Pc infecté
Mon pc est infecté, quand je lance mon anti-virus zonelabs il bloque sur l'analyse du fichier _default.pif et m'affiche un écran bleu qui m'oblige à éteindre l'ordi. De plus avant le blocage plusieurs fenêtres messages de sécurité de windows apparaissent me disant que l'ordi est en danger. Je redémarre et essaye d'accéder au site kaspersky pour faire un scan en ligne mais il m'affiche cette page ne peut être trouvée. Du coup je ne sais pas si je peux accéder à d'autres sites pour télécharger par exemple rsit ou hijackthis. Donc je dois le faire au boulot et les mettre sur une cle usb ou un cd : probleme je ne peux telecharger de fichiers exe. Existe-t-il un zip de rsit ?
Que dois-je faire ?
Merci d'avance
Configuration: Windows XP Internet Explorer 7.0
30 réponses
Une infection informatique est suspectée lorsque l'antivirus Zonelabs bloque l'analyse sur le fichier _default.pif et déclenche un écran bleu, avec des alertes de sécurité Windows XP. Des messages d'alerte indiquent que l'ordinateur est en danger et l'accès au scan en ligne (Kaspersky) est impossible, obligeant à redémarrer et compliquant l'installation d'outils comme rsit ou HijackThis. En cas de contrainte professionnelle, des solutions proposées incluent l'usage de GenProc via des archives ZIP et le décryptage de rapports pour orienter les actions, avec des précautions supplémentaires. D'autres échanges évoquent l'existence d'alternatives comme la déconnexion du net, l'utilisation d'un autre PC pour télécharger des outils, et l'importance de veiller à ne pas exécuter de fichiers EXE sans vérification.
-
Contributeur sécuritéOk tiens nous au courant
Effectivement.
Et merci d'avoir prévenu.
Bye. -
Contributeur sécuritéok tiens nous au courant
-
Contributeur sécuritésinon tente ceci:
télécharge OTM
http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTM.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.
(attention bien mettre :files)
:processes
explorer.exe
:services
ethxvqrq
amirnlkl
hhtgmre
mbr
pkjqju
qhayq
xpxbtxvt
dwshd
:files
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6MSSBC9B\x[2]
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q4X69W16\x[1]
C:\WINDOWS\system32\66.scr
C:\WINDOWS\SYSTEM\1SASS.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\ETHXVQRQ.SYS
C:\WINDOWS\system\smsc.exe
C:\WINDOWS\system\1sass.exe
C:\WINDOWS\system\smsc.exe
C:\WINDOWS\System32\66.scr
C:\WINDOWS\System32\40.scr
C:\WINDOWS\System32\86.scr
C:\WINDOWS\system32\drivers\ethxvqrq.sys
C:\WINDOWS\System32\??.scr
C:\WINDOWS\system32\021.tmp
C:\WINDOWS\system32\082.tmp
C:\WINDOWS\system32\??.tmp
C:\DOCUME~1\hic\LOCALS~1\Temp\mbr.sys
C:\WINDOWS\system32\04.tmp
C:\WINDOWS\system32\04.tmp
C:\WINDOWS\system32\090.tmp
C:\WINDOWS\System32\drivers\dwshd.sys
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WSSVC"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system\1sass.exe"=-
"C:\WINDOWS\system\smsc.exe"=-
"C:\WINDOWS\System32\66.scr"=-
"C:\WINDOWS\System32\40.scr"=-
"C:\WINDOWS\System32\86.scr"=-
:commands
[purity]
[emptytemp]
[start explorer]
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTM\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
_______________________
puis
colle un scan avec bitdefender free -
Contributeur sécuritéSalut tente combofix seul ensuite essaye le CFscript ...
++ -
Contributeur sécuritéPour fusionner:
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
_______________
telecharge combofix:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Sauvegarde le sur ton bureau et pas ailleurs !
_________________
Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
Driver ::
ethxvqrq
amirnlkl
hhtgmre
mbr
pkjqju
qhayq
xpxbtxvt
dwshd
File::
C:\WINDOWS\system\1sass.exe
C:\WINDOWS\system\smsc.exe
C:\WINDOWS\System32\66.scr
C:\WINDOWS\System32\40.scr
C:\WINDOWS\System32\86.scr
C:\WINDOWS\system32\drivers\ethxvqrq.sys
C:\WINDOWS\System32\??.scr
C:\WINDOWS\system32\021.tmp
C:\WINDOWS\system32\082.tmp
C:\WINDOWS\system32\??.tmp
C:\DOCUME~1\hic\LOCALS~1\Temp\mbr.sys
C:\WINDOWS\system32\04.tmp
C:\WINDOWS\system32\04.tmp
C:\WINDOWS\system32\090.tmp
C:\WINDOWS\System32\drivers\dwshd.sys
Registry::
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WSSVC"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system\1sass.exe"=-
"C:\WINDOWS\system\smsc.exe"=-
"C:\WINDOWS\System32\66.scr"=-
"C:\WINDOWS\System32\40.scr"=-
"C:\WINDOWS\System32\86.scr"=-
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
___________________________
repare windows comme ceci
• Cliquez sur le menu Démarrer
• Sélectionnez exécuter
• tapez SFC*/scannow (l'astérix représentant un espace) puis cliquez sur OK
Une popup peut alors apparaitre : Insérez le CD-ROM de Windows XP puis cliquez sur le bouton Recommencer...
Ceci ne supprime aucun programme, ni de données de votre disque dur, pas même la configuration et vos icônes.
La vérification et la réparation des fichiers s’effectuent alors ...
__________________________
remets un rapport rsit et dis si encore des soucis-
-
Contributeur sécurité@hicHello,
Effectue ce qui est demandé dans le message N° 79 de Jlpjlp et poste ensuite ce rapport: C:\ComboFix.txt
@+ -
@Trying2j'essaie depuis 14h15 et ça ne marche pas
je fais exécuter combofix (après avoir fait glisser CFScriprt sur l'icône) et il ne se passe rien.
j'ai attendu longtemps (rien qu'a voir l'heure qu'il est) avant d'arrêter le pc or j'ai dû m'y prendre à plusieurs reprises.
ça rame, rame, rame ... selon les cas après le login le bureau mets un temps fou à s'afficher et en plus j'ai le message d'erreur suivant : error while unpacking program, code LP5.
-
-
par contre ça rame de nouveau
-
voila un rapport
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== REGISTRY ==========
========== FILES ==========
File move failed. F:\LaunchU3.exe scheduled to be moved on reboot.
J:\LaunchU3.exe moved successfully.
C:\procexp.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: am
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 23005016 bytes
->Google Chrome cache emptied: 7408548 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: hic
->Temp folder emptied: 9598257 bytes
->Temporary Internet Files folder emptied: 5282213 bytes
->Java cache emptied: 0 bytes
User: hif
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
User: LocalService
->Temp folder emptied: 32913 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 137832 bytes
User: lou
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 1172882 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 4096 bytes
File delete failed. C:\WINDOWS\temp\tmp000063c9\tmp00000000 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT063df.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied: 256 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 44,63 mb
OTM by OldTimer - Version 3.0.0.2 log created on 06262009_215445
Files moved on Reboot...
File move failed. F:\LaunchU3.exe scheduled to be moved on reboot.
File C:\WINDOWS\temp\tmp000063c9\tmp00000000 not found!
C:\WINDOWS\temp\ZLT063df.TMP moved successfully.
Registry entries deleted on Reboot... -
Contributeur sécurité@ Hic, ne fais pas la manip avec OTM, elle est inutile.
Télécharge le RT de BitDefender.
Double clique sur le fichier téléchargé pour le dézipper.
Clique ensuite sur le fichier nommé: cleaner_gui.exe
Une fenêtre s'ouvre: Clique sur Start.
Si l'infection est détectée, l'utilitaire te le dira et lancera le nettoyage.
A la fin il te sera proposé de redémarrer: Accepte en cliquant sur Yes.
Poste nous un rapport Rsit ensuite quand tu auras redémarré ton pc. -
Contributeur sécuritéJe vous laisse .. je pars maintenant.
A+ tard :)
-
Contributeur sécuritéSalut :
Branche tes sources externes sans les ouvrir
Si vous etes sous Vista Désactivez l'UAC
Télécharge OTM (Old Timer) sur ton bureau:
---> Sous XP: Double-clique sur OTM.exe afin de le lancer.
Sous Vista: fais un clic droit sur OTM et choisis "exécuter en tant qu'administrateur"
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:Processes
explorer.exe
:Reg
:Files
F:\LaunchU3.exe
J:\LaunchU3.exe
C:\procexp.exe
:Commands
[start explorer]
[emptytemp]
[purity]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTM.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
Ensuite:
Télécharge Random's System Information Tool (RSIT) par random/random et sauvegarde-le sur ton Bureau.
* Double-clique sur RSIT.exe afin de lancer RSIT.
* Clique sur Continue à l'écran " Disclaimer of warranty ".
* Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
* Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (qui sera affiché) ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
Note : Les deux rapports sont également sauvegardés %systemdrive%\rsit ou C:\rsit
++-
Logfile of random's system information tool 1.06 (written by random/random)
Run by hic at 2009-06-26 22:21:17
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 6 GB (32%) free of 17 GB
Total RAM: 511 MB (41% free)
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-73586283-1801674531-1007.job
C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 544032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-26 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-06-26 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 544032]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CoolSwitch"=C:\WINDOWS\system32\taskswitch.exe [2001-10-19 45632]
"FastUser"=C:\WINDOWS\system32\fast.exe [2001-10-19 49216]
"FreePDF Assistant"=C:\Program Files\FreePDF_XP\fpassist.exe [2003-12-29 130560]
"NeroCheck"=C:\WINDOWS\system32\\NeroCheck.exe [2001-07-09 155648]
"SSBkgdUpdate"=C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-09-30 155648]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-03-21 69632]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2007-12-11 267048]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-02-18 981384]
"VX1000"=C:\WINDOWS\vVX1000.exe [2007-04-10 709992]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2007-05-17 279912]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-12-11 286720]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-06-26 148888]
"BDAgent"=C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [2009-03-19 778240]
"WSSVC"=C:\WINDOWS\system\smsc.exe [2009-06-26 23552]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-19 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lsass]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SVCWINSPOOL]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WM System Decode Application]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\lsass]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SVCWINSPOOL]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WM System Decode Application]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=FFFFFFFF
"NoDrives"=0
"NoFind"=0
"NoFolderOptions"=0
"NoRun"=0
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Sony\Media Manager for PSP 2.5\MediaManager.exe"="C:\Program Files\Sony\Media Manager for PSP 2.5\MediaManager.exe:*:Enabled:Media Manager for PSP 2.5"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\system\msdct.exe"="C:\WINDOWS\system\msdct.exe:*:WM System Decode Application"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\WINDOWS\system32\taskswitch.exe"="C:\WINDOWS\system32\taskswitch.exe:*:Enabled:ENABLE"
"C:\Program Files\FreePDF_XP\fpassist.exe"="C:\Program Files\FreePDF_XP\fpassist.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system\1sass.exe"="C:\WINDOWS\system\1sass.exe:*:Microsoft Enabled"
"C:\WINDOWS\system\smsc.exe"="C:\WINDOWS\system\smsc.exe:*:Microsoft Enabled"
"C:\WINDOWS\System32\66.scr"="C:\WINDOWS\System32\66.scr:*:Microsoft Enabled"
"C:\WINDOWS\System32\40.scr"="C:\WINDOWS\System32\40.scr:*:Microsoft Enabled"
"C:\WINDOWS\System32\86.scr"="C:\WINDOWS\System32\86.scr:*:Microsoft Enabled"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
======List of files/folders created in the last 2 months======
2009-06-26 22:21:17 ----D---- C:\rsit
2009-06-26 21:51:48 ----D---- C:\_OTM
2009-06-26 21:43:32 ----RASHD---- C:\autorun.inf
2009-06-26 21:35:57 ----A---- C:\UsbFix.txt
2009-06-26 20:38:31 ----D---- C:\UsbFix
2009-06-26 16:08:40 ----D---- C:\Documents and Settings\hic\Application Data\BitDefender
2009-06-26 16:07:36 ----D---- C:\Program Files\BitDefender
2009-06-26 16:07:36 ----D---- C:\Documents and Settings\All Users\Application Data\BitDefender
2009-06-26 16:05:38 ----D---- C:\Program Files\Fichiers communs\BitDefender
2009-06-26 14:46:58 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-26 14:29:45 ----D---- C:\WINDOWS\Sun
2009-06-26 14:24:15 ----A---- C:\WINDOWS\system32\javaws.exe
2009-06-26 14:24:15 ----A---- C:\WINDOWS\system32\javaw.exe
2009-06-26 14:24:15 ----A---- C:\WINDOWS\system32\java.exe
2009-06-26 14:24:15 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-06-26 14:23:18 ----D---- C:\Program Files\Java
2009-06-25 23:04:53 ----D---- C:\Program Files\CCleaner
2009-06-25 22:31:51 ----D---- C:\Program Files\Panda Security
2009-06-25 22:26:39 ----D---- C:\Program Files\trend micro
2009-06-25 20:37:02 ----D---- C:\Documents and Settings\hic\Application Data\Malwarebytes
2009-06-25 20:34:55 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-25 20:34:55 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-25 18:24:42 ----SHD---- C:\RECYCLER
2009-06-25 16:43:57 ----A---- C:\WINDOWS\zip.exe
2009-06-25 16:43:57 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-06-25 16:43:57 ----A---- C:\WINDOWS\SWSC.exe
2009-06-25 16:43:57 ----A---- C:\WINDOWS\SWREG.exe
2009-06-25 16:43:57 ----A---- C:\WINDOWS\sed.exe_RenameGenProc
2009-06-25 16:43:57 ----A---- C:\WINDOWS\PEV.exe
2009-06-25 16:43:57 ----A---- C:\WINDOWS\NIRCMD.exe
2009-06-25 16:43:57 ----A---- C:\WINDOWS\grep.exe_RenameGenProc
2009-06-25 16:43:11 ----D---- C:\WINDOWS\ERDNT
2009-06-25 16:43:02 ----SD---- C:\antibagle
2009-06-24 20:32:33 ----A---- C:\Eula.txt
2009-06-24 19:44:48 ----D---- C:\Documents and Settings\hic\Application Data\Sun
2009-06-22 20:46:00 ----D---- C:\WINDOWS\Minidump
2009-06-01 19:00:02 ----D---- C:\WINDOWS\WLTB Custom Button Feeds
2009-06-01 18:59:59 ----SD---- C:\WINDOWS\system32\%SystemDrive%
2009-06-01 18:59:59 ----D---- C:\WINDOWS\Google Toolbar
2009-06-01 16:14:46 ----D---- C:\Program Files\Western Digital
2009-06-01 15:51:48 ----D---- C:\Program Files\Fichiers communs\eSellerate
2009-06-01 15:30:19 ----D---- C:\Program Files\Western Digital Corporation
2009-06-01 15:12:58 ----D---- C:\Program Files\Microsoft LifeCam
2009-06-01 15:03:35 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-06-01 15:01:26 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-06-01 15:01:26 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-06-01 15:01:26 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-06-01 15:01:25 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-06-01 15:01:23 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-06-01 15:01:23 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-06-01 15:01:22 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-06-01 15:01:21 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-06-01 15:01:18 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-06-01 15:00:53 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-06-01 15:00:53 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-06-01 15:00:52 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-06-01 15:00:51 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-06-01 15:00:49 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-06-01 15:00:48 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-06-01 15:00:46 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-06-01 15:00:45 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-06-01 15:00:42 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-06-01 14:59:05 ----RA---- C:\WINDOWS\VX1000.ini
2009-06-01 14:59:05 ----RA---- C:\WINDOWS\system32\LCCoin14.dll
2009-06-01 14:59:05 ----RA---- C:\WINDOWS\system32\cVX1000.dll
2009-06-01 14:59:04 ----RA---- C:\WINDOWS\VX1000.dll
