Proleme rundll32 error
Configuration: Windows Vista Internet Explorer 7.0
29 réponses
Problème central: à l'ouverture du PC sous Windows Vista et Internet Explorer 7, une fenêtre d'erreur affiche 'error rundll32 error loading dll32' et Avast ne fonctionne plus. Plusieurs éléments de réponse recommandent d'imprimer puis d'installer Malwarebytes en français, puis de lancer un examen complet après mise à jour, afin de détecter et supprimer les objets infectés. En cas de succès partiel ou de redémarrage nécessaire, l'utilisateur est invité à consulter le rapport du logiciel et à relancer le scan, puis à vérifier que Avast retrouve son fonctionnement. D'autres échanges évoquent l'usage d'outils complémentaires et l'examen des rapports pour assurer que les programmes de sécurité retrouvent leur rôle après le nettoyage et la remise en route.
-
Bon desintalles les logiciels de desinfection inutiles avec ceci
Télécharge OTCleanIt de OldTimer sur ton Bureau
http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe
Lance OTCleanIt avec un double-clic (sous Vista, lance-le en cliquant droit sur OTCleanIt.exe et en sélectionnant "exécuter en tant qu'administrateur")
Appuie sur le bouton "CleanUp!"
A la question "begin cleanup process?", réponds "YES"
A la fin de l'opération, si OTCleanIt demande de redémarrer ("Do you want to reboot now?"), ferme ce que tu es en train de faire (internet, documents divers...) et clique sur "YES":
Au redémarrage, OTCleanIt aura supprimé les outils de désinfection, et se sera même auto-détruit!
Ensuite
Fais un scan en ligne ici Kasper Online (Avec Internet Explorer).
- En bas à droite, clique sur Démarrer Online-scanner.
- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.
- Accepte les Contrôles ActiveX.
- Choisis Poste de travail pour le scan.
- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.
- Pour t'aider à utiliser le scan en ligne :
NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne. -
Search Navipromo version 3.7.7 commencé le 17/05/2009 à 11:16:12.43
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Ultimate ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
BIOS : Ver 1.00PARTTBLx
USER : veronika ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:74 Go (Free:36 Go)
D:\ (CD or DVD)
Recherche executé en mode normal
*** Recherche dossiers dans "C:\Windows" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***
*** Recherche dossiers dans "C:\ProgramData" ***
*** Recherche dossiers dans "" ***
*** Recherche dossiers dans "C:\Users\veronika\AppData\Local\virtualstore\Program Files" ***
*** Recherche dossiers dans "C:\Users\veronika\AppData\Local" ***
*** Recherche dossiers dans "C:\Users\veronika\AppData\Roaming" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\Windows\system32" *
* Recherche dans "C:\Users\veronika\AppData\Local\Microsoft" *
* Recherche dans "C:\Users\veronika\AppData\Local" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\Windows\system32" :
* Dans "C:\Users\veronika\AppData\Local\Microsoft" :
* Dans "C:\Users\veronika\AppData\Local" :
3)Recherche Certificats :
Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche autres dossiers et fichiers connus :
*** Analyse terminée le 17/05/2009 à 11:35:01.89 ***
VOILA LE RAPPORT -
et oui je l ai bien mis en tant qu administrateur
-
ca ne scan pas ca inscrit recherche terminer ensuite ca ecris veuillez patienter le scan peut durer une dizaine de minute et ca ne scan pas
-
Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
- Vas dans "Démarrer" puis Panneau de configuration.
- Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
- Clique sur Continuer.
- Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
- Valide par OK et redémarre.
Tuto
Télécharge maintenant NAVILOG1 depuis-ce lien
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis :
"Exécuter en tant qu'administrateur".
Au menu principal, Fais le choix 1
Laisse toi guider et patiente.
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche le blocnote va s'ouvrir.
Copie-colle l'intégralité du rapport dans une réponse.
