Aller au contenu

restanco

Membres
  • Compteur de contenus

    321
  • Inscription

  • Dernière visite

Tout ce qui a été posté par restanco

  1. Bonjour Je ne suis pas arrivé à installer antivir, alors de guère lasse j'ai réinstallé avast. Et mon ordi n'a jamais été aussi rapide depuis. Merci tout de même. et bon week-end.
  2. Bonsoir Après le scan, tout a l'air de fonctionner normalement, j'ouvre avast, cclean, tun up et tous les logiciels habituels. Merci et bonne soirée.
  3. Voic le nouveau rapport : ############################## [ FindyKill V4.728 ] # User : mesureux (Administrateurs) # MESUREUX-9A93E3 # Update on 13/05/09 by Chiquitine29 # Start at: 18:52:20 | 15/05/2009 # Website : http://pagesperso-orange.fr/NosTools/findykill.html # AMD Athlon 64 X2 Dual Core Processor 4400+ # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2 # Internet Explorer 6.0.2900.2180 # Windows Firewall Status : Enabled # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ] # FW : ActiveArmor Firewall[ (!) Disabled ]1.0 # A:\ # Lecteur de disquettes 3 ½ pouces # C:\ # Disque fixe local # 221.62 Go (139.27 Go free) [VIDEOS] # NTFS # D:\ # Disque CD-ROM # E:\ # Disque fixe local # 76.67 Go (62.54 Go free) [DONNÉES] # FAT32 # F:\ # Disque fixe local # 244.14 Go (195.23 Go free) [PROGRAMMES] # NTFS # G:\ # Disque fixe local # 149.01 Go (97.5 Go free) [DIVERS] # FAT32 # I:\ # Disque CD-ROM ############################## [ Active Processes ] F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\csrss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe F:\Program Files\Bonjour\mDNSResponder.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\logonui.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\Java\jre6\bin\jqs.exe F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe F:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\Installer\MSI38.tmp F:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp139.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\TUProgSt.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe F:\WINDOWS\system32\wbem\wmiapsrv.exe F:\WINDOWS\system32\wbem\wmiprvse.exe F:\WINDOWS\system32\wbem\wmiprvse.exe F:\WINDOWS\system32\userinit.exe F:\WINDOWS\Explorer.EXE F:\Program Files\SeekappSrch\seekapp.exe ################## [ Infected Files \ Folders ] Deleted ! F:\WINDOWS\Prefetch\1158062.EXE-0B1D0AAD.pf Deleted ! F:\WINDOWS\Prefetch\128171.EXE-23A6D539.pf Deleted ! F:\WINDOWS\Prefetch\128843.EXE-0F118BD7.pf Deleted ! F:\WINDOWS\Prefetch\202578.EXE-0E75C25E.pf Deleted ! F:\WINDOWS\Prefetch\204406.EXE-24870BE4.pf Deleted ! F:\WINDOWS\Prefetch\206015.EXE-2D956575.pf Deleted ! F:\WINDOWS\Prefetch\207828.EXE-02256382.pf Deleted ! F:\WINDOWS\Prefetch\211765.EXE-344DFE93.pf Deleted ! F:\WINDOWS\Prefetch\217281.EXE-3B5A1E03.pf Deleted ! F:\WINDOWS\Prefetch\221187.EXE-16EC5943.pf Deleted ! F:\WINDOWS\Prefetch\222953.EXE-34E16EF5.pf Deleted ! F:\WINDOWS\Prefetch\2347359.EXE-1F26A77E.pf Deleted ! F:\WINDOWS\Prefetch\2347390.EXE-01788CBF.pf Deleted ! F:\WINDOWS\Prefetch\236125.EXE-11F886D0.pf Deleted ! F:\WINDOWS\Prefetch\241000.EXE-02C7BB44.pf Deleted ! F:\WINDOWS\Prefetch\243078.EXE-2B9F4F36.pf Deleted ! F:\WINDOWS\Prefetch\244812.EXE-1F19E576.pf Deleted ! F:\WINDOWS\Prefetch\2467859.EXE-1E4B6A52.pf Deleted ! F:\WINDOWS\Prefetch\2471546.EXE-3328B12F.pf Deleted ! F:\WINDOWS\Prefetch\2481437.EXE-21DE115E.pf Deleted ! F:\WINDOWS\Prefetch\2486406.EXE-0D98E2BE.pf Deleted ! F:\WINDOWS\Prefetch\2486562.EXE-0B5B3A93.pf Deleted ! F:\WINDOWS\Prefetch\2507312.EXE-01EDEFC9.pf Deleted ! F:\WINDOWS\Prefetch\261000.EXE-01DAE412.pf Deleted ! F:\WINDOWS\Prefetch\2734656.EXE-28C5962F.pf Deleted ! F:\WINDOWS\Prefetch\2756765.EXE-1FCAA655.pf Deleted ! F:\WINDOWS\Prefetch\301593.EXE-0A0DF35A.pf Deleted ! F:\WINDOWS\Prefetch\500046.EXE-01E4D544.pf Deleted ! F:\WINDOWS\Prefetch\518468.EXE-31CE2063.pf Deleted ! F:\WINDOWS\Prefetch\606562.EXE-12EDBD7F.pf Deleted ! F:\WINDOWS\Prefetch\612546.EXE-3911BD9C.pf Deleted ! F:\WINDOWS\Prefetch\664937.EXE-163A9D18.pf Deleted ! F:\WINDOWS\Prefetch\94109.EXE-1C835C15.pf Deleted ! F:\WINDOWS\Prefetch\95062.EXE-0148ED0B.pf Deleted ! F:\WINDOWS\Prefetch\96921.EXE-26936B39.pf Deleted ! F:\WINDOWS\Prefetch\FLEC006.EXE-13C5958A.pf Deleted ! F:\WINDOWS\Prefetch\MDELK.EXE-0EF461CE.pf Deleted ! F:\WINDOWS\Prefetch\WINTEMS.EXE-377E42D4.pf Deleted ! F:\WINDOWS\Prefetch\WINUPGRO.EXE-0F8DCEDB.pf Deleted ! F:\WINDOWS\Prefetch\WINUPGRO.EXE-340DD355.pf Deleted ! F:\WINDOWS\system32\ban_list.txt Deleted ! F:\WINDOWS\system32\mdelk.exe Deleted ! F:\WINDOWS\system32\wintems.exe Deleted ! "F:\Documents and Settings\mesureux\Application Data\drivers\srosa2.sys" Deleted ! "F:\Documents and Settings\mesureux\Application Data\drivers\wfsintwq.sys" Deleted ! "F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe" Deleted ! "F:\Documents and Settings\mesureux\Application Data\m\data.oct" Deleted ! "F:\Documents and Settings\mesureux\Application Data\m\flec006.exe" Deleted ! "F:\Documents and Settings\mesureux\Application Data\m\list.oct" Deleted ! "F:\Documents and Settings\mesureux\Application Data\m\srvlist.oct" Deleted ! "F:\Documents and Settings\mesureux\Application Data\drivers\downld" Deleted ! "F:\Documents and Settings\mesureux\Application Data\drivers" Deleted ! "F:\Documents and Settings\mesureux\Application Data\m\shared" Deleted ! "F:\Documents and Settings\mesureux\Application Data\m" ################## [ Infected Temp Files ] Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_6[1].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\D4VY771V\b64_1[1].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_3[1].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_3[2].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\N50K4VVV\b64[1].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\N50K4VVV\b64[2].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_1[1].