Virus
mon ordi est infecté. le gestionnaire des taches est toujours verouillé c'est a dire je ne peux pas y cliquer. l'ordi est trop lent.
le pire c ke l'antivirus ne fonctionne pas aussi.je sais plus koi faire. g utilisé plusieurs antivirus mais en vain.
et si j'essaye le formatage, je vais perdre beaucoup de fichiers dans l'ordi. et si je les garde dans d'autres mémoires le probleme est que je sais pas s'ils sont infectés ou non (les fichiers).
kelle est la soluton?
merci d'avance.
Configuration: Windows XP Firefox 3.0.7
83 réponses
Un ordinateur sous Windows XP est infecté, le gestionnaire des tâches est verrouillé et l’ordinateur est lent, l’antivirus ne fonctionne plus et le risque de perte de données lors d’un formatage est élevé. Des solutions proposées incluent l’usage d’outils de nettoyage et de détection comme ATF Cleaner et ComboFix, déconnecter l’ordinateur du réseau, puis nettoyer les traces dans le registre et les dossiers temporaires. Les guides recommandent d’exécuter les outils sans redémarrage entre les étapes, de désactiver temporairement l’antivirus, puis de consulter le rapport généré pour confirmer l’élimination des nuisibles et rétablir le pare-feu et l’antivirus.
-
"NoDrives"=
"NoFolderOptions"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\art-lantis 4.5\Art-lantis.exe"="C:\Program Files\art-lantis 4.5\Art-lantis.exe:*:Enabled:Art*lantis for Win32"
"C:\WINDOWS\system32\rtcshare.exe"="C:\WINDOWS\system32\rtcshare.exe:*:Disabled:Partage de l'application RTC"
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.321\French\setup.exe"="C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.321\French\setup.exe:*:Enabled:Programme d'installation de Kaspersky Internet Security 7.0"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer"
"C:\SCANJET\PrecisionScanLT\hppwrsav.exe"="C:\SCANJET\PrecisionScanLT\hppwrsav.exe:*:Enabled:ipsec"
"C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe:*:Enabled:ipsec"
"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe:*:Enabled:ipsec"
"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avscan.exe"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avscan.exe:*:Enabled:ipsec"
"C:\Program Files\Unlocker\Unlocker.exe"="C:\Program Files\Unlocker\Unlocker.exe:*:Enabled:ipsec"
"C:\Program Files\MSN Messenger\usnsvc.exe"="C:\Program Files\MSN Messenger\usnsvc.exe:*:Enabled:ipsec"
"C:\Program Files\Real\RealPlayer\RecordingManager.exe"="C:\Program Files\Real\RealPlayer\RecordingManager.exe:*:Enabled:ipsec"
"C:\DOCUME~1\poi\LOCALS~1\Temp\rtcoa.exe"="C:\DOCUME~1\poi\LOCALS~1\Temp\rtcoa.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winqwxi.exe"="C:\WINDOWS\TEMP\winqwxi.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winmfpnd.exe"="C:\WINDOWS\TEMP\winmfpnd.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wingagkqu.exe"="C:\WINDOWS\TEMP\wingagkqu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winfvjksy.exe"="C:\WINDOWS\TEMP\winfvjksy.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\qihl.exe"="C:\WINDOWS\TEMP\qihl.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\kiih.exe"="C:\WINDOWS\TEMP\kiih.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\yvclyp.exe"="C:\WINDOWS\TEMP\yvclyp.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\nsnyxk.exe"="C:\WINDOWS\TEMP\nsnyxk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winfprmk.exe"="C:\WINDOWS\TEMP\winfprmk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\iluv.exe"="C:\WINDOWS\TEMP\iluv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winjmfx.exe"="C:\WINDOWS\TEMP\winjmfx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winpxcrjm.exe"="C:\WINDOWS\TEMP\winpxcrjm.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winfedx.exe"="C:\WINDOWS\TEMP\winfedx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wintecq.exe"="C:\WINDOWS\TEMP\wintecq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winwkkv.exe"="C:\WINDOWS\TEMP\winwkkv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\qjkknl.exe"="C:\WINDOWS\TEMP\qjkknl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\poi\LOCALS~1\Temp\yejbju.exe"="C:\DOCUME~1\poi\LOCALS~1\Temp\yejbju.exe:*:Enabled:ipsec"
"C:\DOCUME~1\poi\LOCALS~1\Temp\waewkw.exe"="C:\DOCUME~1\poi\LOCALS~1\Temp\waewkw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\poi\LOCALS~1\Temp\wintmmmny.exe"="C:\DOCUME~1\poi\LOCALS~1\Temp\wintmmmny.exe:*:Enabled:ipsec"
"C:\DOCUME~1\poi\LOCALS~1\Temp\winfwtgjt.exe"="C:\DOCUME~1\poi\LOCALS~1\Temp\winfwtgjt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\poi\LOCALS~1\Temp\eeqcn.exe"="C:\DOCUME~1\poi\LOCALS~1\Temp\eeqcn.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\diievy.exe"="C:\WINDOWS\TEMP\diievy.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\qesw.exe"="C:\WINDOWS\TEMP\qesw.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\khmge.exe"="C:\WINDOWS\TEMP\khmge.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\xytvrr.exe"="C:\WINDOWS\TEMP\xytvrr.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winxpdkx.exe"="C:\WINDOWS\TEMP\winxpdkx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winscmcx.exe"="C:\WINDOWS\TEMP\winscmcx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\aryek.exe"="C:\WINDOWS\TEMP\aryek.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winiogt.exe"="C:\WINDOWS\TEMP\winiogt.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\oodvlo.exe"="C:\WINDOWS\TEMP\oodvlo.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wingasjd.exe"="C:\WINDOWS\TEMP\wingasjd.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winrplacs.exe"="C:\WINDOWS\TEMP\winrplacs.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winmieiod.exe"="C:\WINDOWS\TEMP\winmieiod.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\kvqs.exe"="C:\WINDOWS\TEMP\kvqs.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wingoyf.exe"="C:\WINDOWS\TEMP\wingoyf.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winrqqwfc.exe"="C:\WINDOWS\TEMP\winrqqwfc.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wineedjrk.exe"="C:\WINDOWS\TEMP\wineedjrk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\kbli.exe"="C:\WINDOWS\TEMP\kbli.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winnonpv.exe"="C:\WINDOWS\TEMP\winnonpv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winlttpsu.exe"="C:\WINDOWS\TEMP\winlttpsu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winpxibwx.exe"="C:\WINDOWS\TEMP\winpxibwx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winwrhh.exe"="C:\WINDOWS\TEMP\winwrhh.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winqhtvrq.exe"="C:\WINDOWS\TEMP\winqhtvrq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winvvmg.exe"="C:\WINDOWS\TEMP\winvvmg.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wineoqc.exe"="C:\WINDOWS\TEMP\wineoqc.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\jrdna.exe"="C:\WINDOWS\TEMP\jrdna.exe:*:Enabled:ipsec"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\TEMP\mlpgq.exe"="C:\WINDOWS\TEMP\mlpgq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winrokg.exe"="C:\WINDOWS\TEMP\winrokg.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\qkwexr.exe"="C:\WINDOWS\TEMP\qkwexr.