Ordi infecté

Résolu
bonsoir,
lorsque je me connecte j'ai a chaque fois une alerte comme quoi je suis infecté et qui me demande d'aller faire un scan sur une adresse imposé et bien sur payant
j'ai essayé different scan avec a square free,spybot rien de concluant,nod32 me trouve un virus tsr.boot

merci de bien vouloir m'aider
Configuration: Windows XP
Firefox 2.0.0.14

112 réponses

Résumé de la discussion

La discussion porte sur une alerte d’infection qui s’affiche systématiquement lors de la connexion et pousse à un scan payant, sous Windows XP et Firefox 2.0.0.14. Des conseils préconisent des outils et des mesures de nettoyage comme ToolsCleaner, CCleaner et Malwarebytes, puis des vérifications de sécurité telles que Windows Update et la prévention via un mot de passe fort. Les échanges évoquent des résultats de scans réels, avec des détections d’Adware.Gamesbar, des entrées de registre associées et des fichiers nuisibles ensuite mis en quarantaine ou supprimés. En cas d’impossibilité d’accès au net, la discussion suggère de vérifier le secteur MBR et le routage, tandis que des rapports Malwarebytes confirment des éléments d’adware et nécessitent des nettoyages ciblés.

Bobot (l’IA à votre service)
  1. ok j'ai fait passé l'info
    merci a toi et a tous ceux qui sont intervenu
    a++
    1. ToolsCleaner supprime tous les outils utilisés donc vaut mieux le passer. Pour qu'il supprime tout :)

      Tu peux mettre le sujet en résolu
      1. cool merci pour les info!
        ,apres pour le rapport je sais pas trop,si tu te souviens c'etait l'ordi d'un pote,et en ce moment il a pas trop le temps je vais quand meme lui passer l'info
        1. * Je t'invite à lire ceci :
          *https://www.malekal.com/proteger-pc-virus-pirates/
          *http://forum.telecharger.01net.com/microhebdo/6/tuto-securite/mesures_preventives_avant_navigation_sinternet_et_entretien-346836/messages-1.html
          *Utilise Windows Update
          *Télécharge https://filehippo.com/windows/tuning-utilities/ tu l'installes et il te liste ce qu'il faut mettre à jour avec les liens correspondants.

          *Télécharge ToolsCleaner (A.Rothstein) sur ton Bureau:
          http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
          *Clique sur Recherche et laisse le scan se terminer.
          *Clique sur Suppression pour finaliser.
          *Tu peux, si tu le souhaites, te servir des Options facultatives.
          *Clique sur Quitter, pour que le rapport puisse se créer.
          *Poste le rapport C:\TCleaner.txt

          ------------------------------------------------------------------------------------------­­-------------------------

          1.Ouvre le Menu Démarrer
          2.Clique-droit sur Poste de travail
          3.Clique sur Propriétés
          4.Positionne-toi dans l'onglet Restauration du système
          5.Coche Désactiver la restauration système
          6.Valide par Ok
          7.Redémarre
          8.Reproduis les manipulations 1 à 3
          9.Décoche Désactiver la restauration système
          10.Valide par Ok

          ------------------------------------------------------------------------------------------­­-------------------------

          *Télécharge Ccleaner :
          Clique sur le premier Download now > Choisis la version Slim
          Installe Ccleaner.
          Nettoie Windows et la base de registre en suivant ce tuto :
          https://www.malekal.com/tutoriel-ccleaner/#mozTocId223895

          ------------------------------------------------------------------------------------------­­-------------------------

          Si tu as un routeur (ou une box), as-tu changé le mot de passe par défaut ? Sinon, fais le rapidement : un trojan s'attaque au mot de passe des routeurs en cherchant si le mot de passe ne figure pas dans une liste préétablie. Si oui, il prend le contrôle de l'ordi (et de la totalité du réseau). Un bon mot de passe doit avoir au moins 8 caractères et comprendre des lettres (en majuscule et en minuscule), des chiffres et des caractères spéciaux (é, #, ...). Il doit être conservé soigneusement (pour être retrouvé en cas d'oubli) ailleurs que sur un support informatique
          Par la même occasion, tu peux changer l'ensemble de tes mots de passe, certaines infections réussissent à récupérer les mots de passe..notamment les numéros de Carte Bancaire si tu consultes ta banque en ligne..

          ------------------------------------------------------------------------------------------­­-------------------------
          1. bonjour

            c'est toujours moi,
            la manip antivir a était faite et il ne trouve rien,apparament l'ordi n'affiche plus de message d'infection lors de surf sur le net donc tout est rentré dans l'ordre!!
            encore merci,bon help et a++
            1. yes ca pourra toujours me servir!!mais sur ce coup la je vais lui laisser le bebe
              1. Y'a une solution effectivement, je me suis trompé.

                Mais c'est vraiment pas pratique du tout.
                Il faut télécharger via un PC relié au net la mise à jour manuelle, c'est un fichier .vdf. Il contient toutes les MAJ donc le fichier est très très lourd
                Il est sur le site d'Avira :
                https://www.avira.com/

                Tu peux via une clé usb transférer les MAJ.
                Tu ouvres Antivir
                Update -> Manual update
                Spécifie le fichier téléchargé. Et c'est tout

                Reste plus qu'à lancer un scan en mode sans échec
                1. alors ca c'est vilain,ya moyen mais tu veu pas me le dire!!
                  bon je te remercie meme si tu te couche un peu tot lol,ainsi que tous ceux qui sont intervenu sur ce post
                  a++
                  1. le hic c'est que j'ai un modem interne(pci)
                    je pense que le mieux est de lui rendre le pc,qu'il puisse finir la desinfection en ayant acces au net,je ne cloture donc pas le post et laisse mon pote entre de bonne main!!
                    sinon ya une question qui me trotte,on telecharge les MAJ donc si j'installe antivir, je fait les MAJ,j'ai aucun moyen de les transférer sur un autre ordi ?j'sais pas copier\coller le dossier de program file?
                    1. lol.

                      Bon, il m'énerve sérieusement ce satané virus.

