Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Infection Trojan Horse Crypt. YCS


Messages recommandés

Bonjour,

je me permets de poster car aujourd'hui AVG a détecté un "Trojan Horse Crypt. YCS" qu'il a alors placé en quarantaine. Le soucis est qu'ensuite j'ai eu plusieurs choses curieuses telles que le changement de mes préférences de windows update, le changement de thème ainsi que l'explorer qui a freezé plusieurs fois. J'ai exécuté une analyse avg en mode sans échec mais je n'ai rien trouvé de plus...

 

Voici ci-dessous le rapport HijackThis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:49:56, on 03.08.2010

Platform: Unknown Windows (WinNT 6.01.3504)

MSIE: Internet Explorer v8.00 (8.00.7600.16385)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\AVG\AVG9\avgtray.exe

C:\Windows\Dell\PanelMgr\SSMMgr.exe

C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe

C:\Program Files\Mozilla Thunderbird\thunderbird.exe

C:\Program Files\PuTTY\pageant.exe

C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

C:\Program Files\AVG\AVG9\avgui.exe

C:\Program Files\HijackThis\HijackThis.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\taskmgr.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [Dell PanelMgr] C:\Windows\Dell\PanelMgr\SSMMgr.exe /autorun

O4 - HKLM\..\Run: [2335dn Scan2PC] "C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files\Mozilla Thunderbird\thunderbird.exe

O4 - Startup: Shortcut to pageant.exe.lnk = C:\Program Files\PuTTY\pageant.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Edit with &XML Spy - C:\Program Files\XML Spy Suite\spy.htm

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\XML Spy Suite\spy.htm (HKCU)

O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\XML Spy Suite\spy.htm (HKCU)

O13 - Gopher Prefix:

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = **

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = **

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = **

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe

O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe

O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

 

--

End of file - 4531 bytes

 

 

Merci d'avance pour votre réponse.

Modifié par maxr397
Lien vers le commentaire
Partager sur d’autres sites

Bonjour,

 

STP, poste tes rapports sans balises code ou quote. Colle-les tels que copiés dans le fichier texte.

 

Télécharge random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

  • Double-clique sur RSIT.exe afin de lancer RSIT.
     
    Important :
    * Sous Vista : il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
     
    * Sous Windows 7 : Il faut mettre le fichier RSIT.exe sur le bureau, faire un clic droit dessus et dans Propriétés, onglet Compatibilité, cocher la case "Exécuter ce programme en mode compatibilité pour" et dans le menu choisir Vista SP2 et la case dans Niveau de privilège.
    Valide par Appliquer.
     
  • Clique Continue à l'écran Disclaimer.
  • Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

 

@++

Lien vers le commentaire
Partager sur d’autres sites

tout d'abord merci de ta réponse.

 

voici le fichier info.txt

 

info.txt logfile of random's system information tool 1.08 2010-08-03 18:47:32

 

======Uninstall list======

 

-->"C:\Program Files\InstallShield Installation Information\{91029ED4-04B8-40EF-A70F-30C9AA538358}\Setup.exe" -runfromtemp -l0x0009 -removeonly

µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}

2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}

7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"

Add-in ODF pour Microsoft Word-->MsiExec.exe /I{E6738F45-D704-4D83-9E51-24695E717D09}

Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe -maintain plugin

Adobe Reader 9.3.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A93000000001}

Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"

Advertising Center-->MsiExec.exe /X{B2EC4A38-B545-4A00-8214-13FE0E915E6D}

Apple Application Support-->MsiExec.exe /I{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}

Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}

AVG 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL

AvgAdmin 9.0-->C:\Program Files\AVG\AVG9 Admin\Common\setup.exe /UNINSTALL

CASE Studio 2 ver.-->"C:\Program Files\RKSoft\CASEStudio2\Uninstall_CS2_GBI\unins000.exe"

Complément Microsoft Enregistrer en tant que PDF ou XPS pour programmes Microsoft Office 2007-->MsiExec.exe /X{90120000-00B2-040C-0000-0000000FF1CE}

Corel PaintShop Photo Pro X3-->c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\Setup\{DEAEB5DB-04FA-489D-94EF-8600898B93EE}\SetupARP.exe /arp

Corel PaintShop Photo Pro X3-->MsiExec.exe /I{DE4BF4BE-3CDC-43B5-BBDA-DDDA73103111}

Dell 2335 Fax-->C:\Program Files\InstallShield Installation Information\{E3CAE4F2-97CE-4985-8732-2206EF495147}\Setup.exe -runfromtemp -l0x0009 -removeonly -removeonly

Dell 2335dn MFP Software Uninstall-->C:\Program Files\DELL\Dell 2335dn MFP\Install\setup.exe /Uninstall