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\oqjbs.exe"="C:\WINDOWS\TEMP\oqjbs.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\xusx.exe"="C:\WINDOWS\TEMP\xusx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winpkcxol.exe"="C:\WINDOWS\TEMP\winpkcxol.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winscvmy.exe"="C:\WINDOWS\TEMP\winscvmy.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winvphw.exe"="C:\WINDOWS\TEMP\winvphw.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winwuic.exe"="C:\WINDOWS\TEMP\winwuic.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\sgtj.exe"="C:\WINDOWS\TEMP\sgtj.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\cxrkqo.exe"="C:\WINDOWS\TEMP\cxrkqo.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\vyna.exe"="C:\WINDOWS\TEMP\vyna.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\lwepv.exe"="C:\WINDOWS\TEMP\lwepv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winiyvb.exe"="C:\WINDOWS\TEMP\winiyvb.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\vpwx.exe"="C:\WINDOWS\TEMP\vpwx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\lnvrjy.exe"="C:\WINDOWS\TEMP\lnvrjy.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\bnsew.exe"="C:\WINDOWS\TEMP\bnsew.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winuuuq.exe"="C:\WINDOWS\TEMP\winuuuq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winwhqrha.exe"="C:\WINDOWS\TEMP\winwhqrha.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\iknqr.exe"="C:\WINDOWS\TEMP\iknqr.exe:*:Enabled:ipsec"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\WINDOWS\TEMP\nqtbyh.exe"="C:\WINDOWS\TEMP\nqtbyh.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\uxqmsy.exe"="C:\WINDOWS\TEMP\uxqmsy.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wamc.exe"="C:\WINDOWS\TEMP\wamc.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\qoix.exe"="C:\WINDOWS\TEMP\qoix.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winemtcgu.exe"="C:\WINDOWS\TEMP\winemtcgu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winjuyjn.exe"="C:\WINDOWS\TEMP\winjuyjn.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winnppjwg.exe"="C:\WINDOWS\TEMP\winnppjwg.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winvjyk.exe"="C:\WINDOWS\TEMP\winvjyk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\uvbp.exe"="C:\WINDOWS\TEMP\uvbp.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\vhger.exe"="C:\WINDOWS\TEMP\vhger.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winitfd.exe"="C:\WINDOWS\TEMP\winitfd.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}]
shell\aUtoplaY\command - F:\firy.pif
shell\AutoRun\command - F:\firy.pif
shell\ExplOrE\command - F:\firy.pif
shell\Open\command - F:\firy.pif
======File associations======
.scr - open - "C:\WINDOWS\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2009-06-24 07:06:32 ----D---- C:\rsit
2009-06-02 19:55:29 ----D---- C:\Documents and Settings\poi\Application Data\Dev-Cpp
2009-06-02 19:54:41 ----D---- C:\Dev-Cpp
======List of files/folders modified in the last 1 months======
2009-06-24 07:07:10 ----D---- C:\Program Files\trend micro
2009-06-24 07:03:53 ----D---- C:\Program Files\Mozilla Firefox
2009-06-24 07:00:19 ----D---- C:\Documents and Settings\poi\Application Data\Skype
2009-06-24 07:00:05 ----D---- C:\WINDOWS\temp
2009-06-24 06:23:00 ----D---- C:\Documents and Settings\poi\Application Data\skypePM
2009-06-22 14:52:35 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-22 14:51:02 ----D---- C:\WINDOWS\system32\drivers
2009-06-21 18:35:19 ----A---- C:\WINDOWS\NeroDigital.ini
2009-06-20 00:57:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-17 23:32:09 ----D---- C:\Program Files\Yahoo!
2009-06-17 23:32:09 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-06-17 23:32:05 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-06-17 23:30:51 ----D---- C:\WINDOWS\Prefetch
2009-06-17 23:29:29 ----D---- C:\WINDOWS\system32
2009-06-16 16:20:05 ----SD---- C:\Documents and Settings\poi\Application Data\Microsoft
2009-06-14 23:06:55 ----D---- C:\WINDOWS\system32\wbem
2009-06-14 23:06:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-06-01 09:51:14 ----A---- C:\WINDOWS\system32\MRT.exe
2009-05-30 16:10:54 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-26 17:45:29 ----A---- C:\WINDOWS\ppdrv.ini
2009-05-25 20:37:15 ----SH---- C:\boot.ini
2009-05-25 20:37:15 ----A---- C:\WINDOWS\win.ini
2009-05-25 20:37:15 ----A---- C:\WINDOWS\system.ini
2009-05-25 20:36:45 ----D---- C:\WINDOWS\pss
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R1 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-09-28 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-04-02 20747]
R2 CdaC15BA;CdaC15BA; \??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS []
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2008-03-20 15781]
R2 NwlnkIpx;Protocole de transport compatible NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NetBIOS NWLink; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-09-28 63232]
R2 NwlnkSpx;Protocole NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-09-28 55936]
R2 PPSCAN;PPSCAN; C:\WINDOWS\system32\drivers\PPSCAN.sys [2002-03-29 91520]
R3 abp470n5;abp470n5; \??\C:\WINDOWS\system32\drivers\fijkog.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-04 3797632]
R3 BridgeMP;Miniport de pont MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2004-09-21 10804]
R3 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\system32\DRIVERS\vbtenum.sys [2005-01-13 12500]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2005-03-18 42496]
R3 MODEMCSA;Périphérique de filtrage de flux Unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 Ptserial;W2K Conexant Serial Device Driver; C:\WINDOWS\system32\DRIVERS\ptserial.sys [2004-05-24 362878]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-09-28 5888]
R3 RT73;RT73 USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt73.sys [2006-01-12 252928]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2004-10-19 61312]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2004-11-05 82148]
R3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2005-06-01 227712]
R3 Vmodem;W2K Vmodem; C:\WINDOWS\system32\DRIVERS\vmodem.sys [2004-03-20 703737]
R3 Vpctcom;W2K Vpctcom; C:\WINDOWS\system32\DRIVERS\vpctcom.sys [2004-03-20 804754]
R3 Vvoice;W2K Vvoice; C:\WINDOWS\system32\DRIVERS\vvoice.sys [2004-03-20 70384]
S3 admjoy;Enumérateur de ports jeu Aureal; C:\WINDOWS\system32\DRIVERS\admjoy.sys [2004-08-03 10880]
S3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgntflt.sys []
S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2004-10-19 20096]
S3 Bridge;Pont MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2005-01-17 23000]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\WINDOWS\system32\drivers\BTNetFilter.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2003-01-05 717263]
S3 es1969;Pilote audio ESS Solo (WDM); C:\WINDOWS\system32\drivers\es1969.sys [2001-08-17 72192]
S3 FETNDIS;Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet; C:\WINDOWS\system32\DRIVERS\fetnd5.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 irsir;Pilote série infrarouge Microsoft; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 mf;mf; C:\WINDOWS\system32\DRIVERS\mf.sys [2008-04-13 63744]