                      As-tu supprimé tous les cracks, keygen, etc présents sur le PC ?

                      Ensuite,
                      Ce que tu aurais pu faire c'est un scan avec Antivir mis à jour mais vu que tu n'as pas le net..il a un PC portable ? Tu as le PC chez toi ? Tu as le net chez toi non ? Tu te connectes comment ? En éthernet ? Si oui, branche ton cable éthernet sur son PC, désactive voire désinstalle nod32, installe antivir mets le à jour et lance un scan complet en mode sans échec.
                      Et copie/colle le rapport final
                      1. Tu vas me dire que ton collègue ne télécharge que ce qui n'est pas sous Copyright ? J'ai du mal à y croire...
                        c'est clair je vais pas te mentir et te prendre pour un C..

                        ecoute pour le comportement du pc ,ca a l'air pas mal,mais comme je n'ai pas acces au net depuis lui je ne peu pas pour l'instant t'en dire plus

                        il doit d'ailleurs passer le recuperer pour voir ce que ca a donné,je vien de relancer un scan avec nod et toujour cette trace de virus

                        apres legal pas legal,si nous étions tous soumis a la loi de la meme facon ok,malheureusement la justice a plusieur vitesse!!
                        moi j'aurais voter un impot pour"l'idole des jeunes" afin de palier a la perte d'argent du au p2p et au taux d'imposition lol
                        1. pour le p2p,je connais et respecte le point de vu de CCM mais je ne le partage pas entièrement,linux et d'autres utilise ce moyen de diffusion en toute légalité,c'est un moyen de partage gratuit et libre

                          A partir du moment où le noyau Linux est open source, ce serait complètement débile de ne pas le mettre à disposition...
                          Tu vas me dire que ton collègue ne télécharge que ce qui n'est pas sous Copyright ? J'ai du mal à y croire...

                          Comment se comporte le PC ?

                          Tu peux lui dire aussi de supprimer tous les cracks, keygens, serials etc..qu'il a. Ce sera déjà une bonne chose.

                          le risque zero n'existe pas,le meilleur antivirus est au bout de la souris
                          D'accord avec toi sur ce point.

                          Après légal ou illégal : Le P2P et ses conséquences
                          1. re
                            desolé pour le retard

                            au sujet d'antivir oui il etait installé mais mon collegue la desinstallé suite a divers probleme avec

                            pour le p2p,je connais et respecte le point de vu de CCM mais je ne le partage pas entièrement,linux et d'autres utilise ce moyen de diffusion en toute légalité,c'est un moyen de partage gratuit et libre

                            la desinfection que tu effectue sur l'ordi de mon collegue est libre et gratuite,pourtant chez un pro elle aurait etait facturé ,concurrence déloyale?? après le partage censuré,a quand l'entraide??

                            au sujet des risques encourus(virus) hier sur un forum serieux(ccm)une personne me conseillé un lien vers un antivirus(?)ou plutot vers un bon moyen d'infecter un peu plus lordi,donc!!
                            comme il est souvent dis ici meme:le risque zero n'existe pas,le meilleur antivirus est au bout de la souris
                            voici apres mon avis le rapport de OTmoveit:

                            C:\Windows\PSEXESVC.EXE moved successfully.
                            c:\Users\lululedet\Documents\cc104crk.exe moved successfully.
                            c:\Users\lululedet\Documents\cueclub.exe moved successfully.
                            File/Folder c:\Users\lululedet\Documents\logiciels de lul\YamiPod.exe not found.
                            File/Folder c:\Users\lululedet\Documents\logiciels de lul\NOD32 2.7 french\NOD32.patch\NOD32.FiX.v2.1.exe not found.
                            File/Folder c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\TU2008TrialEN.exe not found.
                            File/Folder c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\Keygen\TU2008 Keymaker.exe not found.

                            OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06072008_151453
                            1. Fais ceci :
                              Veuillez svp envoyer le fichier C:\upload_moi_PC-de-lululedet.tar.gz a l'adresse http://upload.malekal.com

                              C'est sûr qu'avec 3 logiciels de téléchargement (limewire, uTorrent , emule) + des keygens, cracks, ton PC survivra trèèèèèèès longtemps...

                              c:\Users\lululedet\Documents\logiciels de lul\antivir_workstation_win7u_en_h.exe
                              Tu l'as juste téléchargé mais pas installé si ?
                              c:\Users\lululedet\Documents\logiciels de lul\LimeWirePro.4.14.0.exe
                              c:\Users\lululedet\Documents\logiciels de lul\setupyse.exe ==> c'est quoi ?
                              c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\TU2008TrialEN.exe
                              c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\Keygen\TU2008 Keymaker.exe

                              En continuant comme ça, dans une semaine tu reviens nous voir...

                              *Télécharge OTMoveIt (d’Old_Timer) sur ton Bureau.
                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

                              *Double-clique sur OTMoveIt.exe pour le lancer.
                              *Copie la liste qui se trouve ci-dessous et colle-la dans le cadre de gauche de OTMoveIt : Paste List of Files/Folders to be moved.

                              C:\Windows\PSEXESVC.EXE
                              c:\Users\lululedet\Documents\cc104crk.exe
                              c:\Users\lululedet\Documents\cueclub.exe
                              c:\Users\lululedet\Documents\logiciels de lul\YamiPod.exe
                              c:\Users\lululedet\Documents\logiciels de lul\NOD32 2.7 french\NOD32.patch\NOD32.FiX.v2.1.exe
                              c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\TU2008TrialEN.exe
                              c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\Keygen\TU2008 Keymaker.exe


                              *Clique sur MoveIt! Pour lancer la suppression.
                              *Le résultat apparaitra dans le cadre Results.
                              *Clique sur Exit pour fermer.
                              *Poste le rapport situé dans C:\_OTMoveIt\MovedFiles. Exemple:(01282008_131348.log )

                              *Il te sera peut-être demander de redémarrer le PC pour achever la suppression.
                              Si c'est le cas accepte par Yes

                              En tout cas, c'est un sacré bordel là dedans !
                              1. voila ,desolé mais je vais devoir m'absenter ce soir !

