

François-Joseph
Membres-
Compteur de contenus
34 -
Inscription
-
Dernière visite
Tout ce qui a été posté par François-Joseph
-
Le navigateur n'arrive pas à trouver l'adresse DNS de Google
François-Joseph a répondu à un(e) sujet de François-Joseph dans Windows 10
Bonsoir, Toujours le même souci pas d'amélioration les "pc" perdent la connexion bien que la box indique l'heure ... Malgré que les caches soient vides, le navigateur ne trouve pas Google souvent, avec chrome ou Firefox sur w 10 ou Linux mint ... Merci pour votre réponse ...salutations cordiales -
Le navigateur n'arrive pas à trouver l'adresse DNS de Google
François-Joseph a répondu à un(e) sujet de François-Joseph dans Windows 10
Merci Dylav, Je vais suivre ton avis sur W10 et Linux mint, en vidant sur Firefox et chrome ce dernier je ne l'utilise quasiment jamais. D'autre part comment est -il possible de plouffer sur un site de tchat en cam et en postant de la musique avec 6.5 à 7.2 méga de connexion ? Encore merci bon dimanche ... -
Le navigateur n'arrive pas à trouver l'adresse DNS de Google
François-Joseph a posté un sujet dans Windows 10
Bonjour, En effet, mes deux navigateurs Firefox l'usuel et chrome l'occasionnel ne trouvent plus plus google à chaque demande et ceci aussi sur linux installé sur le même pc (tour) de même j'ai le même soucis sur mon portable ... J'ai contacté mon FAI free pour eux la connexion est bonne ...pas de leur ressort. Ce souci est récent moins de huit jours enn pa -
[Résolu] Plus de réception mail sur une boîte Freefr
François-Joseph a répondu à un(e) sujet de Wullfk dans Internet & Réseaux
Bonjour à tous, Je viens de voir ce forum, j'utilise aussi Free (par contre j'ai migré vers Zimbra, voir sur site de Free).J'ai aussi utilisé Thunderbird pour Seven et Ubuntu, c'est du passé... J'utilise Gmx mail (excellente messagerie) et j'y rapatie toutes mes autres adresses qu'elles soient en "free.fr ou hotmail.fr", néanmoins, il faut vider le serveur quand il arrive à saturation en vidant toute la messagerie sur Zimbra voire Webmail. Avec TB n'oubliez pas de compacter de temps en temps ... Salutations FJ Z -
Probable infection (résolu)
François-Joseph a répondu à un(e) sujet de François-Joseph dans Analyses et éradication malwares
Bonjour, Je n'ai plus de symptômes particuliers, sauf une infection détectée par mbam avant d'avoir posté le log hijackThis (11 problèmes,que j'ai éliminés avec malwarebyte, non sans mal )Des craintes subsistaient... J'utilise Seven 64 bites. Existe t-il un moyen de rappel pour être à jour avec Java et Adobe ... Merci pour l'aide je vais me mettre au boulot. Salutations, bon W-E. François-Joseph -
Probable infection (résolu)
François-Joseph a répondu à un(e) sujet de François-Joseph dans Analyses et éradication malwares
Bonjour, ci-joint les deux logs: Salutations François-Joseph Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Version de la base de données: 5519 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 14/01/2011 17:39:56 mbam-log-2011-01-14 (17-39-56).txt Type d'examen: Examen rapide Elément(s) analysé(s): 152945 Temps écoulé: 47 seconde(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté) Results of screen317's Security Check version 0.99.8 Windows 7 (UAC is disabled!) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: avast! Free Antivirus WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Java 6 Update 22 Out of date Java installed! Adobe Flash Player 10.1.102.64 Adobe Reader 9.4.1 - Français Out of date Adobe Reader installed! Mozilla Thunderbird (3.1.7) ```````````````````````````````` Process Check: objlist.exe by Laurent ThreatFire TFService.exe Alwil Software Avast5 AvastSvc.exe Alwil Software Avast5 AvastUI.exe ``````````End of Log```````````` -
On m'a oublié !