HijackThis 2.0.2-->"C:\Program Files\HijackThis\HijackThis.exe" /uninstall

ICA-->MsiExec.exe /I{DEAEB5DB-04FA-489D-94EF-8600898B93EE}

IETester v0.4.2 (remove only)-->"C:\Program Files\IETester\uninstall.exe"

IPM_PSP_CL-->MsiExec.exe /I{DE99075E-7D25-4B96-B32E-BFE6FBFAA644}

IPM_PSP_COM-->MsiExec.exe /I{DEF8C145-CC4F-4DAA-AD5C-E707C07AEE50}

Java 2 Runtime Environment, SE v1.4.2_06-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142060}

Java 2 SDK, SE v1.4.2_06-->MsiExec.exe /I{35A3A4F4-B792-11D6-A78A-00B0D0142060}

Java 6 Update 20-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}

Java SE Development Kit 6 Update 20-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160200}

Ma-Config.com-->MsiExec.exe /X{14E3D14B-7852-477D-ACE2-895AF4322804}

Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"

Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client

Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}

Microsoft Office Excel 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall EXCEL /dll OSETUP.DLL

Microsoft Office Excel 2007-->MsiExec.exe /X{90120000-0016-0000-0000-0000000FF1CE}

Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}

Microsoft Office PowerPoint 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall POWERPOINT /dll OSETUP.DLL

Microsoft Office PowerPoint 2007-->MsiExec.exe /X{90120000-0018-0000-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}

Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}

Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}

Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}

Microsoft Office Visio MUI (English) 2007-->MsiExec.exe /X{90120000-0054-0409-0000-0000000FF1CE}

Microsoft Office Visio Professional 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall VISPRO /dll OSETUP.DLL

Microsoft Office Visio Professional 2007-->MsiExec.exe /X{90120000-0051-0000-0000-0000000FF1CE}

Microsoft Office Word 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WORD /dll OSETUP.DLL

Microsoft Office Word 2007-->MsiExec.exe /X{90120000-001B-0000-0000-0000000FF1CE}

Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}

Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}

Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}

Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}

MozBackup 1.4.10-->C:\Program Files\MozBackup\Uninstall.exe

Mozilla Firefox (3.6.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe

Mozilla Sunbird (0.9)-->C:\Program Files\Mozilla Sunbird\uninstall\uninst.exe

Mozilla Thunderbird (3.0.6)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe

MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

Nero 9 Lite-->C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="XM2C-50A9-HH4M-0ZM8-4X06-9P25-5A46-618P-AH19-6647"

Nero ControlCenter-->MsiExec.exe /X{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}

Nero Installer-->MsiExec.exe /X{E8A80433-302B-4FF1-815D-FCC8EAC482FF}

Nero Online Upgrade-->MsiExec.exe /X{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}

Nero StartSmart-->MsiExec.exe /X{7748AC8C-18E3-43BB-959B-088FAEA16FB2}

neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}

Notepad++-->C:\Program Files\Notepad++\uninstall.exe

Opera 10.60-->MsiExec.exe /X{1D2C96C3-A3F3-49E7-B839-95279DED837F}

PSPPContent-->MsiExec.exe /I{DE8B9311-ADE7-4EDE-B121-326CAA3D225D}

PSPPRO_DCRAW-->MsiExec.exe /I{DEF1928A-FC01-48E7-A7E6-4651D42EF6A1}

PuTTY version 0.57-->"C:\Program Files\PuTTY\unins000.exe"

QuickTime-->MsiExec.exe /I{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}

Realtek Ethernet Controller Driver For Windows Vista and Later-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.exe -runfromtemp -removeonly

Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly

Rep-Listing-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{887EF08A-011E-477C-B6CB-01E540538ADB}\setup.exe" -l0x40c -removeonly

Safari-->MsiExec.exe /I{EAFEF30E-3789-49C7-A6D9-77C12E005BAC}

Setup-->MsiExec.exe /I{DE612A3D-0DCC-4055-BB6A-0036F31158A0}

SPSS Statistics 17.0-->MsiExec.exe /X{46B65150-F8AA-42F2-94FB-2729A8AE5F7E}

TortoiseSVN 1.6.9.19725 (32 bit)-->MsiExec.exe /X{4B6A3B5E-D26E-4690-A061-F3E2FB10F0E5}

UltraCompare v7.00-->MsiExec.exe /I{DA7ADA42-C7F3-436D-ADAE-B0CE1E4A5C22}

UltraEdit-32 Uninstall-->C:\PROGRA~1\ULTRAE~1\UEDIT32.EXE /UNINSTALL

UltraVNC 1.0.8.2-->"C:\Program Files\UltraVNC\unins000.exe"

VLC media player 1.1.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe

XML Spy Suite 4.4-->MsiExec.exe /I{4059B475-06E5-4E5C-8549-B7857AB33668}

Zattoo4 4.0.5-->C:\Program Files\Zattoo4\uninst.exe

 

======System event log======

 

Computer Name: Marsalis.****

Event Code: 1014

Message: Name resolution for the name **** timed out after none of the configured DNS servers responded.