                                DiagHelp version v1.4 - http://www.malekal.com
                                excute le 06/06/2008 à 20:44:28.05

                                Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
                                C:\Windows\prefetch\CONIME.EXE-9781FD5F.pf -->06/06/2008 20:44:22
                                C:\Windows\prefetch\CMD.EXE-4A81B364.pf -->06/06/2008 20:44:22
                                C:\Windows\prefetch\CHCP.COM-61043047.pf -->06/06/2008 20:44:22
                                C:\Windows\prefetch\WMIADAP.EXE-F8DFDFA2.pf -->06/06/2008 20:43:47
                                C:\Windows\prefetch\SEARCHFILTERHOST.EXE-77482212.pf -->06/06/2008 20:43:18
                                C:\Windows\prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf -->06/06/2008 20:43:17
                                C:\Windows\prefetch\DLLHOST.EXE-5E46FA0D.pf -->06/06/2008 20:43:07
                                C:\Windows\prefetch\UTORRENT.EXE-1070971C.pf -->06/06/2008 20:43:01
                                C:\Windows\prefetch\WUDFHOST.EXE-AFFEF87C.pf -->06/06/2008 20:42:49
                                C:\Windows\prefetch\WMPLAYER.EXE-BAD6BD53.pf -->06/06/2008 20:42:49

                                C:\Windows\System32\drivers\amon.sys -->03/06/2008 21:59:32
                                C:\Windows\System32\drivers\nod32drv.sys -->03/06/2008 21:59:30
                                C:\Windows\System32\drivers\mbamcatchme.sys -->30/05/2008 01:06:40
                                C:\Windows\System32\drivers\mbam.sys -->30/05/2008 01:06:36
                                C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf -->02/04/2008 12:57:11
                                C:\Windows\System32\drivers\sptd.sys -->07/02/2008 13:57:58
                                C:\Windows\System32\drivers\GEARAspiWDM.sys -->29/01/2008 12:01:28

                                C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->06/06/2008 20:41:47
                                C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->06/06/2008 20:41:47
                                C:\Windows\System32\PerfStringBackup.INI -->06/06/2008 17:34:33
                                C:\Windows\System32\perfh00C.dat -->06/06/2008 17:34:33
                                C:\Windows\System32\perfh009.dat -->06/06/2008 17:34:33
                                C:\Windows\System32\perfc00C.dat -->06/06/2008 17:34:33
                                C:\Windows\System32\perfc009.dat -->06/06/2008 17:34:33
                                C:\Windows\System32\jupdate-1.6.0_06-b02.log -->05/06/2008 17:15:12
                                C:\Windows\System32\imon.dll -->03/06/2008 21:59:33
                                C:\Windows\System32\FNTCACHE.DAT -->21/05/2008 21:31:42
                                C:\Windows\System32\mrt.exe -->09/05/2008 23:35:04
                                C:\Windows\System32\ifxcardm.dll -->01/04/2008 22:05:47
                                C:\Windows\System32\axaltocm.dll -->01/04/2008 22:05:46
                                C:\Windows\System32\QuickTimeVR.qtx -->28/03/2008 23:37:26
                                C:\Windows\System32\QuickTime.qts -->28/03/2008 23:37:26
                                C:\Windows\System32\javaws.exe -->25/03/2008 02:37:01
                                C:\Windows\System32\javaw.exe -->25/03/2008 01:28:43
                                C:\Windows\System32\java.exe -->25/03/2008 01:28:39
                                C:\Windows\System32\gameux.dll -->08/03/2008 06:21:55
                                C:\Windows\System32\GameUXLegacyGDFs.dll -->08/03/2008 04:08:55
                                C:\Windows\System32\kd1394.dll -->29/02/2008 09:14:21
                                C:\Windows\System32\winresume.exe -->29/02/2008 09:11:56
                                C:\Windows\System32\winload.exe -->29/02/2008 09:11:54
                                C:\Windows\System32\srcore.dll -->29/02/2008 08:53:39
                                C:\Windows\System32\srclient.dll -->29/02/2008 08:53:38

                                C:\Windows\bootstat.dat -->06/06/2008 20:41:39
                                C:\Windows\WindowsUpdate.log -->06/06/2008 19:45:20
                                C:\Windows\QTFont.qfn -->06/06/2008 11:04:58
                                C:\Windows\setuperr.log -->05/06/2008 22:23:08
                                C:\Windows\setupact.log -->05/06/2008 22:23:08
                                C:\Windows\PFRO.log -->05/06/2008 19:59:23
                                C:\Windows\PSEXESVC.EXE -->05/06/2008 18:25:50
                                C:\Windows\system.ini -->05/06/2008 18:24:56
                                C:\Windows\WININIT.INI -->25/05/2008 07:41:01
                                C:\Windows\QTFont.for -->20/05/2008 23:25:29
                                C:\Windows\WindowsShell.Manifest -->01/04/2008 22:29:13
                                C:\Windows\nsreg.dat -->25/01/2008 17:30:30
                                C:\Windows\adidsl.ini -->25/01/2008 01:21:59
                                C:\Windows\Fast800.ini -->25/01/2008 01:21:30
                                C:\Windows\adiras.ini -->25/01/2008 01:21:30

                                winlogon.exe
                                Verified: Signed
                                svchost.exe
                                Verified: Signed
                                ws2_32.dll
                                Verified: Signed
                                user32.dll
                                Verified: Signed
                                tcpip.sys
                                Verified: Signed
                                ndis.sys
                                Verified: Signed
                                null.sys
                                Verified: Signed

                                ListDLLs v2.25 - DLL lister for Win9x/NT
                                Copyright (C) 1997-2004 Mark Russinovich
                                Sysinternals - www.sysinternals.com

                                ------------------------------------------------------------------------------
                                explorer.exe pid: 676
                                Command line: C:\Windows\Explorer.EXE