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_3[1].jpg Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\file[1].txt Deleted ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\W16JKDYF\b64_3[1].jpg ################## [ Registry / Infected keys ] Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S Deleted ! HKEY_CURRENT_USER\Software\bisoft Deleted ! HKEY_CURRENT_USER\Software\DateTime4 Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Droppix_Label_Maker_2.8.5_(Key+Serial) Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\hldrrr Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\install_patch Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\key_gen Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\mdelk Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\nideiect Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro Deleted ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\FFC Deleted ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\MuleAppData Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit" Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe" Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key" ################## [ Cleaning Removable drives ] Deleted ! C:\InfoSat.txt Deleted ! C:\Muestras Deleted ! F:\Avenger ################## [ Registry / Mountpoint2 ] # -> Not found ! ################## [ States / Restarting of services ] # Services : [ Auto=2 / Request=3 / Disable=4 ] # Ndisuio -> # Type of startup =3 # Ip6Fw -> # Type of startup =2 # SharedAccess -> # Type of startup =2 # wuauserv -> # Type of startup =2 # wscsvc -> # Type of startup =2 # Safe boot mode restored ! ################## [ Searching Other Infections ] # Références de comparaison Bagle MD5 : File ... : F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe CRC32 .. : 4a129020 MD5 .... : 1d7613ea55402d45bf9b6ceb1b4325be # -> Nothing found. ################## [ Corrupted files # Re-Installation required ] E:\Généalogie personnelle\Documents\fich_fam truc\LAUNCH.EXE E:\Généalogie personnelle\Documents\fich_fam mesu\LAUNCH.EXE E:\Généalogie personnelle\Mes passions 2007\fich_fam mesu\LAUNCH.EXE E:\Généalogie personnelle\Mes passions 2007\fich_fam truc\LAUNCH.EXE E:\Généalogie personnelle\Mes passions 2008\fich_fam mesu\LAUNCH.EXE E:\Généalogie personnelle\Mes passions 2008\fich_fam truc\LAUNCH.EXE E:\Généalogie personnelle\Archives\Mes passions 2003\fich_fam mesu\LAUNCH.EXE E:\Généalogie personnelle\Archives\Mes passions 2003\fich_fam truc\LAUNCH.EXE E:\Généalogie\Pages Web\Mes passions 2003\fichfam-mesu\LAUNCH.EXE E:\Généalogie\Pages Web\Mes passions 2003\fichfam-truc\LAUNCH.EXE F:\Program Files\a-squared Free\a2cmd.exe F:\Program Files\a-squared Free\a2service.exe F:\Program Files\a-squared Free\a2upd.exe F:\Program Files\Ashampoo\Ashampoo Burning Studio 8\ash_updateMediator.exe F:\Program Files\Driver-Soft\DriverGenius\LiveUpdate.exe F:\Program Files\Fichiers communs\Labtec\QCDRV\BIN\Update.exe F:\Program Files\Geneatique2009\Update.Exe F:\Program Files\Jasc Software Inc\Animation Shop 3\register.exe F:\Program Files\Magellan\VantagePoint\Update.exe F:\Program Files\Micro Application\Cartes de Visite\Update\Update.exe F:\Program Files\Mozilla Firefox\uninstall\helper.exe F:\Program Files\Protectis\Update.Exe F:\Program Files\Spybot - Search & Destroy\blindman.exe F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe F:\Program Files\Spybot - Search & Destroy\Update.exe F:\Program Files\Unlocker\UnlockerAssistant.exe F:\WINDOWS\$hf_mig$\KB873339\update\update.exe F:\WINDOWS\$hf_mig$\KB885835\update\update.exe F:\WINDOWS\$hf_mig$\KB885836\update\update.exe F:\WINDOWS\$hf_mig$\KB886185\update\update.exe F:\WINDOWS\$hf_mig$\KB887472\update\update.exe F:\WINDOWS\$hf_mig$\KB888302\update\update.exe F:\WINDOWS\$hf_mig$\KB890046\update\update.exe F:\WINDOWS\$hf_mig$\KB890859\update\update.exe F:\WINDOWS\$hf_mig$\KB891781\update\update.exe F:\WINDOWS\$hf_mig$\KB893756\update\update.exe F:\WINDOWS\$hf_mig$\KB894391\update\update.exe F:\WINDOWS\$hf_mig$\KB896358\update\update.exe F:\WINDOWS\$hf_mig$\KB896423\update\update.exe F:\WINDOWS\$hf_mig$\KB896428\update\update.exe F:\WINDOWS\$hf_mig$\KB898461\update\update.exe F:\WINDOWS\$hf_mig$\KB899587\update\update.exe F:\WINDOWS\$hf_mig$\KB899591\update\update.exe F:\WINDOWS\$hf_mig$\KB900485\update\update.exe F:\WINDOWS\$hf_mig$\KB900725\update\update.exe F:\WINDOWS\$hf_mig$\KB901017\update\update.exe F:\WINDOWS\$hf_mig$\KB901214\update\update.exe F:\WINDOWS\$hf_mig$\KB902400\update\update.exe F:\WINDOWS\$hf_mig$\KB904942\update\update.exe F:\WINDOWS\$hf_mig$\KB905414\update\update.exe F:\WINDOWS\$hf_mig$\KB905749\update\update.exe F:\WINDOWS\$hf_mig$\KB908519\update\update.exe F:\WINDOWS\$hf_mig$\KB908531\update\update.exe F:\WINDOWS\$hf_mig$\KB910437\update\update.exe F:\WINDOWS\$hf_mig$\KB911164\update\update.exe F:\WINDOWS\$hf_mig$\KB911280\update\update.exe F:\WINDOWS\$hf_mig$\KB911562\update\update.exe F:\WINDOWS\$hf_mig$\KB911927\update\update.exe F:\WINDOWS\$hf_mig$\KB913580\update\update.exe F:\WINDOWS\$hf_mig$\KB914388\update\update.exe F:\WINDOWS\$hf_mig$\KB914389\update\update.exe F:\WINDOWS\$hf_mig$\KB915865\update\update.exe F:\WINDOWS\$hf_mig$\KB916595\update\update.exe F:\WINDOWS\$hf_mig$\KB918118\update\update.exe F:\WINDOWS\$hf_mig$\KB918439\update\update.exe F:\WINDOWS\$hf_mig$\KB920213\update\update.exe F:\WINDOWS\$hf_mig$\KB920670\update\update.exe F:\WINDOWS\$hf_mig$\KB920683\update\update.exe F:\WINDOWS\$hf_mig$\KB920685\update\update.exe F:\WINDOWS\$hf_mig$\KB920872\update\update.exe F:\WINDOWS\$hf_mig$\KB922582\update\update.exe F:\WINDOWS\$hf_mig$\KB922819\update\update.exe F:\WINDOWS\$hf_mig$\KB923414\update\update.exe F:\WINDOWS\$hf_mig$\KB923561\update\update.exe F:\WINDOWS\$hf_mig$\KB923980\update\update.exe F:\WINDOWS\$hf_mig$\KB924270\update\update.exe F:\WINDOWS\$hf_mig$\KB925720\update\update.exe F:\WINDOWS\$hf_mig$\KB925902\update\update.exe F:\WINDOWS\$hf_mig$\KB926255\update\update.exe F:\WINDOWS\$hf_mig$\KB926436\update\update.exe F:\WINDOWS\$hf_mig$\KB927779\update\update.exe F:\WINDOWS\$hf_mig$\KB927802\update\update.exe F:\WINDOWS\$hf_mig$\KB927891\update\update.exe F:\WINDOWS\$hf_mig$\KB928255\update\update.exe F:\WINDOWS\$hf_mig$\KB928843\update\update.exe F:\WINDOWS\$hf_mig$\KB929123\update\update.exe F:\WINDOWS\$hf_mig$\KB930178\update\update.exe F:\WINDOWS\$hf_mig$\KB930916\update\update.exe F:\WINDOWS\$hf_mig$\KB931261\update\update.exe F:\WINDOWS\$hf_mig$\KB931784\update\update.exe F:\WINDOWS\$hf_mig$\KB932168\update\update.exe F:\WINDOWS\$hf_mig$\KB932823-v3\update\update.exe F:\WINDOWS\$hf_mig$\KB933729\update\update.exe F:\WINDOWS\$hf_mig$\KB935839\update\update.exe F:\WINDOWS\$hf_mig$\KB935840\update\update.exe F:\WINDOWS\$hf_mig$\KB936021\update\update.exe F:\WINDOWS\$hf_mig$\KB938127\update\update.exe F:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe F:\WINDOWS\$hf_mig$\KB938464\update\update.exe F:\WINDOWS\$hf_mig$\KB938828\update\update.exe F:\WINDOWS\$hf_mig$\KB941202\update\update.exe F:\WINDOWS\$hf_mig$\KB941644\update\update.exe F:\WINDOWS\$hf_mig$\KB941693\update\update.exe F:\WINDOWS\$hf_mig$\KB942763\update\update.exe F:\WINDOWS\$hf_mig$\KB943055\update\update.exe F:\WINDOWS\$hf_mig$\KB943460\update\update.exe F:\WINDOWS\$hf_mig$\KB943485\update\update.exe F:\WINDOWS\$hf_mig$\KB944338-v2\update\update.exe F:\WINDOWS\$hf_mig$\KB944653\update\update.exe F:\WINDOWS\$hf_mig$\KB945553\update\update.exe F:\WINDOWS\$hf_mig$\KB946026\update\update.exe