2009-06-01 14:59:04 ----RA---- C:\WINDOWS\vVX1000.exe
2009-06-01 14:59:04 ----RA---- C:\WINDOWS\vVX1000.dll
2009-06-01 14:58:43 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2009-05-29 19:53:15 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-05-21 20:13:57 ----D---- C:\Documents and Settings\All Users\Application Data\Fnac
2009-05-21 20:13:55 ----D---- C:\Program Files\Fnac
2009-05-21 11:27:01 ----D---- C:\Documents and Settings\All Users\Application Data\hps
2009-05-21 11:23:14 ----D---- C:\Program Files\Photocite Collection 4
2009-05-07 19:40:22 ----D---- C:\Documents and Settings\All Users\Application Data\{3AB7D18B-6873-453C-A0C7-D330283EDE14}
======List of files/folders modified in the last 2 months======
2009-06-26 22:21:18 ----D---- C:\WINDOWS\Prefetch
2009-06-26 22:13:43 ----D---- C:\WINDOWS\Temp
2009-06-26 22:07:32 ----D---- C:\WINDOWS\Internet Logs
2009-06-26 22:07:30 ----SHD---- C:\WINDOWS\CSC
2009-06-26 21:56:32 ----D---- C:\WINDOWS\system32
2009-06-26 21:55:06 ----D---- C:\WINDOWS\system32\drivers
2009-06-26 21:20:47 ----D---- C:\WINDOWS
2009-06-26 18:51:15 ----SHD---- C:\WINDOWS\Installer
2009-06-26 18:50:04 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-06-26 18:42:09 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-06-26 18:18:41 ----D---- C:\WINDOWS\system
2009-06-26 16:07:36 ----RD---- C:\Program Files
2009-06-26 16:05:38 ----D---- C:\Program Files\Fichiers communs
2009-06-26 14:17:34 ----D---- C:\WINDOWS\security
2009-06-26 14:16:36 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-26 13:10:34 ----SD---- C:\WINDOWS\Tasks
2009-06-25 23:30:57 ----SHD---- C:\System Volume Information
2009-06-25 23:30:57 ----D---- C:\WINDOWS\system32\Restore
2009-06-25 22:31:50 ----HD---- C:\WINDOWS\inf
2009-06-25 18:18:33 ----D---- C:\WINDOWS\network diagnostic
2009-06-25 17:42:09 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-06-25 17:39:34 ----A---- C:\WINDOWS\system.ini
2009-06-25 17:14:56 ----D---- C:\WINDOWS\SoftwareDistribution
2009-06-25 17:12:41 ----D---- C:\WINDOWS\system32\config
2009-06-25 17:10:00 ----D---- C:\WINDOWS\AppPatch
2009-06-25 16:32:50 ----D---- C:\WINDOWS\Help
2009-06-22 19:45:10 ----A---- C:\rollback.ini
2009-06-21 22:45:00 ----D---- C:\Photos
2009-06-21 15:28:13 ----D---- C:\WINDOWS\system32\ZoneLabs
2009-06-06 12:33:40 ----D---- C:\Program Files\Google
2009-06-06 12:33:40 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-06-01 16:29:09 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-06-01 15:17:54 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-06-01 15:16:09 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-06-01 15:04:28 ----D---- C:\Program Files\Windows Media Player
2009-06-01 15:01:29 ----D---- C:\WINDOWS\system32\DirectX
2009-06-01 15:01:18 ----RSD---- C:\WINDOWS\assembly
2009-06-01 14:59:05 ----D---- C:\WINDOWS\twain_32
2009-05-21 12:28:32 ----A---- C:\WINDOWS\win.ini
2009-05-21 12:16:02 ----D---- C:\Documents and Settings\hic\Application Data\U3
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-19 40320]
R1 KLIF;KLIF; C:\WINDOWS\system32\DRIVERS\klif.sys [2008-12-11 148496]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-02-18 353672]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 bdfm;BDFM; C:\WINDOWS\system32\drivers\bdfm.sys [2009-06-26 145544]
R3 bdfsfltr;bdfsfltr; C:\WINDOWS\system32\drivers\bdfsfltr.sys [2009-04-06 266376]
R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys []
R3 EL90XBC;Pilote de la carte EtherLink XL 90XB/C 3Com; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-12-19 539008]
R3 sysdrv32;Play Port I/O Driver; \??\C:\WINDOWS\system32\drivers\sysdrv32.sys []
R3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-19 12672]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-19 57600]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-19 20480]
R3 VX1000;VX-1000; C:\WINDOWS\system32\DRIVERS\VX1000.sys [2007-04-10 1966312]
S1 ethxvqrq;ethxvqrq; C:\WINDOWS\system32\drivers\ethxvqrq.sys []
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-19 14848]
S2 port135sik;port135sik; \??\C:\WINDOWS\system32\drivers\port135sik.sys []
S3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 amirnlkl;amirnlkl; \??\C:\WINDOWS\system32\021.tmp []
S3 catchme;catchme; \??\C:\DOCUME~1\hic\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 hhtgmre;hhtgmre; \??\C:\WINDOWS\system32\082.tmp []
S3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-19 9600]
S3 mbr;mbr; \??\C:\DOCUME~1\hic\LOCALS~1\Temp\mbr.sys []
S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-19 12288]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 pkjqju;pkjqju; \??\C:\WINDOWS\system32\04.tmp []
S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
S3 qhayq;qhayq; \??\C:\WINDOWS\system32\04.tmp []
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
S3 TSP;TSP; \??\C:\WINDOWS\system32\drivers\klif.sys []
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;Motorola USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2004-08-03 25600]
S3 usbsermptxp;Motorola USB Modem Driver for MPT XP; C:\WINDOWS\system32\DRIVERS\usbsermptxp.sys [2007-05-18 25600]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 xpxbtxvt;xpxbtxvt; \??\C:\WINDOWS\system32\090.tmp []
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []
S4 sr;Pilote de filtre de restauration système; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-19 73600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeActiveFileMonitor;Adobe Active File Monitor; C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-12 98304]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-10-31 110592]
R2 InteractiveLogon;InteractiveLogon; C:\WINDOWS\system32\Fast.exe [2001-10-19 49216]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-06-26 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2006-09-24 61440]
R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2009-04-29 419096]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-05-17 271720]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-02-18 2402184]
R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [2009-04-21 1631512]
R2 WM System Decode Application;WM System Decode Application; C:\WINDOWS\system\msdct.exe [2009-06-26 1052672]
R3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2007-12-11 504104]
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect; C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-12 118784]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-05-13 68096]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-27 182768]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2004-08-19 14336]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
-----------------EOF-----------------
-
-
Contributeur sécuritéslt merci d'avoir pris le relais car je suis occupé. Faire donc usbfix option 2 . À plus dès que possible ...
-
-
@fix200voila le rapport de usbfix
############################## [ UsbFix V3.033 ]
# User : hic (Administrateurs) # SWEETHOME
# Update on 15/06/09 by C_XX
# Start at: 21:10:36 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) 4 CPU 2.40GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.11
# Windows Firewall Status : Enabled
# AV : Protection System 1.0 [ Enabled | (!) Outdated ]
# AV : ZoneAlarm Security Suite Antivirus 8.0.298.004 [ (!) Disabled | Updated ]
# FW : ZoneAlarm Security Suite Firewall[ Enabled ]8.0.298.004
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 16,91 Go (5,13 Go free) # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque amovible # 7,67 Go (4,27 Go free) # FAT32