François-Joseph a répondu à un(e) sujet de Gof dans Analyses et éradication malwares
Bonjour, J'ai posté un log HIJACKTHIS le 08/01/2011 à 14h36 sous: "Infection probable" François-Joseph. Quelqu'un pourrait-il me rassurer en vérifiant le log. Merci,salutations. F-J ZECH -
Bonjour, Bonne et heureuse année à tous... Nouvelle année, nouveaux problèmes je pense ... Bravo pour le site des forums j'aime bien.J'aimerais vous soumettre mon dernier scan, qui me semble pas net...Ci-joint le scan HiJackThis Merci pour l'aide ...A+ FJZ Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:07:24, on 08/01/2011 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16700) Boot mode: Normal Running processes: C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Windows\SysWOW64\svchost.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe C:\Program Files (x86)\ThreatFire\TFService.exe c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe D:\Téléchargements\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hp-desktop | MSN.fr R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hp-desktop | MSN.fr R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Easybits Shared Services for Windows (ezSharedSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe O23 - Service: @C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll,-101 (getPlusHelper) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\x64\maconfservice.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: ProgDVB Scheduler Service (ProgDVBService) - Unknown owner - C:\Program Files\ProgDVB\ProgDVBService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files (x86)\ThreatFire\TFService.exe O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe -- End of file - 23043 bytes
-
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Bonsoir Loup blanc, Mes deux ports Usb sont "J et K" je repose ma question: après l'installation de USB-set la détection automatique est elle supprimée ? Je joins les captures actuelles de USB-set. Salutations F-J -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Bonjour Loup blanc, Depuis que j'ai coché "E" Dans tous les utilisateurs (prioritaires): La détection automatique pour le lecteur CD/DVD fonctionne à nouveau mais pas pour les deux ports USB je m'en accommode ... Je vais remettre en service USB-set sinon il ne sert plus à rien. PS: je voulais joindre deux captures, le site a du mal à s'ouvrir et quand il s'ouvre il ne réagit plus. Salutations F-J -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Mes excuses Loup blanc, Il est tard et je fais conneries, ci joint le bon lien pour la capture: Merci à toi, je me coucherais moins bête. -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
plutôt ceci: -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Bonsoir Loup blanc, http://yfrog.com/eqcapture011zj Je n'ai pas vérifié je pense que c'est cela. Salutations. F-J -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Bonjour Loup blanc, Oui j'ai redémarré l'ordi, l'exécution automatique ne fonctionne ni pour le lecteur CD/DVD ni les ports usb à l'avant de l'ordi. Pour paramétrer USB-set j'ai pris les références sur vos explications sur le forum. Je n'ai pas réussi à insérer une capture d'écran à la suite de ce texte, à la limite je peux les joindre par mail. Salutations F-J. -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
-
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Salut Loup blanc, Après la manip cela a fonctionné une fois. Depuis c'est fini, en plus la "Vaccination est inactive" toutes les fonctions "Réglages des fonctions Autorun" sont en rouges sauf la dernière "Inhiber la fonction Autorun" qui est en vert. Est ce que USB-set désactive la fonction "Détection automatique des périphériques et médias amovibles" ? Salutations F-J -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Salut à toi Loup blanc, J'avais déjà réinstallé USB-set, maintenant je vais faire le reste de tes conseils je te tiendrais au courant ... Pour l'heure, je dois sortir mon Bull terrier me réclame. Merci et salutations cordiales. F-J -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Bonsoir, La valeur de la clé est bonne, pourtant plus d'exécution automatique. -
Plus d'exécution automatique pour les médias
François-Joseph a répondu à un(e) sujet de François-Joseph dans Sécurisation, prévention
Bonsoir, Après les manipulations déjà sitées, plus de fenêtres d'exécution automatique... Après l'installation et lors du paramétrage, en mettant une clef "usb, s'ouvrait une fenêtre en précisant que le port est déjà vacciné et l'ouverture de la clef ne s'effectuait pas. Ne trouvant pas la solution j'ai désinstaller avec l'outil de Seven pour me retrouver avec les problèmes déjà évoqués ...Ce n'est que plus tard que j'ai découvert le désinstalleur spécifique ... Par quelle solution puis-je remédier à mon problème ? Merci pour l'aide, salutations. F-J -
Plus d'exécution automatique pour les médias
François-Joseph a posté un sujet dans Sécurisation, prévention
Bonjour, Suite à l'installation et désinstallation de "Usb set", la reconnaissance de l'exécution automatique pour les médias ne se fait plus. Comment y remédier ? Merci pour la réponse, salutations cordiales. F-J -
Infection
François-Joseph a répondu à un(e) sujet de François-Joseph dans Analyses et éradication malwares
Merci Pear, Je joins les deux résultats -----------\\ ToolBar S&D 1.2.8 XP/Vista "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 ) Option : [1] ( 23/03/2009|19:33 ) -----------\\ Recherche de Fichiers / Dossiers ... C:\DOCUME~1\F-J\APPLIC~1\Dealio C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\temp C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\alerts.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\alerts_over.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\alerts_rec.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\alerts_rec_over.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\chevron-small.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\DealioSearch.html C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\deals-leftcap.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\deal_report.jpg C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\ebay_login.jpg C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\err_mainwindow.html C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\err_toolbar.html C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\global_scripts.js C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\headerbgthin.jpg C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\highlight-bg.png C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\logo.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\logo_over.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\man_toolbar.css C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\man_toolbar.html C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\man_toolbar.js C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\man_toolbarl.js C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\post-this-deal.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\post-this-deal_over.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\scripts.js C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\scroller.js C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\search-chevron.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\search-chevron_over.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\search_bg_blink.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\separator.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\settings.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\settings_over.gif C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\res\yahoo-search.png C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\index.76.35 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.10.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.109.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.110.