F:\WINDOWS\$hf_mig$\KB946648\update\update.exe F:\WINDOWS\$hf_mig$\KB948590\update\update.exe F:\WINDOWS\$hf_mig$\KB950749\update\update.exe F:\WINDOWS\$hf_mig$\KB950759-IE7\update\update.exe F:\WINDOWS\$hf_mig$\KB950760\update\update.exe F:\WINDOWS\$hf_mig$\KB950762\update\update.exe F:\WINDOWS\$hf_mig$\KB950974\update\update.exe F:\WINDOWS\$hf_mig$\KB951066\update\update.exe F:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe F:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe F:\WINDOWS\$hf_mig$\KB951698\update\update.exe F:\WINDOWS\$hf_mig$\KB951748\update\update.exe F:\WINDOWS\$hf_mig$\KB952004\update\update.exe F:\WINDOWS\$hf_mig$\KB952287\update\update.exe F:\WINDOWS\$hf_mig$\KB952954\update\update.exe F:\WINDOWS\$hf_mig$\KB953838-IE7\update\update.exe F:\WINDOWS\$hf_mig$\KB953839\update\update.exe F:\WINDOWS\$hf_mig$\KB954211\update\update.exe F:\WINDOWS\$hf_mig$\KB954600\update\update.exe F:\WINDOWS\$hf_mig$\KB955069\update\update.exe F:\WINDOWS\$hf_mig$\KB955839\update\update.exe F:\WINDOWS\$hf_mig$\KB956391\update\update.exe F:\WINDOWS\$hf_mig$\KB956572\update\update.exe F:\WINDOWS\$hf_mig$\KB956802\update\update.exe F:\WINDOWS\$hf_mig$\KB956803\update\update.exe F:\WINDOWS\$hf_mig$\KB956841\update\update.exe F:\WINDOWS\$hf_mig$\KB957095\update\update.exe F:\WINDOWS\$hf_mig$\KB957097\update\update.exe F:\WINDOWS\$hf_mig$\KB958215\update\update.exe F:\WINDOWS\$hf_mig$\KB958644\update\update.exe F:\WINDOWS\$hf_mig$\KB958687\update\update.exe F:\WINDOWS\$hf_mig$\KB958690\update\update.exe F:\WINDOWS\$hf_mig$\KB959426\update\update.exe F:\WINDOWS\$hf_mig$\KB960225\update\update.exe F:\WINDOWS\$hf_mig$\KB960714\update\update.exe F:\WINDOWS\$hf_mig$\KB960715\update\update.exe F:\WINDOWS\$hf_mig$\KB960803\update\update.exe F:\WINDOWS\$hf_mig$\KB961118\update\update.exe F:\WINDOWS\$hf_mig$\KB961373\update\update.exe F:\WINDOWS\$hf_mig$\KB963027\update\update.exe F:\WINDOWS\$hf_mig$\KB967715\update\update.exe F:\WINDOWS\$NtUninstallKB873339$\update.exe F:\WINDOWS\$NtUninstallKB885835$\update.exe F:\WINDOWS\$NtUninstallKB885836$\update.exe F:\WINDOWS\$NtUninstallKB886185$\update.exe F:\WINDOWS\$NtUninstallKB888302$\update.exe F:\WINDOWS\$NtUninstallKB890046$\update.exe F:\WINDOWS\$NtUninstallKB890859$\update.exe F:\WINDOWS\$NtUninstallKB891781$\update.exe F:\WINDOWS\$NtUninstallKB893756$\update.exe F:\WINDOWS\$NtUninstallKB894391$\update.exe F:\WINDOWS\$NtUninstallKB896358$\update.exe F:\WINDOWS\$NtUninstallKB896423$\update.exe F:\WINDOWS\$NtUninstallKB896428$\update.exe F:\WINDOWS\$NtUninstallKB899587$\update.exe F:\WINDOWS\$NtUninstallKB899591$\update.exe F:\WINDOWS\$NtUninstallKB900485$\update.exe F:\WINDOWS\$NtUninstallKB900725$\update.exe F:\WINDOWS\$NtUninstallKB901017$\update.exe F:\WINDOWS\$NtUninstallKB901214$\update.exe F:\WINDOWS\$NtUninstallKB902400$\update.exe F:\WINDOWS\$NtUninstallKB904942$\update.exe F:\WINDOWS\$NtUninstallKB905414$\update.exe F:\WINDOWS\$NtUninstallKB905749$\update.exe F:\WINDOWS\$NtUninstallKB908519$\update.exe F:\WINDOWS\$NtUninstallKB908531$\update.exe F:\WINDOWS\$NtUninstallKB910437$\update.exe F:\WINDOWS\$NtUninstallKB911280$\update.exe F:\WINDOWS\$NtUninstallKB911562$\update.exe F:\WINDOWS\$NtUninstallKB911927$\update.exe F:\WINDOWS\$NtUninstallKB913580$\update.exe F:\WINDOWS\$NtUninstallKB914388$\update.exe F:\WINDOWS\$NtUninstallKB914389$\update.exe F:\WINDOWS\$NtUninstallKB915865$\update.exe F:\WINDOWS\$NtUninstallKB916595$\update.exe F:\WINDOWS\$NtUninstallKB918118$\update.exe F:\WINDOWS\$NtUninstallKB918439$\update.exe F:\WINDOWS\$NtUninstallKB920670$\update.exe F:\WINDOWS\$NtUninstallKB920683$\update.exe F:\WINDOWS\$NtUninstallKB920685$\update.exe F:\WINDOWS\$NtUninstallKB920872$\update.exe F:\WINDOWS\$NtUninstallKB922582$\update.exe F:\WINDOWS\$NtUninstallKB923980$\update.exe F:\WINDOWS\$NtUninstallKB924270$\update.exe F:\WINDOWS\$NtUninstallKB925720$\update.exe F:\WINDOWS\$NtUninstallKB925902$\update.exe F:\WINDOWS\$NtUninstallKB926255$\update.exe F:\WINDOWS\$NtUninstallKB926436$\update.exe F:\WINDOWS\$NtUninstallKB927779$\update.exe F:\WINDOWS\$NtUninstallKB927802$\update.exe F:\WINDOWS\$NtUninstallKB928255$\update.exe F:\WINDOWS\$NtUninstallKB928843$\update.exe F:\WINDOWS\$NtUninstallKB929123$\update.exe F:\WINDOWS\$NtUninstallKB930178$\update.exe F:\WINDOWS\$NtUninstallKB930916$\update.exe F:\WINDOWS\$NtUninstallKB931261$\update.exe F:\WINDOWS\$NtUninstallKB932823-v3$\update.exe F:\WINDOWS\$NtUninstallKB935839$\update.exe F:\WINDOWS\$NtUninstallKB935840$\update.exe F:\WINDOWS\$NtUninstallKB938464$\update.exe F:\WINDOWS\$NtUninstallKB943055$\update.exe F:\WINDOWS\$NtUninstallKB943485$\update.exe F:\WINDOWS\$NtUninstallKB944653$\update.exe F:\WINDOWS\$NtUninstallKB945553$\update.exe F:\WINDOWS\$NtUninstallKB946026$\update.exe F:\WINDOWS\$NtUninstallKB950749$\update.exe F:\WINDOWS\$NtUninstallKB950762$\update.exe F:\WINDOWS\$NtUninstallKB950974$\update.exe F:\WINDOWS\$NtUninstallKB951066$\update.exe F:\WINDOWS\$NtUninstallKB951376-v2$\update.exe F:\WINDOWS\$NtUninstallKB951698$\update.exe F:\WINDOWS\$NtUninstallKB951748$\update.exe F:\WINDOWS\$NtUninstallKB952287$\update.exe F:\WINDOWS\$NtUninstallKB952954$\update.exe F:\WINDOWS\SoftwareDistribution\Download\074c3fbb87eb1081867606c573826739\update\update.exe F:\WINDOWS\SoftwareDistribution\Download\2355f18161c4d9205abb66936b92cf18\update\update.exe F:\WINDOWS\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\update\update.exe F:\WINDOWS\SoftwareDistribution\Download\a37a907ce729d9b027006f974e62dcad\update\update.exe F:\WINDOWS\SoftwareDistribution\Download\d43a20c40794c502928d4b7d8ff0ea20\update\update.exe F:\WINDOWS\SoftwareDistribution\Download\e9a7a6846a2553591a8aa92d2f6f48fd\update\update.exe F:\WINDOWS\SoftwareDistribution\Download\f61bf99964e2e43c23df7037c527a203\update\update.exe F:\WINDOWS\system32\dllcache\register.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\clamscan.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\ClamTray.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\ClamWin.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\freshclam.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\OlAddin.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\sigtool.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\ClamWin\App\ClamWin\bin\WClose.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\Firefox\App\Firefox\uninstall\helper.exe G:\Downloads\Liberty Ultimate 4.3 FR\LiberKey\Apps\Thunderbird\App\thunderbird\uninstall\helper.exe G:\Program Files\Power Screen Capture\mvc.exe ################################### [ Cracks / Keygens / Serials ] C:\keygen.exe ################## [ ! End of Report # FindyKill V4.728 ! ]