# F:\ # Disque CD-ROM # 5,46 Mo (0 Mo free) [U3 System] # CDFS
# J:\ # Disque amovible # 1,9 Go (3,09 Mo free) # FAT
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\Fast.exe
C:\WINDOWS\System32\alg.exe
################## [ Fichiers # Dossiers infectieux ]
Supprimé ! C:\WINDOWS\system32\drivers\sysdrv32.sys
Supprimé ! E:\autorun.inf
Supprimé ! E:\recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
(!) Non supprimé ! F:\autorun.inf
Supprimé ! J:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Supprimé ! HKLM\SYSTEM\CurrentControlSet\Services\sysdrv32
Supprimé ! HKLM\SYSTEM\ControlSet003\Services\sysdrv32
# HKLM\software\microsoft\security center "AntiVirusOverride" # -> Reset sucessfully !
################## [ Registre # Mountpoints2 ]
Supprimé ! HKCU\...\Explorer\MountPoints2\E\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{0a84aa0e-4ead-11de-8d18-0011802d8f46}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[08/05/2007 13:40|--a------|0] - C:\AUTOEXEC.BAT
[08/05/2007 13:34|---hs----|212] - C:\boot.ini
[19/08/2004 19:36|-rahs----|4952] - C:\Bootfont.bin
[08/05/2007 13:40|--a------|0] - C:\CONFIG.SYS
[28/07/2006 09:32|--a------|7005] - C:\Eula.txt
[?|?|?] - C:\hiberfil.sys
[08/05/2007 13:40|-rahs----|0] - C:\IO.SYS
[28/05/2007 16:31|--ah-----|301] - C:\IPH.PH
[08/05/2007 13:40|-rahs----|0] - C:\MSDOS.SYS
[19/08/2004 19:43|-rahs----|47564] - C:\NTDETECT.COM
[19/08/2004 19:43|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[03/02/2009 10:32|--a------|3550592] - C:\procexp.exe
[22/06/2009 19:45|--a------|1113] - C:\rollback.ini
[01/06/2009 15:39|--ah-----|268] - C:\sqmdata00.sqm
[01/06/2009 19:33|--ah-----|268] - C:\sqmdata01.sqm
[01/06/2009 19:39|--ah-----|268] - C:\sqmdata02.sqm
[14/06/2009 20:57|--ah-----|232] - C:\sqmdata03.sqm
[16/06/2009 20:17|--ah-----|268] - C:\sqmdata04.sqm
[16/06/2009 20:48|--ah-----|172] - C:\sqmdata05.sqm
[18/06/2009 12:39|--ah-----|268] - C:\sqmdata06.sqm
[21/06/2009 13:29|--ah-----|232] - C:\sqmdata07.sqm
[15/02/2009 12:36|--ah-----|232] - C:\sqmdata08.sqm
[24/02/2009 14:59|--ah-----|268] - C:\sqmdata09.sqm
[01/03/2009 14:37|--ah-----|232] - C:\sqmdata10.sqm
[26/03/2009 20:34|--ah-----|232] - C:\sqmdata11.sqm
[26/03/2009 20:34|--ah-----|232] - C:\sqmdata12.sqm
[29/03/2009 15:09|--ah-----|232] - C:\sqmdata13.sqm
[29/03/2009 15:09|--ah-----|232] - C:\sqmdata14.sqm
[31/03/2009 20:39|--ah-----|268] - C:\sqmdata15.sqm
[01/04/2009 20:44|--ah-----|232] - C:\sqmdata16.sqm
[03/05/2009 11:47|--ah-----|232] - C:\sqmdata17.sqm
[10/05/2009 13:38|--ah-----|268] - C:\sqmdata18.sqm
[17/05/2009 12:32|--ah-----|232] - C:\sqmdata19.sqm
[01/06/2009 15:39|--ah-----|244] - C:\sqmnoopt00.sqm
[01/06/2009 19:33|--ah-----|244] - C:\sqmnoopt01.sqm
[01/06/2009 19:39|--ah-----|244] - C:\sqmnoopt02.sqm
[14/06/2009 20:57|--ah-----|244] - C:\sqmnoopt03.sqm
[16/06/2009 20:17|--ah-----|244] - C:\sqmnoopt04.sqm
[16/06/2009 20:48|--ah-----|172] - C:\sqmnoopt05.sqm
[18/06/2009 12:39|--ah-----|244] - C:\sqmnoopt06.sqm
[21/06/2009 13:29|--ah-----|244] - C:\sqmnoopt07.sqm
[15/02/2009 12:36|--ah-----|244] - C:\sqmnoopt08.sqm
[24/02/2009 14:59|--ah-----|244] - C:\sqmnoopt09.sqm
[01/03/2009 14:37|--ah-----|244] - C:\sqmnoopt10.sqm
[26/03/2009 20:34|--ah-----|244] - C:\sqmnoopt11.sqm
[26/03/2009 20:34|--ah-----|244] - C:\sqmnoopt12.sqm
[29/03/2009 15:09|--ah-----|244] - C:\sqmnoopt13.sqm
[29/03/2009 15:09|--ah-----|244] - C:\sqmnoopt14.sqm
[31/03/2009 20:39|--ah-----|244] - C:\sqmnoopt15.sqm
[01/04/2009 20:44|--ah-----|244] - C:\sqmnoopt16.sqm
[03/05/2009 11:47|--ah-----|244] - C:\sqmnoopt17.sqm
[10/05/2009 13:38|--ah-----|244] - C:\sqmnoopt18.sqm
[17/05/2009 12:32|--ah-----|244] - C:\sqmnoopt19.sqm
[26/06/2009 21:20|--a------|5881] - C:\UsbFix.txt
[26/01/2009 13:30|--a------|559233] - E:\Annonciation de Cellesto BOTTICELLI.odt
[16/04/2009 17:17|--a------|49460] - E:\800px-Hampton_Court_main_entrance.jpg
[16/04/2009 17:18|--a------|89607] - E:\641px-Hampton_Court_Great_Gatehouse.jpg
[16/04/2009 17:18|--a------|86935] - E:\800px-Hampton_Court_03.jpg
[16/04/2009 17:18|--a------|99145] - E:\800px-HamptonCurt.jpg
[16/04/2009 17:23|--a------|27134] - E:\350px-Hampton-Court-E.jpg
[16/04/2009 17:23|--a------|29945] - E:\300px-Hampton-Court-F.jpg
[16/04/2009 17:51|--a------|4365] - E:\images.jpg
[16/04/2009 17:51|--a------|117710] - E:\HamptonCourt.jpg
[16/04/2009 17:51|--a------|3614] - E:\CA5KO1V1CAI5DNJHCAEB0M9ECAWXOVJTCAUDCHMDCASEES1MCAPB3DRJCA0582K1CANL7G7CCAFR8I1RCA7524F5CA0O7TNPCAOX4K03CACH2C1UCABA2SF0CAN3X0T3CAHZUD2MCAWFNN6CCAYTZF21CAHVZAPW.jpg
[19/05/2009 16:47|--a------|14525] - E:\mariotte.ltp
[12/02/2007 21:53|-r-------|277] - F:\autorun.inf
[13/02/2007 03:33|-r-------|1110016] - F:\LaunchU3.exe
[13/02/2007 04:23|-r-------|4558081] - F:\LaunchPad.zip
[12/02/2007 18:33|-ra------|1110016] - J:\LaunchU3.exe
[02/02/2009 10:14|--a------|32256] - J:\CD_Cover1.doc
[02/02/2009 10:16|--a------|32256] - J:\CD_Cover2.doc
[02/02/2009 10:26|--a------|32256] - J:\CD_Cover3.doc
[02/02/2009 12:58|--a------|32256] - J:\CD_Cover4.doc
[02/02/2009 13:03|--a------|32256] - J:\CD_Cover5.doc
[02/02/2009 13:06|--a------|32256] - J:\CD_Cover6.doc
[26/06/2009 18:55|--a------|1618] - J:\BOOTEX.LOG
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# J:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.033 ! ] -
voila le rapport
############################## [ UsbFix V3.033 ]
# User : hic (Administrateurs) # SWEETHOME
# Update on 15/06/09 by C_XX
# Start at: 21:36:03 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) 4 CPU 2.40GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.11
# Windows Firewall Status : Disabled
# AV : Protection System 1.0 [ Enabled | (!) Outdated ]
# AV : ZoneAlarm Security Suite Antivirus 8.0.298.004 [ (!) Disabled | Updated ]
# FW : ZoneAlarm Security Suite Firewall[ Enabled ]8.0.298.004
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 16,91 Go (5,43 Go free) # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque amovible # 7,67 Go (4,27 Go free) # FAT32
# F:\ # Disque CD-ROM # 5,46 Mo (0 Mo free) [U3 System] # CDFS
# G:\ # Disque amovible # 978,72 Mo (5,03 Mo free) [STORE'N'GO] # FAT
# H:\ # Disque amovible # 3,73 Go (47,24 Mo free) [UDISK] # FAT32
# I:\ # Disque fixe local # 931,28 Go (929,37 Go free) [My Book] # FAT32
# J:\ # Disque amovible # 1,9 Go (3,12 Mo free) # FAT
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\Fast.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Fichiers # Dossiers infectieux ]
Supprimé ! C:\WINDOWS\system32\drivers\sysdrv32.sys
(!) Non supprimé ! F:\autorun.inf
Supprimé ! I:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Supprimé ! HKLM\SYSTEM\CurrentControlSet\Services\sysdrv32
################## [ Registre # Mountpoints2 ]
################## [ Listing des fichiers présent ]
[08/05/2007 13:40|--a------|0] - C:\AUTOEXEC.BAT
[08/05/2007 13:34|---hs----|212] - C:\boot.ini
[19/08/2004 19:36|-rahs----|4952] - C:\Bootfont.bin
[08/05/2007 13:40|--a------|0] - C:\CONFIG.SYS
[28/07/2006 09:32|--a------|7005] - C:\Eula.txt
[?|?|?] - C:\hiberfil.sys
[08/05/2007 13:40|-rahs----|0] - C:\IO.SYS
[28/05/2007 16:31|--ah-----|301] - C:\IPH.PH
[08/05/2007 13:40|-rahs----|0] - C:\MSDOS.SYS
[19/08/2004 19:43|-rahs----|47564] - C:\NTDETECT.COM
[19/08/2004 19:43|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[03/02/2009 10:32|--a------|3550592] - C:\procexp.exe
[22/06/2009 19:45|--a------|1113] - C:\rollback.ini
[01/06/2009 15:39|--ah-----|268] - C:\sqmdata00.sqm
[01/06/2009 19:33|--ah-----|268] - C:\sqmdata01.sqm
[01/06/2009 19:39|--ah-----|268] - C:\sqmdata02.sqm
[14/06/2009 20:57|--ah-----|232] - C:\sqmdata03.sqm
[16/06/2009 20:17|--ah-----|268] - C:\sqmdata04.sqm