S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-09-28 12288]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
S3 scsiscan;Pilote de scanneur SCSI; C:\WINDOWS\system32\DRIVERS\scsiscan.sys [2008-04-13 11520]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 wdm_au8830;Pilote audio Aureal Vortex 8830 (WDM); C:\WINDOWS\system32\drivers\adm8830.sys [2001-08-17 747392]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirScheduler;Avira AntiVir Premium Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe [2008-10-15 68865]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2005-01-27 176128]
R2 C-DillaCdaC11BA;C-DillaCdaC11BA; C:\WINDOWS\system32\drivers\CDAC11BA.EXE [2008-01-16 54784]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S2 AntiVirMailService;Avira AntiVir Premium MailGuard; C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2008-07-11 164097]
S2 AntiVirService;Avira AntiVir Premium Guard; C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe [2008-10-15 151297]
S2 antivirwebservice;Avira AntiVir Premium WebGuard; C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [2008-06-12 258305]
S2 AVEService;Avira AntiVir Premium MailGuard helper service; C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2008-05-09 41217]
S2 NWCWorkstation;Service client pour NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 676120]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 162864]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 166768]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF----------------- -
info.txt logfile of random's system information tool 1.06 2009-06-24 07:07:15
======Uninstall list======
-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
Apple Software Update-->MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
Art-lantis 4.5-->C:\WINDOWS\unvise32.exe C:\Program Files\Art-lantis 4.5\Art.uninstal.log
Athan Basic 3.0 -->C:\WINDOWS\iun6002.exe "C:\Program Files\Athan\irunin.ini"
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
AutoCAD 2004-->MsiExec.exe /I{5783F2D7-0201-0409-0002-0060B0CE6BBA}
Autodesk Express Viewer-->C:\PROGRA~1\Autodesk\AUTODE~1\Setup.exe /remove
Avira AntiVir Premium-->C:\Program Files\Avira\AntiVir PersonalEdition Premium\setup.exe /REMOVE
Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}
Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}
BlueSoleil-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9F499B8-D1F0-42FC-84BE-CC552123CCCB}\Setup.exe" -l0x40c
CA VMN Anti-Spyware (remove only)-->"C:\Program Files\CA VMN Anti-Spyware\uninstall.exe"
CA Yahoo! Anti-Spy (remove only)-->"C:\Program Files\CA Yahoo! Anti-Spy\uninstall.exe"
Canon PhotoRecord-->MsiExec.exe /X{D958FAC4-BAE0-4B1D-A42E-DE9BFDE7DDEE}
Canon PIXMA iP1000-->C:\WINDOWS\system32\CNMCP6e.exe "-PRINTERNAMECanon PIXMA iP1000" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP1000 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP1000 Installer\Inst2\cnmi0409.dll"
Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe C:\Program Files\Canon\Easy-PhotoPrint\uninst.ini
Canon Utilities Easy-PrintToolBox-->C:\WINDOWS\BJPSUNST.EXE
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Collection Microsoft Encarta 2006-->MsiExec.exe /I{06180000-3E21-46D6-9A91-D927BA08F41D}
Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}
Dev-C++ 5 beta 9 release (4.9.9.2)-->"C:\Dev-Cpp\uninstall.exe"
Direct Show Ogg Vorbis Filter (remove only)-->"C:\WINDOWS\system32\OggDSuninst.exe"
DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Driver Detective-->C:\Program Files\InstallShield Installation Information\{621C02EA-AAFF-4026-A903-165D59529A16}\setup.exe -runfromtemp -l0x0409
EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}
FindyKill-->C:\FindyKill\Uninstal.exe
Free FLV Converter V 6.32-->"C:\Program Files\Free FLV Converter\unins000.exe"
Gif Movie Gear 4-->"C:\Program Files\Visicom Media\GMG 4\uninst-gmg.exe"
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
HP PrecisionScan LT Software-->C:\SCANJET\PrecisionScanLT\uninstal.exe C:\SCANJET\PrecisionScanLT\uninstal.cfg
HSP56 Modem Drivers-->ptuninst.exe
IKEA HomePlanner Bedroom-->MsiExec.exe /I{36E7C1C1-E5F7-4E22-8B40-7B333FC616E3}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
L&H TTS3000 Français-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\LHTTSFRF.inf, Uninstall
LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate"
Macromedia Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Matroska (remove only)-->"C:\Program Files\Matroska\uninstall.exe"
Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{3585ED1C-74C5-43B0-A232-831B96A12A2B}
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office FrontPage 2003-->MsiExec.exe /I{9017040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft Office XP Web Components-->MsiExec.exe /I{9026040C-6000-11D3-8CFE-0050048383C9}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
MixVibes PRO 4 uninstall-->C:\Program Files\MixVibesPro4\uninstall.exe
Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Navigation par onglets (Windows Live Toolbar)-->MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}
Nero 7 Premium-->MsiExec.exe /I{70AB1576-7883-2313-C650-7A71270B1036}
OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}
Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
Ralink Wireless LAN Card-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E91E8912-769D-42F0-8408-0E329443BABC}\setup.exe" -l0x9 -removeonly
RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
Registry Mechanic 7.0-->"C:\Program Files\Registry Mechanic\unins000.exe"
SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Sonic Foundry Sound Forge 6.0a-->MsiExec.exe /I{6CDC68BB-C997-4ADC-9BA0-6293FB88521E}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
StairDesigner 6.03a-->C:\Program Files\Boole & Partners\StairDesigner 6\Uninstall.exe
Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
UsbFix-->C:\Program Files\UsbFix\Uninstal.exe
VIA Platform Device Manager-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VIA/S3G Display Driver-->C:\PROGRA~1\VIA\UChromeP\s3minset.exe /u C:\PROGRA~1\VIA\UChromeP\UChromeP.uns
Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {05AE605F-3146-46ED-BC52-0A14EBF57962}
Windows Live Toolbar-->MsiExec.exe /X{05AE605F-3146-46ED-BC52-0A14EBF57962}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Yahoo! Extras-->C:\PROGRA~1\Yahoo!\Common\unyext.exe
Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Software Update-->C:\PROGRA~1\Yahoo!\SOFTWA~1\UNINST~1.EXE
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
======Security center information======
AV: Avira AntiVir PersonalEdition (disabled) (outdated)
AV: Kaspersky Anti-Virus (outdated)
======System event log======
Computer Name: ES-1
Event Code: 7001
Message: Le service Avira AntiVir Premium MailGuard dépend du service Avira AntiVir Premium MailGuard helper service qui n'a pas pu démarrer en raison de l'erreur :
Le service n'a pas répondu assez vite à la demande de lancement ou de contrôle.
