurent\Application Data\Skype
2008-09-12 20:20 . 2008-09-13 16:00 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
2008-09-12 20:20 . 2008-09-12 20:20 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-09-12 20:17 . 2008-09-17 08:26 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-09-12 20:16 . 2008-09-12 20:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-09-12 20:12 . 2008-09-12 20:12 22,458,664 --a------ C:\Program Files\skypesetup.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 21:04 --------- d-----w C:\Program Files\Wanadoo
2008-10-11 14:31 --------- d-----w C:\Program Files\CFWebAdvancedU
2008-10-11 13:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-10-10 07:15 10,070 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
2008-10-06 02:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-01 00:22 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-02 15:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 13:47 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-08-20 13:46 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-20 13:43 357,936 ----a-w C:\Program Files\RealPlayer11GOLD_fr.exe
2008-08-19 14:26 --------- d-----w C:\Documents and Settings\Laurent\Application Data\Shareaza
2008-08-19 14:21 --------- d-----w C:\Program Files\Shareaza
2008-08-19 14:21 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Shareaza
2008-08-19 14:19 5,265,101 ----a-w C:\Program Files\shareaza_2.3.1.0_win32.exe
2008-08-19 13:53 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-19 13:51 14,156,170 ----a-w C:\Program Files\klcodec414f.exe
2008-08-11 17:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\IM
2008-08-11 09:59 --------- d-----w C:\Program Files\IncrediMail
2008-08-11 09:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-04-28 10:43 1,616,896 ----a-w C:\Program Files\Relax zen.pps
2008-04-03 18:49 199,168 ----a-w C:\Program Files\Office 2007 Service Pack 1 Changes_all.xls
2008-01-30 19:45 19,004,560 ----a-w C:\Program Files\setupfre.exe
2008-01-30 19:38 22,845,992 ----a-w C:\Program Files\AdbeRdr80_fr_FR.exe
2007-12-21 09:07 18,164,640 ----a-w C:\Program Files\aaw2007.exe
2007-11-15 03:56 525,920 ----a-w C:\Program Files\music_fr.exe
2007-10-25 00:49 4,162,920 ----a-w C:\Program Files\sweetimsetup.exe
2007-10-24 14:58 2,628,296 ----a-w C:\Program Files\ccsetup201.exe
2007-10-24 14:46 19,271,412 ----a-w C:\Program Files\scribus-1.3.3.9-win32-install.exe
2007-10-18 12:58 1,622,584 ----a-w C:\Program Files\CuteWriter.exe
2007-10-16 08:31 7,218,088 ----a-w C:\Program Files\psa30se_fr_fr.exe
2007-10-07 15:49 3,851,578 ----a-w C:\Program Files\dvmpegv6.exe
2007-10-07 15:17 18,502,160 ------w C:\Program Files\te4xp_trial_4.3.1.222_setup_fr.exe
2007-10-07 15:06 20,227,576 ----a-w C:\Program Files\te4xp_retail_4.3.1.222_setup_fr.exe
2007-10-07 14:54 11,981,422 ------w C:\Program Files\gordian.knot.codec.pack.1.9.setup.exe
2007-10-07 14:37 1,052,120 ------w C:\Program Files\mjpegcodecv3.2.4.zip
2007-10-07 14:25 43 ----a-w C:\Program Files\i_view32.ini
2007-10-07 14:24 1,156,096 ----a-w C:\Program Files\iview400_setup.exe
2007-10-07 14:23 72,388 ----a-w C:\Program Files\french400.exe
2007-09-21 15:21 6,373,796 ----a-w C:\Program Files\Install Marco Polo Anglais 4.exe
2007-08-27 14:18 880,280 ----a-w C:\Program Files\Google_Updater.exe
2007-08-26 13:37 7,943,248 ----a-w C:\Program Files\CFP_Setup_English_2.4.18.184.exe
2007-07-30 12:08 21,093,584 ----a-w C:\Program Files\webinst.exe
2007-07-30 11:43 20,579,112 ----a-w C:\Program Files\mny07trl.exe
2007-07-04 14:30 12,819,266 ----a-w C:\Program Files\klcodec325f.exe
2007-06-16 12:31 25,839,688 ----a-w C:\Program Files\wmp11-windowsxp-x86-fr-fr.exe
2007-05-31 17:02 14,072,008 ----a-w C:\Program Files\installexperiencepack.exe
2007-04-30 12:05 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-04-25 08:53 1,615 ----a-w C:\Program Files\changesfr.txt
2007-02-23 18:36 476,776 ----a-w C:\Program Files\incredimail_install.exe
2007-02-01 12:30 9,258,851 ----a-w C:\Program Files\gestionnaire_internethd.exe
2007-02-01 05:41 3,132,036 ----a-w C:\Program Files\orangedesktopsearch.exe