Referme le blocnote
Le rapport fixnavi.txt est en outre sauvegardé a la racine du disque
TUTO -
Malwarebytes' Anti-Malware 1.36
Version de la base de données: 2142
Windows 6.0.6001 Service Pack 1
16/05/2009 7:08:57 PM
mbam-log-2009-05-16 (19-08-57).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 175413
Temps écoulé: 2 hour(s), 57 minute(s), 4 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 8
Fichier(s) infecté(s): 144
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dll (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Users\veronika\AppData\Roaming\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380 (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Program Files\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Users\veronika\AppData\Roaming\RegTool\Logs\2009-05-12 09-29-320.log (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-61.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-62.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-63.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-64.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-65.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-66.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-67.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-68.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-69.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-70.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-71.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-72.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-73.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-74.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-75.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-76.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-77.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-78.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-79.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-80.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-81.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-82.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-83.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-84.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-85.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-86.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-87.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-88.db (Rogue.RegTool) -> Not selected for removal.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-89.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-90.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-91.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-92.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-93.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-94.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-95.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-96.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-97.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-98.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-99.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Evidence.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Junk.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Registry.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Update.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\resultsw.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs\2009-02-23 08-37-490.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs\2009-02-23 09-51-060.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\Favorites\Free Porn Videos - Sex, Porno, Porn Tube, Free XXX Porn - PornFuZe.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\veronika\Favorites\Free porn videos - Sex, XXX, free pornos at You Porn.com.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Windows\Tasks\RegTool Scan.job (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Windows\Tasks\ErrorFix Scan.job (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.36
Version de la base de données: 2142
Windows 6.0.6001 Service Pack 1
16/05/2009 7:08:57 PM
mbam-log-2009-05-16 (19-08-57).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 175413
Temps écoulé: 2 hour(s), 57 minute(s), 4 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 8
Fichier(s) infecté(s): 144
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dll (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Users\veronika\AppData\Roaming\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380 (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Program Files\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Users\veronika\AppData\Roaming\RegTool\Logs\2009-05-12 09-29-320.log (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-61.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-62.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-63.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-64.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-65.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-66.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-67.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-68.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-69.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-70.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-71.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-72.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-73.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-74.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-75.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-76.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-77.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-78.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-79.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-80.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-81.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-82.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-83.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-84.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-85.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-86.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-87.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-88.db (Rogue.RegTool) -> Not selected for removal.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-89.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-90.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-91.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-92.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-93.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-94.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-95.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-96.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-97.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-98.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-99.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Evidence.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Junk.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Registry.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results\Update.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\resultsw.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs\2009-02-23 08-37-490.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs\2009-02-23 09-51-060.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\Favorites\Free Porn Videos - Sex, Porno, Porn Tube, Free XXX Porn - PornFuZe.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\veronika\Favorites\Free porn videos - Sex, XXX, free pornos at You Porn.com.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Windows\Tasks\RegTool Scan.job (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Windows\Tasks\ErrorFix Scan.job (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.36
Version de la base de données: 2142
Windows 6.0.6001 Service Pack 1
16/05/2009 7:08:57 PM
mbam-log-2009-05-16 (19-08-57).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 175413
Temps écoulé: 2 hour(s), 57 minute(s), 4 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 8
Fichier(s) infecté(s): 144
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dll (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Users\veronika\AppData\Roaming\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380 (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\Results (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\ErrorFix\Logs (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Program Files\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Users\veronika\AppData\Roaming\RegTool\Logs\2009-05-12 09-29-320.log (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData\Roaming\RegTool\QuarantineW\2009-05-12 09-42-380\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\veronika\AppData -
Peux tu poster le rapport,je lis pas encore dans les boules de cristal
-
voila c est fait
-
Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
Télécharges :
Malwarebytes ou :
Malwarebytes
* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
* Potasses le Tuto pour te familiariser avec le prg :
( cela dis, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
* Lance Malwarebyte's .
Fais un examen dit "Complet" .
--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) -
Télécharges et installes le logiciel de diagnostic :
ici Hijackthis
ou ici Hijackthis
ou ici Hijackthis
ou renommé
Ouvre hijackthis
fais scan only
coches ces lignes sur leur gauche:
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://ma-config.com/activex/hardwaredetection_3_1_1_0.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
tu les coches et tu clic sur "fix checked"
et tu fermes le programme. -
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Ultimate ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
BIOS : Ver 1.00PARTTBLx
USER : veronika ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:74 Go (Free:37 Go)
D:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 16/05/2009|15:38 )
[ UAC => 0 ]
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr"
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\veronika\Favorites\YouTube - crackhead gets booked stealing at shoppers.url
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 16/05/2009|15:39 - Option : [1]
-----------\\ Fin du rapport a 15:39:42.99
voila -
Desactives ton uac le temps de la desinfection
Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
- Vas dans "Démarrer" puis Panneau de configuration.
- Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
- Clique sur Continuer.
- Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
- Valide par OK et redémarre.
Tuto
Ensuite executes tous les logiciels utilisés en tant qu'administrateur (cliques droit avec la souris)
Télécharge TOOLBAR S&D( de Eric_71/Team IDN ) sur ton bureau :
( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )
!! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!
* Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
--> Tapes ( option " recherche " ) puis tape sur [Entrée].
Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse
( le rapport est en outre sauvegardé ici -> C:\TB.txt ) -
Logfile of random's system information tool 1.06 (written by random/random)
Run by veronika at 2009-05-16 15:09:43
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 38 GB (50%) free of 76 GB
Total RAM: 1013 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:07 PM, on 16/05/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\veronika\Desktop\RSIT.exe
C:\Program Files\trend micro\veronika.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [dll] rundll32 dll32,sm
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://ma-config.com/activex/hardwaredetection_3_1_1_0.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
-
info.txt logfile of random's system information tool 1.06 2009-05-16 14:57:26
======Uninstall list======
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\Windows\UNNeroShowTime.exe /UNINSTALL
-->C:\Windows\UNNeroVision.exe /UNINSTALL
-->C:\Windows\UNRecode.exe /UNINSTALL
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Ares 2.1.1-->"C:\Program Files\Ares\uninstall.exe"
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Chessmaster Challenge (remove only)-->"C:\Program Files\PlayFirst\Chessmaster Challenge\Uninstall.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\UIU32a.exe -U -Iwis30B2a.inf
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
Highlight Viewer (Windows Live Toolbar)-->MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Quick Launch Buttons 6.30 J1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0009 -removeonly uninst
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Intel(R) Network Connections Drivers-->Prounstl.exe
iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Map Button (Windows Live Toolbar)-->MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Nero 7 Premium-->MsiExec.exe /I{235BBFC6-D863-4066-A01A-3BD504C31033}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Quick Zip 4.60.019-->"C:\Program Files\QuickZip4\unins000.exe"
QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
RICOH R5C83x/84x Flash Media Controller Driver Ver.1.00.01A-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x9 anything
Smart Menus (Windows Live Toolbar)-->MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
Windows Live Favorites for Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar Extension (Windows Live Toolbar)-->MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
======Security center information======
AS: Windows Defender
======System event log======
Computer Name: veronika-PC
Event Code: 7000
Message: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error:
The system cannot find the path specified.
Record Number: 43473
Source Name: Service Control Manager
Time Written: 20090406000256.000000-000
Event Type: Error
User:
Computer Name: veronika-PC
Event Code: 6008
Message: The previous system shutdown at 9:42:25 PM on 05/04/2009 was unexpected.
Record Number: 43529
Source Name: EventLog
Time Written: 20090406014342.000000-000
Event Type: Error
User:
Computer Name: veronika-PC
Event Code: 15016
Message: Unable to initialize the security package Kerberos for server side authentication. The data field contains the error number.
Record Number: 43538
Source Name: Microsoft-Windows-HttpEvent
Time Written: 20090406014350.369551-000
Event Type: Error
User:
Computer Name: veronika-PC
Event Code: 7000
Message: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error:
The system cannot find the path specified.
Record Number: 43590
Source Name: Service Control Manager
Time Written: 20090406014412.000000-000
Event Type: Error
User:
Computer Name: veronika-PC
Event Code: 6008
Message: The previous system shutdown at 1:25:08 AM on 06/04/2009 was unexpected.
Record Number: 43650
Source Name: EventLog
Time Written: 20090406113648.000000-000
Event Type: Error
User:
=====Application event log=====
Computer Name: veronika-PC
Event Code: 1000
Message: Faulting application DllHost.exe, version 6.0.6000.16386, time stamp 0x4549b14e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x019db5ed, process id 0x8ac, application start time 0x01c9d6548772efe1.
