HELLPPP virus message xp guardian

Bonjour,
suite a un virus mon pc rame, j'ai parfois plus accès a internet quand je veut ouvrir par exemple itunes jai une fenetre qui m' indique ouvrir avec tel ou tel programme alors qu' auparavant les applications s' ouvrais quand je double cliquer dessus quand je souhaite ajouter ou suppimer des logiciels dans le panneaux de configuration je ne peut plus j'ai le message suivant qui s'affiche : C:\windows\system32\rundll32.exe. J ai telecharger avast qui ne veut pas se lancer et ni se desinstaller j'ai du telecharger l' antivirus trend micro internet qui semble fonctionner et qui m'as detecter des virus et les as supprimer mais lorsque je lance un autre antivirus a_squared free il me trouve deux virus qui ne peut pas supprimer donc je ne sait pas quel virus j'ai choper je souhaiterais que l' on m' apporte de l'aide afin que je puisse utiliser mon pc comme auparavant ce que je peut vous apporter au niveau d'a_squared free: key:hkey_local_machine\software\paladin ne peut pas etre supprimer et key:hkey_local_machine\software\malware ne peut pas etre supprimer. Au niveau de xp j'ai un message d'alerter de xp guardian 2010 : trojan psw win 32 coced.219 voila je suis sous windows xp pro merci de votre aide
Configuration: Windows XP / Internet Explorer 7.0

30 réponses

Résumé de la discussion

Un utilisateur sous Windows XP Pro signale un ralentissement et des problèmes d'ouverture de fichiers et de programmes après une infection, avec un message C:\windows\system32\rundll32.exe et des détections de virus par Trend Micro et ASquared. Plusieurs conseils techniques proposent des outils de décontamination, notamment OTL OldTimer, Tools Cleaner et des procédures de scan en mode sans échec, puis la publication des rapports via un service d'hébergement pour évaluation. D'autres interventions évoquent Combofix, Zeb-Restore, ESET Online Scanner et Malwarebytes, ainsi que des mesures préventives comme désactiver temporairement la restauration système, mettre Windows à jour et nettoyer la base registre.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut maelys011

    Télécharge OTL (de OldTimer) et enregistre-le sur ton Bureau.
    http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/

    Faire un clique droit et renomme-le en OTL.com

    - Quitte les applications en cours afin de ne pas interrompre le scan.
    - Double clique sur OTL.com présent sur le bureau pour lancer le programme
    - Une fenêtre apparaît. Dans la section Output en haut de cette fenêtre, coche "Minimal Output". Fais de même avec "Scan All Users".
    - Coche également les cases à côté de "LOP Check" et "Purity Check".
    - Dans la zone Extra List, coche "Use Safelist".

    Ne modifie pas les autres paramètres!

    - Clique sur le bouton Run Scan.
    - Une fois l'analyse terminée, deux fenêtres vont s'ouvrir dans le Bloc-notes : OTL.txt et Extras.txt. Ils se trouvent au même endroit que OTListIT2 (donc par défaut sur le Bureau).

    Utilise cjoint.com pour poster en lien tes rapports :
    https://www.cjoint.com/

    - Clique sur Parcourir pour aller chercher le rapport
    - Clique sur Ouvrir ensuite sur Créer le lien Cjoint

    - Fais un copier/coller du lien qui est devant Le lien a été créé: dans ta prochaine réponse.

    @++ :)
    1
  2. GRRRR j'ai un enorme soucis le lien OTL ne fonctionne pas quand je clique dessus il me dis internet explorer ne peut pas afficher cette page web
    0
    1. Contributeur sécurité
      Salut maelys011

      Essai avec un clic droit sur le lien :

      Pour Internet Explorer

      - Choisi Enregistrer la cible sous ...

      Pour Firefox

      - Choisi Enregistrer la cible du lien sous...

      - Choisi le bureau comme lieu d'enregistrement

      - Donne lui ce nom OTL.com clique sur Enregistrer

      Continu le reste de la procédure

      Sinon voir en mode sans échec avec prise en charge réseau

      @++ :)
      1
      1. bon ben j' ai enfin reussi a telecharger OTL mais quand je doucle clique dessus la fenetre s' ouvre et disparait aussitot et j'ai aussi le meme probleme en mode sans echec avec prise en charge reseau y' as t' il une autre solution ???
        0
        1. Contributeur sécurité
          Salut maelys011

          Faire un clique droit sur OTL.exe et renomme-le en OTL.com et enter

          Essai de nouveau avec OTL.com

          @++ :)
          1
          1. coucou dédétraqué voici le rapport il est long :