2007-10-07 14:57 56 --sh--r C:\WINDOWS\system32\48A91A5E46.sys
2007-10-07 14:57 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 122880]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Orange Desktop Search"="C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe" [2007-01-17 4938016]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-03-08 20480]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"EPSON Stylus DX4200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-08 98304]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\J‚r“me\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-02-27 27136]
C:\Documents and Settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - C:\Documents and Settings\HP_Propri‚taire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-04-09 152616]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-03-08 450560]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DVMA"= dvicmau.dll
"msacm.dvmpega"= dvacmau.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
--a------ 2004-10-14 17:55 32768 C:\PROGRA~1\Wanadoo\GestMAJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--a------ 2004-08-23 15:49 20480 C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 468768]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
.
Contenu du dossier 'Tâches planifiées'
2008-04-03 C:\WINDOWS\Tasks\Restauration du système.job
- C:\WINDOWS\system32\Restore\rstrui.exe [2008-04-14 04:34]
2008-10-11 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-11 23:01:36
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\FTRTSVC.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\IncrediMail\bin\ImApp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\system32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\system32\searchprotocolhost.exe
C:\WINDOWS\system32\searchfilterhost.exe
.
**************************************************************************
.
Heure de fin: 2008-10-11 23:07:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-11 21:07:43
ComboFix2.txt 2008-10-11 20:07:18
Avant-CF: 137 439 821 824 octets libres
Après-CF: 137,418,485,760 octets libres
324 --- E O F --- 2008-09-17 01:00:48
Avira AntiVir Personal
Report file date: samedi 11 octobre 2008 23:26
Scanning for 1677110 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: NOM-EB85C523610
Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
ANTIVIR2.VDF : 7.0.7.12 4066816 Bytes 08/10/2008 18:14:24
ANTIVIR3.VDF : 7.0.7.28 120320 Bytes 11/10/2008 18:14:25
Engineversion : 8.1.1.35
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.76 319867 Bytes 11/10/2008 18:14:36
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
AERDL.DLL : 8.1.1.2 438644 Bytes 11/10/2008 18:14:35
AEPACK.DLL : 8.1.2.3 364918 Bytes 11/10/2008 18:14:33
AEOFFICE.DLL : 8.1.0.25 196986 Bytes 11/10/2008 18:14:31
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 11/10/2008 18:14:30
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 11/10/2008 18:14:27
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 11/10/2008 18:14:26
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 11/10/2008 18:14:25
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 11 octobre 2008 23:26
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'issch.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Scan process 'ALCXMNTR.EXE' - '1' Module(s) have been scanned
Scan process 'WOOBrowser.exe' - '1' Module(s) have been scanned
Scan process 'kbd.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'Mise-a-jour-LiveSearch.exe' - '1' Module(s) have been scanned
Scan process 'Notification-LiveSearch.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
Scan process 'backWeb-8876480.exe' - '1' Module(s) have been scanned
Scan process 'OrangeDesktopSearch.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'searchindexer.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Scan process 'E_FATIAEE.EXE' - '1' Module(s) have been scanned
Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
53 processes with 53 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD2
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '73' files ).