Record Number: 4359
Source Name: Service Control Manager
Time Written: 20090428182017.000000+060
Event Type: error
User:
Computer Name: ES-1
Event Code: 7000
Message: Le service Avira AntiVir Premium MailGuard helper service n'a pas pu démarrer en raison de l'erreur :
Le service n'a pas répondu assez vite à la demande de lancement ou de contrôle.
Record Number: 4358
Source Name: Service Control Manager
Time Written: 20090428182017.000000+060
Event Type: error
User:
Computer Name: ES-1
Event Code: 7009
Message: Délai (30000 millisecondes) d'attente pour une connexion du service Avira AntiVir Premium MailGuard helper service.
Record Number: 4357
Source Name: Service Control Manager
Time Written: 20090428182017.000000+060
Event Type: error
User:
Computer Name: ES-1
Event Code: 7000
Message: Le service Avira AntiVir Premium Guard n'a pas pu démarrer en raison de l'erreur :
Le service n'a pas répondu assez vite à la demande de lancement ou de contrôle.
Record Number: 4356
Source Name: Service Control Manager
Time Written: 20090428182017.000000+060
Event Type: error
User:
Computer Name: ES-1
Event Code: 7009
Message: Délai (30000 millisecondes) d'attente pour une connexion du service Avira AntiVir Premium Guard.
Record Number: 4355
Source Name: Service Control Manager
Time Written: 20090428182017.000000+060
Event Type: error
User:
=====Application event log=====
Computer Name: ES-1D0DC7C34A5A
Event Code: 12001
Message: The Messenger Sharing USN Journal Reader service started successfully.
Record Number: 717
Source Name: usnjsvc
Time Written: 20090125202325.000000+060
Event Type:
User:
Computer Name: ES-1
Event Code: 12001
Message: The Messenger Sharing USN Journal Reader service started successfully.
Record Number: 702
Source Name: usnjsvc
Time Written: 20090123185133.000000+060
Event Type:
User:
Computer Name: ES-1
Message: The Messenger Sharing USN Journal Reader service started successfully.
Record Number: 687
Source Name: usnjsvc
Time Written: 20090123131111.000000+060
Event Type:
User:
Computer Name: ES-1
Event Code: 1517
Message: Windows a sauvegardé le Registre utilisateur ES-1D0DC7C34A5A\poi alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.
Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.
Record Number: 677
Source Name: Userenv
Time Written: 20090122210543.000000+060
Event Type: warning
User: AUTORITE NT\SYSTEM
Computer Name: ES-1
Event Code: 4113
Message:
Record Number: 672
Source Name: Avira AntiVir
Time Written: 20090122204243.000000+060
Event Type: warning
User: AUTORITE NT\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\Autodesk Shared
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
-----------------EOF----------------- -
Modérateur1/
---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
2/
--> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
--> Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
--> Clique sur Continue à l'écran Disclaimer.
--> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
--> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit. -
salut,
http://www.cijoint.fr/cjlink.php?file=cj200906/cijuA3fy4l.txt
http://www.cijoint.fr/cjlink.php?file=cj200906/cijtw1cLjf.txt -
Modérateur--> Télécharge OTL (de OldTimer) sur ton Bureau.
--> Double-clique sur OTL pour le lancer. Prends le soin de fermer toutes les autres fenêtres Windows afin de ne pas interrompre le scan.
(Sous Vista, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)
--> Une fenêtre apparaît. Dans la section Output en haut de cette fenêtre, coche Minimal Output.
--> Coche également les cases à côté de LOP Check et Purity Check.
--> Dans la zone Extra List, coche Use SafeList si ce n'est pas déjà fait.
--> Enfin, clique sur le bouton Run Scan. Le scan ne prendra pas beaucoup de temps.
--> Une fois l'analyse terminée, deux fenêtres vont s'ouvrir dans le Bloc-notes : OTL.txt et Extras.txt. Ils se trouvent au même endroit que OTL (donc par défaut sur le Bureau).
Pour me transmettre les rapports :
--> Clique sur ce lien : http://www.cijoint.fr/
--> Clique sur Parcourir... et cherche le fichier du rapport que tu souhaites me transmettre.
--> Clique sur Ouvrir.
--> Clique sur Cliquez ici pour déposer le fichier.
--> Un lien de cette forme, http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt, est ajouté dans la page.
--> Copie ce lien dans ta réponse. -
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service\Driver abp470n5 deleted successfully.
========== FILES ==========
File/Folder C:\WINDOWS\system32\drivers\fijkog.sys not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\poi\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\fauyec.exe scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\fugydk.exe scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05032009_144647
Files moved on Reboot...
File C:\DOCUME~1\poi\LOCALS~1\Temp\etilqs_XMp8jvqvNpyxD56h3Fx0 not found!
File C:\WINDOWS\temp\nwpuq.exe not found!
File C:\WINDOWS\temp\piwf.exe not found!
File C:\WINDOWS\temp\winxlnvy.exe not found!
File C:\Documents and Settings\poi\Local Settings\Application Data\Mozilla\Firefox\Profiles\abxziayz.default\Cache\_CACHE_001_ not found!
File C:\Documents and Settings\poi\Local Settings\Application Data\Mozilla\Firefox\Profiles\abxziayz.default\Cache\_CACHE_002_ not found!
File C:\Documents and Settings\poi\Local Settings\Application Data\Mozilla\Firefox\Profiles\abxziayz.default\Cache\_CACHE_003_ not found!
File C:\Documents and Settings\poi\Local Settings\Application Data\Mozilla\Firefox\Profiles\abxziayz.default\Cache\_CACHE_MAP_ not found!
File C:\Documents and Settings\poi\Local Settings\Application Data\Mozilla\Firefox\Profiles\abxziayz.default\urlclassifier3.sqlite not found! -
Modérateur---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
abp470n5
:files
C:\WINDOWS\system32\drivers\fijkog.sys
:commands
[purity]
[emptytemp]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log -
le gestionnaire des taches est toujours verrouillé et l'antivirus comme d'habitude, je peux pas l'exécuter
le PC reste comme d'habitude apparemment. -
ModérateurDes améliorations ?
-
Process Explorer.EXE killed successfully!
[Processes - Safe List]
No active process named asydr.exe was found!
File C:\WINDOWS\TEMP\asydr.exe not found.
No active process named winlqgjbr.exe was found!
File C:\WINDOWS\TEMP\winlqgjbr.exe not found.
No active process named winrxklnl.exe was found!
File C:\WINDOWS\TEMP\winrxklnl.exe not found.