            OTL Extras logfile created on: 04/03/2010 14:54:40 - Run 1 OTL by OldTimer - Version 3.1.33.0 Folder = C:\Documents and Settings\keemy\Bureau Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 958,00 Mb Total Physical Memory | 518,00 Mb Available Physical Memory | 54,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 181,12 Gb Total Space | 160,85 Gb Free Space | 88,81% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded Drive H: | 5,17 Gb Total Space | 5,17 Gb Free Space | 99,99% Space Free | Partition Type: FAT32 I: Drive not present or media not loaded Computer Name: PCTITAN Current User Name: keemy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] [HKEY_USERS\S-1-5-21-1454471165-884357618-682003330-1004\SOFTWARE\Classes\] .exe [@ = secfile] -- C:\Documents and Settings\keemy\Local Settings\Application Data\av.exe File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Scan with Ad-aware...] -- "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "%1" "+SD" (Lavasoft Sweden) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "UpdatesDisableNotify" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "AntiVirusOverride" = 1 "FirewallOverride" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 "48113:TCP" = 48113:TCP:LocalSubNet:Enabled:maconfig_tcp "48113:UDP" = 48113:UDP:LocalSubNet:Enabled:maconfig_udp "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare -- (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\SFR\Gestionnaire de Connexion SFR\ABCd.exe" = C:\Program Files\SFR\Gestionnaire de Connexion SFR\ABCd.exe:*:Enabled:Gestionnaire de connexions SFR -- File not found "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare -- (Microsoft Corporation) "C:\Program Files\ma-config.com\maconfservice.exe" = C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice -- (CybelSoft) "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation) "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.) "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime "{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live "{2075CB0A-D26F-4DAA-B424-5079296B43BA}" = Windows Live FolderShare "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86 "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox "{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3762698E-E9DF-4DD8-99F1-8192D0F8EE06}" = Nokia_Multimedia_Common_Components_2_5 "{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale "{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel "{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite "{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support "{425FFD94-36BD-4933-881B-FE0B9DADF2B7}" = Ma-Config.com "{4634B21A-CC07-4396-890C-2B8168661FEA}" = Windows Live Writer "{46ABBC54-1872-4AA3-95E2-F2C063A63F31}" = Installation Windows Live "{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}" = Nokia Software Updater "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{5DD76286-9BE7-4894-A990-E905E91AC818}" = Windows Live Mail "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6E127288-02BD-4DB8-B46B-D9B2BB3C268C}" = Windows Messenger 5.1 "{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{770F1BEC-2871-4E70-B837-FB8525FFA3B1}" = Windows Live Messenger "{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}" = Windows Live Call "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security "{9D6B740F-D9A2-45A6-BDC4-0A453D499FE6}" = PC Connectivity Solution "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A528306A-C5EC-481C-A619-6106334E6800}" = Nokia Ovi Player "{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support "{B131E59D-202C-43C6-84C9-68F0C37541F1}" = Galerie de photos Windows Live "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}" = Windows Live Contrôle parental "{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari "{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}" = Assistant de connexion Windows Live "{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes "{F7D27C70-90F5-49B9-B188-0A133C0CE353}" = Windows Live Toolbar "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio "504244733D18C8F63FF584AEB290E3904E791693" = Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0) "AbiWord2" = AbiWord 2.6.8 "Ad-aware 6 Professional" = Ad-aware 6 Professional "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "a-squared Free_is1" = a-squared Free 4.5 "Audacity_is1" = Audacity 1.2.6 "CCleaner" = CCleaner "E8A6D621B6D3FC5D43C68C549D959DE76EEF5D84" = Package de pilotes Windows - Nokia Modem (06/01/2009 4.1) "F779F5541ABD99C95C03B0FD5E3C058B22DA0FF7" = Package de pilotes Windows - Nokia Modem (06/01/2009 7.01.0.3) "Google Updater" = Outil de mise à jour Google "ie8" = Windows Internet Explorer 8 "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.30 "Macromedia Shockwave Player" = Macromedia Shockwave Player "McAfee Security Scan" = McAfee Security Scan Plus "Messenger Plus! Live" = Messenger Plus! Live "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8) "Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition "Nokia PC Suite" = Nokia PC Suite "RealPlayer 12.0" = RealPlayer "RightMark Audio Analyzer 5.5" = RightMark Audio Analyzer 5.5 "VLC media player" = VLC media player 1.0.3 "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows XP Service" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Installation Windows Live "WMFDist11" = Windows Media Format 11 runtime "Word Reader 5.5" = Word Reader 5.5 "Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7 "Yahoo! Companion" = Yahoo! Toolbar [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1454471165-884357618-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Facebook Plug-In" = Facebook Plug-In "Notification de cadeaux MSN" = Notification de cadeaux MSN [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ System Events ] Error - 02/03/2010 17:38:22 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7000 Description = Le service aswFsBlk n'a pas pu démarrer en raison de l'erreur : %%2 Error - 02/03/2010 17:38:22 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7023 Description = Le service SSHNAS s'est arrêté avec l'erreur : %%126 Error - 03/03/2010 08:03:17 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7000 Description = Le service aswFsBlk n'a pas pu démarrer en raison de l'erreur : %%2 Error - 03/03/2010 08:03:17 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7023 Description = Le service SSHNAS s'est arrêté avec l'erreur : %%126 Error - 03/03/2010 10:47:35 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7000 Description = Le service aswFsBlk n'a pas pu démarrer en raison de l'erreur : %%2 Error - 03/03/2010 10:47:35 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7023 Description = Le service SSHNAS s'est arrêté avec l'erreur : %%126 Error - 03/03/2010 21:50:18 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7000 Description = Le service aswFsBlk n'a pas pu démarrer en raison de l'erreur : %%2 Error - 03/03/2010 21:50:18 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7023 Description = Le service SSHNAS s'est arrêté avec l'erreur : %%126 Error - 04/03/2010 09:37:37 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7000 Description = Le service aswFsBlk n'a pas pu démarrer en raison de l'erreur : %%2 Error - 04/03/2010 09:37:37 | Computer Name = PCTITAN | Source = Service Control Manager | ID = 7023 Description = Le service SSHNAS s'est arrêté avec l'erreur : %%126 < End of report >
            0
            1. Contributeur sécurité
              Salut maelys011