Record Number: 860

Source Name: Microsoft-Windows-DNS-Client

Time Written: 20100422093113.657210-000

Event Type: Warning

User: NT AUTHORITY\NETWORK SERVICE

 

Computer Name: Marsalis.****

Event Code: 1014

Message: Name resolution for the name **** timed out after none of the configured DNS servers responded.

Record Number: 858

Source Name: Microsoft-Windows-DNS-Client

Time Written: 20100422092843.616147-000

Event Type: Warning

User: NT AUTHORITY\NETWORK SERVICE

 

Computer Name: Marsalis.****

Event Code: 1014

Message: Name resolution for the name **** timed out after none of the configured DNS servers responded.

Record Number: 857

Source Name: Microsoft-Windows-DNS-Client

Time Written: 20100422092613.575083-000

Event Type: Warning

User: NT AUTHORITY\NETWORK SERVICE

 

Computer Name: Marsalis.****

Event Code: 1014

Message: Name resolution for the name **** timed out after none of the configured DNS servers responded.

Record Number: 849

Source Name: Microsoft-Windows-DNS-Client

Time Written: 20100422092351.375633-000

Event Type: Warning

User: NT AUTHORITY\NETWORK SERVICE

 

Computer Name: marsalis

Event Code: 41

Message: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Record Number: 334

Source Name: Microsoft-Windows-Kernel-Power

Time Written: 20100422074737.022409-000

Event Type: Critical

User: NT AUTHORITY\SYSTEM

 

=====Application event log=====

 

Computer Name: marsalis

Event Code: 1530

Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

 

DETAIL -

5 user registry handles leaked from \Registry\User\S-1-5-21-3678589622-2439322646-1881941484-1001:

Process 500 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1001

Process 500 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1001

Process 500 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1001\Software\Microsoft\SystemCertificates\My

Process 500 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1001\Software\Microsoft\SystemCertificates\CA

Process 500 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1001\Software\Microsoft\SystemCertificates\Disallowed

 

Record Number: 459

Source Name: Microsoft-Windows-User Profiles Service

Time Written: 20100426103216.724574-000

Event Type: Warning

User: NT AUTHORITY\SYSTEM

 

Computer Name: ugarte

Event Code: 11

Message: Possible Memory Leak. Application (C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted) (PID: 764) has passed a non-NULL pointer to RPC for an [out] parameter marked [allocate(all_nodes)]. [allocate(all_nodes)] parameters are always reallocated; if the original pointer contained the address of valid memory, that memory will be leaked. The call originated on the interface with UUID ({3F31C91E-2545-4B7B-9311-9529E8BFFEF6}), Method number (10). User Action: Contact your application vendor for an updated version of the application.

Record Number: 399

Source Name: Microsoft-Windows-RPC-Events

Time Written: 20100426085448.261988-000

Event Type: Warning

User: NT AUTHORITY\LOCAL SERVICE

 

Computer Name: ugarte

Event Code: 1530

Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

 

DETAIL -

1 user registry handles leaked from \Registry\User\S-1-5-21-3678589622-2439322646-1881941484-1001:

Process 3628 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1001

 

Record Number: 377

Source Name: Microsoft-Windows-User Profiles Service

Time Written: 20100423084538.995210-000

Event Type: Warning

User: NT AUTHORITY\SYSTEM

 

Computer Name: marsalis

Event Code: 1530

Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

 

DETAIL -

1 user registry handles leaked from \Registry\User\S-1-5-21-3678589622-2439322646-1881941484-1000:

Process 720 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3678589622-2439322646-1881941484-1000

 

Record Number: 198

Source Name: Microsoft-Windows-User Profiles Service

Time Written: 20100422075829.879147-000

Event Type: Warning

User: NT AUTHORITY\SYSTEM

 

Computer Name: marsalis

Event Code: 1008

Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.

 

Record Number: 115

Source Name: Microsoft-Windows-Search

Time Written: 20100422083939.000000-000

Event Type: Warning

User:

 

=====Security event log=====

 

Computer Name: 37L4247D28-05

Event Code: 4735

Message: A security-enabled local group was changed.

 

Subject:

Security ID: S-1-5-18

Account Name: 37L4247D28-05$

Account Domain: WORKGROUP

Logon ID: 0x3e7

 

Group:

Security ID: S-1-5-32-551

Group Name: Backup Operators

Group Domain: Builtin

 

Changed Attributes:

SAM Account Name: -

SID History: -

 

Additional Information:

Privileges: -

Record Number: 5

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100421162805.761239-000

Event Type: Audit Success

User:

 

Computer Name: 37L4247D28-05

Event Code: 4731

Message: A security-enabled local group was created.