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{955BE0B8-BC85-4CAF-856E-8E0D8B610560}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{955BE0B8-BC85-4CAF-856E-8E0D8B610560}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{147D6308-0614-4112-89B1-31402F9B82C4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{147D6308-0614-4112-89B1-31402F9B82C4}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{147D6308-0614-4112-89B1-31402F9B82C4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{147D6308-0614-4112-89B1-31402F9B82C4}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{77BF5300-1474-4EC7-9980-D32B190E9B07} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77BF5300-1474-4EC7-9980-D32B190E9B07}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{C461FBFE-C0DE-4757-89DD-A5A833B9AC1F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C461FBFE-C0DE-4757-89DD-A5A833B9AC1F}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\dfulp.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\edjm.exe deleted successfully.
File C:\Documents and Settings\poi\Local Settings\temp\edjm.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\gndw.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\hlpkmr.exe deleted successfully.
File C:\Documents and Settings\poi\Local Settings\temp\hlpkmr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\mrpadc.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\qtose.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\smrut.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\umvyw.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\vlva.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\vsya.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\windajm.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winfgnln.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\wingtyqb.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winlmunmd.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winnffd.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winngta.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winofels.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winogdv.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winpmjeru.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winpwed.exe deleted successfully.
File C:\Documents and Settings\poi\Local Settings\temp\winpwed.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winquunm.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winryssge.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\wintepa.exe deleted successfully.
File C:\Documents and Settings\poi\Local Settings\temp\wintepa.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winusai.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winvcjv.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winwbungj.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winxbunpk.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winxqwanf.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\winypfuxn.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\xdtfbf.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\xnbtio.exe deleted successfully.
File C:\Documents and Settings\poi\Local Settings\temp\xnbtio.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\DOCUME~1\poi\LOCALS~1\Temp\yosqf.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\asydr.exe deleted successfully.
File C:\WINDOWS\TEMP\asydr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\cjobk.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\fnnlca.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\hlha.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\kkfj.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\oejyvn.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\pcnba.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\winclkkxo.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\winhedy.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\winlqgjbr.exe deleted successfully.
File C:\WINDOWS\TEMP\winlqgjbr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\winrxklnl.exe deleted successfully.
File C:\WINDOWS\TEMP\winrxklnl.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\TEMP\winuxprk.exe deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AUTOplaY\commaNd\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AUTOplaY\commaNd not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AutoRun\command not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\exPlorE\CommAND\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\exPlorE\CommAND not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\oPen\cOMMand\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\oPen\cOMMand not found.
[Files/Folders - Created Within 30 Days]
C:\Documents and Settings\poi\Bureau\ComboFix.exe moved successfully.
C:\Qoobox\Quarantine\Registry_backups folder moved successfully.
C:\Qoobox\Quarantine\C folder moved successfully.
C:\Qoobox\Quarantine folder moved successfully.
C:\Qoobox\BackEnv folder moved successfully.
C:\Qoobox folder moved successfully.
[Files/Folders - Modified Within 30 Days]
File C:\WINDOWS\Temp\winrxklnl.exe not found!
File C:\WINDOWS\Temp\asydr.exe not found!
File C:\WINDOWS\Temp\winlqgjbr.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\winiptvh.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\imfoqb.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\hlpkmr.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\winilbn.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\winpwed.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\vxkuab.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\wintugt.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\wintepa.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\edjm.exe not found!
File C:\Documents and Settings\poi\Local Settings\temp\xnbtio.exe not found!
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
[Purity]
Purity scan complete.
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\poi\Local Settings\temp\Perflib_Perfdata_65c.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\poi\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\winilofda.exe scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\winpicng.exe scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\winxxgc.exe scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
RecycleBin -> emptied.
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.14.0 fix logfile created on 04212009_204219
Files moved on Reboot...
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
File C:\Documents and Settings\poi\Local Settings\temp\Perflib_Perfdata_65c.dat not found!
File C:\WINDOWS\temp\winilofda.exe not found!
File C:\WINDOWS\temp\winpicng.exe not found!
File C:\WINDOWS\temp\winxxgc.exe not found!
Registry entries deleted on Reboot... -
ModérateurOuvre le dossier OTScanIt2 et fais un double-clic sur OTScanIt2.exe pour lancer le programme (si tu es sous Windows Vista, fais un clic-droit sur le programme et choisis Exécuter en tant qu'administrateur).
Fais un copier/coller du texte ci-dessous (entre les deux espaces) dans la zone de saisie intitulée "Paste fix here" puis clique sur le bouton Run Fix.
[Kill Explorer]
[Unregister Dlls]
[Processes - Safe List]
YY -> asydr.exe -> %SystemRoot%\TEMP\asydr.exe
YY -> winlqgjbr.exe -> %SystemRoot%\TEMP\winlqgjbr.exe
YY -> winrxklnl.exe -> %SystemRoot%\TEMP\winrxklnl.exe
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {955BE0B8-BC85-4CAF-856E-8E0D8B610560} [HKLM] -> Reg Error: Value error. [Reg Error: Value error.]
YN -> {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKLM] -> Reg Error: Value error. [Reg Error: Value error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{147D6308-0614-4112-89B1-31402F9B82C4}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{147D6308-0614-4112-89B1-31402F9B82C4}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Console Java (Sun)]
YN -> CmdMapping\\"{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}" [HKLM] -> [Reg Error: Key error.]
YN -> CmdMapping\\"{77BF5300-1474-4EC7-9980-D32B190E9B07}" [HKLM] -> [Reg Error: Key error.]