[16/06/2009 20:48|--ah-----|172] - C:\sqmdata05.sqm
[18/06/2009 12:39|--ah-----|268] - C:\sqmdata06.sqm
[21/06/2009 13:29|--ah-----|232] - C:\sqmdata07.sqm
[15/02/2009 12:36|--ah-----|232] - C:\sqmdata08.sqm
[24/02/2009 14:59|--ah-----|268] - C:\sqmdata09.sqm
[01/03/2009 14:37|--ah-----|232] - C:\sqmdata10.sqm
[26/03/2009 20:34|--ah-----|232] - C:\sqmdata11.sqm
[26/03/2009 20:34|--ah-----|232] - C:\sqmdata12.sqm
[29/03/2009 15:09|--ah-----|232] - C:\sqmdata13.sqm
[29/03/2009 15:09|--ah-----|232] - C:\sqmdata14.sqm
[31/03/2009 20:39|--ah-----|268] - C:\sqmdata15.sqm
[01/04/2009 20:44|--ah-----|232] - C:\sqmdata16.sqm
[03/05/2009 11:47|--ah-----|232] - C:\sqmdata17.sqm
[10/05/2009 13:38|--ah-----|268] - C:\sqmdata18.sqm
[17/05/2009 12:32|--ah-----|232] - C:\sqmdata19.sqm
[01/06/2009 15:39|--ah-----|244] - C:\sqmnoopt00.sqm
[01/06/2009 19:33|--ah-----|244] - C:\sqmnoopt01.sqm
[01/06/2009 19:39|--ah-----|244] - C:\sqmnoopt02.sqm
[14/06/2009 20:57|--ah-----|244] - C:\sqmnoopt03.sqm
[16/06/2009 20:17|--ah-----|244] - C:\sqmnoopt04.sqm
[16/06/2009 20:48|--ah-----|172] - C:\sqmnoopt05.sqm
[18/06/2009 12:39|--ah-----|244] - C:\sqmnoopt06.sqm
[21/06/2009 13:29|--ah-----|244] - C:\sqmnoopt07.sqm
[15/02/2009 12:36|--ah-----|244] - C:\sqmnoopt08.sqm
[24/02/2009 14:59|--ah-----|244] - C:\sqmnoopt09.sqm
[01/03/2009 14:37|--ah-----|244] - C:\sqmnoopt10.sqm
[26/03/2009 20:34|--ah-----|244] - C:\sqmnoopt11.sqm
[26/03/2009 20:34|--ah-----|244] - C:\sqmnoopt12.sqm
[29/03/2009 15:09|--ah-----|244] - C:\sqmnoopt13.sqm
[29/03/2009 15:09|--ah-----|244] - C:\sqmnoopt14.sqm
[31/03/2009 20:39|--ah-----|244] - C:\sqmnoopt15.sqm
[01/04/2009 20:44|--ah-----|244] - C:\sqmnoopt16.sqm
[03/05/2009 11:47|--ah-----|244] - C:\sqmnoopt17.sqm
[10/05/2009 13:38|--ah-----|244] - C:\sqmnoopt18.sqm
[17/05/2009 12:32|--ah-----|244] - C:\sqmnoopt19.sqm
[26/06/2009 21:43|--a------|5636] - C:\UsbFix.txt
[26/01/2009 13:30|--a------|559233] - E:\Annonciation de Cellesto BOTTICELLI.odt
[16/04/2009 17:17|--a------|49460] - E:\800px-Hampton_Court_main_entrance.jpg
[16/04/2009 17:18|--a------|89607] - E:\641px-Hampton_Court_Great_Gatehouse.jpg
[16/04/2009 17:18|--a------|86935] - E:\800px-Hampton_Court_03.jpg
[16/04/2009 17:18|--a------|99145] - E:\800px-HamptonCurt.jpg
[16/04/2009 17:23|--a------|27134] - E:\350px-Hampton-Court-E.jpg
[16/04/2009 17:23|--a------|29945] - E:\300px-Hampton-Court-F.jpg
[16/04/2009 17:51|--a------|4365] - E:\images.jpg
[16/04/2009 17:51|--a------|117710] - E:\HamptonCourt.jpg
[16/04/2009 17:51|--a------|3614] - E:\CA5KO1V1CAI5DNJHCAEB0M9ECAWXOVJTCAUDCHMDCASEES1MCAPB3DRJCA0582K1CANL7G7CCAFR8I1RCA7524F5CA0O7TNPCAOX4K03CACH2C1UCABA2SF0CAN3X0T3CAHZUD2MCAWFNN6CCAYTZF21CAHVZAPW.jpg
[19/05/2009 16:47|--a------|14525] - E:\mariotte.ltp
[12/02/2007 21:53|-r-------|277] - F:\autorun.inf
[13/02/2007 03:33|-r-------|1110016] - F:\LaunchU3.exe
[13/02/2007 04:23|-r-------|4558081] - F:\LaunchPad.zip
[22/02/2008 17:30|--a------|1492589] - G:\DSCF6813.JPG
[16/11/2008 11:52|--a------|3633250] - G:\IMG_1749.JPG
[08/12/2008 17:55|--a------|3122408] - G:\IMG_1898.JPG
[08/12/2008 17:55|--a------|3432780] - G:\IMG_1897.JPG
[25/12/2008 16:43|--a------|3616949] - G:\IMG_2041.JPG
[25/12/2008 16:46|--a------|3409150] - G:\IMG_2049.JPG
[25/12/2008 13:07|--a------|3650683] - G:\IMG_2012.JPG
[25/12/2008 12:28|--a------|3625542] - G:\IMG_2009.JPG
[25/12/2008 12:27|--a------|3271082] - G:\IMG_2008.JPG
[25/12/2008 13:06|--a------|3555647] - G:\IMG_2010.JPG
[04/05/2009 19:17|--a------|473630329] - G:\1er mai 2009.zip
[21/04/2008 12:17|--a------|3588594] - H:\01 01 Piste 1.wma
[21/04/2008 12:17|--a------|4186146] - H:\01 01 01 Piste 1.wma
[21/04/2008 12:17|--a------|3815634] - H:\De temps en temps.wma
[21/04/2008 12:17|--a------|3696162] - H:\02 02 Piste 2.wma
[21/04/2008 12:17|--a------|3146344] - H:\02 02 02 Piste 2.wma
[21/04/2008 12:20|--a------|4473066] - H:\Céline Dion.wma
[21/04/2008 12:17|--a------|3588546] - H:\Reviens.wma
[21/04/2008 12:17|--a------|9737782] - H:\03 03 Piste 3.wma
[21/04/2008 12:18|--a------|4347546] - H:\03 03 03 Piste 3.wma
[21/04/2008 12:18|--a------|3451098] - H:\Elle regarde ma main.wma
[21/04/2008 12:18|--a------|9086398] - H:\04 04 Piste 4.wma
[21/04/2008 12:18|--a------|4706106] - H:\04 04 04 Piste 4.wma
[21/04/2008 12:18|--a------|3469098] - H:\Céline Dion S'il suffisait qu'on s'aime.wma
[21/04/2008 12:18|--a------|4150290] - H:\Si tu ne pleures pas.wma
[21/04/2008 12:18|--a------|9510694] - H:\05 05 Piste 5.wma
[21/04/2008 12:18|--a------|4616466] - H:\05 05 05 Piste 5.wma
[21/04/2008 12:18|--a------|3415314] - H:\Céline Dion avec Garou.wma
[21/04/2008 12:18|--a------|4323594] - H:\Vivé per léi.wma
[21/04/2008 12:19|--a------|4449116] - H:\06 06 Piste 6.wma
[21/04/2008 12:19|--a------|3259888] - H:\06 06 06 06 Piste 6.wma
[21/04/2008 12:19|--a------|2907354] - H:\Céline Dion J'ai déposé mes armes.wma
[21/04/2008 12:19|--a------|4299690] - H:\Là bas.wma
[21/04/2008 12:19|--a------|4437186] - H:\06 06 06 Piste 6.wma
[21/04/2008 12:19|--a------|4652274] - H:\07 07 Piste 7.wma
[21/04/2008 12:19|--a------|3887368] - H:\07 07 07 Piste 7.wma
[21/04/2008 12:19|--a------|4066626] - H:\Minuit se lève.wma
[21/04/2008 12:19|--a------|3983010] - H:\07 07 07 07 07 Piste 7.wma
[21/04/2008 12:20|--a------|4951100] - H:\08 08 Piste 8.wma
[21/04/2008 12:20|--a------|4192170] - H:\08 08 08 08 Piste 8.wma
[21/04/2008 12:20|--a------|3684184] - H:\08 08 08 Piste 8.wma
[21/04/2008 12:20|--a------|4000962] - H:\Céline Dion On ne change pas.wma
[21/04/2008 12:20|--a------|2638362] - H:\08 08 08 08 08 08 08 08 Piste 8.wma
[21/04/2008 12:20|--a------|3343530] - H:\SOS.wma
[21/04/2008 12:20|--a------|3720040] - H:\09 09 09 Piste 9.wma
[21/04/2008 12:20|--a------|3349592] - H:\09 09 Piste 9.wma
[21/04/2008 12:20|--a------|3833562] - H:\Show must go on.wma
[21/04/2008 12:21|--a------|4234002] - H:\09 09 09 09 Piste 9.wma
[21/04/2008 12:21|--a------|5094524] - H:\10 10 Piste 10.wma
[21/04/2008 12:21|--a------|2865522] - H:\Céline Dion Siggy.wma
[21/04/2008 12:21|--a------|3827586] - H:\J'aurai voulu t'offrir.wma
[21/04/2008 12:21|--a------|3409314] - H:\10 10 10 10 Piste 10.wma
[21/04/2008 12:21|--a------|3618452] - H:\11 11 Piste 11.wma
[21/04/2008 12:21|--a------|2728106] - H:\11 11 11 Piste 11.wma
[21/04/2008 12:21|--a------|3714114] - H:\Céline Dion L'amour existe encore.wma
[21/04/2008 12:21|--a------|4138338] - H:\Et maintenant.wma
[21/04/2008 12:21|--a------|4759890] - H:\11 11 11 11 Piste 11.wma
[21/04/2008 12:22|--a------|1927322] - H:\12 12 12 12 Piste 12.wma
[21/04/2008 12:22|--a------|4377404] - H:\12 12 Piste 12.wma
[21/04/2008 12:22|--a------|3313722] - H:\Céline Dion avec Goldmann.wma
[21/04/2008 12:22|--a------|4251930] - H:\12 12 12 12 12 Piste 12.wma
[21/04/2008 12:22|--a------|3869444] - H:\13 13 Piste 13.wma
[21/04/2008 12:22|--a------|2584682] - H:\13 13 13 13 Piste 13.wma
[21/04/2008 12:22|--a------|3337626] - H:\Céline Dion Je t'aime encore.wma
[21/04/2008 12:22|--a------|3660306] - H:\13 13 13 Piste 13.wma
[21/04/2008 12:22|--a------|3881456] - H:\14 14 Piste 14.wma
[21/04/2008 12:22|--a------|2847594] - H:\Céline Dion Vole, Vole.wma
[21/04/2008 12:22|--a------|4371450] - H:\14 14 14 Piste 14.wma
[21/04/2008 12:22|--a------|4365512] - H:\15 15 Piste 15.wma
[21/04/2008 12:22|--a------|3391442] - H:\15 15 15 15 Piste 15.wma
[21/04/2008 12:22|--a------|3827658] - H:\Céline Dion Je lui dirais.wma
[21/04/2008 12:23|--a------|3654330] - H:\15 15 15 Piste 15.wma
[21/04/2008 12:23|--a------|4544792] - H:\16 16 Piste 16.wma
[21/04/2008 12:23|--a------|1413386] - H:\16 16 16 16 16 Piste 16.wma
[21/04/2008 12:23|--a------|3678258] - H:\Quand il n'y a que l'amour.wma