                                Base Size Version Path
                                0x00bd0000 0x2cd000 6.00.6001.18000 C:\Windows\Explorer.EXE
                                0x778f0000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
                                0x77a50000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
                                0x76c40000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
                                0x76d10000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
                                0x76a10000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
                                0x766d0000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
                                0x76820000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
                                0x768d0000 0x58000 6.00.6001.18000 C:\Windows\system32\SHLWAPI.dll
                                0x76de0000 0xb0f000 6.00.6001.18000 C:\Windows\system32\SHELL32.dll
                                0x762d0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
                                0x76930000 0x8d000 6.00.6001.18000 C:\Windows\system32\OLEAUT32.dll
                                0x72420000 0x107000 6.00.6001.18000 C:\Windows\system32\SHDOCVW.dll
                                0x75080000 0x3f000 6.00.6001.18000 C:\Windows\system32\UxTheme.dll
                                0x754a0000 0x1a000 6.00.6001.18000 C:\Windows\system32\POWRPROF.dll
                                0x72f70000 0xc000 6.00.6001.18000 C:\Windows\system32\dwmapi.dll
                                0x74140000 0x1ab000 5.02.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll
                                0x75a60000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
                                0x74990000 0xba000 6.00.6001.18000 C:\Windows\system32\PROPSYS.dll
                                0x722d0000 0x146000 6.00.6001.18000 C:\Windows\system32\BROWSEUI.dll
                                0x77b30000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.dll
                                0x76420000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
                                0x74110000 0x30000 6.00.6001.18000 C:\Windows\system32\DUser.dll
                                0x77a40000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
                                0x767a0000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
                                0x74ee0000 0x19e000 6.10.6001.18000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
                                0x736d0000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
                                0x71f10000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
                                0x76000000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
                                0x76570000 0x84000 2001.12.6931.18000 C:\Windows\system32\CLBCatQ.DLL
                                0x75540000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
                                0x71ae0000 0xb2000 6.00.6001.18000 C:\Windows\system32\timedate.cpl
                                0x75100000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
                                0x75e60000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
                                0x76160000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
                                0x740d0000 0x39000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
                                0x719c0000 0x53000 6.00.6001.18000 C:\Windows\System32\actxprxy.dll
                                0x76020000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
                                0x720a0000 0x2b000 6.00.6001.18000 C:\Windows\system32\msutb.dll
                                0x75380000 0xa000 6.00.6001.18000 C:\Windows\system32\WTSAPI32.dll
                                0x75600000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
                                0x738f0000 0x16000 6.00.6001.18000 C:\Windows\System32\shacct.dll
                                0x75c20000 0x11000 6.00.6001.18000 C:\Windows\System32\SAMLIB.dll
                                0x75fa0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
                                0x71920000 0x41000 6.00.6001.18000 C:\Windows\System32\msshsq.dll
                                0x71780000 0xc6000 6.00.6001.18000 C:\Windows\System32\NaturalLanguage6.dll
                                0x75aa0000 0xf1000 6.00.6001.18000 C:\Windows\System32\CRYPT32.dll
                                0x75c00000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
                                0x73a40000 0x1e8000 6.00.6001.18000 C:\Windows\system32\authui.dll
                                0x74060000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
                                0x71540000 0x1a2000 6.00.6001.18032 C:\Windows\System32\gameux.dll
                                0x75830000 0x8000 6.00.6001.18000 C:\Windows\System32\VERSION.dll
                                0x73370000 0x5f000 6.00.6001.18000 C:\Windows\System32\WINHTTP.dll
                                0x76600000 0xd0000 7.00.6001.18023 C:\Windows\system32\WININET.dll
                                0x77a20000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
                                0x769c0000 0x45000 7.00.6001.18000 C:\Windows\system32\iertutil.dll
                                0x73dd0000 0x149000 6.20.1076.0000 C:\Windows\System32\msxml6.dll
                                0x718d0000 0x4c000 1.00.0000.0001 C:\Windows\System32\Wpc.dll
                                0x761a0000 0x129000 7.00.6001.18023 C:\Windows\system32\urlmon.dll
                                0x73630000 0x96000 6.00.6001.18000 C:\Windows\System32\fwpuclnt.dll
                                0x75a20000 0x40000 6.00.6001.18000 C:\Windows\System32\wevtapi.dll
                                0x76170000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
                                0x77a30000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
                                0x71a80000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
                                0x70090000 0x5ce000 7.00.6001.18000 C:\Windows\system32\ieframe.dll
                                0x754c0000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
                                0x76bf0000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
                                0x73960000 0x32000 6.00.6001.18000 C:\Windows\system32\WINMM.dll
                                0x738c0000 0x2f000 6.00.6001.18000 C:\Windows\system32\wdmaud.drv
                                0x73f30000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
                                0x751f0000 0x27000 6.00.6001.18000 C:\Windows\system32\MMDevAPI.DLL
                                0x75390000 0x7000 6.00.6001.18000 C:\Windows\system32\AVRT.dll
                                0x76a60000 0x18a000 6.00.6001.18000 C:\Windows\system32\SETUPAPI.dll
                                0x752c0000 0x2d000 6.00.6001.18000 C:\Windows\system32\WINTRUST.dll
                                0x76770000 0x29000 6.00.6001.18000 C:\Windows\system32\imagehlp.dll
                                0x73890000 0x21000 6.00.6001.18000 C:\Windows\system32\AUDIOSES.DLL
                                0x737c0000 0x66000 6.00.6001.18000 C:\Windows\system32\audioeng.dll
                                0x71970000 0xb000 6.00.6001.18000 C:\Windows\system32\cscapi.dll
                                0x73f20000 0x9000 6.00.6001.18000 C:\Windows\system32\msacm32.drv
                                0x737a0000 0x14000 6.00.6001.18000 C:\Windows\system32\MSACM32.dll