  4. Rien n'y fait, j'ai beau relancer windows, et chaque fois j'ai la même fenêtre et antivir ne s'installe pas.
  5. J'ai télechargé antivir, mais j'ai une fenêtre qui s'ouvre avec : la création de certains fichiers a écoué. ?????
  6. Bonjour Depuis ce matin, il m'est impossible de lancer Avast, CCleaner et a-squarred. Que faire ? Voici un rapport ############################## [ FindyKill V4.728 ] # User : mesureux (Administrateurs) # MESUREUX-9A93E3 # Update on 13/05/09 by Chiquitine29 # Start at: 14:06:16 | 15/05/2009 # Website : http://pagesperso-orange.fr/NosTools/findykill.html # AMD Athlon 64 X2 Dual Core Processor 4400+ # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2 # Internet Explorer 6.0.2900.2180 # Windows Firewall Status : Enabled # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ] # FW : ActiveArmor Firewall[ (!) Disabled ]1.0 # A:\ # Lecteur de disquettes 3 ½ pouces # C:\ # Disque fixe local # 221.62 Go (139.27 Go free) [VIDEOS] # NTFS # E:\ # Disque fixe local # 76.67 Go (62.54 Go free) [DONNÉES] # FAT32 # F:\ # Disque fixe local # 244.14 Go (195.42 Go free) [PROGRAMMES] # NTFS # G:\ # Disque fixe local # 149.01 Go (97.64 Go free) [DIVERS] # FAT32 # I:\ # Disque CD-ROM ############################## [ Processus actifs ] F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\csrss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe F:\Program Files\AskBarDis\bar\bin\AskService.exe F:\Program Files\Bonjour\mDNSResponder.exe F:\WINDOWS\system32\svchost.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\Java\jre6\bin\jqs.exe F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe F:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\Installer\MSI38.tmp F:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp139.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\TUProgSt.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe F:\WINDOWS\system32\wbem\wmiapsrv.exe F:\WINDOWS\Explorer.EXE F:\WINDOWS\system32\RUNDLL32.EXE F:\Program Files\EasySearch\SiteVacuumClient.exe F:\WINDOWS\system32\rundll32.exe F:\WINDOWS\system32\ctfmon.exe F:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe F:\Program Files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe F:\Program Files\SeekappSrch\seekapp.exe F:\Documents and Settings\mesureux\Application Data\m\flec006.exe F:\Program Files\Internet Explorer\IEXPLORE.EXE F:\WINDOWS\system32\wintems.exe F:\WINDOWS\system32\wbem\wmiprvse.exe ################## [ Processus infectieux stoppés ] "F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe" (2148) "F:\Documents and Settings\mesureux\Application Data\m\flec006.exe" (3668) "F:\WINDOWS\system32\wintems.exe" (2520) ################## [ Fichiers / Dossiers infectieux ] Found ! F:\WINDOWS\Prefetch\128843.EXE-0F118BD7.pf Found ! F:\WINDOWS\Prefetch\202578.EXE-0E75C25E.pf Found ! F:\WINDOWS\Prefetch\204406.EXE-24870BE4.pf Found ! F:\WINDOWS\Prefetch\206015.EXE-2D956575.pf Found ! F:\WINDOWS\Prefetch\207828.EXE-02256382.pf Found ! F:\WINDOWS\Prefetch\211765.EXE-344DFE93.pf Found ! F:\WINDOWS\Prefetch\217281.EXE-3B5A1E03.pf Found ! F:\WINDOWS\Prefetch\221187.EXE-16EC5943.pf Found ! F:\WINDOWS\Prefetch\222953.EXE-34E16EF5.pf Found ! F:\WINDOWS\Prefetch\236125.EXE-11F886D0.pf Found ! F:\WINDOWS\Prefetch\243078.EXE-2B9F4F36.pf Found ! F:\WINDOWS\Prefetch\500046.EXE-01E4D544.pf Found ! F:\WINDOWS\Prefetch\518468.EXE-31CE2063.pf Found ! F:\WINDOWS\Prefetch\94109.EXE-1C835C15.pf Found ! F:\WINDOWS\Prefetch\95062.EXE-0148ED0B.pf Found ! F:\WINDOWS\Prefetch\96921.EXE-26936B39.pf Found ! F:\WINDOWS\Prefetch\FLEC006.EXE-13C5958A.pf Found ! F:\WINDOWS\Prefetch\MDELK.EXE-0EF461CE.pf Found ! F:\WINDOWS\Prefetch\WINTEMS.EXE-377E42D4.pf Found ! F:\WINDOWS\system32\ban_list.txt Found ! F:\WINDOWS\system32\mdelk.exe Found ! F:\WINDOWS\system32\wintems.exe Found ! "F:\Documents and Settings\mesureux\Application Data\drivers" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\downld" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\srosa2.sys" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\wfsintwq.sys" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe" Found ! "F:\Documents and Settings\mesureux\Application Data\m" Found ! "F:\Documents and Settings\mesureux\Application Data\m\data.oct" Found ! "F:\Documents and Settings\mesureux\Application Data\m\flec006.exe" Found ! "F:\Documents and Settings\mesureux\Application Data\m\list.oct" Found ! "F:\Documents and Settings\mesureux\Application Data\m\shared" Found ! "F:\Documents and Settings\mesureux\Application Data\m\srvlist.oct" ################## [ Infected Temp Files ] Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_6[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\file[1].txt Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\ieps[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[3].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[4].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[5].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_6[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\servernames[1].htm Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_1[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_6[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_6[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\file[1].txt Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_1[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_6[1].jpg ################## [ Registre / Clés infectieuses ] Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\Droppix_Label_Maker_2.8.5_(Key+Serial) Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\hldrrr Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\install_patch Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\key_gen Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\mdelk Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\msnmsgr Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\nideiect Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\winfilse Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\bisoft Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\DateTime4 Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\FFC Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\MuleAppData Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Droppix_Label_Maker_2.8.5_(Key+Serial) Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\hldrrr Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\install_patch Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\key_gen Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\mdelk Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\nideiect Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S Found ! HKEY_CURRENT_USER\Software\bisoft Found ! HKEY_CURRENT_USER\Software\DateTime4 Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit" Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit" Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe" Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe" Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key" Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key" # (!) HKLM\SYSTEM\...\Services\srosa -> Start = 0x1 # (!) HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1 ################## [ Recherche dans supports amovibles] Found ! C:\InfoSat.txt ################## [ Registre / Mountpoints2 ] # -> Not found ! ################## [ ! Fin du rapport # FindyKill V4.728 ! ]
  7. Bonjour Voici le rapport : ############################## [ FindyKill V4.728 ] # User : mesureux (Administrateurs) # MESUREUX-9A93E3 # Update on 13/05/09 by Chiquitine29 # Start at: 14:06:16 | 15/05/2009 # Website : http://pagesperso-orange.fr/NosTools/findykill.html # AMD Athlon 64 X2 Dual Core Processor 4400+ # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2 # Internet Explorer 6.0.2900.2180 # Windows Firewall Status : Enabled # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ] # FW : ActiveArmor Firewall[ (!) Disabled ]1.0 # A:\ # Lecteur de disquettes 3 ½ pouces # C:\ # Disque fixe local # 221.62 Go (139.27 Go free) [VIDEOS] # NTFS # E:\ # Disque fixe local # 76.67 Go (62.54 Go free) [DONNÉES] # FAT32 # F:\ # Disque fixe local # 244.14 Go (195.42 Go free) [PROGRAMMES] # NTFS # G:\ # Disque fixe local # 149.01 Go (97.64 Go free) [DIVERS] # FAT32 # I:\ # Disque CD-ROM ############################## [ Processus actifs ] F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\csrss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe F:\Program Files\AskBarDis\bar\bin\AskService.exe F:\Program Files\Bonjour\mDNSResponder.exe F:\WINDOWS\system32\svchost.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\Java\jre6\bin\jqs.exe F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe F:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\Installer\MSI38.tmp F:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp139.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\TUProgSt.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe F:\WINDOWS\system32\wbem\wmiapsrv.exe F:\WINDOWS\Explorer.EXE F:\WINDOWS\system32\RUNDLL32.EXE F:\Program Files\EasySearch\SiteVacuumClient.exe F:\WINDOWS\system32\rundll32.exe F:\WINDOWS\system32\ctfmon.exe F:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe F:\Program Files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe F:\Program Files\SeekappSrch\seekapp.exe F:\Documents and Settings\mesureux\Application Data\m\flec006.exe F:\Program Files\Internet Explorer\IEXPLORE.EXE F:\WINDOWS\system32\wintems.exe F:\WINDOWS\system32\wbem\wmiprvse.exe ################## [ Processus infectieux stoppés ] "F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe" (2148) "F:\Documents and Settings\mesureux\Application Data\m\flec006.exe" (3668) "F:\WINDOWS\system32\wintems.exe" (2520) ################## [ Fichiers / Dossiers infectieux ] Found ! F:\WINDOWS\Prefetch\128843.EXE-0F118BD7.pf Found ! F:\WINDOWS\Prefetch\202578.EXE-0E75C25E.pf Found ! F:\WINDOWS\Prefetch\204406.EXE-24870BE4.pf Found ! F:\WINDOWS\Prefetch\206015.EXE-2D956575.pf Found ! F:\WINDOWS\Prefetch\207828.EXE-02256382.pf Found ! F:\WINDOWS\Prefetch\211765.EXE-344DFE93.pf Found ! F:\WINDOWS\Prefetch\217281.EXE-3B5A1E03.pf Found ! F:\WINDOWS\Prefetch\221187.EXE-16EC5943.pf Found ! F:\WINDOWS\Prefetch\222953.EXE-34E16EF5.pf Found ! F:\WINDOWS\Prefetch\236125.EXE-11F886D0.pf Found ! F:\WINDOWS\Prefetch\243078.EXE-2B9F4F36.pf Found ! F:\WINDOWS\Prefetch\500046.EXE-01E4D544.pf Found ! F:\WINDOWS\Prefetch\518468.EXE-31CE2063.pf Found ! F:\WINDOWS\Prefetch\94109.EXE-1C835C15.pf Found ! F:\WINDOWS\Prefetch\95062.EXE-0148ED0B.pf Found ! F:\WINDOWS\Prefetch\96921.EXE-26936B39.pf Found ! F:\WINDOWS\Prefetch\FLEC006.EXE-13C5958A.pf Found ! F:\WINDOWS\Prefetch\MDELK.EXE-0EF461CE.pf Found ! F:\WINDOWS\Prefetch\WINTEMS.EXE-377E42D4.pf Found ! F:\WINDOWS\system32\ban_list.txt Found ! F:\WINDOWS\system32\mdelk.exe Found ! F:\WINDOWS\system32\wintems.exe Found ! "F:\Documents and Settings\mesureux\Application Data\drivers" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\downld" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\srosa2.sys" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\wfsintwq.sys" Found ! "F:\Documents and Settings\mesureux\Application Data\drivers\winupgro.exe" Found ! "F:\Documents and Settings\mesureux\Application Data\m" Found ! "F:\Documents and Settings\mesureux\Application Data\m\data.oct" Found ! "F:\Documents and Settings\mesureux\Application Data\m\flec006.exe" Found ! "F:\Documents and Settings\mesureux\Application Data\m\list.oct" Found ! "F:\Documents and Settings\mesureux\Application Data\m\shared" Found ! "F:\Documents and Settings\mesureux\Application Data\m\srvlist.oct" ################## [ Infected Temp Files ] Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\b64_6[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\file[1].txt Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\01234567\ieps[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[3].