YN -> CmdMapping\\"{C461FBFE-C0DE-4757-89DD-A5A833B9AC1F}" [HKLM] -> [Reg Error: Key error.]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\dfulp.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\dfulp.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\dfulp.exe:*:Enabled:ipsec]
YY -> "C:\DOCUME~1\poi\LOCALS~1\Temp\edjm.exe" -> C:\Documents and Settings\poi\Local Settings\temp\edjm.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\edjm.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\gndw.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\gndw.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\gndw.exe:*:Enabled:ipsec]
YY -> "C:\DOCUME~1\poi\LOCALS~1\Temp\hlpkmr.exe" -> C:\Documents and Settings\poi\Local Settings\temp\hlpkmr.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\hlpkmr.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\mrpadc.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\mrpadc.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\mrpadc.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\qtose.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\qtose.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\qtose.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\smrut.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\smrut.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\smrut.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\umvyw.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\umvyw.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\umvyw.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\vlva.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\vlva.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\vlva.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\vsya.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\vsya.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\vsya.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\windajm.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\windajm.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\windajm.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winfgnln.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winfgnln.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winfgnln.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\wingtyqb.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\wingtyqb.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\wingtyqb.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winlmunmd.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winlmunmd.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winlmunmd.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winnffd.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winnffd.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winnffd.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winngta.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winngta.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winngta.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winofels.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winofels.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winofels.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winogdv.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winogdv.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winogdv.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winpmjeru.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winpmjeru.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winpmjeru.exe:*:Enabled:ipsec]
YY -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winpwed.exe" -> C:\Documents and Settings\poi\Local Settings\temp\winpwed.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winpwed.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winquunm.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winquunm.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winquunm.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winryssge.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winryssge.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winryssge.exe:*:Enabled:ipsec]
YY -> "C:\DOCUME~1\poi\LOCALS~1\Temp\wintepa.exe" -> C:\Documents and Settings\poi\Local Settings\temp\wintepa.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\wintepa.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winusai.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winusai.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winusai.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winvcjv.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winvcjv.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winvcjv.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winwbungj.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winwbungj.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winwbungj.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winxbunpk.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winxbunpk.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winxbunpk.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winxqwanf.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winxqwanf.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winxqwanf.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\winypfuxn.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\winypfuxn.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\winypfuxn.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\xdtfbf.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\xdtfbf.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\xdtfbf.exe:*:Enabled:ipsec]
YY -> "C:\DOCUME~1\poi\LOCALS~1\Temp\xnbtio.exe" -> C:\Documents and Settings\poi\Local Settings\temp\xnbtio.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\xnbtio.exe:*:Enabled:ipsec]
YN -> "C:\DOCUME~1\poi\LOCALS~1\Temp\yosqf.exe" -> C:\DOCUME~1\poi\LOCALS~1\Temp\yosqf.exe [C:\DOCUME~1\poi\LOCALS~1\Temp\yosqf.exe:*:Enabled:ipsec]
YY -> "C:\WINDOWS\TEMP\asydr.exe" -> C:\WINDOWS\TEMP\asydr.exe [C:\WINDOWS\TEMP\asydr.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\cjobk.exe" -> C:\WINDOWS\TEMP\cjobk.exe [C:\WINDOWS\TEMP\cjobk.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\fnnlca.exe" -> C:\WINDOWS\TEMP\fnnlca.exe [C:\WINDOWS\TEMP\fnnlca.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\hlha.exe" -> C:\WINDOWS\TEMP\hlha.exe [C:\WINDOWS\TEMP\hlha.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\kkfj.exe" -> C:\WINDOWS\TEMP\kkfj.exe [C:\WINDOWS\TEMP\kkfj.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\oejyvn.exe" -> C:\WINDOWS\TEMP\oejyvn.exe [C:\WINDOWS\TEMP\oejyvn.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\pcnba.exe" -> C:\WINDOWS\TEMP\pcnba.exe [C:\WINDOWS\TEMP\pcnba.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\winclkkxo.exe" -> C:\WINDOWS\TEMP\winclkkxo.exe [C:\WINDOWS\TEMP\winclkkxo.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\winhedy.exe" -> C:\WINDOWS\TEMP\winhedy.exe [C:\WINDOWS\TEMP\winhedy.exe:*:Enabled:ipsec]
YY -> "C:\WINDOWS\TEMP\winlqgjbr.exe" -> C:\WINDOWS\TEMP\winlqgjbr.exe [C:\WINDOWS\TEMP\winlqgjbr.exe:*:Enabled:ipsec]
YY -> "C:\WINDOWS\TEMP\winrxklnl.exe" -> C:\WINDOWS\TEMP\winrxklnl.exe [C:\WINDOWS\TEMP\winrxklnl.exe:*:Enabled:ipsec]
YN -> "C:\WINDOWS\TEMP\winuxprk.exe" -> C:\WINDOWS\TEMP\winuxprk.exe [C:\WINDOWS\TEMP\winuxprk.exe:*:Enabled:ipsec]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AUTOplaY\commaNd ->
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AUTOplaY\commaNd\\"" -> F:\qmbr.pif [F:\qmbr.pif]
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AutoRun\command ->
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\AutoRun\command\\"" -> F:\qmbr.pif [F:\qmbr.pif]
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\exPlorE\CommAND ->
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\exPlorE\CommAND\\"" -> F:\qmbr.pif [F:\qmbr.pif]
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\oPen\cOMMand ->
YN -> \{1638ae09-c067-11dc-88b1-8488c0ac5ecb}\ShEll\oPen\cOMMand\\"" -> F:\qmbr.pif [F:\qmbr.pif]
[Files/Folders - Created Within 30 Days]
NY -> 1 C:\*.tmp files -> C:\*.tmp
NY -> 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> ComboFix.exe -> %UserProfile%\Bureau\ComboFix.exe
NY -> Qoobox -> %SystemDrive%\Qoobox
[Files/Folders - Modified Within 30 Days]
NY -> 1 C:\*.tmp files -> C:\*.tmp
NY -> 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> winrxklnl.exe -> %SystemRoot%\Temp\winrxklnl.exe
NY -> asydr.exe -> %SystemRoot%\Temp\asydr.exe
NY -> winlqgjbr.exe -> %SystemRoot%\Temp\winlqgjbr.exe
NY -> winiptvh.exe -> %UserProfile%\Local Settings\temp\winiptvh.exe
NY -> imfoqb.exe -> %UserProfile%\Local Settings\temp\imfoqb.exe
NY -> hlpkmr.exe -> %UserProfile%\Local Settings\temp\hlpkmr.exe
NY -> winilbn.exe -> %UserProfile%\Local Settings\temp\winilbn.exe
NY -> winpwed.exe -> %UserProfile%\Local Settings\temp\winpwed.exe
NY -> vxkuab.exe -> %UserProfile%\Local Settings\temp\vxkuab.exe
NY -> wintugt.exe -> %UserProfile%\Local Settings\temp\wintugt.exe
NY -> wintepa.exe -> %UserProfile%\Local Settings\temp\wintepa.exe
NY -> edjm.exe -> %UserProfile%\Local Settings\temp\edjm.exe
NY -> xnbtio.exe -> %UserProfile%\Local Settings\temp\xnbtio.exe
NY -> qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat
NY -> qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat
[Purity]
[Empty Temp Folders]
[Reboot]
L'exécution devrait être très rapide. Lorsque la correction est terminée, soit tu verras un message t'annonçant que c'est fini (finished), soit tu seras invité à faire redémarrer le PC pour terminer l'exécution. Si c'est fini, clique sur le bouton Ok et le Bloc-notes va s'ouvrir pour afficher un rapport de toutes les actions réalisées. Envoie-moi ces informations en réponse.
Si un redémarrage est nécessaire, clique sur le bouton "Yes" pour faire redémarrer la machine. Après ce redémarrage, OTScanIt2 va finir de déplacer les fichiers qui ne pouvaient pas l'être précédemment, puis le Bloc-notes va s'ouvrir et afficher à ce moment-là les résultats finaux. Envoie-moi ces informations en réponse.
Poste-moi le rapport sur le forum. -
Modérateur--> Télécharge OTScanIt2.exe sur ton Bureau, et fais un double-clic dessus pour extraire les fichiers. Cela va créer un dossier nommé OTScanIt2 sur ton Bureau.
N.B : Si pendant le téléchargement et/ou l’installation tu reçois une alerte de ton antivirus, ignore-la. Certains composants de OTScanIt peuvent être détectés comme un virus par certains antivirus. Pense aussi à désactiver tes protections résidentes durant la procédure.