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.12.52 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.13.58 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.130.58 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.135.50 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.153.44 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.155.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.156.49 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.16.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.161.52 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.178.66 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.184.55 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.188.52 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.189.45 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.196.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.198.56 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.199.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.200.53 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.201.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.202.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.203.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.205.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.213.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.214.49 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.215.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.216.67 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.217.67 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.218.52 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.219.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.220.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.221.57 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.222.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.223.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.226.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.227.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.228.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.229.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.23.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.239.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.24.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.240.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.241.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.242.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.243.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.244.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.245.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.247.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.248.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.249.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.250.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.251.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.252.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.253.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.254.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.255.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.256.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.257.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.279.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.28.58 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.282.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.283.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.284.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.289.67 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.290.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.291.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.296.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.297.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.304.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.307.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.308.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.31.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.310.46 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.311.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.315.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.316.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.317.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.318.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.319.49 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.32.48 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.334.44 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.335.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.336.44 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.337.44 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.338.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.339.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.34.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.340.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.341.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.349.50 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.35.48 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.350.50 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.351.51 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.352.54 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.353.51 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.354.51 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.357.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.358.52 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.359.52 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.360.53 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.361.54 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.362.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.363.58 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.364.54 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.365.53 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.367.56 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.368.58 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.369.55 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.370.56 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.371.56 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.372.57 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.373.55 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.375.56 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.376.57 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.377.55 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.378.65 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.384.58 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.386.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.387.59 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.388.59 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.389.59 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.390.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.391.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.392.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.393.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.394.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.396.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.397.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.398.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.399.60 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.403.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.404.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.405.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.406.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.407.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.408.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.409.61 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.412.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.413.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.414.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.415.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.416.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.417.