              Ce rapport est illisible et je n'ai pas l'autre rapport, on va faire autrement :

              Faire un clic droit sur ce lien :

              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              Pour Internet Explorer

              - Choisi Enregistrer la cible sous ...

              Pour Firefox

              - Choisi Enregistrer la cible du lien sous...

              - Choisi le bureau comme lieu d'enregistrement

              - Donne lui ce nom maelys.exe clique sur Enregistrer

              Important Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
              https://forum.pcastuces.com/default.asp
              https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

              ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

              Double clique sur maelys.exe, clique sur OUI et valide par Entrée

              Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

              NOTE : Le rapport se trouve également ici : C:\Combofix.txt

              Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

              @++ :)
              1
              1. autre soucis j'essaie depuis une semaine de poster un rapport sur le forum mais en vain sa m' indique que j' ai deja posté ce message alors que non comment faire ?
                0
                1. Contributeur sécurité
                  Salut maelys011

                  Utilise cjoint.com pour poster en lien ton rapport :
                  https://www.cjoint.com/

                  - Clique sur Parcourir pour aller chercher le rapport
                  - Clique sur Ouvrir ensuite sur Créer le lien Cjoint

                  - Fais un copier/coller du lien qui est devant Le lien a été créé: dans ta prochaine réponse.

                  @++ :)
                  1
                  1. Contributeur sécurité
                    Salut maelys011

                    Faire un scan de ce fichier bguno.sys ici :

                    https://www.virustotal.com/gui/

                    Clique sur Parcourir et copie/colle ceci :
                    C:\WINDOWS\System32\drivers\bguno.sys
                    Après tu clique sur Envoyer le fichier et attendre le résultat de l’analyse.

                    Si il te dit que le fichier a déjà été analysé, sélectionne le bouton :
                    Reanalyse le fichier maintenant et attendre le résultat de l'analyse, poste le résultat au complet.

                    Poste le résultat au complet

                    Aide : http://bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm

                    @++ :)
                    1
                    1. alors j' ai suivi la procedure mais sa m' ecris ceci : 0 bytes size received / Se ha recibido un archivo vacio
                      0
                      1. Contributeur sécurité
                        Salut maelys011

                        -Télécharge et installe MalwareByte's Anti-Malware
                        http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                        - Mets le à jour

                        ---

                        - Redémarre en mode sans échec :

                        Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

                        ---

                        - Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.
                        - Sélectionne Exécuter un examen complet si ce n'est pas déjà fait
                        - clique sur Rechercher

                        - Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur OK

                        - Si MalwareByte's n'a rien détecté, clique sur OK Un rapport va apparaître ferme-le.

                        - Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

                        - Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

                        Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur OK

                        Tutoriel pour MalwareByte's ici :
                        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                        @++ :)
                        1
                        1. re voila le rapport :

                          Malwarebytes' Anti-Malware 1.44
                          Version de la base de données: 3872
                          Windows 5.1.2600 Service Pack 3 (Safe Mode)
                          Internet Explorer 8.0.6001.18702

                          16/03/2010 14:03:30
                          mbam-log-2010-03-16 (14-03-21).txt

                          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
                          Eléments examinés: 205196
                          Temps écoulé: 1 hour(s), 45 minute(s), 26 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 12
                          Valeur(s) du Registre infectée(s): 6
                          Elément(s) de données du Registre infecté(s): 5
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 15

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.BHO) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.BHO) -> No action taken.
                          HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> No action taken.
                          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys (Rootkit.TDSS) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> No action taken.
                          HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\TOY5KNQ8OC (Trojan.FakeAlert) -> No action taken.

                          Valeur(s) du Registre infectée(s):
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.BHO) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> No action taken.