Note : Tu dois avoir ouvert une session avec un compte ayant les droits Administrateur pour exécuter ce programme.
--> Ferme TOUS LES AUTRES PROGRAMMES et laisse travailler OTScanIt2.
--> Ouvre le dossier OTScanIt2 et fais un double-clic sur OTScanIt2.exe pour lancer le programme (si tu es sous Windows Vista, fais un clic droit sur le programme et choisis Exécuter en tant qu'administrateur).
--> Sous "File Age" en haut, clique sur le menu déroulant et sélectionne "30 Days".
--> Sous Additional Scans, coche les cases situées devant les éléments suivants afin de les sélectionner : Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - NetSvcs, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, et Evnt - EventViewer Logs ( Last 10 Errors).
--> Sous "Rootkit Search", sélectionne "Yes".
--> Ne modifie aucun autre paramètre.
--> Ensuite, clique sur le bouton Run Scan dans la barre d'outils.
--> Laisse le programme tourner sans intervenir.
--> Lorsque l'analyse est terminée le Bloc-notes va s'ouvrir pour afficher le fichier rapport.
--> Clique sur le menu Format et vérifie que Retour automatique à la ligne n'est pas coché. S'il l'est, clique dessus afin de le décocher.
--> Essaie de poster le rapport sur le forum. Si tu ne peux pas, clique sur mon pseudo et tu auras mon adresse mail pour pouvoir me l'envoyer. -
ModérateurOn te donne des nouvelles dès que possible.
-
mes amis, quoi faire maintenant? le PC est devenu très très très lent.tellement je ne peux pas travailler avec . je commence à perdre l'espoir
:( -
Running from: c:\documents and settings\*****\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
AV: Kaspersky Anti-Virus *On-access scanning enabled* (Outdated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.
2009-04-11 19:49 . 2009-04-11 19:49 <REP> d-------- C:\32788R22FWJFW
2009-04-11 19:06 . 2009-04-11 19:06 <REP> d-------- c:\windows\system32\fr-fr
2009-04-10 21:08 . 2009-04-10 21:08 54,156 --ah----- c:\windows\QTFont.qfn
2009-04-10 21:08 . 2009-04-10 21:08 1,409 --a------ c:\windows\QTFont.for
2009-04-10 17:50 . 2009-04-10 17:50 <REP> d-------- c:\documents and settings\poi\Application Data\Malwarebytes
2009-04-10 17:49 . 2009-04-10 18:08 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-10 17:49 . 2009-04-10 17:49 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-10 17:49 . 2009-04-06 15:32 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-10 17:49 . 2009-04-06 15:32 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-04-10 15:12 . 2009-04-10 15:14 <REP> d-------- C:\rsit
2009-04-08 23:55 . 2009-04-11 19:05 1,374 --a------ c:\windows\imsins.BAK
2009-04-02 19:49 . 2005-05-17 14:24 311,296 --a------ c:\windows\system32\AegisI5.exe
2009-04-02 19:49 . 2006-01-18 08:08 290,918 --a------ c:\windows\system32\Install7x.dll
2009-04-02 19:49 . 2006-01-12 18:46 252,928 --a------ c:\windows\system32\drivers\rt73.sys
2009-04-02 19:49 . 2005-10-17 18:50 245,376 --a------ c:\windows\system32\drivers\rt2500usb.SYS
2009-04-02 19:49 . 2009-04-02 19:49 20,747 --a------ c:\windows\system32\drivers\AegisP.sys
2009-04-02 19:49 . 2005-11-30 10:33 2,048 --a------ c:\windows\system32\drivers\rt73.bin
2009-04-02 19:49 . 2005-08-19 14:51 138 --a------ c:\windows\filespec7x
2009-04-02 19:44 . 2009-04-02 19:48 <REP> d-------- c:\program files\RALINK
2009-03-18 13:07 . 2009-04-10 15:14 <REP> d-------- c:\program files\trend micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-10 20:33 --------- d-----w c:\documents and settings\poi\Application Data\Skype
2009-04-10 15:03 --------- d-----w c:\documents and settings\poi\Application Data\skypePM
2009-04-02 18:48 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-25 16:30 --------- d-----w c:\program files\Messenger Plus! Live
2009-03-18 16:02 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-12 20:08 --------- d-----w c:\documents and settings\poi\Application Data\Desktopicon
2009-03-12 20:04 --------- d-----w c:\documents and settings\poi\Application Data\Ahead
2009-03-08 19:02 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-03-08 18:56 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-08 18:55 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-08 18:55 10,563 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-08 18:38 --------- d-----w c:\program files\Windows Sidebar
2009-03-08 18:38 --------- d-----w c:\program files\Norton AntiVirus
2009-03-07 22:41 --------- d-----w c:\program files\Kaspersky Lab
2009-03-07 22:22 --------- d-----w c:\program files\Unlocker
2009-03-07 18:54 --------- d-----w c:\documents and settings\poi\Application Data\CoSoSys
2009-03-02 21:07 --------- d-----w c:\program files\CA Yahoo! Anti-Spy
2009-02-20 21:12 --------- d-----w c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-02-19 06:04 --------- d-----w c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-02-13 22:24 --------- d-----w c:\documents and settings\poi\Application Data\LimeWire
2007-12-18 12:17 630 ----a-w c:\program files\Art-lantis 4.5.lnk
2004-08-03 23:54 384 --sh--r c:\windows\inf\sdatabl.sav.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-10-22 259600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nLite"="c:\windows\inf\nlite.cmd" [2004-08-25 385]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2009-04-02 667648]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/usprestrt\[u]0/usprestrt\[u]0/usprestrt
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^poi^Menu Démarrer^Programmes^Démarrage^RocketDock.lnk]
path=c:\documents and settings\poi\Menu Démarrer\Programmes\Démarrage\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 113520 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 2008-06-12 13:28 266497 c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-04-21 16:03 167936 c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:54 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E06FDXRC_103937]
--a------ 2005-06-04 17:03 371408 c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E06FDXRC_1687046]
--a------ 2005-06-04 17:03 371408 c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E06FDXRC_373953]
--a------ 2005-06-04 17:03 371408 c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E06FDXRC_471453]
--a------ 2005-06-04 17:03 371408 c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E06FDXRC_620234]
--a------ 2005-06-04 17:03 371408 c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
--a------ 2004-01-14 13:10 589824 c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hppwrsav]
--a------ 1999-06-07 12:27 105472 c:\scanjet\PrecisionScanLT\hppwrsav.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1767936 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 364544 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
--a------ 2005-06-20 18:53 1056768 c:\program files\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2008-11-07 14:31 22042920 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 03:25 214416 c:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-22 18:17 259600 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2008-05-02 05:15 85504 c:\program files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-02-13 19:29 113152 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2008-05-03 17:12 4744432 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
-ra------ 2004-01-30 01:33 180224 c:\windows\system32\pctspk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-10-04 14:12 90112 c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2005-03-08 03:33 53248 c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\art-lantis 4.5\\Art-lantis.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\French\\setup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\SCANJET\\PrecisionScanLT\\hppwrsav.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BTNtService.exe"=
"c:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\Avira\\AntiVir PersonalEdition Premium\\avscan.exe"=
"c:\\Program Files\\Unlocker\\Unlocker.exe"=
"c:\\Program Files\\MSN Messenger\\usnsvc.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 PPSCAN;PPSCAN;c:\windows\system32\drivers\ppscan.sys [2009-01-11 91520]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\fijkog.sys --> c:\windows\system32\drivers\fijkog.sys [?]