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[4].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64[5].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\b64_6[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\4XQ3OLUR\servernames[1].htm Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_1[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_6[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\b64_6[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\JWRV2OSZ\file[1].txt Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_1[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_1[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_3[1].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_3[2].jpg Found ! F:\Documents and Settings\mesureux\Local Settings\Temporary Internet Files\Content.IE5\U9QRE701\b64_6[1].jpg ################## [ Registre / Clés infectieuses ] Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\Droppix_Label_Maker_2.8.5_(Key+Serial) Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\hldrrr Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\install_patch Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\key_gen Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\mdelk Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\msnmsgr Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\nideiect Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\winfilse Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\bisoft Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\DateTime4 Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\FFC Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\MuleAppData Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Droppix_Label_Maker_2.8.5_(Key+Serial) Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\hldrrr Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\install_patch Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\key_gen Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\mdelk Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\nideiect Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S Found ! HKEY_CURRENT_USER\Software\bisoft Found ! HKEY_CURRENT_USER\Software\DateTime4 Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit" Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit" Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe" Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe" Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key" Found ! HKEY_USERS\S-1-5-21-1708537768-1844823847-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key" # (!) HKLM\SYSTEM\...\Services\srosa -> Start = 0x1 # (!) HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1 ################## [ Recherche dans supports amovibles] Found ! C:\InfoSat.txt ################## [ Registre / Mountpoints2 ] # -> Not found ! ################## [ ! Fin du rapport # FindyKill V4.728 ! ]
  8. Bonjour Lorsque je veux lancer avast j'ai le message suivant : ashAvast.exe n'est pas une application Win32 valide. Que doi-je faire ? Merci d'avance
  9. Bonjour Je viens d'acquérier un lecteur enregistreur DVD Samsung DVD-SH875. Je reçois la télé avec un tuner adsl de chez orange. Comment faire pour réaliser la connexion de l'ensemble. La notice du tuner orange et la notice du lecteur sont pas explicite même contradictoire. Si je me sers d'une multi prise péritel (2 entrées) comment faire cette connexion ? Merci d'avance.
  10. Merci je vais imprimer pour le décodeur que j'ai. Cordialement
  11. Merci pour la réponse, mais le hic est que je ne retrouve plus le manuel du décodeur. Cordialement
  12. Bonjour Je ne sais pas si ma question est dans le bon forum, mais je voudrais raccorder une décodeur adsl orange avec un lecteur enregistreur de DVD avec tuner tnt intégré et une téle. Merci d'avance. Cordialement
  13. restanco

    Problème écran

    Chose bizarre, mlais après une bonne nuit de sommeil de l'ordi, ce matin tout est rtentré dans l'ordre. Bizarre.
  14. restanco

    Problème écran

    Bonsoir Je viens d'allumer mon ordi est j'ai l'affichage de l'écran qui est décalé vers le haut. J'ai l'icône de ma corbeille qui est coupé en deux, le bas de la corbeille est en haut de l'écran et le haut de la corbeille se trouve sous la bande "démarrer". Que faire ? Merci d'avance.
  15. J'attendrais d'avoir ie8 pour essayer de l'installer, mais pour l'instant ce n'est qu'une version béta.
  16. C'est le risque car ie7 ne s'installe pas correctement et me bloque l'accès à internet, je suis obligé de passer par firefox qui ne me plaît pas.
  17. Bonjour J'ai réinstallé ie6 et tout fonctionne normalement maintenant. Merci pour le dépannage. Cordialement
  18. Re J'ai voulu faire une restauration et il est impossible de faire une restauration à la date indiquée.
  19. Re bonjour J'ai voulu installer ie7 et maintenant je n'ai plus accès à internet explorer après avoir désinstaller l'ancienne version. Pourquoi ? Merci d'avance.
  20. Bonjour Voici le nouveau rapport Hijackthis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:45:49, on 21/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe F:\Program Files\a-squared Free\a2service.exe F:\WINDOWS\Explorer.EXE F:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe F:\Program Files\Bonjour\mDNSResponder.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\WINDOWS\System32\FTRTSVC.exe F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe F:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe F:\WINDOWS\system32\nvsvc32.exe G:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe F:\WINDOWS\system32\svchost.exe g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe F:\WINDOWS\system32\RUNDLL32.EXE F:\Program Files\Analog Devices\Core\smax4pnp.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe F:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe F:\WINDOWS\system32\ctfmon.exe F:\Program Files\MSN Messenger\msnmsgr.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe F:\Program Files\Logitech\SetPoint\SetPoint.exe F:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe F:\Program Files\TruDirect\TruDirectTray.exe F:\Program Files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe F:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE F:\Program Files\MSN Messenger\usnsvc.exe G:\Downloads\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file) O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - F:\Program Files\IEPro\iepro.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file) O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DefragTaskBar] "g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [soundMAXPnP] F:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [avgnt] "F:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [iSUSScheduler] "F:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: TMMonitor.lnk = F:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe O4 - Global Startup: TruDirectTray.lnk = F:\Program Files\TruDirect\TruDirectTray.exe O4 - Global Startup: WL-8316 Configuration Utility.lnk = F:\Program Files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/e/37.09/Hbo...o/uploader2.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichier...ion_3_0_3_0.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - F:\Program Files\a-squared Free\a2service.exe O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - F:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - F:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Droppix Service - Droppix - F:\Program Files\Fichiers communs\Droppix\DxService.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - F:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - F:\WINDOWS\System32\FTRTSVC.exe O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - F:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - F:\WINDOWS\system32\drivers\pclepci.sys O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Unknown owner - F:\Program Files\Fichiers communs\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (file missing) -- End of file - 11453 bytes D'autre part je vais installer ie7. Bonne journée
  21. Bonjour Voici le rapport HijackThis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:13:40, on 20/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe F:\Program Files\a-squared Free\a2service.exe F:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe F:\Program Files\Bonjour\mDNSResponder.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe F:\WINDOWS\System32\FTRTSVC.exe F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe F:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\Explorer.EXE F:\WINDOWS\system32\svchost.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe G:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe F:\WINDOWS\system32\RUNDLL32.EXE F:\Program Files\Analog Devices\Core\smax4pnp.exe F:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe F:\WINDOWS\system32\ctfmon.exe F:\Program Files\MSN Messenger\msnmsgr.exe F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe F:\Program Files\Logitech\SetPoint\SetPoint.exe F:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe F:\Program Files\TruDirect\TruDirectTray.exe F:\Program Files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe F:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE F:\Program Files\MSN Messenger\usnsvc.exe F:\Program Files\eMule\emule.exe G:\Downloads\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file) O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - F:\Program Files\IEPro\iepro.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file) O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DefragTaskBar] "g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [soundMAXPnP] F:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [avgnt] "F:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [iSUSScheduler] "F:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: TMMonitor.lnk = F:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe O4 - Global Startup: TruDirectTray.lnk = F:\Program Files\TruDirect\TruDirectTray.exe O4 - Global Startup: WL-8316 Configuration Utility.lnk = F:\Program Files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/e/37.09/Hbo...o/uploader2.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichier...ion_3_0_3_0.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - F:\Program Files\a-squared Free\a2service.exe O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - F:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - F:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - g:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Droppix Service - Droppix - F:\Program Files\Fichiers communs\Droppix\DxService.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - F:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - F:\WINDOWS\System32\FTRTSVC.exe O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - F:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - F:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - F:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - F:\WINDOWS\system32\drivers\pclepci.sys O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Unknown owner - F:\Program Files\Fichiers communs\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (file missing) -- End of file - 11555 bytes Bonne journée.