                          Elément(s) de données du Registre infecté(s):
                          HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          C:\Documents and Settings\Invité\Local Settings\Temp\_VOID7383.tmp (Trojan.FakeAlert) -> No action taken.
                          C:\Documents and Settings\Invité\Local Settings\Temp\_VOID7930.tmp (Trojan.FakeAlert) -> No action taken.
                          C:\Documents and Settings\Invité\Local Settings\Temp\_VOID7e51.tmp (Rootkit.TDSS) -> No action taken.
                          C:\Documents and Settings\Invité\Local Settings\Temp\_VOID7efc.tmp (Rootkit.TDSS) -> No action taken.
                          C:\Documents and Settings\Invité\Local Settings\Temp\_VOID8045.tmp (Rootkit.TDSS) -> No action taken.
                          C:\Documents and Settings\keemy\Local Settings\Temp\_VOID7932.tmp (Rootkit.TDSS) -> No action taken.
                          C:\WINDOWS\system32\_VOIDkbocntjlhb.dll (Rootkit.TDSS) -> No action taken.
                          C:\WINDOWS\system32\_VOIDlgxmjdmogy.dll (Rootkit.TDSS) -> No action taken.
                          C:\WINDOWS\system32\_VOIDtfnldoultl.dll (Rootkit.TDSS) -> No action taken.
                          C:\Documents and Settings\All Users\Application Data\mswintmp.dat (Malware.Trace) -> No action taken.
                          C:\Documents and Settings\All Users\Application Data\_VOIDkrl32mainweq.dll (Rootkit.TDSS) -> No action taken.
                          C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll (Rootkit.TDSS) -> No action taken.
                          C:\WINDOWS\system32\_VOIDvmyniqgrvt.dat (Rootkit.TDSS) -> No action taken.
                          C:\Documents and Settings\keemy\Local Settings\Temp\_VOIDb78a.tmp (Rootkit.TDSS) -> No action taken.
                          C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.
                          0
                          1. Contributeur sécurité
                            Salut maelys011

                            Supprime le Combofix renommé que je t'ai fais télécharger.

                            Télécharge combofix.exe (de sUBs) sur le bureau :

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                            http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                            Important Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
                            https://forum.pcastuces.com/default.asp
                            https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

                            ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

                            Double clique sur combofix.exe, clique sur OUI et valide par Entrée

                            Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                            NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                            Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

                            @++ :)
                            1
                            1. voici le rapport combofix

                              ComboFix 10-03-16.05 - keemy 17/03/2010 18:18:59.1.1 - x86
                              Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.958.596 [GMT 1:00]
                              Lancé depuis: c:\documents and settings\keemy\Bureau\ComboFix.exe
                              AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
                              FW: Pare-feu personnel Trend Micro *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
                              * Un nouveau point de restauration a été créé
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\recycler\S-1-5-21-1660163187-7360307294-371064680-9918
                              c:\recycler\S-1-5-21-7262364519-5484560398-323761058-8417
                              c:\recycler\S-1-5-21-8311700388-7490470563-326890603-1011
                              c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
                              c:\windows\system32\driVERs\bguno.sys
                              c:\windows\system32\install.exe
                              c:\windows\system32\msconfig.exe
                              H:\Autorun.inf

                              Une copie infectée de c:\windows\system32\srsvc.dll a été trouvée et désinfectée
                              Copie restaurée à partir de - c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\srsvc.dll

                              .
                              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              -------\Legacy_SSHNAS
                              -------\Legacy_bguno
                              -------\Service_bguno

                              ((((((((((((((((((((((((((((( Fichiers créés du 2010-02-17 au 2010-03-17 ))))))))))))))))))))))))))))))))))))
                              .