Starting the file scan:
Begin scan in 'C:\' <HP_PAVILION>
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Laurent\Mes documents\Mes fichiers reçus\img_659_JPG.zip
[0] Archive type: ZIP
--> img_659_JPG.zip
[1] Archive type: ZIP
--> img865.jpg_jpolj@hotmail.fr.com
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to '49581bae.qua'!
Begin scan in 'D:\' <HP_RECOVERY>
End of the scan: dimanche 12 octobre 2008 00:10
Used time: 44:28 Minute(s)
The scan has been done completely.
8091 Scanning directories
534371 Files were scanned
1 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
1 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
534368 Files not concerned
15356 Archives were scanned
6 Warnings
1 Notes
Report file date: samedi 11 octobre 2008 23:26
Scanning for 1677110 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: NOM-EB85C523610
Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
ANTIVIR2.VDF : 7.0.7.12 4066816 Bytes 08/10/2008 18:14:24
ANTIVIR3.VDF : 7.0.7.28 120320 Bytes 11/10/2008 18:14:25
Engineversion : 8.1.1.35
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.76 319867 Bytes 11/10/2008 18:14:36
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
AERDL.DLL : 8.1.1.2 438644 Bytes 11/10/2008 18:14:35
AEPACK.DLL : 8.1.2.3 364918 Bytes 11/10/2008 18:14:33
AEOFFICE.DLL : 8.1.0.25 196986 Bytes 11/10/2008 18:14:31
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 11/10/2008 18:14:30
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 11/10/2008 18:14:27
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 11/10/2008 18:14:26
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 11/10/2008 18:14:25
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 11 octobre 2008 23:26
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'issch.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Scan process 'ALCXMNTR.EXE' - '1' Module(s) have been scanned
Scan process 'WOOBrowser.exe' - '1' Module(s) have been scanned
Scan process 'kbd.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'Mise-a-jour-LiveSearch.exe' - '1' Module(s) have been scanned
Scan process 'Notification-LiveSearch.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
Scan process 'backWeb-8876480.exe' - '1' Module(s) have been scanned
Scan process 'OrangeDesktopSearch.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'searchindexer.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Scan process 'E_FATIAEE.EXE' - '1' Module(s) have been scanned
Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
53 processes with 53 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD2
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '73' files ).
Starting the file scan:
Begin scan in 'C:\' <HP_PAVILION>
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Laurent\Mes documents\Mes fichiers reçus\img_659_JPG.zip
[0] Archive type: ZIP
--> img_659_JPG.zip
[1] Archive type: ZIP
--> img865.jpg_jpolj@hotmail.fr.com
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to '49581bae.qua'!
Begin scan in 'D:\' <HP_RECOVERY>
End of the scan: dimanche 12 octobre 2008 00:10
Used time: 44:28 Minute(s)
The scan has been done completely.
8091 Scanning directories
534371 Files were scanned
1 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
1 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
534368 Files not concerned
15356 Archives were scanned
6 Warnings
1 Notes
pas de y dans le script, (c/)
et le dossier sdfix ne se crée pas sur le bureau, j'en trouve un dans c/ est ce le meme ????
et le dossier sdfix ne se crée pas sur le bureau, j'en trouve un dans c/ est ce le meme ????