[21/04/2008 12:23|--a------|4281866] - H:\17 17 17 17 Piste 17.wma
[21/04/2008 12:23|--a------|3893394] - H:\Céline Dion avec IlDivo.wma
[21/04/2008 12:23|--a------|3983048] - H:\18 18 Piste 18.wma
[21/04/2008 12:23|--a------|3475074] - H:\01 01 01 01 Piste 1.wma
[10/09/2008 15:57|--a------|260141] - H:\Brennus 2.JPG
[10/09/2008 15:57|--a------|247079] - H:\brennus 3.jpg
[25/09/2008 09:55|--a------|1330651648] - H:\Diaporama Pergola.ppt
[21/04/2008 12:23|--a------|6242036] - H:\A fleur de vous.mp3
[08/12/2008 19:10|--a------|3070296] - H:\IMG_1945.JPG
[08/12/2008 17:55|--a------|3432780] - H:\IMG_1897.JPG
[08/12/2008 17:55|--a------|3122408] - H:\IMG_1898.JPG
[21/04/2008 12:23|--a------|5909293] - H:\Danse soleil.mp3
[08/12/2008 17:57|--a------|3617727] - H:\IMG_1906.JPG
[08/12/2008 17:57|--a------|3509454] - H:\IMG_1908.JPG
[08/12/2008 17:57|--a------|3524249] - H:\IMG_1905.JPG
[08/12/2008 17:54|--a------|3092104] - H:\IMG_1896.JPG
[21/04/2008 12:25|--a------|5429521] - H:\Avec des si.mp3
[21/04/2008 12:25|--a------|6049631] - H:\Bling bling.mp3
[21/04/2008 12:25|--a------|5984020] - H:\Amour sans loi.mp3
[21/04/2008 12:26|--a------|7034766] - H:\Ali and marisa.mp3
[21/04/2008 12:26|--a------|5119703] - H:\Amitie oubliee.mp3
[21/04/2008 12:28|--a------|5480754] - H:\Audrey.mp3
[21/04/2008 12:28|--a------|5373405] - H:\Bisous sucres.mp3
[21/04/2008 12:28|--a------|6188235] - H:\Bon moment.mp3
[19/04/2007 08:43|--a------|160056] - H:\ATHIS 2.jpg
[10/03/2008 09:15|--a------|124176] - H:\Dc22.jpg
[10/03/2008 09:15|--a------|77427] - H:\Dc31.jpg
[10/03/2008 09:15|--a------|121529] - H:\Dc21.jpg
[28/09/2001 13:00|--a------|83794] - H:\Dc34.jpg
[29/11/2007 08:19|--a------|64259] - H:\Dc16.JPG
[25/03/2008 08:31|--a------|74590] - H:\Dc15.JPG
[25/03/2008 08:31|--a------|74590] - H:\Dc314.JPG
[25/03/2008 08:31|--a------|74590] - H:\Dc35.JPG
[25/03/2008 08:31|--a------|92860] - H:\Dc13.JPG
[25/03/2008 08:31|--a------|99784] - H:\Dc14.JPG
[02/01/2008 13:11|--a------|4263470] - H:\Dc42.JPG
[02/01/2008 12:55|--a------|4612028] - H:\Dc12.JPG
[02/01/2008 12:55|--a------|4612028] - H:\Dc315.JPG
[27/03/2008 08:23|--a------|43325] - H:\Dc41.JPG
[14/03/2008 15:47|--a------|68333] - H:\Dc11.jpg
[14/03/2008 15:46|--a------|50565] - H:\Dc10.jpg
[25/03/2008 08:31|--a------|37285] - H:\Dc9.JPG
[27/03/2008 08:23|--a------|87319] - H:\Dc40.JPG
[27/03/2008 08:23|--a------|95264] - H:\Dc316.JPG
[27/03/2008 08:23|--a------|95264] - H:\Dc39.JPG
[05/11/2006 00:24|--a------|614311] - H:\Dc8.JPG
[09/09/2006 01:50|--a------|606200] - H:\Dc317.JPG
[27/03/2008 08:23|--a------|83527] - H:\Dc38.JPG
[06/06/2006 19:44|--a------|678910] - H:\Dc26.JPG
[23/05/2008 11:52|--a------|22254] - H:\Dc350.JPG
[25/03/2008 08:31|--a------|37975] - H:\Dc6.JPG
[27/03/2008 08:23|--a------|33659] - H:\Dc37.JPG
[10/10/2007 13:52|--a------|36667] - H:\Dc33.JPG
[12/02/2008 17:53|--a------|2352036] - H:\Dc25.jpg
[10/03/2008 08:49|--a------|34108] - H:\Dc24.jpg
[10/03/2008 08:49|--a------|13749] - H:\Dc318.jpg
[10/03/2008 08:49|--a------|13749] - H:\Dc32.jpg
[10/03/2008 08:49|--a------|20292] - H:\Dc23.jpg
[25/03/2008 08:31|--a------|53538] - H:\Dc5.JPG
[10/03/2008 09:14|--a------|147067] - H:\Dc20.jpg
[10/03/2008 09:14|--a------|161784] - H:\Dc30.jpg
[10/03/2008 09:14|--a------|178533] - H:\Dc19.jpg
[10/03/2008 09:13|--a------|107855] - H:\Dc18.jpg
[19/04/2007 08:43|--a------|160056] - H:\Dc319.jpg
[19/04/2007 09:18|--a------|24667] - H:\Dc320.JPG
[20/03/2008 08:42|--a------|1490182] - H:\Dc4.JPG
[25/03/2008 08:31|--a------|51803] - H:\Dc17.JPG
[26/04/2005 11:50|--a------|20067] - H:\Dc29.jpg
[07/03/2008 09:30|--a------|59387] - H:\Dc28.JPG
[27/03/2008 08:23|--a------|68119] - H:\Dc36.JPG
[02/07/2008 15:17|--a------|273920] - H:\CPG à imprimer.xls
[07/07/2004 10:16|--a------|48704] - H:\same.exe
[16/07/2008 14:16|--a------|3065631] - H:\IMG_0886.JPG
[16/07/2008 14:16|--a------|3624057] - H:\IMG_0889.JPG
[16/07/2008 14:16|--a------|3441324] - H:\IMG_0888.JPG
[16/07/2008 14:17|--a------|3447888] - H:\IMG_0891.JPG
[16/07/2008 14:19|--a------|3468717] - H:\IMG_0896.JPG
[16/07/2008 14:15|--a------|3438731] - H:\IMG_0882.JPG
[16/07/2008 14:16|--a------|3600533] - H:\IMG_0885.JPG
[16/07/2008 11:28|--a------|3478698] - H:\IMG_0874.JPG
[16/07/2008 11:28|--a------|3967516] - H:\IMG_0875.JPG
[16/07/2008 14:15|--a------|4024314] - H:\IMG_0881.JPG
[16/07/2008 14:38|--a------|3820793] - H:\IMG_0901.JPG
[16/07/2008 14:42|--a------|3766738] - H:\IMG_0905.JPG
[16/07/2008 14:18|--a------|2647951] - H:\IMG_0894.JPG
[11/07/2008 13:15|--a------|1468622] - H:\DSCF6907.JPG
[11/07/2008 13:15|--a------|1544430] - H:\DSCF6908.JPG
[11/07/2008 13:16|--a------|1471884] - H:\DSCF6909.JPG
[11/07/2008 13:16|--a------|1480856] - H:\DSCF6910.JPG
[11/07/2008 13:17|--a------|1442812] - H:\DSCF6911.JPG
[11/07/2008 13:17|--a------|1443497] - H:\DSCF6912.JPG
[11/07/2008 13:18|--a------|1455016] - H:\DSCF6913.JPG
[11/07/2008 13:18|--a------|1468113] - H:\DSCF6914.JPG
[11/07/2008 13:18|--a------|1470574] - H:\DSCF6915.JPG
[11/07/2008 13:20|--a------|1477549] - H:\DSCF6917.JPG
[11/07/2008 13:23|--a------|1454520] - H:\DSCF6918.JPG
[11/07/2008 13:23|--a------|1478516] - H:\DSCF6919.JPG
[11/07/2008 13:25|--a------|1476401] - H:\DSCF6920.JPG
[11/07/2008 13:26|--a------|1469741] - H:\DSCF6921.JPG
[11/07/2008 13:27|--a------|1482255] - H:\DSCF6924.JPG
[11/07/2008 13:39|--a------|1501345] - H:\DSCF6927.JPG
[11/07/2008 13:39|--a------|1473134] - H:\DSCF6928.JPEG
[28/08/2008 13:04|--a------|3226563] - H:\IMG_1412.JPG
[28/08/2008 13:04|--a------|3520830] - H:\IMG_1413.JPG
[28/08/2008 13:19|--a------|3293326] - H:\IMG_1414.JPG
[28/08/2008 13:25|--a------|4628910] - H:\IMG_1415.JPG
[28/08/2008 13:28|--a------|3672805] - H:\IMG_1416.JPG
[28/08/2008 13:28|--a------|3632575] - H:\IMG_1417.JPG
[28/08/2008 14:08|--a------|6748680] - H:\IMG_1418.JPG
[28/08/2008 14:08|--a------|5522547] - H:\IMG_1419.JPG
[28/08/2008 14:27|--a------|3364810] - H:\IMG_1421.JPG
[30/08/2008 19:10|--a------|3205835] - H:\IMG_1459.JPG
[10/09/2008 15:57|--a------|290890] - H:\Brennus 1.JPG
[12/02/2007 18:33|-ra------|1110016] - J:\LaunchU3.exe
[02/02/2009 10:14|--a------|32256] - J:\CD_Cover1.doc
[02/02/2009 10:16|--a------|32256] - J:\CD_Cover2.doc
[02/02/2009 10:26|--a------|32256] - J:\CD_Cover3.doc
[02/02/2009 12:58|--a------|32256] - J:\CD_Cover4.doc
[02/02/2009 13:03|--a------|32256] - J:\CD_Cover5.doc
[02/02/2009 13:06|--a------|32256] - J:\CD_Cover6.doc
[26/06/2009 18:55|--a------|1618] - J:\BOOTEX.LOG
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# I:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# J:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.033 ! ]
-
-
Contributeur sécuritéConficker toujours ...
**********************************************************
********************* Option 2 (Nettoyage) *********************
**********************************************************
▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés (!) sans les ouvrir (!)
▶ Fais un double-clic sur le raccourci UsbFix présent sur ton bureau
▶ choisis l'option 2 ( Suppression )
▶ Ton bureau disparaîtra et le PC redémarrera .
▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra avec le bureau .
▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
Tutoriel nettoyage
++ -
Contributeur sécuritéSalut lis bien ce qu'on t'écrit :
*Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectés sans les ouvrir. *Double clique sur le raccourci UsbFix présent sur ton bureau. *Choisi l'option 1 ( Recherche ) *Laisse travailler l'outil. *Ensuite poste le rapport UsbFix.txt qui apparaîtra dans ton prochain message.