S3 es1969;Pilote audio ESS Solo (WDM);c:\windows\system32\drivers\es1969.sys [2005-11-28 72192]
S3 scsiscan;Pilote de scanneur SCSI;c:\windows\system32\drivers\scsiscan.sys [2009-01-11 10880]
S3 wdm_au8830;Pilote audio Aureal Vortex 8830 (WDM);c:\windows\system32\drivers\adm8830.sys [2006-08-31 747392]
--- Other Services/Drivers In Memory ---
*Deregistered* - AntiVirScheduler
*Deregistered* - AudioSrv
*Deregistered* - BITS
*Deregistered* - BlueSoleil Hid Service
*Deregistered* - Browser
*Deregistered* - C-DillaCdaC11BA
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - ImapiService
*Deregistered* - Irmon
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NWCWorkstation
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42]
2009-04-11 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{A057A204-BACC-4D26-8287-79A187E26987} - (no file)
MSConfigStartUp-Cmaudio - cmicnfg.cpl
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?4da68c61d46244d8959fccf8ff8804ea
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?4da68c61d46244d8959fccf8ff8804ea
LSP: avsda.dll
FF - ProfilePath - c:\documents and settings\poi\Application Data\Mozilla\Firefox\Profiles\abxziayz.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-11 20:00:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1343024091-1708537768-725345543-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\گ•€|ےےےے"•€|ù•رw*]
"C040710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(628)
c:\windows\system32\avsda.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Premium\sched.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Completion time: 2009-04-11 20:06:40 - machine was rebooted [poi]
ComboFix-quarantined-files.txt 2009-04-11 19:06:35
Pre-Run: 18,370,330,624 octets libres
Post-Run: 18,250,993,664 octets libres
300 --- E O F --- 2009-04-11 18:07:35 -
Re,
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
As-tu bien supprimer les éléments infectés?
Si tu ne la pas fait alors refais un scan et supprime les éléments découverts.
Si oui ton pare feu et ton antivirus remarchent-ils ?
Bon, alors fais cette manip sans redémarrer entre ATFCleaner et Combofix stp :
> Télécharge ATF Cleaner par Atribune sur ton bureau.
- Démarre ATF-Cleaner et coche la dernière case nommé 'select all'.
- Clique sur <Empty Selected> et au message "Done Cleaning" sur <Ok>
NB : Si tu utilises Firefox ou Opera :
- Clique sur Firefox ou Opera en haut puis choisis <Select All>.
- Clique sur le bouton <Empty Selected> (NB : Si tu veux conserver tes mots de passe sauvegardés alors clique sur <No> à l'invite).
- Clique sur <Main> pour revenir à menu principal
- Clique sur <Exit>, du menu prinicipal, pour quitter ATFcleaner.
NB : Si le prefetch est nettoyé le redémarrage du PC sera plus lent.
Puis,
> Télécharge ComboFix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe (par sUBs) sur ton Bureau.
Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
- Double clique combofix.exe puis accepte le contrat de licence.
- Si Combofix ne trouve pas de console de récupération système d'installée alors accepte son installation.
- A la fin de l'installation de la console de récupération Combofix va te proposer de lancer une recherche de nuisibles. Clique alors sur <Oui>.
Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer la machine.
- Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
PS2 : Il peut s'avérer que le rapport soit trop long pour être publié totalement. Dans ce cas utilise ce service http://www.cijoint.fr pour me l'envoyer (dépose le fichier puis poste le lien sur le forum).
Bon courage.
On va y arriver. ;)
A+ -
Malwarebytes' Anti-Malware 1.36
Version de la base de données: 1962
Windows 5.1.2600 Service Pack 2
2009-04-10 18:08:44
mbam-log-2009-04-10 (18-08-21).txt
Type de recherche: Examen rapide
Eléments examinés: 76456
Temps écoulé: 7 minute(s), 38 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 5
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté) -
Hummm...
Fais ceci stp :
> Télécharge MalwareByte's Anti-Malware :
- Installe le programme puis lance le.
NB : S'il te manque COMCTL32.OCX alors télécharge le ici
- Fais les mises à jour (clique sur "Mises à jour" puis "Recherche de mises à jour").
- Clique sur "Executer un examen rapide" puis "Rechercher" et sélectionne tous tes disques durs => le scan débute....patiente...
- A la fin du scanne, clique sur "supprimer" (Si des éléments sont difficiles à supprimer, un message te demandera de redémarrer : clique sur <Oui> alors)
- après suppression des infections : un rapport va être généré : sauvegarde le et poste le sur forum.
NB : Si tu as besoin : Tuto
Après,
>Télécharge et installe Ccleaner (logiciel à conserver et à utiliser régulièrement) : https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/ , si besoin est tu trouveras des Tutoriaux ici, ici et là.
(N'installe pas la Yahoo Toolbar)
> Démarre en mode sans échec : (image). Si problème : tuto ici
>Lance Ccleaner,,
- Choisi l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures" (tout doit être supprimé).
- Dans l'onglet "Nettoyeur" clique sur "Analyse".
- Une fois l'analyse terminée, clique sur "Lancer le Nettoyage".
- Recommence jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).
- Dans l'onglet "registre" => Recherches des erreurs => Réparer les erreurs sélectionnées => enregistre une sauvegarde => corriger toutes erreurs sélectionnées => ok => fermer.
N.B : Si Ccleaner te propose d'enregistrer une sauvegarde, reponds oui et enregistre sous 'Bureau'
- Recommence jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).
Ces logiciels sont à conserver.
-
alors, quoi faire???!!
-
2009-04-10 ---- 16:48:53.67
----------------------------------
§§§§§§ [oebgt.exe ] §§§§§§
----------------------------------
[X] Registre
-------------- [ ] rapide
-- Fichier --- [ ] disque systeme
------------- [X] complete
********************
[Registre]
********************
*******************
[Fichier]
*******************
*********************
[Même date]
*********************
Aucun fichier créé à la même date détecté
Outil Aide Diagnostic By !aur3n7 Version 1.1
----------------------------------
§§§§§ Fin Rapport §§§§§
----------------------------------
- 1
- 2
- 3
- 4
- 5