 

Subject:

Security ID: S-1-5-18

Account Name: 37L4247D28-05$

Account Domain: WORKGROUP

Logon ID: 0x3e7

 

New Group:

Security ID: S-1-5-32-551

Group Name: Backup Operators

Group Domain: Builtin

 

Attributes:

SAM Account Name: Backup Operators

SID History: -

 

Additional Information:

Privileges: -

Record Number: 4

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100421162805.761239-000

Event Type: Audit Success

User:

 

Computer Name: 37L4247D28-05

Event Code: 4902

Message: The Per-user audit policy table was created.

 

Number of Elements: 0

Policy ID: 0x23300

Record Number: 3

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100421162805.745639-000

Event Type: Audit Success

User:

 

Computer Name: 37L4247D28-05

Event Code: 4624

Message: An account was successfully logged on.

 

Subject:

Security ID: S-1-0-0

Account Name: -

Account Domain: -

Logon ID: 0x0

 

Logon Type: 0

 

New Logon:

Security ID: S-1-5-18

Account Name: SYSTEM

Account Domain: NT AUTHORITY

Logon ID: 0x3e7

Logon GUID: {00000000-0000-0000-0000-000000000000}

 

Process Information:

Process ID: 0x4

Process Name:

 

Network Information:

Workstation Name: -

Source Network Address: -

Source Port: -

 

Detailed Authentication Information:

Logon Process: -

Authentication Package: -

Transited Services: -

Package Name (NTLM only): -

Key Length: 0

 

This event is generated when a logon session is created. It is generated on the computer that was accessed.

 

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

 

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

 

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

 

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

 

The authentication information fields provide detailed information about this specific logon request.

- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.

- Transited services indicate which intermediate services have participated in this logon request.

- Package name indicates which sub-protocol was used among the NTLM protocols.

- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.

Record Number: 2

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100421162805.620838-000

Event Type: Audit Success

User:

 

Computer Name: 37L4247D28-05

Event Code: 4608

Message: Windows is starting up.

 

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.

Record Number: 1

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100421162805.620838-000

Event Type: Audit Success

User:

 

======Environment variables======

 

"ComSpec"=%SystemRoot%\system32\cmd.exe

"FP_NO_HOST_CHECK"=NO

"NUMBER_OF_PROCESSORS"=4

"OS"=Windows_NT

"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\PROGRA~1\ULTRAE~1;C:\Program Files\TortoiseSVN\bin;C:\Program Files\QuickTime\QTSystem\

"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC

"PROCESSOR_ARCHITECTURE"=x86

"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 30 Stepping 5, GenuineIntel

"PROCESSOR_LEVEL"=6

"PROCESSOR_REVISION"=1e05

"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\

"TEMP"=%SystemRoot%\TEMP

"TMP"=%SystemRoot%\TEMP

"USERNAME"=SYSTEM

"windir"=%SystemRoot%

"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip

"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

 

-----------------EOF-----------------

 

 

et le fichier log.txt

 

Logfile of random's system information tool 1.08 (written by random/random)

Run by maxime at 2010-08-03 18:48:44

Microsoft Windows 7 Professional Service Pack 2

System drive C: has 33 GB (44%) free of 76 GB

Total RAM: 3191 MB (42% free)

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 18:48:47, on 03.08.2010

Platform: Windows 7 (WinNT 6.00.3504)

MSIE: Internet Explorer v8.00 (8.00.7600.16385)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\AVG\AVG9\avgtray.exe

C:\Windows\Dell\PanelMgr\SSMMgr.exe

C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe

C:\Program Files\Mozilla Thunderbird\thunderbird.exe

C:\Program Files\PuTTY\pageant.exe

C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

C:\Program Files\AVG\AVG9\avgui.exe

C:\Windows\system32\taskmgr.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Program Files\Microsoft Office\Office12\EXCEL.EXE

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\UltraEdit\UEDIT32.EXE

C:\Users\******\Desktop\RSIT.exe

C:\Program Files\trend micro\maxime.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Actualité, Sport et Vidéo

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN : Hotmail, Messenger, Actualité, Sport et Vidéo

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Actualité, Sport et Vidéo

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [Dell PanelMgr] C:\Windows\Dell\PanelMgr\SSMMgr.exe /autorun

O4 - HKLM\..\Run: [2335dn Scan2PC] "C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe"

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files\Mozilla Thunderbird\thunderbird.exe

O4 - Startup: Shortcut to pageant.exe.lnk = C:\Program Files\PuTTY\pageant.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Edit with &XML Spy - C:\Program Files\XML Spy Suite\spy.htm

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\XML Spy Suite\spy.htm (HKCU)

O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\XML Spy Suite\spy.htm (HKCU)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ****