                                0x73790000 0x7000 6.00.6001.18000 C:\Windows\system32\midimap.dll
                                0x75ba0000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll
                                0x718b0000 0x9000 6.00.6001.18000 C:\Windows\system32\ExplorerFrame.dll
                                0x739e0000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
                                0x72990000 0x202000 4.00.6001.18000 C:\Windows\system32\msi.dll
                                0x70740000 0x28c000 6.00.6001.18000 C:\Windows\System32\NLSData000c.dll
                                0x6e8c0000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
                                0x70b20000 0x92000 6.00.6001.18000 C:\Windows\system32\stobject.dll
                                0x70a60000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
                                0x75410000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
                                0x74a50000 0x45000 2001.12.6931.18000 C:\Windows\system32\es.dll
                                0x6f0c0000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
                                0x6ef90000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
                                0x751c0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
                                0x6f1b0000 0x30b000 6.00.6001.18000 C:\Windows\System32\netshell.dll
                                0x75a00000 0x19000 6.00.6001.18000 C:\Windows\System32\IPHLPAPI.DLL
                                0x759c0000 0x35000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc.DLL
                                0x75c40000 0x2c000 6.00.6001.18000 C:\Windows\System32\DNSAPI.dll
                                0x759b0000 0x7000 6.00.6001.18000 C:\Windows\System32\WINNSI.DLL
                                0x75980000 0x21000 6.00.6001.18000 C:\Windows\System32\dhcpcsvc6.DLL
                                0x751e0000 0xf000 6.00.6001.18000 C:\Windows\System32\nlaapi.dll
                                0x6e630000 0x1bf000 6.00.6001.18000 C:\Windows\system32\pnidui.dll
                                0x73940000 0x17000 6.00.6001.18000 C:\Windows\system32\QUtil.dll
                                0x74090000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
                                0x753a0000 0x66000 6.00.6001.18000 C:\Windows\system32\FirewallAPI.dll
                                0x712c0000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
                                0x10000000 0x17000 2.05.0003.0011 C:\Windows\system32\MsnChatHook.dll
                                0x03a90000 0x22000 2.05.0023.4035 C:\Windows\system32\ShowErrMsg.dll
                                0x03b60000 0x4a000 2.05.0109.4035 C:\Windows\system32\sysenv.dll
                                0x72d90000 0x42000 6.00.6001.18000 C:\Windows\system32\WINSPOOL.DRV
                                0x764f0000 0x73000 6.00.6001.18000 C:\Windows\system32\comdlg32.dll
                                0x038e0000 0x15000 2.05.0015.4035 C:\Windows\system32\BatchCrypto.dll
                                0x07770000 0x64000 2.02.0000.0034 C:\Windows\system32\CryptoAPI.dll
                                0x72ea0000 0x9b000 8.00.50727.1434 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll
                                0x04710000 0x3c000 2.05.0026.0032 C:\Windows\system32\keyManager.dll
                                0x6ff80000 0x10f000 8.00.50727.0762 C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL
                                0x711d0000 0x87000 8.00.50727.1434 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll
                                0x74af0000 0xdc000 6.00.6001.18000 C:\Windows\system32\dbghelp.dll
                                0x71350000 0xf000 8.00.50727.0762 C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80FRA.DLL
                                0x71520000 0x12000 6.00.6001.18000 C:\Windows\system32\Wlanapi.dll
                                0x74320000 0x17c000 6.00.6001.18000 C:\Windows\system32\OneX.DLL
                                0x74950000 0xe000 6.00.6001.18000 C:\Windows\system32\eappprxy.dll
                                0x742f0000 0x24000 6.00.6001.18000 C:\Windows\system32\eappcfg.dll
                                0x758e0000 0x45000 6.00.6001.18000 C:\Windows\system32\bcrypt.dll
                                0x6fd90000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
                                0x6eec0000 0x23000 6.00.6001.18000 C:\Windows\system32\wpdshserviceobj.dll
                                0x6e170000 0x43000 6.00.6001.18000 C:\Windows\System32\srchadmin.dll
                                0x6e120000 0x4a000 6.00.6001.18000 C:\Windows\system32\ntshrui.dll
                                0x6e0e0000 0x3c000 7.00.6001.18000 C:\Windows\system32\webcheck.dll
                                0x6dca0000 0x21c000 6.00.6001.18000 C:\Windows\System32\SyncCenter.dll
                                0x6f060000 0xb000 6.00.6001.18000 C:\Windows\system32\mssprxy.dll
                                0x6e020000 0x51000 6.00.6001.18000 C:\Windows\system32\imapi2.dll
                                0x6e1d0000 0x39000 6.00.6001.18000 C:\Windows\system32\wscntfy.dll
                                0x71f20000 0xb000 6.00.6001.18000 C:\Windows\system32\WSCAPI.dll
                                0x6ff10000 0x2e000 6.00.6001.18000 C:\Windows\System32\QAgent.dll
                                0x71850000 0xb000 6.00.6001.18000 C:\Windows\system32\wbem\wbemprox.dll
                                0x6fb00000 0x5b000 6.00.6001.18000 C:\Windows\system32\wbemcomn.dll
                                0x71500000 0x10000 6.00.6001.18000 C:\Windows\system32\wbem\wbemsvc.dll
                                0x6f6e0000 0x99000 6.00.6001.18000 C:\Windows\system32\wbem\fastprox.dll
                                0x75be0000 0x18000 6.00.6001.18000 C:\Windows\system32\NTDSAPI.dll
                                0x6df20000 0xf9000 6.00.6001.18000 C:\Windows\system32\bthprops.cpl
                                0x6d8b0000 0x2b000 6.00.6001.18000 C:\Windows\system32\PortableDeviceTypes.dll
                                0x6f8e0000 0x46000 6.00.6001.18000 C:\Windows\system32\PortableDeviceApi.dll
                                0x75ee0000 0x5f000 6.00.6001.18000 C:\Windows\system32\SXS.DLL
                                0x75120000 0x15000 6.00.6001.18000 C:\Windows\system32\Cabinet.dll
                                0x74000000 0x2f000 1.02.1009.0000 C:\Windows\system32\xmllite.dll
                                0x70ec0000 0x16000 6.00.6001.18000 C:\Windows\system32\thumbcache.dll
                                0x6d390000 0x30000 6.00.6001.18000 C:\Windows\system32\MLANG.dll
                                0x6ca80000 0x223000 6.00.6001.18000 C:\Windows\system32\NetworkExplorer.dll
                                0x08da0000 0x9b000 C:\PROGRA~1\IZArc\IZArcCM.dll
                                0x6ca60000 0x18000 6.00.6001.18000 C:\Windows\system32\olepro32.dll
                                0x0b170000 0x82f000 7.15.0011.0154 C:\Windows\system32\nvcpl.dll
                                0x07650000 0x56000 7.15.0011.0154 C:\Windows\system32\nvapi.dll
                                0x6c4f0000 0x57000 6.00.6001.18000 C:\Windows\system32\zipfldr.dll
                                0x6c490000 0x60000 6.00.6001.18000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
                                0x01e80000 0x27000 2.05.0014.0000 C:\Windows\system32\eDStoolbar.dll
                                0x6d930000 0x1b000 8.00.50727.0762 C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL
                                0x01eb0000 0x10000 8.00.0000.0456 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