  22. Voici le rapport d'antivir : Avira AntiVir Personal Report file date: mercredi 19 novembre 2008 12:02 Scanning for 1040492 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: MESUREUX-9A93E3 Version information: BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00 AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 09:57:53 AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40 LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19 LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 16:52:41 ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 16:52:44 ANTIVIR2.VDF : 7.1.0.89 221184 Bytes 16/11/2008 16:52:46 ANTIVIR3.VDF : 7.1.0.104 80384 Bytes 18/11/2008 16:52:48 Engineversion : 8.2.0.34 AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 11:05:56 AESCRIPT.DLL : 8.1.1.15 332156 Bytes 18/11/2008 16:53:04 AESCN.DLL : 8.1.1.5 123251 Bytes 18/11/2008 16:53:02 AERDL.DLL : 8.1.1.3 438645 Bytes 18/11/2008 16:53:01 AEPACK.DLL : 8.1.3.4 393591 Bytes 18/11/2008 16:52:59 AEOFFICE.DLL : 8.1.0.30 196986 Bytes 18/11/2008 16:52:57 AEHEUR.DLL : 8.1.0.71 1487222 Bytes 18/11/2008 16:52:56 AEHELP.DLL : 8.1.2.0 119159 Bytes 18/11/2008 16:52:52 AEGEN.DLL : 8.1.1.4 319861 Bytes 18/11/2008 16:52:51 AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 11:05:56 AECORE.DLL : 8.1.5.0 172407 Bytes 18/11/2008 16:52:49 AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 11:05:56 AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05 AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01 AVREP.DLL : 8.0.0.2 98344 Bytes 18/11/2008 16:52:48 AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40 AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23 AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49 SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02 SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40 NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10 RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07 RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: f:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, E:, F:, G:, Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: mercredi 19 novembre 2008 12:02 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'usnsvc.exe' - '1' Module(s) have been scanned Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned Scan process 'WL-8316 Configuration Utility.exe' - '1' Module(s) have been scanned Scan process 'TruDirectTray.exe' - '1' Module(s) have been scanned Scan process 'TMMonitor.exe' - '1' Module(s) have been scanned Scan process 'SetPoint.exe' - '1' Module(s) have been scanned Scan process 'LogitechDesktopMessenger.exe' - '1' Module(s) have been scanned Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'defragTaskBar.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'nSvcIp.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned Scan process 'defragActivityMonitor.exe' - '1' Module(s) have been scanned Scan process 'nSvcLog.exe' - '1' Module(s) have been scanned Scan process 'Apache.exe' - '1' Module(s) have been scanned Scan process 'NBService.exe' - '1' Module(s) have been scanned Scan process 'MDM.EXE' - '1' Module(s) have been scanned Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned Scan process 'Apache.exe' - '1' Module(s) have been scanned Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned Scan process 'aDefragService.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'a2service.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 44 processes with 44 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Master boot sector HD1 [iNFO] No virus was found! Master boot sector HD2 [iNFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Boot sector 'E:\' [iNFO] No virus was found! Boot sector 'F:\' [iNFO] No virus was found! Boot sector 'G:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '74' files ). Starting the file scan: Begin scan in 'C:\' <VIDEOS> Begin scan in 'E:\' <DONNÉES> E:\System Volume Information\_restore{151BD613-ADE3-40C9-A6AB-40FEECC7C4DF}\RP2\A0000090.exe [DETECTION] Contains HEUR/Crypted suspicious code [NOTE] The file was moved to '4953f5c0.qua'! E:\System Volume Information\_restore{151BD613-ADE3-40C9-A6AB-40FEECC7C4DF}\RP2\A0000091.exe [0] Archive type: RAR SFX (self extracting) --> TopRank.exe [DETECTION] Is the TR/Buzus.xuu Trojan [NOTE] The file was moved to '4953f5c1.qua'! Begin scan in 'F:\' <PROGRAMMES> F:\pagefile.sys [WARNING] The file could not be opened! Begin scan in 'G:\' <DIVERS> G:\System Volume Information\_restore{151BD613-ADE3-40C9-A6AB-40FEECC7C4DF}\RP2\A0000089.exe [0] Archive type: ZIP SFX (self extracting) --> Mosaic - Tomb of Mystery Deluxe\mosaictombofmystery.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was moved to '49540e75.qua'! End of the scan: mercredi 19 novembre 2008 14:15 Used time: 2:13:33 Hour(s) The scan has been done completely. 18829 Scanning directories 1117346 Files were scanned 2 viruses and/or unwanted programs were found 1 Files were classified as suspicious: 0 files were deleted 0 files were repaired 3 files were moved to quarantine 0 files were renamed 1 Files cannot be scanned 1117342 Files not concerned 15490 Archives were scanned 1 Warnings 3 Notes Je veux bien url Merci et bonne soirée
  23. Ok je vais le faire. Que pense tu de antivir par rapport à avast ? Je ne t'envoies pas le rapport après antivir ? Merci du dépannage.