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ****

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ****

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe

O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe

O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\maconfservice.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

 

--

End of file - 4946 bytes

 

======Scheduled tasks folder======

 

C:\Windows\tasks\At1.job

 

======Registry dump======

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-10 41760]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-06-23 2065760]

"Dell PanelMgr"=C:\Windows\Dell\PanelMgr\SSMMgr.exe [2008-06-17 541936]

"2335dn Scan2PC"=C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe [2008-07-07 495616]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel File Shell Monitor]

c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe []

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]

C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe [2010-06-27 526992]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

 

C:\Users\********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

Mozilla Thunderbird.lnk - C:\Program Files\Mozilla Thunderbird\thunderbird.exe

Shortcut to pageant.exe.lnk - C:\Program Files\PuTTY\pageant.exe

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="avgrsstx.dll"

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=5

"ConsentPromptBehaviorUser"=3

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=145

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

 

======File associations======

 

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

 

======List of files/folders created in the last 1 months======

 

2010-08-03 18:47:27 ----D---- C:\Program Files\trend micro

2010-08-03 18:47:26 ----D---- C:\rsit

2010-08-03 18:29:45 ----D---- C:\Users\****\AppData\Roaming\Malwarebytes

2010-08-03 18:29:35 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys

2010-08-03 18:29:34 ----D---- C:\ProgramData\Malwarebytes

2010-08-03 18:29:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware

2010-08-03 18:29:34 ----A---- C:\Windows\system32\drivers\mbam.sys

2010-08-03 17:32:06 ----D---- C:\Program Files\HijackThis

2010-08-03 17:07:43 ----D---- C:\Windows\Minidump

2010-08-03 15:29:00 ----A---- C:\Windows\ntbtlog.txt

2010-08-03 15:23:23 ----D---- C:\Users\****\AppData\Roaming\QuickScan

2010-07-30 16:35:21 ----D---- C:\Users\****\AppData\Roaming\IDMComp

2010-07-30 16:35:17 ----D---- C:\Program Files\UltraCompare

2010-07-28 11:30:46 ----D---- C:\Program Files\QuickTime

2010-07-28 11:25:47 ----D---- C:\Users\****\AppData\Roaming\Media Player Classic

2010-07-23 12:23:22 ----RSH---- C:\ProgramData\28CC72B72A.sys

2010-07-23 12:23:22 ----ASH---- C:\ProgramData\KGyGaAvL.sys

2010-07-23 12:22:15 ----D---- C:\ProgramData\Corel

2010-07-23 12:22:15 ----D---- C:\Program Files\Common Files\Protexis

2010-07-23 12:21:33 ----D---- C:\Users\****\AppData\Roaming\Corel

2010-07-23 12:21:03 ----D---- C:\ProgramData\Ulead Systems

2010-07-23 12:21:03 ----D---- C:\Program Files\Common Files\Corel

2010-07-23 12:20:53 ----A---- C:\Windows\system32\xactengine2_10.dll

2010-07-23 12:20:53 ----A---- C:\Windows\system32\d3dx10_36.dll

2010-07-23 12:20:53 ----A---- C:\Windows\system32\D3DCompiler_36.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\xinput1_3.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\xactengine2_9.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\xactengine2_8.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\X3DAudio1_2.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx9_36.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx9_35.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx9_34.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx10_35.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx10_34.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\D3DCompiler_35.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\D3DCompiler_34.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\xactengine2_7.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\xactengine2_6.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\xactengine2_5.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx9_33.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx9_32.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx10_33.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx10.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\D3DCompiler_33.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xinput1_2.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xinput1_1.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xactengine2_4.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xactengine2_3.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xactengine2_2.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\x3daudio1_1.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\d3dx9_31.dll

2010-07-23 12:20:49 ----A---- C:\Windows\system32\xactengine2_1.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\xactengine2_0.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\x3daudio1_0.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_30.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_29.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_28.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_27.dll