                                ListDLLs v2.25 - DLL lister for Win9x/NT
                                Copyright (C) 1997-2004 Mark Russinovich
                                Sysinternals - www.sysinternals.com

                                ------------------------------------------------------------------------------
                                winlogon.exe pid: 952
                                Command line: winlogon.exe

                                Base Size Version Path
                                0x00760000 0x50000 6.00.6001.18000 C:\Windows\system32\winlogon.exe
                                0x778f0000 0x127000 6.00.6001.18000 C:\Windows\system32\ntdll.dll
                                0x77a50000 0xdb000 6.00.6001.18000 C:\Windows\system32\kernel32.dll
                                0x76c40000 0xc6000 6.00.6001.18000 C:\Windows\system32\ADVAPI32.dll
                                0x76d10000 0xc3000 6.00.6001.18000 C:\Windows\system32\RPCRT4.dll
                                0x766d0000 0x9d000 6.00.6001.18000 C:\Windows\system32\USER32.dll
                                0x76a10000 0x4b000 6.00.6001.18023 C:\Windows\system32\GDI32.dll
                                0x76820000 0xaa000 7.00.6001.18000 C:\Windows\system32\msvcrt.dll
                                0x76000000 0x14000 6.00.6001.18000 C:\Windows\system32\Secur32.dll
                                0x75410000 0x25000 6.00.6001.18000 C:\Windows\system32\WINSTA.dll
                                0x76160000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
                                0x76020000 0x1e000 6.00.6001.18000 C:\Windows\system32\USERENV.dll
                                0x77b30000 0x1e000 6.00.6001.18000 C:\Windows\system32\IMM32.DLL
                                0x76420000 0xc8000 6.00.6001.18000 C:\Windows\system32\MSCTF.dll
                                0x77a40000 0x9000 6.00.6001.18000 C:\Windows\system32\LPK.DLL
                                0x767a0000 0x7d000 1.626.6001.18000 C:\Windows\system32\USP10.dll
                                0x55580000 0xc000 2.00.0000.0009 c:\windows\system32\uxtuneup.dll
                                0x74af0000 0xdc000 6.00.6001.18000 C:\Windows\system32\dbghelp.dll
                                0x75080000 0x3f000 6.00.6001.18000 C:\Windows\system32\uxtheme.dll
                                0x74be0000 0x3e000 6.00.6001.18000 C:\Windows\system32\shsvcs.dll
                                0x75fa0000 0x2c000 6.00.6001.18000 C:\Windows\system32\apphelp.dll
                                0x754c0000 0x21000 6.00.6001.18000 C:\Windows\system32\NTMARTA.DLL
                                0x76bf0000 0x4a000 6.00.6001.18000 C:\Windows\system32\WLDAP32.dll
                                0x76170000 0x2d000 6.00.6001.18000 C:\Windows\system32\WS2_32.dll
                                0x77a30000 0x6000 6.00.6001.18000 C:\Windows\system32\NSI.dll
                                0x75c20000 0x11000 6.00.6001.18000 C:\Windows\system32\SAMLIB.dll
                                0x762d0000 0x144000 6.00.6001.18000 C:\Windows\system32\ole32.dll
                                0x75540000 0x3b000 6.00.6001.18000 C:\Windows\system32\rsaenh.dll
                                0x736d0000 0xb3000 6.00.6001.18000 C:\Windows\system32\WindowsCodecs.dll
                                0x75e60000 0x75000 6.00.6001.18000 C:\Windows\system32\NETAPI32.dll
                                0x75a60000 0x3a000 6.00.6001.18000 C:\Windows\system32\slc.dll
                                0x75ba0000 0x14000 6.00.6001.18000 C:\Windows\system32\MPR.dll

                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\Windows\system32

                                19/01/2008 09:33 6 144 csrss.exe
                                1 fichier(s) 6 144 octets
                                0 Rép(s) 40 872 116 224 octets libres

                                Contenu de Downloaded Program Files
                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\Windows\Downloaded Program Files

                                05/06/2008 13:55 <REP> .
                                05/06/2008 13:55 <REP> ..
                                18/09/2006 23:26 65 desktop.ini
                                1 fichier(s) 65 octets

                                Total des fichiers listés :
                                1 fichier(s) 65 octets
                                2 Rép(s) 40 872 116 224 octets libres

                                Recherche de rootkit! (Merci S!Ri)

                                Recherche d'infections connues

                                Export des clefs sensibles..