                              2010-03-16 10:44 . 2010-03-16 10:44 -------- d-----w- c:\documents and settings\keemy\Application Data\Malwarebytes
                              2010-03-16 10:44 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                              2010-03-16 10:44 . 2010-03-16 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                              2010-03-16 10:44 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                              2010-03-14 14:49 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
                              2010-03-14 14:33 . 2010-03-14 14:33 -------- d-----w- c:\windows\system32\MpEngineStore
                              2010-03-13 15:32 . 2010-03-13 15:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
                              2010-03-12 06:43 . 2010-03-12 06:43 -------- d-----w- c:\documents and settings\Invité.PCTITAN
                              2010-03-02 22:21 . 2010-03-02 22:21 -------- d-----w- c:\documents and settings\keemy\Application Data\dvdcss
                              2010-03-01 12:50 . 2010-03-01 12:50 50354 ----a-w- c:\documents and settings\keemy\Application Data\Facebook\uninstall.exe
                              2010-03-01 12:50 . 2010-03-01 12:50 -------- d-----w- c:\documents and settings\keemy\Application Data\Facebook
                              2010-02-26 06:41 . 2010-02-26 06:41 847040 ----a-w- c:\documents and settings\keemy\Application Data\Facebook\axfbootloader.dll
                              2010-02-26 06:41 . 2010-02-26 06:41 5582848 ----a-w- c:\documents and settings\keemy\Application Data\Facebook\npfbplugin_1_0_3.dll
                              2010-02-24 03:53 . 2010-02-24 03:53 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
                              2010-02-24 03:53 . 2010-02-24 03:53 -------- d-----w- c:\program files\NOS
                              2010-02-24 02:04 . 2010-02-24 02:01 59920 ----a-w- c:\windows\system32\drivers\tmactmon.sys
                              2010-02-24 02:04 . 2010-02-24 02:01 50704 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
                              2010-02-24 02:04 . 2010-02-24 02:01 158224 ----a-w- c:\windows\system32\drivers\tmcomm.sys
                              2010-02-24 02:02 . 2010-02-24 03:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Trend Micro
                              2010-02-24 02:02 . 2010-02-24 02:04 -------- d-----w- c:\program files\Trend Micro
                              2010-02-24 02:01 . 2010-02-24 02:01 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
                              2010-02-24 02:01 . 2010-02-24 02:01 36368 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
                              2010-02-24 02:01 . 2010-02-24 02:01 339984 ----a-w- c:\windows\system32\drivers\TM_CFW.sys
                              2010-02-24 02:01 . 2010-02-24 02:01 225808 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
                              2010-02-24 02:01 . 2010-02-24 02:01 1223832 ----a-w- c:\windows\system32\drivers\vsapint.sys
                              2010-02-23 17:43 . 2010-02-23 17:47 -------- d-----w- C:\audacity_1_2_temp
                              2010-02-23 17:24 . 2010-02-19 18:31 31936 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
                              2010-02-23 17:24 . 2010-02-19 18:31 29344 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
                              2010-02-22 15:00 . 2010-02-22 15:00 -------- d-----w- c:\windows\system32\drivers\NIS
                              2010-02-22 14:47 . 2010-02-22 14:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PCSettings
                              2010-02-22 01:37 . 2010-02-22 01:37 -------- d-----w- c:\documents and settings\keemy\Local Settings\Application Data\Help
                              2010-02-21 16:34 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
                              2010-02-21 16:34 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
                              2010-02-21 16:34 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
                              2010-02-21 16:34 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
                              2010-02-21 16:34 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
                              2010-02-21 16:34 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
                              2010-02-21 16:34 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
                              2010-02-21 16:34 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
                              2010-02-21 16:34 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
                              2010-02-21 16:06 . 2010-02-21 16:06 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
                              2010-02-21 16:01 . 2010-02-21 16:01 -------- d-----w- c:\program files\CCleaner
                              2010-02-21 04:06 . 2010-02-21 05:11 -------- d-----w- c:\program files\a-squared Free
                              2010-02-21 03:13 . 2010-02-21 03:31 -------- d-----w- c:\windows\system32\drivers\NAV
                              2010-02-21 03:13 . 2010-02-21 03:13 -------- d-----w- c:\program files\Windows Sidebar
                              2010-02-21 03:13 . 2010-02-23 01:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
                              2010-02-21 03:13 . 2010-02-22 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
                              2010-02-21 02:40 . 2010-03-16 10:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                              2010-02-20 19:08 . 2010-02-20 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
                              2010-02-20 19:08 . 2010-02-20 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
                              2010-02-20 19:08 . 2010-02-20 19:08 -------- d-----w- c:\program files\McAfee Security Scan
                              2010-02-20 16:29 . 2010-02-23 01:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                              2010-02-20 03:18 . 2009-12-16 15:05 471040 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
                              2010-02-20 03:18 . 2009-12-16 15:05 347136 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
                              2010-02-20 03:18 . 2009-12-16 15:05 340992 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
                              2010-02-20 03:18 . 2009-12-16 15:05 43008 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
                              2010-02-20 03:18 . 2009-12-16 15:05 1452032 ----a-w- c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
                              2010-02-20 02:32 . 2010-02-20 02:32 -------- d-----w- c:\documents and settings\keemy\Application Data\Yahoo!
                              2010-02-20 02:32 . 2010-02-20 02:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
                              2010-02-20 02:32 . 2010-02-20 02:32 -------- d-----w- c:\program files\Yahoo!
                              2010-02-20 02:14 . 2010-02-20 02:14 -------- d-----w- c:\documents and settings\keemy\Local Settings\Application Data\Google
                              2010-02-20 02:13 . 2010-02-20 02:13 -------- d-----w- c:\documents and settings\keemy\Local Settings\Application Data\Mozilla
                              2010-02-20 02:02 . 2010-02-24 01:42 -------- d-----w- c:\documents and settings\Invité
                              2010-02-20 01:45 . 2010-02-20 01:45 -------- d-----w- C:\2356729980481e854c2a5ed6
                              2010-02-20 01:31 . 2010-02-20 01:31 552 ----a-w- c:\windows\system32\d3d8caps.dat
                              2010-02-20 01:29 . 2010-02-20 01:29 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
                              2010-02-16 01:52 . 2010-02-16 01:52 -------- d-----w- c:\program files\iPod
                              2010-02-16 01:52 . 2010-02-16 01:52 -------- d-----w- c:\program files\iTunes
                              2010-02-16 01:52 . 2010-02-16 01:52 -------- d-----w- c:\program files\Bonjour
                              2010-02-16 01:51 . 2010-02-16 01:52 -------- d-----w- c:\program files\QuickTime
                              2010-02-16 01:51 . 2010-02-16 01:51 -------- d-----w- c:\program files\Apple Software Update
                              2010-02-16 01:51 . 2009-08-28 18:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
                              2010-02-16 01:51 . 2009-08-28 18:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
                              2010-02-15 17:52 . 2010-02-15 17:52 -------- d-----w- c:\program files\Fichiers communs\xing shared