2010-07-23 12:20:46 ----A---- C:\Windows\system32\d3dx9_26.dll

2010-07-23 12:20:46 ----A---- C:\Windows\system32\d3dx9_25.dll

2010-07-23 12:20:46 ----A---- C:\Windows\system32\d3dx9_24.dll

2010-07-23 11:04:06 ----D---- C:\Program Files\Microsoft Silverlight

2010-07-22 12:12:49 ----D---- C:\Users\****\AppData\Roaming\Notepad++

2010-07-22 12:12:49 ----D---- C:\Program Files\Notepad++

2010-07-21 15:05:05 ----D---- C:\Users\****\AppData\Roaming\TortoiseSVN

2010-07-21 09:27:14 ----D---- C:\Program Files\Replisting

2010-07-16 16:54:43 ----D---- C:\Documents and Settings

2010-07-16 10:07:28 ----D---- C:\dataexport

2010-07-16 09:26:49 ----D---- C:\Windows\system32\Adobe

2010-07-13 09:36:11 ----D---- C:\temp

2010-07-13 08:39:27 ----A---- C:\Windows\system32\ntdll.dll

2010-07-13 08:39:26 ----A---- C:\Windows\system32\kernel32.dll

2010-07-13 08:39:26 ----A---- C:\Windows\system32\apphelp.dll

2010-07-07 14:48:42 ----A---- C:\Windows\vbaddin.ini

2010-07-07 14:48:25 ----A---- C:\Windows\ODBC.INI

2010-07-07 09:58:37 ----D---- C:\Program Files\XML Spy Suite

2010-07-07 09:58:37 ----D---- C:\Program Files\Altova

2010-07-07 09:57:35 ----D---- C:\Program Files\XML Spy Suite 4.4

2010-07-06 19:02:56 ----D---- C:\Users\****\AppData\Roaming\vlc

2010-07-06 19:02:44 ----D---- C:\Program Files\VideoLAN

 

======List of files/folders modified in the last 1 months======

 

2010-08-03 18:48:17 ----A---- C:\Windows\UEDIT32.INI

2010-08-03 18:47:50 ----D---- C:\Windows\Temp

2010-08-03 18:47:29 ----D---- C:\Windows\Prefetch

2010-08-03 18:47:27 ----RD---- C:\Program Files

2010-08-03 18:29:35 ----D---- C:\Windows\system32\drivers

2010-08-03 18:29:34 ----HD---- C:\ProgramData

2010-08-03 18:16:08 ----D---- C:\Eclipse3.5

2010-08-03 17:49:45 ----SHD---- C:\Windows\Installer

2010-08-03 17:49:45 ----D---- C:\Windows\system32\Tasks

2010-08-03 17:49:04 ----SHD---- C:\System Volume Information

2010-08-03 17:28:50 ----D---- C:\Windows\System32

2010-08-03 17:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI

2010-08-03 17:28:49 ----D---- C:\Windows\inf

2010-08-03 17:07:43 ----D---- C:\Windows

2010-08-03 12:28:26 ----D---- C:\Windows\system32\drivers\Avg

2010-08-02 18:57:55 ----D---- C:\Windows\system32\config

2010-07-30 17:46:14 ----D---- C:\Users\****\AppData\Roaming\uTorrent

2010-07-29 09:40:46 ----D---- C:\Program Files\Safari

2010-07-29 08:43:59 ----D---- C:\Windows\system32\catroot2

2010-07-28 11:28:12 ----D---- C:\ProgramData\Apple Computer

2010-07-26 14:58:29 ----D---- C:\Program Files\Mozilla Firefox

2010-07-23 12:22:15 ----D---- C:\Program Files\Common Files

2010-07-23 12:21:03 ----D---- C:\Program Files\Corel

2010-07-23 12:20:49 ----RSD---- C:\Windows\assembly

2010-07-23 12:20:48 ----D---- C:\Windows\Microsoft.NET

2010-07-23 12:20:40 ----D---- C:\Windows\winsxs

2010-07-23 12:15:36 ----D---- C:\Windows\Tasks

2010-07-22 16:50:05 ----D---- C:\SVN

2010-07-21 11:53:44 ----D---- C:\Program Files\Mozilla Thunderbird

2010-07-21 09:27:14 ----HD---- C:\Program Files\InstallShield Installation Information

2010-07-16 10:51:58 ----SD---- C:\Users\****\AppData\Roaming\Microsoft

2010-07-16 09:27:24 ----D---- C:\Windows\system32\Macromed

2010-07-16 08:22:59 ----D---- C:\Windows\system32\wdi

2010-07-13 08:39:52 ----D---- C:\Windows\system32\en-US

2010-07-13 08:39:51 ----D---- C:\Program Files\Microsoft.NET

2010-07-13 08:39:38 ----D---- C:\Windows\AppPatch

2010-07-13 08:39:25 ----D---- C:\Windows\system32\catroot

2010-07-09 12:32:35 ----D---- C:\Windows\system32\NDF

2010-07-07 14:49:22 ----D---- C:\ProgramData\Microsoft Help

2010-07-07 14:48:34 ----D---- C:\Program Files\Common Files\microsoft shared

2010-07-07 14:48:33 ----SD---- C:\ProgramData\Microsoft

 

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R0 amdxata;amdxata; C:\Windows\system32\DRIVERS\amdxata.sys [2009-07-14 23616]

R0 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys [2010-06-03 52872]

R0 CNG;CNG; C:\Windows\System32\Drivers\cng.sys [2009-07-14 369568]

R0 fvevol;@%SystemRoot%\system32\drivers\fvevol.sys,-100; C:\Windows\System32\DRIVERS\fvevol.sys [2009-09-26 194488]