++-
-
Contributeur sécurité
-
@Trying2voila le rapport
############################## [ UsbFix V3.033 ]
# User : hic (Administrateurs) # SWEETHOME
# Update on 15/06/09 by C_XX
# Start at: 20:48:34 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) 4 CPU 2.40GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.11
# Windows Firewall Status : Disabled
# AV : Protection System 1.0 [ Enabled | (!) Outdated ]
# AV : ZoneAlarm Security Suite Antivirus 8.0.298.004 [ (!) Disabled | Updated ]
# FW : ZoneAlarm Security Suite Firewall[ Enabled ]8.0.298.004
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 16,91 Go (5,14 Go free) # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque amovible # 7,67 Go (4,27 Go free) # FAT32
# F:\ # Disque CD-ROM # 5,46 Mo (0 Mo free) [U3 System] # CDFS
# G:\ # Disque fixe local # 931,28 Go (929,37 Go free) [My Book] # FAT32
# J:\ # Disque amovible # 1,9 Go (3,09 Mo free) # FAT
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system32\Fast.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\FreePDF_XP\fpassist.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="hic"
HKLM_logon: "AltDefaultUserName"="hic"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: CoolSwitch=C:\WINDOWS\system32\taskswitch.exe
HKLM_Run: FastUser=C:\WINDOWS\system32\fast.exe
HKLM_Run: FreePDF Assistant=C:\Program Files\FreePDF_XP\fpassist.exe
HKLM_Run: NeroCheck=C:\WINDOWS\system32\\NeroCheck.exe
HKLM_Run: SSBkgdUpdate="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
HKLM_Run: OpwareSE4="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
HKLM_Run: ZoneAlarm Client="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
HKLM_Run: VX1000=C:\WINDOWS\vVX1000.exe
HKLM_Run: LifeCam="C:\Program Files\Microsoft LifeCam\LifeExp.exe"
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: BDAgent="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
HKLM_Run: WSSVC=C:\WINDOWS\system\smsc.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
HKLM_expl: "NoDriveAutoRun"=dword:03ffffff
HKLM_expl: "NoDriveTypeAutoRun"=dword:00000143
HKCU_expl: "NoDrives"=dword:00000000
HKCU_expl: "NoDriveAutoRun"=dword:03ffffff
################## [ Fichiers # Dossiers infectieux ]
Présent ! C:\WINDOWS\system32\drivers\sysdrv32.sys
Présent ! E:\autorun.inf
Présent ! E:\recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
Présent ! F:\autorun.inf
Présent ! G:\autorun.inf
Présent ! J:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Présent ! HKLM\SYSTEM\CurrentControlSet\Services\sysdrv32
Présent ! HKLM\SYSTEM\ControlSet002\Services\sysdrv32
Présent ! HKLM\SYSTEM\ControlSet003\Services\sysdrv32
Présent ! HKLM\software\microsoft\security center "AntiVirusOverride" ( 0x1 )
################## [ Registre # Mountpoints2 ]
HKCU\...\Explorer\MountPoints2\E\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{0a84aa0e-4ead-11de-8d18-0011802d8f46}\Shell\AutoRun\Command
################## [ ! Fin du rapport # UsbFix V3.033 ! ]
-
-
Contributeur sécurité@ Hic:
*Télécharge et installe UsbFix de C_XX & Chiquitine29.
*Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectés sans les ouvrir.
*Double clique sur le raccourci UsbFix présent sur ton bureau.
*Choisi l'option 1 ( Recherche )
*Laisse travailler l'outil.
*Ensuite poste le rapport UsbFix.txt qui apparaîtra dans ton prochain message. -
Contributeur sécuritéJe pense que c'est une toute nouvelle variante .. :(
-
Contributeur sécuritéTu avais raison alors ...
c'est une variante qui modifie la valeur HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
++ -
Contributeur sécuritéSalut a tous :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
qzxbpao
ptqveqfy
....
Infecté par Conficker .... :(
Bon courage a vous ...
++-
Contributeur sécuritéEt pourtant: Ce message et le suivant...
-
-
-
Contributeur sécuritéTu peux me dire si je dois désinstaller toutes les applis téléchargées et quand ?
Ne t'inquiète pas : c'est prévu.
Comment tourne ton pc?
Tu peux me faire un dernier rapport Hijack stp?
Télécharge hijackthis et poste moi le rapport dans ta prochaine réponse.
Comment générer un rapport. (merci à Balltrap 34 pour la démo)-
il tourne relativement bien mais par moment il rame
voila le rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:36:05, on 26/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system\msdct.exe
C:\WINDOWS\system32\Fast.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\FreePDF_XP\fpassist.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\hic\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [WSSVC] C:\WINDOWS\system\smsc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [LocalService] C:\Documents and Settings\LocalService\LocalService.exe /i (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
O23 - Service: WM System Decode Application - Unknown owner - C:\WINDOWS\system\msdct.exe
-
je ne comprends pas pourquoi par moments je ne peux accéder à certaines pages web en mode normal alors qu'en mode sans échec avec réseau j'y arrive et par moment j'y arrive de manière normale.
par exemple : hier soir je n'arrive pas à accéder du coup j'appelle mon beauf en lui demandant de les zipper et de me les envoyer par mail. je me connecte et du coup je peux télécharger alors que son mail n'est jamais arrivé.
!!!!!!!!!
?????? -
-
Contributeur sécurité@hicC'est normal que ton pc ne tourne pas rond, tu es toujours infecté.
Je me renseigne pour trouver la solution adéquate.
@+
-
-
Contributeur sécuritéTu as bien modifier ces deux cases avant le nettoyage?
* clique sur "Options", "Avancé" et décoche la case: "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
*Dans Nettoyeur/Windows /avancé il faut cocher la case vieilles données du prefetch.-
je viens de le faire voila le log
NETTOYAGE COMPLET - (2.212 secs)
------------------------------------------------------------------------------------------
4,58MB supprimés.
------------------------------------------------------------------------------------------
Détails des fichiers effacés
------------------------------------------------------------------------------------------
Fichiers Temporaires d'Internet Explorer (fichiers 135) 4,58MB
C:\Documents and Settings\hic\Cookies\hic@weborama[1].txt 265 bytes
C:\Documents and Settings\hic\Cookies\hic@xiti[1].txt 107 bytes
C:\Documents and Settings\hic\Cookies\hic@ad.yieldmanager[1].txt 397 bytes
C:\Documents and Settings\hic\Cookies\hic@commentcamarche[1].txt 501 bytes
C:\Documents and Settings\hic\Cookies\hic@doubleclick[2].txt 121 bytes
C:\Documents and Settings\hic\Cookies\hic@smartadserver[2].txt 398 bytes
C:\Documents and Settings\hic\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 405 bytes
------------------------------------------------------------------------------------------
-
-
Contributeur sécuritétu as quel antivirus? Télécharge bitdefender free ( je dis bien free) et colle un rapport avec
-
j'ai ZoneAlarm Security Suite Version 8.0.298.004
voila le log de bitdefender
BitDefender - Fichier journal
Produit : BitDefender Free Edition 2009
Version : BitDefender UIScanner v.12
Tâche d'analyse : Analyse approfondie
Date du journal : 26/06/2009 17:17:52
Chemin du journal : C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\deep_scan\1246029472_1_02.xml
Analyse des chemins :Chemin 0000: C:\
Options d’analyse :Détecter les virus : Oui
Détecter les adwares : Oui
Détecter les spywares : Oui
Analyser les applications : Oui
Détecter les dialers : Oui
Détecter les rootkits : Oui
Options de sélection de cible :Analyser les clés du registre : Oui
Analyser les cookies : Oui
Analyser les secteurs de boot : Oui
Analyser les processus mémoire : Oui
Analyser les archives : Oui
Analyser les fichiers enpaquetés : Oui
Analyser les e-mails : Non
Analyser tous les fichiers : Oui
Analyse heuristique : Oui
Extensions analysées :
Extensions exclues :
Traitement de la cible :Action par défaut pour les objets infectés : Désinfecter
Action par défaut pour les objets suspects : Aucune
Action par défaut pour les objets camouflés : Aucune
Action par défaut pour les objets infectés : Aucune
Action par défaut pour les objets suspects encryptés : Aucune
Action par défaut pour les objets protégés par mot de passe : Enregistrer comme non analysé
Résumé de l'analyseNombre de signatures de virus : 3577112
Plugins archives : 44
Plugins e-mail : 6
Plugins d'analyse : 13
Plugins système : 5
Plugins de décompression : 7
Résumé de l'analyse généraleEléments analysés : 0
Eléments infectés : 0
Eléments suspects : 0
Eléments résolus : 9
Éléments non résolus : 10
Eléments protégés : 0
Éléments ultra-compressés : 1
Virus individuels trouvés : 0
Répertoires analysés : 0
Secteur de boot analysés : 0
Archives analysés : 0
Erreurs I/O : 0
Temps d'analyse : 00:51:42
Fichiers par seconde : 0
Résumé des processus analysésAnalysé : 0
Infecté : 0
Résumé des clés de registre analyséesAnalysé : 0
Infecté : 0
Résumé des cookies analysésAnalysé : 0
Infecté : 0
Problèmes non résolus :Nom de l'objet Nom de la menace État final
[System]=]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\WSSVC=]C:\WINDOWS\SYSTEM\SMSC.EXE Packer.Krunchy.B Aucune action possible
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6MSSBC9B\x[2] Packer.Krunchy.B Aucune action possible
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q4X69W16\x[1] Packer.Krunchy.B Aucune action possible
C:\WINDOWS\system\smsc.exe Packer.Krunchy.B Aucune action possible
C:\WINDOWS\system32\66.scr Packer.Krunchy.B Aucune action possible
C:\WINDOWS\system\smsc.exe Rootkit-Éléments cachés Masquer
[System]=]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\lsass=]C:\WINDOWS\SYSTEM\1SASS.EXE Trojan.Agent.AMQF Aucune action possible
[System]=]HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\ETHXVQRQ\ImagePath=]C:\WINDOWS\SYSTEM32\DRIVERS\ETHXVQRQ.SYS Trojan.Rlsloupa.A Aucune action possible
C:\WINDOWS\system\smsc.exe Worm.Generic.61394 Échec de la désinfection
Problèmes résolusNom de l'objet Nom de la menace État final
C:\WINDOWS\system32\drivers\sysdrv32.sys Rootkit.17518 Supprimé
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6MSSBC9B\x[1] Trojan.Agent.AMQF Supprimé
C:\WINDOWS\system32\31.scr Trojan.Buzus.DA Supprimé
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\I9VHXSQ6\doc[1].htm Trojan.Rlsloupa.A Supprimé
C:\WINDOWS\system32\drivers\ethxvqrq.sys Trojan.Rlsloupa.A Supprimé
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6MSSBC9B\cilawqd[1].jpg Worm.Generic.61186 Supprimé
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6MSSBC9B\x[2] Worm.Generic.61394 Supprimé
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q4X69W16\x[1] Worm.Generic.61394 Supprimé
C:\WINDOWS\system32\66.scr Worm.Generic.61394 Supprimé
Objets non scannés :Nom de l'objet Raison État final
C:\Documents and Settings\hic\Local Settings\Temporary Internet Files\Content.IE5\EXOUQQPW\bitdefender_free_2009_32b[1].exe=](IExpress 0) Ultracompressé Pas analysé -
Contributeur sécurité@hicTu avais lancé le nettoyage "classique" avec CCleaner?