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.418.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.419.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.420.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.421.62 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.423.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.424.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.425.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.426.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.427.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.428.65 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.429.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.430.63 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.432.65 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.433.64 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.434.65 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.435.64 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.436.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.437.64 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.438.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.439.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.440.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.442.73 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.443.73 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.444.73 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.445.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.446.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.450.67 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.451.67 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.452.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.453.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.454.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.456.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.457.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.458.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.459.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.460.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.462.74 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.463.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.464.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.465.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.468.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.469.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.470.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.471.73 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.472.70 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.478.74 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.479.73 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.480.68 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.481.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.482.74 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.49.67 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.50.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.500.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.501.74 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.502.71 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.51.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.52.72 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.520.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.521.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.522.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.53.51 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.531.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.532.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.534.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.54.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.55.45 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.56.69 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.57.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.58.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.593.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.595.76 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.63.57 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.66.47 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.70.75 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\rules\rules.1.71.43 C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\temp\dealio-14315.log C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127\temp\dod_cache.xml C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio C:\DOCUME~1\F-J\APPLIC~1\Search Settings C:\DOCUME~1\F-J\APPLIC~1\Search Settings\kb127 C:\DOCUME~1\F-J\APPLIC~1\Search Settings\kb127\res C:\DOCUME~1\F-J\APPLIC~1\Search Settings\kb127\temp C:\Program Files\Search Settings C:\Program Files\Search Settings\kb127 C:\Program Files\Search Settings\SearchSettings.exe C:\Program Files\Search Settings\kb127\res C:\Program Files\Search Settings\kb127\SearchSettings.dll C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll C:\Program Files\Search Settings\kb127\temp -----------\\ Extensions (F-J) - {0b457cAA-602d-484a-8fe7-c1d894a011ba} => fireshot (F-J) - {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} => imagezoom (F-J) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper (F-J) - {247042CB-2281-483B-AC2D-230B2F3774CB} => littlebird (F-J) - {247042CB-2281-483B-AC2D-230B2F3774CB} => littlebird (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ca (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-cs (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-da (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-de (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-en-US (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-es-AR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-es-ES (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-eu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-fr (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ga-IE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-hu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-is (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-it (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ja-JP-mac (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ja (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ka (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ko (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-lt (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-nb-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-nl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-nn-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-pl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-pt-BR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-pt-PT (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ro (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ru (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-sk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-sl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-sv-SE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-uk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-zh-CN (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-zh-TW (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ca (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-cs (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-da (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-de (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-en-US (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-es-AR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-es-ES (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-eu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-fr (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ga-IE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-hu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-is (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-it (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ja-JP-mac (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ja (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ka (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ko (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-lt (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-nb-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-nl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-nn-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-pl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-pt-BR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-pt-PT (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ro (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ru (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-sk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-sl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-sv-SE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-uk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-zh-CN (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-zh-TW (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "Start Page"="http://google.fr/"'>http://google.fr/" "Search Page"="http://www.google.com"'>http://www.google.com" "Search Bar"="http://www.google.com/ie"'>http://www.google.com/ie"'>http://www.google.com/ie"'>http://www.google.com/ie" "SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"'>http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" "Default_Search_URL"="http://www.google.com/ie" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"'>http://go.microsoft.com/fwlink/?LinkId=69157"'>http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" --------------------\\ Recherche d'autres infections Aucune autre infection trouvée ! 1 - "C:\ToolBar SD\TB_1.txt" - 23/03/2009|19:33 - Option : [1] -----------\\ Fin du rapport a 19:33:58,34 -----------\\ ToolBar S&D 1.2.8 XP/Vista "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 ) Option : [2] ( 23/03/2009|19:36 ) -----------\\ SUPPRESSION Supprime! - C:\DOCUME~1\F-J\APPLIC~1\Dealio\kb127 Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio Supprime! - C:\DOCUME~1\F-J\APPLIC~1\Search Settings\kb127 Supprime! - C:\Program Files\Search Settings\kb127 Supprime! - C:\Program Files\Search Settings\SearchSettings.exe Supprime! - C:\DOCUME~1\F-J\APPLIC~1\Dealio Supprime! - C:\DOCUME~1\F-J\APPLIC~1\Search Settings Supprime! - C:\Program Files\Search Settings -----------\\ Recherche de Fichiers / Dossiers ... -----------\\ Extensions (F-J) - {0b457cAA-602d-484a-8fe7-c1d894a011ba} => fireshot (F-J) - {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} => imagezoom (F-J) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper (F-J) - {247042CB-2281-483B-AC2D-230B2F3774CB} => littlebird (F-J) - {247042CB-2281-483B-AC2D-230B2F3774CB} => littlebird (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ca (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-cs (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-da (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-de (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-en-US (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-es-AR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-es-ES (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-eu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-fr (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ga-IE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-hu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-is (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-it (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ja-JP-mac (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ja (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ka (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ko (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-lt (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-nb-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-nl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-nn-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-pl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-pt-BR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-pt-PT (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ro (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-ru (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-sk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-sl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-sv-SE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-uk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-zh-CN (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar-zh-TW (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => calendar (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ca (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-cs (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-da (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-de (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-en-US (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-es-AR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-es-ES (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-eu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-fr (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ga-IE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-hu (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-is (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-it (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ja-JP-mac (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ja (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ka (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ko (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-lt (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-nb-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-nl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-nn-NO (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-pl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-pt-BR (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-pt-PT (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ro (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-ru (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-sk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-sl (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-sv-SE (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-uk (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-zh-CN (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning-zh-TW (F-J) - {e2fda1a4-762b-4020-b5ad-a41df1933103} => lightning -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "Start Page"="http://google.fr/" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com/ie" "SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" "Default_Search_URL"="http://www.google.com/ie" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.com/" --------------------\\ Recherche d'autres infections Aucune autre infection trouvée ! 1 - "C:\ToolBar SD\TB_1.txt" - 23/03/2009|19:33 - Option : [1] 2 - "C:\ToolBar SD\TB_2.txt" - 23/03/2009|19:37 - Option : [2] -----------\\ Fin du rapport a 19:37:31,73 Je reste sur le forum pour connaitre votre analyse, encore merci, je ne peux que louer "Zebulon" à mes connaissances. -