R0 hwpolicy;@%systemroot%\system32\drivers\hwpolicy.sys,-101; C:\Windows\System32\drivers\hwpolicy.sys [2009-07-14 13904]

R0 KSecPkg;KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [2009-12-11 133720]

R0 pcw;Performance Counters for Windows Driver; C:\Windows\System32\drivers\pcw.sys [2009-07-14 43088]

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-06-03 691696]

R0 storflt;@%SystemRoot%\system32\vmstorfltres.dll,-1000; C:\Windows\system32\DRIVERS\vmstorfl.sys [2009-07-14 40896]

R0 vdrvroot;Microsoft Virtual Drive Enumerator Driver; C:\Windows\system32\DRIVERS\vdrvroot.sys [2009-07-14 32832]

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-06-23 216400]

R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-06-03 29584]

R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-06-23 243024]

R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]

R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]

R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]

R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]

R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2008-04-25 5120]

R3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]

R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]

R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]

R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]

R3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 20992]

R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]

R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]

R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]

R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]

R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]

S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys []

S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]

S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]

S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]

S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]

S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]

S3 AsrCDDrv;AsrCDDrv; \??\C:\Windows\system32\Drivers\AsrCDDrv.sys []

S3 axxratv7;axxratv7; C:\Windows\system32\drivers\axxratv7.sys []

S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-14 430080]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]

S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2010-05-01 14336]

S3 drmkaud;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]

S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-14 3100160]

S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]

S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]

S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-14 26624]

S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]

S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]

S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]

S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]

S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]

S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]

S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]

S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]

S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]

S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]

S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]

S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]

S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]

S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]

S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]

S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]

S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]

S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]

S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]

S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]

S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]

 

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]

R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-21 921952]

R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-06-23 308136]

R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]

R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]

S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]

S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2010-05-11 271728]

S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]

S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]

S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-01 1343400]

S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]

 

-----------------EOF-----------------

 

avant de voir ta réponse, j'avais dejà lancé une analyse MBAM dont voici le rapport:

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Database version: 4386

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

03.08.2010 18:58:44

mbam-log-2010-08-03 (18-38-44).txt

 

Scan type: Full scan (C:\|D:\|G:\|)

Objects scanned: 414561

Time elapsed: 26 minute(s), 59 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

C:\Users\****\AppData\Local\Temp\tpvmi.exe (Virus.Agent) -> Quarantined and deleted successfully.

C:\Windows\Temp\1024.tmp (Rootkit.Dropper) -> Quarantined and deleted successfully.

 

voici donc le nouveau log.txt de RSIT

 

Logfile of random's system information tool 1.08 (written by random/random)

Run by maxime at 2010-08-03 19:05:00

Microsoft Windows 7 Professional Service Pack 2

System drive C: has 33 GB (44%) free of 76 GB

Total RAM: 3191 MB (69% free)

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 19:05:02, on 03.08.2010

Platform: Windows 7 (WinNT 6.00.3504)

MSIE: Internet Explorer v8.00 (8.00.7600.16385)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskhost.exe

C:\Windows\Explorer.EXE

C:\Program Files\AVG\AVG9\avgtray.exe

C:\Windows\Dell\PanelMgr\SSMMgr.exe

C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe

C:\Program Files\PuTTY\pageant.exe

C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Program Files\UltraCompare\uc.exe

C:\Users\****\Desktop\RSIT.exe

C:\Program Files\trend micro\maxime.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Actualité, Sport et Vidéo

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN : Hotmail, Messenger, Actualité, Sport et Vidéo

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Actualité, Sport et Vidéo

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [Dell PanelMgr] C:\Windows\Dell\PanelMgr\SSMMgr.exe /autorun

O4 - HKLM\..\Run: [2335dn Scan2PC] "C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe"

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files\Mozilla Thunderbird\thunderbird.exe

O4 - Startup: Shortcut to pageant.exe.lnk = C:\Program Files\PuTTY\pageant.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Edit with &XML Spy - C:\Program Files\XML Spy Suite\spy.htm

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\XML Spy Suite\spy.htm (HKCU)

O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\XML Spy Suite\spy.htm (HKCU)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ****

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ****

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ****

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe

O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe

O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\maconfservice.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

 

--

End of file - 4685 bytes

 

======Scheduled tasks folder======

 

C:\Windows\tasks\At1.job

 

======Registry dump======

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-10 41760]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-06-23 2065760]

"Dell PanelMgr"=C:\Windows\Dell\PanelMgr\SSMMgr.exe [2008-06-17 541936]

"2335dn Scan2PC"=C:\Windows\twain_32\Dell\Dell2335\Scan2Pc.exe [2008-07-07 495616]

"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel File Shell Monitor]

c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe []

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]

C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe [2010-06-27 526992]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