  24. Je n'ai pas le logo fites glisser cfscript sur combofix, mais je pense que cela a fonctionné, voici le nouveau comboFix.txt : ComboFix 08-11-18.05 - mesureux 2008-11-19 10:42:21.3 - NTFSx86 Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2529 [GMT 1:00] Lancé depuis: f:\documents and settings\mesureux\Bureau\ComboFix.exe Commutateurs utilisés :: f:\documents and settings\mesureux\Bureau\CFScript.txt * Un nouveau point de restauration a été créé FILE :: f:\windows\system32\drivers\srosa2.sys . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . f:\windows\system32\drivers\srosa2.sys . ((((((((((((((((((((((((((((((((((((((( Pilotes/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ASWSP -------\Legacy_SETUPNTGLM7X -------\Legacy_SK9OU0S -------\Service_aswSP -------\Service_SetupNTGLM7X -------\Service_sK9Ou0s ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-19 au 2008-11-19 )))))))))))))))))))))))))))))))))))) . 2008-11-18 23:06 . 2008-11-18 23:09 <REP> d-------- f:\windows\system32\NtmsData 2008-11-18 17:45 . 2008-11-18 17:45 <REP> d-------- f:\program files\Avira 2008-11-18 17:45 . 2008-11-18 17:45 <REP> d-------- f:\documents and settings\All Users\Application Data\Avira 2008-11-18 17:25 . 2006-03-02 13:00 13,463,552 --a--c--- f:\windows\system32\dllcache\hwxjpn.dll 2008-11-18 17:24 . 2004-05-13 00:39 876,653 --a--c--- f:\windows\system32\dllcache\fp4awel.dll 2008-11-18 17:23 . 2008-11-18 17:23 488 -rah----- f:\windows\system32\logonui.exe.manifest 2008-11-18 17:22 . 2008-11-18 17:22 749 -rah----- f:\windows\WindowsShell.Manifest 2008-11-18 17:22 . 2008-11-18 17:22 749 -rah----- f:\windows\system32\wuaucpl.cpl.manifest 2008-11-18 17:22 . 2008-11-18 17:22 749 -rah----- f:\windows\system32\sapi.cpl.manifest 2008-11-18 17:22 . 2008-11-18 17:22 749 -rah----- f:\windows\system32\ncpa.cpl.manifest 2008-11-18 17:13 . 2008-11-18 17:32 <REP> d-------- f:\windows\NV860348.TMP 2008-11-18 16:54 . 2006-03-02 13:00 24,661 --a------ f:\windows\system32\spxcoins.dll 2008-11-18 16:54 . 2006-03-02 13:00 24,661 --a--c--- f:\windows\system32\dllcache\spxcoins.dll 2008-11-18 16:54 . 2006-03-02 13:00 13,312 --a------ f:\windows\system32\irclass.dll 2008-11-18 16:54 . 2006-03-02 13:00 13,312 --a--c--- f:\windows\system32\dllcache\irclass.dll 2008-11-18 10:33 . 2008-11-18 10:33 <REP> d-------- f:\program files\Alwil Software 2008-11-16 23:19 . 2008-11-16 23:19 <REP> d-------- f:\documents and settings\mesureux\Application Data\BHV 2008-11-15 18:13 . 2008-11-15 18:23 <REP> d-------- f:\documents and settings\mesureux\Application Data\PanoramaStudio 2008-11-15 18:12 . 2008-11-17 09:54 <REP> d-------- f:\program files\PanoramaStudio 2008-11-14 17:46 . 2008-11-14 17:46 <REP> d-------- f:\documents and settings\mesureux\Application Data\BSD Concept 2008-11-14 17:46 . 2008-11-14 17:46 <REP> d-------- f:\documents and settings\All Users\Application Data\BSD Concept 2008-11-14 17:46 . 2008-11-14 17:46 <REP> d-------- f:\documents and settings\All Users\Application Data\BSD 2008-11-14 14:40 . 2008-11-14 14:40 <REP> d-------- f:\windows\Recettes 2008-11-14 14:38 . 1999-03-03 05:01 212,440 --a------ f:\windows\system32\DBCLIENT.DLL 2008-11-14 14:38 . 1999-06-21 05:10 184,832 --a------ f:\windows\system32\BDEADMIN.CPL 2008-11-13 15:50 . 2008-11-13 15:50 0 --a------ f:\windows\~tmp.INI 2008-11-13 15:22 . 1998-07-30 07:24 192,784 --a------ f:\windows\system32\TABCTL32.OCX 2008-11-13 15:19 . 2008-11-13 15:19 <REP> d-------- f:\windows\system32\Adobe 2008-11-13 15:19 . 2008-11-13 15:19 <REP> d-------- f:\windows\Profiles 2008-11-13 15:19 . 2008-11-13 15:19 <REP> d-------- f:\documents and settings\mesureux\Application Data\InterTrust 2008-11-13 15:00 . 2008-11-13 15:00 20 --a------ f:\windows\SIERRA.INI 2008-11-10 13:57 . 2008-11-10 14:39 <REP> d-------- f:\program files\Web Publish 2008-11-10 13:57 . 2008-11-10 13:57 0 --a------ f:\windows\MSREGUSR.INI 2008-11-10 12:00 . 2008-11-10 12:00 21,840 --a------ f:\windows\system32\SIntfNT.dll 2008-11-10 12:00 . 2008-11-10 12:00 17,212 --a------ f:\windows\system32\SIntf32.dll 2008-11-10 12:00 . 2008-11-10 12:00 12,067 --a------ f:\windows\system32\SIntf16.dll 2008-11-09 23:21 . 2008-11-09 23:21 <REP> d-------- f:\program files\directx 2008-11-08 10:33 . 2008-11-08 10:33 <REP> d-------- f:\program files\Inter Each 2008-11-07 13:54 . 2008-11-07 13:54 <REP> d-------- f:\program files\Java 2008-11-05 21:33 . 2008-11-05 21:33 28,672 --a------ f:\windows\system32\coclean.exe 2008-11-05 09:30 . 2008-11-05 09:33 <REP> d-------- f:\windows\NV2241284.TMP 2008-11-05 09:29 . 2008-11-05 09:29 <REP> d-------- F:\NVIDIA 2008-11-04 23:21 . 2008-11-04 23:41 <REP> d-------- f:\windows\NV37163680.TMP 2008-11-04 23:20 . 2008-11-04 23:25 <REP> d-------- f:\windows\NV25563088.TMP 2008-11-04 17:00 . 2008-11-04 17:00 <REP> d-------- f:\windows\system32\AGEIA 2008-11-04 17:00 . 2008-11-04 17:00 <REP> d-------- f:\program files\AGEIA Technologies 2008-11-04 16:59 . 2008-11-04 17:02 <REP> d-------- f:\windows\NV25601196.TMP 2008-11-04 16:44 . 2008-11-04 16:44 <REP> d-------- f:\program files\SystemRequirementsLab 2008-11-03 14:43 . 2008-11-17 22:51 <REP> d-------- f:\program files\Avast4 2008-11-01 19:00 . 2008-11-01 20:49 <REP> d-------- f:\program files\Ontrack 2008-10-30 14:05 . 2008-10-30 14:05 <REP> d-------- f:\documents and settings\All Users\Application Data\MonteCristo 2008-10-25 09:19 . 2008-10-25 09:54 <REP> d-------- f:\program files\FileZilla 2008-10-23 16:21 . 2008-10-23 16:45 <REP> d-------- f:\documents and settings\mesureux\Application Data\FileZilla 2008-10-21 14:59 . 2002-02-18 17:40 6,200 --a------ f:\windows\system32\INT13EXT.VXD . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-18 17:44 --------- d-----w f:\program files\MSN Messenger 2008-11-18 16:57 --------- d-----w f:\documents and settings\mesureux\Application Data\Inter Each 2008-11-18 11:34 --------- d-----w f:\program files\a-squared Free 2008-11-18 08:11 --------- d-----w f:\program files\eMule 2008-11-17 18:03 --------- d-----w f:\program files\Fichiers communs\Adobe 2008-11-17 14:31 --------- d-----w f:\documents and settings\mesureux\Application Data\U3 2008-11-16 22:26 --------- d-----w f:\documents and settings\mesureux\Application Data\Généatique2009 2008-11-16 22:19 --------- d--h--w f:\program files\InstallShield Installation Information 2008-11-14 15:50 --------- d-----w f:\program files\Serials 2005 2008-11-13 14:22 --------- d-----w f:\program files\Micro Application 2008-11-06 21:58 --------- d-----w f:\documents and settings\All Users\Application Data\Drv Audio Dog About 2008-11-04 15:59 --------- d-----w f:\program files\Fichiers communs\Wise Installation Wizard 2008-11-04 08:29 --------- d-----w f:\program files\Malwarebytes' Anti-Malware 2008-10-30 13:22 74,752 ----a-w f:\windows\ST6UNST.EXE 2008-10-30 13:22 --------- d-----w f:\program files\Affranchissements 2008-10-29 17:19 --------- d-----w f:\documents and settings\All Users\Application Data\ashampoo 2008-10-25 08:08 --------- d-----w f:\program files\CuteFTP 2008-10-23 14:17 --------- d-----w f:\documents and settings\mesureux\Application Data\ComptaAsso 2008-10-22 15:10 38,496 ----a-w f:\windows\system32\drivers\mbamswissarmy.sys 2008-10-22 15:10 15,504 ----a-w f:\windows\system32\drivers\mbam.sys 2008-10-18 09:18 --------- d-----w f:\program files\Fichiers communs\Micro Application Shared 2008-10-18 08:47 --------- d-----w f:\documents and settings\All Users\Application Data\Micro Application 2008-10-17 12:43 --------- d-----w f:\documents and settings\mesureux\Application Data\APLI 2008-10-16 15:03 --------- d-----w f:\program files\Fichiers communs\ACD Systems 2008-10-14 21:21 --------- d-----w f:\program files\Common Files 2008-10-14 15:53 --------- d-----w f:\documents and settings\mesureux\Application Data\Uniblue 2008-10-14 15:53 --------- d-----w f:\documents and settings\All Users\Application Data\DriverScanner 2008-10-14 15:49 --------- d-----w f:\documents and settings\mesureux\Application Data\uTorrent 2008-10-14 15:46 --------- d-----w f:\program files\uTorrent 2008-10-07 12:33 6,133,856 ----a-w f:\windows\system32\drivers\nv4_mini.sys 2008-10-07 09:55 --------- d-----w f:\program files\Magellan 2008-10-04 15:04 --------- d-----w f:\program files\Smart Projects 2008-10-04 13:03 --------- d-----w f:\program files\Alcohol Soft 2008-10-04 11:42 717,296 ----a-w f:\windows\system32\drivers\sptd.sys 2008-10-04 11:42 --------- d-----w f:\documents and settings\mesureux\Application Data\DAEMON Tools 2008-10-03 14:10 --------- d-----w f:\program files\Unlocker 2008-10-02 12:32 --------- d-----w f:\program files\Logitech 2008-09-30 14:37 --------- d-----w f:\documents and settings\mesureux\Application Data\Nero 2008-09-30 14:33 --------- d-----w f:\program files\Fichiers communs\Nero 2008-09-30 14:24 --------- d-----w f:\program files\Nero 2008-09-30 14:23 --------- d-----w f:\program files\Windows Sidebar 2008-09-30 14:20 --------- d-----w f:\documents and settings\All Users\Application Data\Nero 2008-09-29 21:10 --------- d-----w