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2010-03-16 18:30 . 2010-02-15 15:31 -------- d-----w- c:\documents and settings\keemy\Application Data\vlc
                              2010-03-13 14:37 . 2009-11-24 02:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
                              2010-02-24 01:38 . 2009-11-20 00:09 16208 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                              2010-02-22 02:06 . 2010-02-14 22:14 16208 ----a-w- c:\documents and settings\keemy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                              2010-02-21 16:34 . 2010-02-14 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
                              2010-02-16 01:52 . 2009-12-05 01:16 -------- d-----w- c:\program files\Fichiers communs\Apple
                              2010-02-15 17:52 . 2007-08-23 00:22 -------- d-----w- c:\program files\Fichiers communs\Real
                              2010-02-15 17:51 . 2007-08-22 21:28 499712 ----a-w- c:\windows\system32\msvcp71.dll
                              2010-02-15 17:51 . 2007-08-22 21:28 348160 ----a-w- c:\windows\system32\msvcr71.dll
                              2010-02-15 04:48 . 2010-02-14 22:52 -------- d-----w- c:\documents and settings\keemy\Application Data\Apple Computer
                              2010-02-15 04:15 . 2010-02-14 23:20 -------- d-----w- c:\documents and settings\keemy\Application Data\Nokia
                              2010-02-14 23:24 . 2010-02-14 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
                              2010-02-14 23:24 . 2009-11-24 02:18 -------- d-----w- c:\program files\Fichiers communs\Nokia
                              2010-02-14 23:24 . 2009-11-24 02:16 -------- d-----w- c:\program files\Nokia
                              2010-02-14 23:23 . 2010-02-14 23:23 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\msxml6Exec.exe
                              2010-02-14 23:23 . 2010-02-14 23:23 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\Sleep.exe
                              2010-02-14 23:23 . 2010-02-14 23:23 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\vcredistExec.exe
                              2010-02-14 23:23 . 2010-02-14 23:24 24443520 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\NokiaSoftwareUpdaterSetup_fr[1].exe
                              2010-02-14 23:23 . 2009-11-24 02:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
                              2010-02-14 23:21 . 2010-02-14 23:20 -------- d-----w- c:\documents and settings\keemy\Application Data\PC Suite
                              2010-02-14 22:58 . 2010-02-14 22:58 -------- d-----w- c:\program files\Safari
                              2010-02-14 22:54 . 2010-02-14 22:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
                              2010-02-14 22:14 . 2010-02-14 22:14 86576 ----a-w- c:\documents and settings\keemy\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
                              2010-02-14 22:14 . 2010-02-14 22:14 392728 ----a-w- c:\documents and settings\keemy\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
                              2010-02-14 22:14 . 2010-02-14 22:14 135680 ----a-w- c:\documents and settings\keemy\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                              2010-02-14 22:14 . 2010-02-14 22:14 132672 ----a-w- c:\documents and settings\keemy\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
                              2010-02-14 16:05 . 2009-12-16 03:41 -------- d-----w- c:\program files\Alwil Software
                              2010-02-13 15:44 . 2009-12-06 02:01 33558 ----a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\Firefox_Toolbar_Uninstaller.exe
                              2010-02-13 05:01 . 2009-11-24 05:04 -------- d-----w- c:\documents and settings\Administrateur\Application Data\vlc
                              2010-01-22 18:51 . 2010-01-22 18:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
                              2010-01-20 15:35 . 2009-12-05 02:06 -------- d-----w- c:\program files\Microsoft Silverlight
                              2010-01-19 04:11 . 2010-01-19 04:11 -------- d-----w- c:\program files\AbiSuite2
                              2010-01-19 03:44 . 2010-01-19 03:44 -------- d-----w- c:\program files\Abdio
                              2010-01-18 19:58 . 2009-12-05 01:17 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Apple Computer
                              2010-01-13 14:28 . 2010-01-13 14:28 79856 ----a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\uninstaller.exe
                              2009-12-31 16:50 . 2005-07-09 19:40 353792 ----a-w- c:\windows\system32\drivers\srv.sys
                              2009-12-22 06:23 . 2009-12-22 06:23 9556 ---ha-w- c:\windows\system32\mlfcache.dat
                              2009-12-21 19:07 . 2005-07-09 19:41 916480 ----a-w- c:\windows\system32\wininet.dll
                              .