[b]SDFix: Version 1.234 [/b]
Run by HP_Propri‚taire on 12/10/2008 at 01:29
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\HP_Propri‚taire\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\17E.TMP - Deleted
C:\180.TMP - Deleted
C:\181.TMP - Deleted
C:\182.TMP - Deleted
C:\183.TMP - Deleted
C:\185.TMP - Deleted
C:\562148~1 - Deleted
C:\Program Files\Setup.exe - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-12 01:41:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"="C:\\Program Files\\IncrediMail\\bin\\ImLc.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
"C:\\Program Files\\Shareaza\\Shareaza.exe"="C:\\Program Files\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"="C:\\Program Files\\TVUPlayer\\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
"C:\\Program Files\\TVAnts\\Tvants.exe"="C:\\Program Files\\TVAnts\\Tvants.exe:*:Enabled:TVAnts"
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\HP_PRO~1\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Tue 15 Aug 2006 218 A.SHR --- "C:\BOOT.BAK"
Sun 7 Oct 2007 56 ..SHR --- "C:\WINDOWS\system32\48A91A5E46.sys"
Sun 7 Oct 2007 1,890 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 17 Feb 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 5 Mar 2008 243,200 ...H. --- "C:\Documents and Settings\HP_Propri‚taire\Bureau\~WRL0004.tmp"
Mon 7 Apr 2008 24,064 ...H. --- "C:\Documents and Settings\Laurent\Mes documents\~WRL3930.tmp"
Thu 10 May 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 3 Oct 2006 50,280 ...H. --- "C:\Program Files\Fichiers communs\Adobe\ESD\DLMCleanup.exe"
[b]Finished![/b]
Run by HP_Propri‚taire on 12/10/2008 at 01:29
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\HP_Propri‚taire\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\17E.TMP - Deleted
C:\180.TMP - Deleted
C:\181.TMP - Deleted
C:\182.TMP - Deleted
C:\183.TMP - Deleted
C:\185.TMP - Deleted
C:\562148~1 - Deleted
C:\Program Files\Setup.exe - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-12 01:41:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"="C:\\Program Files\\IncrediMail\\bin\\ImLc.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
"C:\\Program Files\\Shareaza\\Shareaza.exe"="C:\\Program Files\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"="C:\\Program Files\\TVUPlayer\\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
"C:\\Program Files\\TVAnts\\Tvants.exe"="C:\\Program Files\\TVAnts\\Tvants.exe:*:Enabled:TVAnts"
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\HP_PRO~1\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Tue 15 Aug 2006 218 A.SHR --- "C:\BOOT.BAK"
Sun 7 Oct 2007 56 ..SHR --- "C:\WINDOWS\system32\48A91A5E46.sys"
Sun 7 Oct 2007 1,890 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 17 Feb 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 5 Mar 2008 243,200 ...H. --- "C:\Documents and Settings\HP_Propri‚taire\Bureau\~WRL0004.tmp"
Mon 7 Apr 2008 24,064 ...H. --- "C:\Documents and Settings\Laurent\Mes documents\~WRL3930.tmp"
Thu 10 May 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 3 Oct 2006 50,280 ...H. --- "C:\Program Files\Fichiers communs\Adobe\ESD\DLMCleanup.exe"
[b]Finished![/b]
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.336.Crwl L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.336.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.ci L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wsb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy186.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_368.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Bureau\SDFix\backups\backups.zip/backups/Setup.exe Infecté : not-a-virus:WebToolbar.Win32.Zango.bg ignoré
C:\Documents and Settings\HP_Propriétaire\Bureau\SDFix\backups\backups.zip ZIP: infecté - 1 ignoré
C:\Documents and Settings\HP_Propriétaire\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Microsoft\Desktop Search\Logs\OTFSMonLog.txt L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Documents.dfd L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Documents.did L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Documents.dsd L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kdb L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kdl L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kib L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kpf L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.ksb L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Historique\History.IE5\MSHist012008101220081013\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\hpodvd09.log L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\Perflib_Perfdata_c1c.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\_hphtra07.log L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\~DF757C.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chandir.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chandir.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chn.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chn.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\D0000000.FCS L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\inuse.txt L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\L0000006.FCS L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\main.log L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_die.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_die.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_dnd.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_dnd.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_ext.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_ext.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_rcv.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_rcv.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\storydb.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\storydb.idx L'objet est verrouillé ignoré
C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP650\A0087696.exe Infecté : not-a-virus:WebToolbar.Win32.Zango.bg ignoré
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP650\A0087700.exe Infecté : not-a-virus:WebToolbar.Win32.Zango.bg ignoré
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP650\change.log L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
Analyse terminée.