f:\documents and settings\mesureux\Application Data\Smart PC Solutions 2008-09-29 21:09 --------- d-----w f:\program files\Smart PC Solutions 2008-09-22 09:22 --------- d-----w f:\documents and settings\mesureux\Application Data\Carnival Software 2008-09-21 07:57 --------- d-----w f:\program files\FastStone Image Viewer 2008-09-21 07:57 --------- d-----w f:\documents and settings\mesureux\Application Data\FastStone 2008-09-20 07:31 --------- d-----w f:\program files\StudioLine Web 2008-09-20 07:29 --------- d-----w f:\program files\StudioLine3 2008-09-11 21:02 694,800 ----a-w f:\windows\unins006.exe 2008-09-11 21:02 694,800 ----a-w f:\windows\unins005.exe 2008-09-11 21:02 694,800 ----a-w f:\windows\unins004.exe 2008-09-04 20:53 691,545 ----a-w f:\windows\unins003.exe 2008-08-24 15:35 91,744 ----a-w f:\windows\BPMNT.dll 2008-08-24 15:35 1,213,784 ----a-w f:\windows\vsapi32.dll 2008-08-24 15:05 71,749 ----a-w f:\windows\hcextoutput.dll 2008-08-24 15:05 333,576 ----a-w f:\windows\TSC.exe 2008-08-24 15:02 69,689 ----a-w f:\windows\UNZIP.DLL 2008-08-24 15:02 507,904 ----a-w f:\windows\TMUPDATE.DLL 2008-08-24 15:02 286,720 ----a-w f:\windows\PATCH.EXE 2008-08-21 19:33 676,871 ----a-w f:\windows\unins002.exe 2008-08-21 19:32 676,871 ----a-w f:\windows\unins001.exe 2008-08-21 19:32 676,871 ----a-w f:\windows\unins000.exe 2008-08-20 07:00 1,570,816 ----a-w f:\documents and settings\mesureux\Application Data\tsdnwin.dll . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="f:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-09-11 86960] "ctfmon.exe"="f:\windows\system32\ctfmon.exe" [2006-03-02 15360] "msnmsgr"="f:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "DefragTaskBar"="g:\program files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2008-10-09 173408] "Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "avast!"="f:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000] "NvMediaCenter"="f:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "SoundMAXPnP"="f:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352] "avgnt"="f:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "nwiz"="nwiz.exe" [2008-10-07 f:\windows\system32\nwiz.exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 f:\windows\KHALMNPR.Exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="f:\windows\system32\CTFMON.EXE" [2006-03-02 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "tscuninstall"="f:\windows\system32\tscupgrd.exe" [2006-03-02 44544] f:\documents and settings\mesureux\Menu D‚marrer\Programmes\D‚marrage\ Adobe Gamma.lnk - f:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-19 110592] f:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\ Adobe Gamma Loader.lnk - f:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-19 110592] Logitech Desktop Messenger.lnk - f:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-30 67128] Logitech SetPoint.lnk - f:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-31 805392] Microsoft Office.lnk - f:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360] TMMonitor.lnk - f:\program files\ArcSoft\TotalMedia 3\TMMonitor.exe [2008-09-10 249856] TruDirectTray.lnk - f:\program files\TruDirect\TruDirectTray.exe [2008-01-24 421888] WL-8316 Configuration Utility.lnk - f:\program files\PLANET\PLANET WL-8316\WL-8316 Configuration Utility.exe [2008-06-18 786432] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "NoDispSettingPage"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 01:42 72208 f:\program files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.ACDV"= ACDV.dll "vidc.mjpg"= pvmjpg30.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "f:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"= "f:\\Program Files\\Messenger\\msmsgs.exe"= "f:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"= "f:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"= "f:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"= "f:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"= "f:\\Program Files\\BitComet\\BitComet.exe"= "f:\\Program Files\\IEPro\\MiniDM.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "f:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "f:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "f:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"= "f:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"= "f:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"= "f:\\Program Files\\Bonjour\\mDNSResponder.exe"= "f:\\Program Files\\Smart PC Solutions\\Smart PC Suite\\SmartPCSuite.exe"= "g:\\Program Files\\Zattoo\\zattood.exe"= "g:\\Program Files\\Zattoo\\Zattoo2.exe"= "f:\\Program Files\\uTorrent\\uTorrent.exe"= "f:\\Program Files\\CuteFTP\\CUTFTP32.EXE"= "g:\\Program Files\\Zattoo\\Zattoo.exe"= "f:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "f:\\Program Files\\MSN Messenger\\livecall.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8744:TCP"= 8744:TCP:BitComet 8744 TCP "8744:UDP"= 8744:UDP:BitComet 8744 UDP "26748:TCP"= 26748:TCP:BitComet 26748 TCP "26748:UDP"= 26748:UDP:BitComet 26748 UDP "10753:TCP"= 10753:TCP:BitComet 10753 TCP "10753:UDP"= 10753:UDP:BitComet 10753 UDP "8443:TCP"= 8443:TCP:BitComet 8443 TCP "8443:UDP"= 8443:UDP:BitComet 8443 UDP "135:TCP"= 135:TCP:Port DCOM (135) R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;f:\program files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208] S2 aswFsBlk;aswFsBlk;f:\windows\system32\DRIVERS\aswFsBlk.sys [] S2 RoxLiveShare10;LiveShare P2P Server 10;"f:\program files\Fichiers communs\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" [] S2 UxTuneUp;Extension de conception TuneUp;f:\windows\System32\svchost.exe -k netsvcs [2006-03-02 14336] S3 Droppix Service;Droppix Service;"f:\program files\Fichiers communs\Droppix\DxService.exe" [2008-09-03 151552] S3 maconfservice;Ma-Config Service;"f:\program files\ma-config.com\maconfservice.exe" [2008-07-25 191656] S3 MBAMDrvService;MBAMDrvService;\??\f:\windows\system32\drivers\mbam.sys [2008-09-15 15504] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K] \Shell\AutoRun\command - K:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad650738-56fa-11dd-8307-001d601f2149}] \Shell\AutoRun\command - J:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d78917d8-416b-11dd-82ba-001d601f2149}] \Shell\AutoRun\command - J:\LaunchU3.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e107391c-6e88-11dd-a7e7-806d6172696f}] \Shell\AutoRun\command - D:\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e13e252c-7dbe-11dd-a810-001d601f2149}] \Shell\AutoRun\command - J:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f361946a-3dda-11dd-82a9-001d601f2149}] \Shell\AutoRun\command - J:\LaunchU3.exe -a [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "f:\program files\Fichiers communs\LightScribe\LSRunOnce.exe" . Contenu du dossier 'Tâches planifiées' 2008-11-19 f:\windows\Tasks\ACFA101E908D84A2.job - f:\docume~1\mesureux\applic~1\intere~1\Coolsaveokay.exe [] 2008-11-14 f:\windows\Tasks\Maintenance en 1 clic.job - f:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-01-17 13:47] 2008-09-30 f:\windows\Tasks\NeroLiveEpgUpdate-MESUREUX-9A93E3_mesureux.job - f:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 12:51] . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-19 10:48:43 Windows 5.1.2600 Service Pack 2 NTFS Recherche de processus cachés ... Recherche d'éléments en démarrage automatique cachés ... Recherche de fichiers cachés ... Scan terminé avec succès Fichiers cachés: 0 ************************************************************************** . ------------------------ Autres processus actifs ------------------------ . f:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe f:\program files\a-squared Free\a2service.exe f:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe g:\program files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe f:\program files\Bonjour\mDNSResponder.exe f:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe f:\windows\system32\FTRTSVC.exe f:\program files\Fichiers communs\LightScribe\LSSrvc.exe f:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE f:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe f:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe g:\program files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe f:\windows\system32\nvsvc32.exe f:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe f:\windows\system32\rundll32.exe f:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.exe f:\program files\MSN Messenger\usnsvc.exe . ************************************************************************** . Heure de fin: 2008-11-19 10:52:16 - La machine a redémarré ComboFix-quarantined-files.txt 2008-11-19 09:52:12 Avant-CF: 225 382 432 768 octets libres Après-CF: 225,383,759,872 octets libres 288 --- E O F --- 2008-09-21 07:47:11 Merci, et dis moi si c'est ok.
  25. Bonjour J'ai viré avast et pris antivir. Cela a l'air de bien fonctionner. Est ce nécessaire de faire ce que tu m'indiques. Cordialement.
×
×
  • Créer...