Bonjour, J'aurais besoin de votre aide ou avis éclairé selon le rapport ZHPLil faudrait éliminer certaines lignes. Ainsi je me réfère à vous pour le nettoyage. Ci-joint mon log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:10:50, on 23/03/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Raxco\PerfectDisk\PDSched.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe C:\Program Files\Stardock\CursorFX\CursorFX.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\TuneUpDefragService.exe C:\WINDOWS\system32\cidaemon.exe D:\Téléchargements\Outils\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file) O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file) O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\F-J\Application Data\Dealio\kb127\res\DealioSearch.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1171042786343 O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fichiers/har...on.cab?version= O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1D66FAE5-E1DD-4E11-A712-E3E4B9CC79FF}: NameServer = 212.27.53.252,212.27.54.252 O17 - HKLM\System\CS1\Services\Tcpip\..\{1D66FAE5-E1DD-4E11-A712-E3E4B9CC79FF}: NameServer = 212.27.53.252,212.27.54.252 O23 - Service: a-squared Free Service (a2free) - Unknown owner - D:\APPLICATION\a-squared Free\a2service.exe (file missing) O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe O23 - Service: Planificateur Avira AntiVir Premium (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE O23 - Service: Service d'assistance Avira AntiVir Premium MailGuard (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing) O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/F-J/LOCALS~1/Temp/msohtml1/01/clip_image002.gif -- End of file - 8464 bytes Merci de vous pencher sur mon problème. FJZ
-
L'infection perdure malgré le passage de mbam...RESOLU
François-Joseph a répondu à un(e) sujet de François-Joseph dans Analyses et éradication malwares
Merci pour tout. Java est installé ci joint le rapport Le nettoyage avec TCleaner est exécuté. Joyeux NOËL et BONNE ANNEE 2009 à tous. JavaRa 1.12 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Tue Dec 23 00:12:38 2008 Found and removed: C:\Program Files\Java\jre1.6.0_01 Found and removed: C:\Program Files\Java\jre1.6.0_02 Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610001 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610002 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610001 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610002 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610002 Found and removed: SOFTWARE\Classes\JavaPlugin.160_01 Found and removed: SOFTWARE\Classes\JavaPlugin.160_02 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_01 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_02 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_01 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610002 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610001 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610002 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610002 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160010} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160020} Found and removed: Software\Classes\JavaPlugin.160_01 Found and removed: Software\Classes\JavaPlugin.160_02 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_01 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_02 Found and removed: Software\JavaSoft\Java2D\1.6.0_01 Found and removed: Software\JavaSoft\Java2D\1.6.0_02 Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_01 Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_02 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\bin\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\bin\ ------------------------------------ Finished reporting. -
L'infection perdure malgré le passage de mbam...RESOLU
François-Joseph a répondu à un(e) sujet de François-Joseph dans Analyses et éradication malwares
Hello, Je me perds dans l'installation de Java, j'ai JavaRa.exe sur le bureau et le comble je peux l'avoir en français, mais après que cela se corce sur les pages en anglais. Désolé pour le boulot,merci. A+ F-J -
L'infection perdure malgré le passage de mbam...RESOLU
François-Joseph a répondu à un(e) sujet de François-Joseph dans Analyses et éradication malwares
Hello, Entre temps, j'ai continué la suite de la recherche et SDFIX donne ceci: (en fait j'ai du mal à suivre je ne parle pas l'anglais, on se débrouille surtout avec l'aide de gens compétents et serviables, comme toi.Merci, passe. de Bonnes Fêtes.) Rapport SDFIx: SDFix: Version 1.240 Run by F-J on 22/12/2008 at 21:15 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Restoring Default HomePage Value Restoring Default Desktop Components Value Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : C:\WINDOWS\system32 :Explore 57 Total size: 57 bytes. system32: deleted 57 bytes in 1 streams. Checking for remaining Streams C:\WINDOWS\system32 No streams found. Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-22 21:23:36 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\fir ewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2 res.dll,-22019" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\fir ewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2 res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Mon 14 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe" Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll" Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe" Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll" Tue 6 Feb 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Tue 6 Feb 2007 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv19.bak" Sun 11 Feb 2007 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak" Sun 11 Feb 2007 48 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak" Sun 11 Feb 2007 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v3ks.bla.bak" Wed 21 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Mon 14 Apr 2008 471,206 A.SHR --- "C:\_OTMoveIt\MovedFiles\12222008_205105\windows\system32\csrcs.exe" Finished! Rapport HijackThis: SDFix: Version 1.240 Run by F-J on 22/12/2008 at 21:15 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Restoring Default HomePage Value Restoring Default Desktop Components Value Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : C:\WINDOWS\system32 :Explore 57 Total size: 57 bytes. system32: deleted 57 bytes in 1 streams. Checking for remaining Streams C:\WINDOWS\system32 No streams found. Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-22 21:23:36 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\fir ewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2 res.dll,-22019" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\fir ewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2 res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Mon 14 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe" Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll" Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe" Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll" Tue 6 Feb 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Tue 6 Feb 2007 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv19.bak" Sun 11 Feb 2007 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak" Sun 11 Feb 2007 48 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak" Sun 11 Feb 2007 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v3ks.bla.bak" Wed 21 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Mon 14 Apr 2008 471,206 A.SHR --- "C:\_OTMoveIt\MovedFiles\12222008_205105\windows\system32\csrcs.exe" Finished! Rapport HJT: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:44:58, on 22/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE C:\Program Files\Raxco\PerfectDisk\PDSched.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\Téléchargements\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll O3 - Toolbar: (no name) - {FC907671-A480-49CF-8953-F5E5CA145228} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1171042786343 O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.touslesdrivers.com/fichiers/har...on.cab?version= O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1D66FAE5-E1DD-4E11-A712-E3E4B9CC79FF}: NameServer = 212.27.53.252,212.27.54.252 O17 - HKLM\System\CS1\Services\Tcpip\..\{1D66FAE5-E1DD-4E11-A712-E3E4B9CC79FF}: NameServer = 212.27.53.252,212.27.54.252 O23 - Service: a-squared Free Service (a2free) - Unknown owner - D:\APPLICATION\a-squared Free\a2service.exe (file missing) O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe O23 - Service: Planificateur Avira AntiVir Premium (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE O23 - Service: Service d'assistance Avira AntiVir Premium MailGuard (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing) O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 7239 bytes