                                Liste des fichiers en exception sur le pare-feu XP SP2

                                "C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"="C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe:*:Enabled:eDSfsu"
                                "C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"="C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe:*:Enabled:encryption"
                                "C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"="C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe:*:Enabled:decryption"

                                Export de la clef SharedTaskScheduler

                                [SharedTaskScheduler]

                                exports des policies
                                REGEDIT4

                                [System]
                                "ConsentPromptBehaviorAdmin"=dword:00000002
                                "ConsentPromptBehaviorUser"=dword:00000001
                                "EnableInstallerDetection"=dword:00000001
                                "EnableLUA"=dword:00000000
                                "EnableSecureUIAPaths"=dword:00000001
                                "EnableVirtualization"=dword:00000001
                                "PromptOnSecureDesktop"=dword:00000001
                                "ValidateAdminCodeSignatures"=dword:00000000
                                "dontdisplaylastusername"=dword:00000000
                                "legalnoticecaption"=""
                                "legalnoticetext"=""
                                "scforceoption"=dword:00000000
                                "shutdownwithoutlogon"=dword:00000001
                                "undockwithoutlogon"=dword:00000001
                                "FilterAdministratorToken"=dword:00000000
                                "EnableUIADesktopToggle"=dword:00000000
                                "DisableRegistryTools"=dword:00000000
                                "HideLegacyLogonScripts"=dword:00000000
                                "HideLogoffScripts"=dword:00000000
                                "RunLogonScriptSync"=dword:00000001
                                "RunStartupScriptSync"=dword:00000000
                                "HideStartupScripts"=dword:00000000

                                [System\UIPI]

                                [System\UIPI\Clipboard]

                                [System\UIPI\Clipboard\ExceptionFormats]
                                "CF_TEXT"=dword:00000001
                                "CF_BITMAP"=dword:00000002
                                "CF_OEMTEXT"=dword:00000007
                                "CF_DIB"=dword:00000008
                                "CF_PALETTE"=dword:00000009
                                "CF_UNICODETEXT"=dword:0000000d
                                "CF_DIBV5"=dword:00000011

                                Export des clefs sensibles..
                                Rechercher adresses sensibles dans le fichier HOSTS...
                                catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2008-06-06 20:45:24
                                Windows 6.0.6001 Service Pack 1 NTFS

                                scanning hidden services & system hive ...

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
                                "s1"=dword:2df9c43f
                                "s2"=dword:110480d0
                                "h0"=dword:00000001

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
                                "p0"="C:\Program Files\DAEMON Tools\"
                                "h0"=dword:00000000
                                "khjeh"=hex:1b,31,74,14,be,31,bd,56,70,40,04,15,9a,26,df,a4,51,13,17,07,55,..

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
                                "a0"=hex:20,01,00,00,2a,a6,81,63,73,2f,07,a8,7e,dc,e2,a0,5a,a3,01,47,0c,..
                                "khjeh"=hex:f6,b9,46,47,a6,82,a8,03,6a,f8,5a,0e,80,ce,7a,8f,15,6f,d1,a3,c2,..

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
                                "khjeh"=hex:c4,db,e2,74,ef,51,29,68,8e,de,ab,d0,76,89,11,74,81,c9,e3,ed,e4,..
                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
                                "p0"="C:\Program Files\DAEMON Tools\"
                                "h0"=dword:00000000
                                "khjeh"=hex:1b,31,74,14,be,31,bd,56,70,40,04,15,9a,26,df,a4,51,13,17,07,55,..

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
                                "a0"=hex:20,01,00,00,2a,a6,81,63,73,2f,07,a8,7e,dc,e2,a0,5a,a3,01,47,0c,..
                                "khjeh"=hex:f6,b9,46,47,a6,82,a8,03,6a,f8,5a,0e,80,ce,7a,8f,15,6f,d1,a3,c2,..

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
                                "khjeh"=hex:c4,db,e2,74,ef,51,29,68,8e,de,ab,d0,76,89,11,74,81,c9,e3,ed,e4,..

                                scanning hidden registry entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden services: 0
                                hidden files: 0

                                KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

                                Sorry, this version supports only Win2K/XP

                                KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

                                Sorry, this version supports only Win2K/XP

                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\Program Files

                                06/06/2008 18:02 <REP> .
                                06/06/2008 18:02 <REP> ..
                                14/09/2007 10:24 <REP> Acer Arcade Deluxe
                                16/04/2008 22:25 <REP> Acer GameZone
                                14/09/2007 10:37 <REP> Acer Inc
                                16/03/2008 17:51 <REP> Adobe
                                14/09/2007 10:36 <REP> Apoint2K
                                20/05/2008 23:22 <REP> Apple Software Update
                                31/05/2008 10:28 <REP> a-squared Free
                                26/01/2008 20:03 <REP> Bonjour
                                06/02/2008 21:37 <REP> CCleaner
                                05/06/2008 17:13 <REP> Common Files
                                26/07/2007 03:29 <REP> CONEXANT
                                27/02/2008 22:34 <REP> Creative
                                26/07/2007 04:13 <REP> CyberLink
                                05/05/2008 22:48 <REP> Disc2Phone
                                25/05/2008 07:40 <REP> eMule
                                03/06/2008 23:27 <REP> ESET
                                05/05/2008 22:56 <REP> Gamenext
                                07/02/2008 14:02 <REP> Google
                                02/03/2008 21:12 <REP> Guitar Pro 5
                                10/02/2008 17:30 <REP> Hemming
                                25/01/2008 23:13 <REP> Hydroweb L'Yse
                                05/05/2008 20:11 <REP> Internet Explorer
                                20/01/2008 01:26 <REP> Inventel
                                20/05/2008 23:24 <REP> iPod
                                20/05/2008 23:25 <REP> iTunes
                                20/01/2008 22:58 <REP> IZArc
                                20/02/2008 22:24 <REP> Jargon Informatique
                                05/06/2008 17:15 <REP> Java
                                14/09/2007 10:23 <REP> Launch Manager
                                06/02/2008 22:21 <REP> LimeWire
                                05/06/2008 10:57 <REP> Malwarebytes' Anti-Malware
                                10/03/2008 22:45 <REP> Microsoft CAPICOM 2.1.0.2
                                02/11/2006 14:37 <REP> Microsoft Games
                                26/07/2007 04:43 <REP> Microsoft Office
                                26/07/2007 04:43 <REP> Microsoft Works
                                26/07/2007 04:40 <REP> Microsoft.NET
                                01/04/2008 22:21 <REP> Movie Maker
                                27/05/2008 22:49 <REP> Mozilla Firefox
                                02/11/2006 14:37 <REP> MSBuild
                                20/01/2008 08:17 <REP> MSXML 4.0
                                05/03/2008 23:34 <REP> NCH Swift Sound
                                26/07/2007 04:11 <REP> NewTech Infosystems
                                20/05/2008 23:24 <REP> QuickTime
                                14/09/2007 10:26 <REP> Realtek
                                02/11/2006 14:37 <REP> Reference Assemblies
                                25/01/2008 01:19 <REP> SAGEM
                                05/06/2008 20:17 <REP> Trend Micro
                                07/02/2008 20:50 <REP> TuneUp Utilities 2008
                                20/04/2008 17:09 <REP> uTorrent
                                20/01/2008 23:00 <REP> VideoLAN
                                20/01/2008 01:48 <REP> Wanadoo
                                01/04/2008 22:21 <REP> Windows Calendar
                                01/04/2008 22:20 <REP> Windows Collaboration
                                01/04/2008 22:20 <REP> Windows Defender
                                01/04/2008 22:20 <REP> Windows Journal
                                10/03/2008 22:16 <REP> Windows Live
                                03/06/2008 20:56 <REP> Windows Mail
                                01/04/2008 22:20 <REP> Windows Media Player
                                18/01/2008 15:45 <REP> Windows NT
                                01/04/2008 22:20 <REP> Windows Photo Gallery
                                01/04/2008 22:21 <REP> Windows Sidebar
                                05/06/2008 14:23 <REP> Yahoo!
                                0 fichier(s) 0 octets
                                64 Rép(s) 40 871 264 256 octets libres
                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\Program Files\fichiers communs