Record Number: 11216
Source Name: Application Error
Time Written: 20090516183140.000000-000
Event Type: Error
User:
Computer Name: veronika-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-1921634279-322472747-1836765424-1000:
Process 932 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1921634279-322472747-1836765424-1000
Record Number: 11224
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090516183359.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: veronika-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-1921634279-322472747-1836765424-1000_Classes:
Process 592 (\Device\HarddiskVolume1\Windows\System32\csrss.exe) has opened key \REGISTRY\USER\S-1-5-21-1921634279-322472747-1836765424-1000_CLASSES
Process 932 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1921634279-322472747-1836765424-1000_CLASSES
Record Number: 11225
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090516183359.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: veronika-PC
Event Code: 1000
Message: Faulting application DllHost.exe, version 6.0.6000.16386, time stamp 0x4549b14e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x0163b5ed, process id 0xfac, application start time 0x01c9d655d03bc218.
Record Number: 11246
Source Name: Application Error
Time Written: 20090516184044.000000-000
Event Type: Error
User:
Computer Name: veronika-PC
Event Code: 1000
Message: Faulting application DllHost.exe, version 6.0.6000.16386, time stamp 0x4549b14e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x0197b5ed, process id 0x8f8, application start time 0x01c9d65796a03120.
Record Number: 11261
Source Name: Application Error
Time Written: 20090516185337.000000-000
Event Type: Error
User:
=====Security event log=====
Computer Name: veronika-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 24582
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090516185721.921534-000
Event Type: Audit Failure
User:
Computer Name: veronika-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 24583
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090516185721.983934-000
Event Type: Audit Failure
User:
Computer Name: veronika-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 24584
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090516185722.015134-000
Event Type: Audit Failure
User:
Computer Name: veronika-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 24585
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090516185722.046334-000
Event Type: Audit Failure
User:
Computer Name: veronika-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 24586
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090516185722.077534-000
Event Type: Audit Failure
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
"PROCESSOR_REVISION"=0e08
"NUMBER_OF_PROCESSORS"=2
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
-----------------EOF-----------------
voila le premier r apport -
Tu as la procedure du rsit sur le post 6
-
ok je le fais la 1 minute
-
c est quoi le rsit ?????
-
Parfait tu peux me poster le rsit maintenant
-
voila le rapport apres la deuxieme etape
-
############################## [ UsbFix V3.021 # Cleaning ]
# User : veronika (Administrators) # VERONIKA-PC
# Update on 16/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 2:35:10 PM | 5/16/2009
# Genuine Intel(R) CPU T2300 @ 1.66GHz
# Microsoft® Windows Vista™ Ultimate (6.0.6001 32-bit) # Service Pack 1
# Internet Explorer 7.0.6001.18000
# Windows Firewall Status : Disabled
# C:\ # Local Fixed Disk # 74.53 Go (35.02 Go free) # NTFS
# D:\ # CD-ROM Disc
############################## [ Processus actifs ]
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\PSIService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## [ Fichiers # Dossiers infectieux ]
################## [ Registre # Clés Run infectieuses ]
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\...\Explorer\MountPoints2\{878f1aa5-0166-11de-b1c7-00163659f544}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{a6a58800-2698-11de-8fff-00163659f544}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[18/09/2006 05:43 PM|--a------|24] - C:\autoexec.bat
[19/01/2008 03:45 AM|-rahs----|333203] - C:\bootmgr
[23/02/2009 03:41 AM|-ra-s----|8192] - C:\BOOTSECT.BAK
[18/09/2006 05:43 PM|--a------|10] - C:\config.sys
[17/03/2007 07:41 AM|-rahs----|171136] - C:\grldr
[?|?|?] - C:\hiberfil.sys
[21/04/2009 10:26 AM|-rahs----|0] - C:\IO.SYS
[21/04/2009 10:26 AM|-rahs----|0] - C:\MSDOS.SYS
[?|?|?] - C:\pagefile.sys
[17/04/2009 03:34 PM|--a------|9934848] - C:\testcap.avi
[16/05/2009 02:36 PM|--a------|3190] - C:\UsbFix.txt
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ Cracks / Keygens / Serials ]
# -> Nothing found !
################## [ ! Fin du rapport # UsbFix V3.021 ! ]
- 1
- 2