-
@Trying2ravi de te revoir
oui je l'ai fait au moins 2 fois et je viens de le refaire
voila le resultat
NETTOYAGE COMPLET - (19.119 secs)
------------------------------------------------------------------------------------------
98,8MB supprimés.
------------------------------------------------------------------------------------------
Détails des fichiers effacés
------------------------------------------------------------------------------------------
Fichiers Temporaires d'Internet Explorer (fichiers 925) 79,5MB
C:\Documents and Settings\hic\Cookies\hic@support.microsoft[1].txt 262 bytes
C:\Documents and Settings\hic\Cookies\hic@weborama[2].txt 268 bytes
C:\Documents and Settings\hic\Cookies\hic@bluestreak[1].txt 225 bytes
C:\Documents and Settings\hic\Cookies\hic@xiti[2].txt 107 bytes
C:\Documents and Settings\hic\Cookies\hic@m.webtrends[2].txt 185 bytes
C:\Documents and Settings\hic\Cookies\hic@boursoramabanque.solution.weborama[2].txt 429 bytes
C:\Documents and Settings\hic\Cookies\hic@ad.yieldmanager[2].txt 398 bytes
C:\Documents and Settings\hic\Cookies\hic@commentcamarche[2].txt 493 bytes
C:\Documents and Settings\hic\Cookies\hic@atdmt[2].txt 202 bytes
C:\Documents and Settings\hic\Cookies\hic@microsoft[2].txt 397 bytes
C:\Documents and Settings\hic\Cookies\hic@edt02[3].txt 709 bytes
C:\Documents and Settings\hic\Cookies\hic@questionmarket[1].txt 282 bytes
C:\Documents and Settings\hic\Cookies\hic@samsung.solution.weborama[2].txt 393 bytes
C:\Documents and Settings\hic\Cookies\hic@247realmedia[1].txt 196 bytes
C:\Documents and Settings\hic\Cookies\hic@tradedoubler[1].txt 324 bytes
C:\Documents and Settings\hic\Cookies\hic@doubleclick[3].txt 122 bytes
C:\Documents and Settings\hic\Cookies\hic@bitdefender[1].txt 398 bytes
C:\Documents and Settings\hic\Cookies\hic@google[4].txt 323 bytes
C:\Documents and Settings\hic\Cookies\hic@advertising[2].txt 641 bytes
C:\Documents and Settings\hic\Cookies\hic@smartadserver[2].txt 403 bytes
C:\Documents and Settings\hic\Cookies\hic@01net[2].txt 749 bytes
C:\Documents and Settings\hic\Cookies\hic@ad.yieldmanager[1].txt 415 bytes
C:\Documents and Settings\hic\Cookies\hic@advertising[1].txt 506 bytes
C:\Documents and Settings\hic\Cookies\hic@aimfar.solution.weborama[1].txt 118 bytes
C:\Documents and Settings\hic\Cookies\hic@atdmt[1].txt 202 bytes
C:\Documents and Settings\hic\Cookies\hic@bs.serving-sys[2].txt 130 bytes
C:\Documents and Settings\hic\Cookies\hic@cnetfrance[1].txt 76 bytes
C:\Documents and Settings\hic\Cookies\hic@commentcamarche[1].txt 374 bytes
C:\Documents and Settings\hic\Cookies\hic@com[1].txt 95 bytes
C:\Documents and Settings\hic\Cookies\hic@cybermonitor[1].txt 94 bytes
C:\Documents and Settings\hic\Cookies\hic@doubleclick[2].txt 123 bytes
C:\Documents and Settings\hic\Cookies\hic@edt02[2].txt 316 bytes
C:\Documents and Settings\hic\Cookies\hic@forums.cnetfrance[1].txt 444 bytes
C:\Documents and Settings\hic\Cookies\hic@free-av[1].txt 370 bytes
C:\Documents and Settings\hic\Cookies\hic@google[1].txt 130 bytes
C:\Documents and Settings\hic\Cookies\hic@google[3].txt 323 bytes
C:\Documents and Settings\hic\Cookies\hic@serving-sys[1].txt 530 bytes
C:\Documents and Settings\hic\Cookies\hic@smartadserver[1].txt 402 bytes
C:\Documents and Settings\hic\Cookies\hic@ttbmanutan.solution.weborama[2].txt 409 bytes
C:\Documents and Settings\hic\Cookies\hic@weborama[1].txt 271 bytes
C:\Documents and Settings\hic\Cookies\hic@www.01net[2].txt 72 bytes
C:\Documents and Settings\hic\Cookies\hic@xiti[1].txt 107 bytes
C:\Documents and Settings\hic\Cookies\hic@yahoo[1].txt 88 bytes
Marqué pour l'effacement: C:\Documents and Settings\hic\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Marqué pour l'effacement: C:\Documents and Settings\hic\Cookies\index.dat
Marqué pour l'effacement: C:\Documents and Settings\hic\Local Settings\Historique\History.IE5\desktop.ini
Marqué pour l'effacement: C:\Documents and Settings\hic\Local Settings\Historique\History.IE5\index.dat
Marqué pour l'effacement: C:\Documents and Settings\hic\Local Settings\Historique\History.IE5\MSHist012009062620090627\index.dat
C:\Documents and Settings\hic\Recent\bitdefender.txt.lnk 603 bytes
C:\Documents and Settings\hic\Recent\CureIt.log.lnk 726 bytes
C:\Documents and Settings\hic\Recent\Disque1To.pdf.lnk 477 bytes
C:\Documents and Settings\hic\Recent\DoctorWeb.lnk 543 bytes
C:\Documents and Settings\hic\Recent\DrWeb.csv.lnk 453 bytes
C:\Documents and Settings\hic\Recent\DrWeb1.txt.lnk 460 bytes
C:\Documents and Settings\hic\Recent\infection.lnk 379 bytes
C:\Documents and Settings\hic\Recent\INSTALL.LOG.lnk 798 bytes
C:\Documents and Settings\hic\Recent\license.txt.lnk 798 bytes
C:\Documents and Settings\hic\Recent\TCleaner.txt.lnk 472 bytes
C:\Documents and Settings\hic\Recent\ZoneAlarm.lnk 616 bytes
C:\WINDOWS\system32\wbem\Logs\FrameWork.log 702 bytes
C:\WINDOWS\system32\wbem\Logs\wbemess.log 57,15KB
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 739 bytes
C:\WINDOWS\0.log 0 bytes
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log 0,50MB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp 0,12MB
C:\WINDOWS\Debug\UserMode\userenv.log 5,97KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\11\2b98eb8b-3b6d8b70 20,77KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\11\2b98eb8b-3b6d8b70.idx 12,18KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f 1,36MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f-n\decora-d3d.dll 12,50KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f-n\decora-sse.dll 60,00KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f-n\jmc.dll 0,48MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f-n\msvcp71.dll 0,48MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f-n\msvcr71.dll 0,33MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-6e848d7f.idx 10,86KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\24\2a20e358-225fb703 1,61KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\24\2a20e358-225fb703.idx 532 bytes
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\26\2d280e1a-2a3d872f-1.1.1a- 2,82KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\26\2d280e1a-2a3d872f-1.1.1a-.idx 563 bytes
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\32\6c34baa0-76992725 4,38KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\32\6c34baa0-76992725.idx 531 bytes
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\44\50f3f12c-60fc59b8 8,11MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\44\50f3f12c-60fc59b8.idx 0,41MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-7063aa18 5,46KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-7063aa18-n\gluegen-rt.dll 20,00KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-7063aa18.idx 10,58KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\48\26760070-1d0d85de-1.0b06a- 2,92KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\48\26760070-1d0d85de-1.0b06a-.idx 571 bytes
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\59\1ea183bb-3d2b92f1 0,90MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\59\1ea183bb-3d2b92f1.idx 72,42KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-21181cf4 59,82KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-21181cf4-n\jogl.dll 0,30MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-21181cf4-n\jogl_awt.dll 20,00KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-21181cf4-n\jogl_cg.dll 0,11MB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-21181cf4.idx 10,70KB
C:\Documents and Settings\hic\Application Data\Sun\Java\Deployment\cache\6.0\lastAccessed 1 bytes
C:\WINDOWS\Internet Logs\ZALog2009.06.25.txt 5,78MB
C:\Documents and Settings\hic\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 405 bytes
------------------------------------------------------------------------------------------ -
@Trying2tu peux me dire si je dois désinstaller toutes les applis téléchargées et quand ?
-
- 1
- 2