                              ------- Sigcheck -------

                              [7] 2008-04-14 . E598D81197E2E0EC42A0C55772BB00E8 . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\regsvc.dll
                              [7] 2008-04-13 . E598D81197E2E0EC42A0C55772BB00E8 . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
                              [7] 2004-08-19 . B6F76CE10953A141545A0D01F1776885 . 59904 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regsvc.dll

                              c:\windows\System32\regsvc.dll ... manque !!
                              .
                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                              "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-30 1182088]

                              [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
                              [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
                              [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                              [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                              "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-30 1182088]

                              [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
                              [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
                              [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                              [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                              "NoSMBalloonTip"= 0 (0x0)

                              [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                              "ForceClassicControlPanel"= 1 (0x1)
                              "NoSMBalloonTip"= 0 (0x0)

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                              @="Driver"

                              [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^McAfee Security Scan Plus.lnk]
                              path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\McAfee Security Scan Plus.lnk
                              backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup

                              [HKLM\~\startupfolder\C:^Documents and Settings^keemy^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk]
                              path=c:\documents and settings\keemy\Menu Démarrer\Programmes\Démarrage\Notification de cadeaux MSN.lnk
                              backup=c:\windows\pss\Notification de cadeaux MSN.lnkStartup

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
                              2008-04-13 18:34 15360 ------w- c:\windows\system32\ctfmon.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                              "AntiVirusOverride"=dword:00000001
                              "FirewallOverride"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
                              "DisableMonitoring"=dword:00000001

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                              "EnableFirewall"= 0 (0x0)
                              "DisableNotifications"= 1 (0x1)
                              "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "%windir%\\system32\\sessmgr.exe"=
                              "c:\\Program Files\\Messenger\\Msmsgs.exe"=
                              "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                              "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                              "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                              "c:\\Program Files\\iTunes\\iTunes.exe"=

                              R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [21/02/2010 17:34 162512]
                              R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [21/02/2010 05:06 1858144]
                              R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [24/02/2010 03:01 36368]
                              R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [24/02/2010 03:01 339984]
                              R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [24/02/2010 03:04 497008]
                              R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [24/02/2010 03:04 689416]
                              S2 aswFsBlk;aswFsBlk;aswFsBlk.sys --> aswFsBlk.sys [?]
                              S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 14:50 238960]
                              S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 13:49 227232]
                              S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [24/11/2009 03:17 136704]
                              S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [24/11/2009 03:17 8320]
                              S3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [24/02/2010 03:04 50704]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              getPlusHelper REG_MULTI_SZ getPlusHelper
                              .
                              Contenu du dossier 'Tâches planifiées'

                              2010-02-20 c:\windows\Tasks\AppleSoftwareUpdate.job
                              - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                              2010-03-17 c:\windows\Tasks\Google Software Updater.job
                              - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-08-23 02:51]

                              2010-03-17 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
                              - c:\program files\Ask.com\UpdateTask.exe [2009-09-30 09:40]

                              2010-03-17 c:\windows\Tasks\User_Feed_Synchronization-{77A97E75-0666-4149-8C59-067723B20DB3}.job
                              - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]

                              2010-03-17 c:\windows\Tasks\User_Feed_Synchronization-{EDA7F3CF-E7C9-4527-B274-74BC70021070}.job
                              - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
                              .
                              .
                              ------- Examen supplémentaire -------
                              .
                              DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
                              FF - ProfilePath - c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\
                              FF - component: c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
                              FF - component: c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
                              FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
                              FF - plugin: c:\documents and settings\keemy\Application Data\Facebook\npfbplugin_1_0_3.dll
                              FF - plugin: c:\documents and settings\keemy\Application Data\Mozilla\Firefox\Profiles\tmh7r4ov.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
                              FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
                              FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                              FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                              .

                              **************************************************************************

                              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2010-03-17 18:29
                              Windows 5.1.2600 Service Pack 3 NTFS

                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés: 0

                              **************************************************************************
                              .
                              --------------------- DLLs chargées dans les processus actifs ---------------------

                              - - - - - - - > 'explorer.exe'(3496)
                              c:\windows\system32\eappprxy.dll
                              c:\windows\system32\webcheck.dll
                              c:\windows\system32\WPDShServiceObj.dll
                              c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
                              c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
                              c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_fre.nlr
                              c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
                              c:\windows\system32\PortableDeviceTypes.dll
                              c:\windows\system32\PortableDeviceApi.dll
                              .
                              ------------------------ Autres processus actifs ------------------------
                              .
                              c:\program files\Alwil Software\Avast5\AvastSvc.exe
                              c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              c:\program files\Bonjour\mDNSResponder.exe
                              c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
                              c:\program files\Nokia\PC Connectivity Solution\ServiceLayer.exe
                              c:\windows\system32\wbem\wmiapsrv.exe
                              c:\program files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
                              c:\program files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
                              .
                              **************************************************************************
                              .
                              Heure de fin: 2010-03-17 18:32:46 - La machine a redémarré
                              ComboFix-quarantined-files.txt 2010-03-17 17:32