                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders

                                26/07/2007 04:40 <REP> .
                                26/07/2007 04:40 <REP> ..
                                26/07/2007 04:38 <REP> 1036
                                26/10/2006 20:12 40 256 MSOSV.DLL
                                1 fichier(s) 40 256 octets
                                3 Rép(s) 40 871 264 256 octets libres
                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\Program Files\common files

                                05/06/2008 17:13 <REP> .
                                05/06/2008 17:13 <REP> ..
                                16/03/2008 17:51 <REP> Adobe
                                20/05/2008 23:22 <REP> Apple
                                26/07/2007 04:40 <REP> DESIGNER
                                26/07/2007 04:13 <REP> InstallShield
                                05/06/2008 17:13 <REP> Java
                                26/07/2007 04:11 <REP> LightScribe
                                22/03/2008 09:40 <REP> microsoft shared
                                26/07/2007 04:11 <REP> muvee Technologies
                                26/07/2007 04:11 <REP> NewTech Infosystems
                                04/05/2008 21:44 <REP> Oberon Media
                                02/11/2006 13:18 <REP> Services
                                02/11/2006 13:18 <REP> SpeechEngines
                                20/01/2008 19:37 <REP> Symantec Shared
                                01/04/2008 22:20 <REP> System
                                07/02/2008 19:36 <REP> Wise Installation Wizard
                                0 fichier(s) 0 octets
                                17 Rép(s) 40 871 260 160 octets libres
                                Le volume dans le lecteur C s'appelle ACER
                                Le numéro de série du volume est 4C3A-30A6

                                Répertoire de C:\

                                16/08/2005 08:49 40 960 junction.exe
                                1 fichier(s) 40 960 octets
                                0 Rép(s) 40 871 260 160 octets libres

                                c:\Users\lululedet\Documents\cc104crk.exe
                                c:\Users\lululedet\Documents\cueclub.exe
                                c:\Users\lululedet\Documents\logiciels de lul\antivir_workstation_win7u_en_h.exe
                                c:\Users\lululedet\Documents\logiciels de lul\iPod_Support_v3_04.exe
                                c:\Users\lululedet\Documents\logiciels de lul\LimeWirePro.4.14.0.exe
                                c:\Users\lululedet\Documents\logiciels de lul\setupyse.exe
                                c:\Users\lululedet\Documents\logiciels de lul\winamp552_full_all.exe
                                c:\Users\lululedet\Documents\logiciels de lul\YamiPod.exe
                                c:\Users\lululedet\Documents\logiciels de lul\NOD32 2.7 french\NOD32_pour_Windows_NT-2000-XP-64bits-Vista.exe
                                c:\Users\lululedet\Documents\logiciels de lul\NOD32 2.7 french\NOD32.patch\NOD32.FiX.v2.1.exe
                                c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\TU2008TrialEN.exe
                                c:\Users\lululedet\Documents\logiciels de lul\TuneUp_Utilities_2008_7.0.7991+Keygen\Keygen\TU2008 Keymaker.exe

                                ****** Fin du rapport DiagHelp
                                Veuillez svp envoyer le fichier C:\upload_moi_PC-de-lululedet.tar.gz a l'adresse http://upload.malekal.com
                                1. /!\ Merci de bien lire et suivre attentivement ce qui est écrit car tu dois appuyer sur une touche lors du scan.. si tu ne le fais pas le rapport ne sera pas entier et tu devras recommencer /!\

                                  *Télécharge DiagHelp.zip (de Malekal) sur ton bureau
                                  http://www.malekal.com/download/DiagHelp.zip
                                  Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
                                  *Dézippe le et ouvre le nouveau dossier DiagHelp
                                  *Double-clique sur go.cmd (le .cmd peut ne pas apparaître ! )
                                  *Choisis l’option 1 dans la fenêtre qui s’ouvrira.
                                  *Ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand cela t’es demandé..

                                  ATTENTION : pendant l'analyse, après le rapport catchme, il te sera demandé d'appuyer sur une touche afin de poursuivre le scan, suis bien les instructions à l'écran !

                                  *A la fin de l'analyse, ton ordi devra peut-être être redémarré... Une fois l'ordinateur redémarré le rapport va apparaître sur le bloc-note.. Ce dernier se trouve également ici C:\resultat.txt
                                  *Poste le contenu du rapport.

                                  On va voir s'il reste encore des choses.
                                  • 1
                                  • 2
                                  • 3
                                  • 4
                                  • 5
                                  • 6