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.336.Crwl L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.336.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.ci L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wsb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy186.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_368.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Bureau\SDFix\backups\backups.zip/backups/Setup.exe Infecté : not-a-virus:WebToolbar.Win32.Zango.bg ignoré
C:\Documents and Settings\HP_Propriétaire\Bureau\SDFix\backups\backups.zip ZIP: infecté - 1 ignoré
C:\Documents and Settings\HP_Propriétaire\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Microsoft\Desktop Search\Logs\OTFSMonLog.txt L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Documents.dfd L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Documents.did L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Documents.dsd L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kdb L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kdl L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kib L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.kpf L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Orange\Desktop Search\Index\MainChunk\Keywords.ksb L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Historique\History.IE5\MSHist012008101220081013\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\hpodvd09.log L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\Perflib_Perfdata_c1c.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\_hphtra07.log L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\temp\~DF757C.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\HP_Propriétaire\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chandir.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chandir.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chn.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\chn.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\D0000000.FCS L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\inuse.txt L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\L0000006.FCS L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\main.log L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_die.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_die.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_dnd.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_dnd.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_ext.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_ext.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_rcv.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\prs_rcv.idx L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\storydb.dat L'objet est verrouillé ignoré
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\HP_Propriétaire\Data\storydb.idx L'objet est verrouillé ignoré
C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP650\A0087696.exe Infecté : not-a-virus:WebToolbar.Win32.Zango.bg ignoré
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP650\A0087700.exe Infecté : not-a-virus:WebToolbar.Win32.Zango.bg ignoré
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP650\change.log L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
Analyse terminée.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
9 oct. 2008 à 21:23
9 oct. 2008 à 21:23
Le rapport n'est pas complet.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
9 oct. 2008 à 21:45
9 oct. 2008 à 21:45
Toujours incomplet.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
9 oct. 2008 à 22:00
9 oct. 2008 à 22:00
- Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
- Double-clique sur Navilog1.exe afin de lancer l'installation
- Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau
- Appuie sur F ou f puis valide par Entrée
- Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options
- Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix
- Patiente jusqu'au message : *** Analyse Termine le ..... ***
- Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse
- Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt
N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
- Double-clique sur Navilog1.exe afin de lancer l'installation
- Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau
- Appuie sur F ou f puis valide par Entrée
- Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options
- Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix
- Patiente jusqu'au message : *** Analyse Termine le ..... ***
- Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse
- Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt
N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
11 oct. 2008 à 18:04
-->- Recherche:
C:\fixnavi.txt: trouvé !
C:\cleannavi.txt: trouvé !
C:\lopR.txt: trouvé !
C:\TB.txt: trouvé !
C:\Lop SD: trouvé !
C:\_OtMoveIt: trouvé !
C:\Toolbar SD: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\HP_Propriétaire\*.msnfix: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\Msnfix.zip: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\hijackthis.log: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\MsnFix: trouvé !
C:\Documents and Settings\HP_Propriétaire\Bureau\msnfix\MsnFix: trouvé !
C:\Program Files\HJTInstall.exe: trouvé !
C:\Program Files\*.msnfix: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\WINDOWS\msnfix.txt: trouvé !
C:\WINDOWS\*.msnfix: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\HP_Propriétaire\Bureau\Msnfix.zip: supprimé !
C:\Documents and Settings\HP_Propriétaire\Bureau\OtMoveIt2.exe: supprimé !
C:\Program Files\HJTInstall.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\fixnavi.txt: supprimé !
C:\cleannavi.txt: supprimé !
C:\lopR.txt: supprimé !
C:\TB.txt: supprimé !
C:\Documents and Settings\HP_Propriétaire\*.msnfix: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\HP_Propriétaire\Bureau\hijackthis.log: supprimé !
C:\Program Files\*.msnfix: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\WINDOWS\msnfix.txt: supprimé !
C:\WINDOWS\*.msnfix: ERREUR DE SUPPRESSION !!
C:\Lop SD: supprimé !
C:\_OtMoveIt: supprimé !
C:\Toolbar SD: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\HP_Propriétaire\Bureau\MsnFix: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
Corbeille vidée!
Fichiers temporaires nettoyés !