                              Avant-CF: 171 953 520 640 octets libres
                              Après-CF: 175 477 776 384 octets libres

                              WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
                              [boot loader]
                              timeout=2
                              default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
                              [operating systems]
                              h:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                              multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect

                              Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
                              - - End Of File - - 0A3727B55419B77DB7BA5A44FA4FEE26
                              0
                              1. Contributeur sécurité
                                Salut maelys011

                                On va vérifier si rien de caché :

                                Faire un scan avec Nod32 en ligne (il faut utiliser Internet Explorer) ici :

                                https://www.eset.com/int/home/online-scanner/

                                (coche toutes les cases à chaque fois, sauf les deux dernières a la fin du scan, sinon le rapport est supprimer)
                                A la fin, colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt

                                @++ :)
                                1
                                1. ESETSmartInstaller@High as CAB hook log:
                                  OnlineScanner.ocx - registred OK
                                  esets_scanner_update returned -1 esets_gle=1
                                  esets_scanner_update returned -1 esets_gle=1
                                  # version=7
                                  # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
                                  # OnlineScanner.ocx=1.0.0.6211
                                  # api_version=3.0.2
                                  # EOSSerial=239494c66a973b429e0e02b6ef7516c7
                                  # end=stopped
                                  # remove_checked=true
                                  # archives_checked=true
                                  # unwanted_checked=true
                                  # unsafe_checked=true
                                  # antistealth_checked=false
                                  # utc_time=2010-03-18 10:18:06
                                  # local_time=2010-03-18 11:18:06 (+0100, Paris, Madrid)
                                  # country="France"
                                  # lang=1033
                                  # osver=5.1.2600 NT Service Pack 3
                                  # compatibility_mode=513 16777045 100 100 9825 4460989 0 0
                                  # compatibility_mode=768 16777215 100 0 2789049 2789049 0 0
                                  # compatibility_mode=8192 67108863 100 0 10154 10154 0 0
                                  # scanned=18719
                                  # found=0
                                  # cleaned=0
                                  # scan_time=1713
                                  esets_scanner_update returned -1 esets_gle=53251
                                  # version=7
                                  # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
                                  # OnlineScanner.ocx=1.0.0.6211
                                  # api_version=3.0.2
                                  # EOSSerial=239494c66a973b429e0e02b6ef7516c7
                                  # end=finished
                                  # remove_checked=true
                                  # archives_checked=true
                                  # unwanted_checked=true
                                  # unsafe_checked=true
                                  # antistealth_checked=false
                                  # utc_time=2010-03-19 06:34:59
                                  # local_time=2010-03-19 07:34:59 (+0100, Paris, Madrid)
                                  # country="France"
                                  # lang=1033
                                  # osver=5.1.2600 NT Service Pack 3
                                  # compatibility_mode=513 16777045 100 100 3733 4486152 0 0
                                  # compatibility_mode=768 16777215 100 0 2814212 2814212 0 0
                                  # compatibility_mode=8192 67108863 100 0 35317 35317 0 0
                                  # scanned=51249
                                  # found=0
                                  # cleaned=0
                                  # scan_time=6362
                                  esets_scanner_update returned -1 esets_gle=53251
                                  # version=7
                                  # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
                                  # OnlineScanner.ocx=1.0.0.6211
                                  # api_version=3.0.2
                                  # EOSSerial=239494c66a973b429e0e02b6ef7516c7
                                  # end=finished
                                  # remove_checked=true
                                  # archives_checked=true
                                  # unwanted_checked=true
                                  # unsafe_checked=true
                                  # antistealth_checked=true
                                  # utc_time=2010-03-19 01:58:45
                                  # local_time=2010-03-19 02:58:45 (+0100, Paris, Madrid)
                                  # country="France"
                                  # lang=1033
                                  # osver=5.1.2600 NT Service Pack 3
                                  # compatibility_mode=513 16777045 100 100 3780 4511969 0 0
                                  # compatibility_mode=768 16777215 100 0 2840029 2840029 0 0
                                  # compatibility_mode=8192 67108863 100 0 61134 61134 0 0
                                  # scanned=51463
                                  # found=0
                                  # cleaned=0
                                  # scan_time=7171
                                  0
                              2. Contributeur sécurité
                                Salut maelys011

                                Cela est bon, as-tu d'autre souci?

                                @++ :)
                                1
                                1. non c'est bon tout est rentré dans l' ordre merci beaucoup de ton aide tu est le best !!!!
                                  0
                                  • 1
                                  • 2