 

C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

Mozilla Thunderbird.lnk - C:\Program Files\Mozilla Thunderbird\thunderbird.exe

Shortcut to pageant.exe.lnk - C:\Program Files\PuTTY\pageant.exe

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="avgrsstx.dll"

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=5

"ConsentPromptBehaviorUser"=3

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=145

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

 

======File associations======

 

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

 

======List of files/folders created in the last 1 months======

 

2010-08-03 18:47:27 ----D---- C:\Program Files\trend micro

2010-08-03 18:47:26 ----D---- C:\rsit

2010-08-03 18:29:45 ----D---- C:\Users\****\AppData\Roaming\Malwarebytes

2010-08-03 18:29:35 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys

2010-08-03 18:29:34 ----D---- C:\ProgramData\Malwarebytes

2010-08-03 18:29:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware

2010-08-03 18:29:34 ----A---- C:\Windows\system32\drivers\mbam.sys

2010-08-03 17:32:06 ----D---- C:\Program Files\HijackThis

2010-08-03 17:07:43 ----D---- C:\Windows\Minidump

2010-08-03 15:29:00 ----A---- C:\Windows\ntbtlog.txt

2010-08-03 15:23:23 ----D---- C:\Users\****\AppData\Roaming\QuickScan

2010-07-30 16:35:21 ----D---- C:\Users\****\AppData\Roaming\IDMComp

2010-07-30 16:35:17 ----D---- C:\Program Files\UltraCompare

2010-07-28 11:30:46 ----D---- C:\Program Files\QuickTime

2010-07-28 11:25:47 ----D---- C:\Users\****\AppData\Roaming\Media Player Classic

2010-07-23 12:23:22 ----RSH---- C:\ProgramData\28CC72B72A.sys

2010-07-23 12:23:22 ----ASH---- C:\ProgramData\KGyGaAvL.sys

2010-07-23 12:22:15 ----D---- C:\ProgramData\Corel

2010-07-23 12:22:15 ----D---- C:\Program Files\Common Files\Protexis

2010-07-23 12:21:33 ----D---- C:\Users\****\AppData\Roaming\Corel

2010-07-23 12:21:03 ----D---- C:\ProgramData\Ulead Systems

2010-07-23 12:21:03 ----D---- C:\Program Files\Common Files\Corel

2010-07-23 12:20:53 ----A---- C:\Windows\system32\xactengine2_10.dll

2010-07-23 12:20:53 ----A---- C:\Windows\system32\d3dx10_36.dll

2010-07-23 12:20:53 ----A---- C:\Windows\system32\D3DCompiler_36.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\xinput1_3.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\xactengine2_9.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\xactengine2_8.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\X3DAudio1_2.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx9_36.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx9_35.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx9_34.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx10_35.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\d3dx10_34.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\D3DCompiler_35.dll

2010-07-23 12:20:52 ----A---- C:\Windows\system32\D3DCompiler_34.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\xactengine2_7.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\xactengine2_6.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\xactengine2_5.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx9_33.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx9_32.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx10_33.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\d3dx10.dll

2010-07-23 12:20:51 ----A---- C:\Windows\system32\D3DCompiler_33.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xinput1_2.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xinput1_1.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xactengine2_4.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xactengine2_3.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\xactengine2_2.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\x3daudio1_1.dll

2010-07-23 12:20:50 ----A---- C:\Windows\system32\d3dx9_31.dll

2010-07-23 12:20:49 ----A---- C:\Windows\system32\xactengine2_1.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\xactengine2_0.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\x3daudio1_0.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_30.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_29.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_28.dll

2010-07-23 12:20:47 ----A---- C:\Windows\system32\d3dx9_27.dll

2010-07-23 12:20:46 ----A---- C:\Windows\system32\d3dx9_26.dll

2010-07-23 12:20:46 ----A---- C:\Windows\system32\d3dx9_25.dll

2010-07-23 12:20:46 ----A---- C:\Windows\system32\d3dx9_24.dll

2010-07-23 11:04:06 ----D---- C:\Program Files\Microsoft Silverlight

2010-07-22 12:12:49 ----D---- C:\Users\****\AppData\Roaming\Notepad++

2010-07-22 12:12:49 ----D---- C:\Program Files\Notepad++

2010-07-21 15:05:05 ----D---- C:\Users\****\AppData\Roaming\TortoiseSVN

2010-07-21 09:27:14 ----D---- C:\Program Files\Replisting

2010-07-16 16:54:43 ----D---- C:\Documents and Settings

2010-07-16 10:07:28 ----D---- C:\dataexport

2010-07-16 09:26:49 ----D---- C:\Windows\system32\Adobe

2010-07-13 09:36:11 ----D---- C:\temp

2010-07-13 08:39:27 ----A---- C:\Windows\system32\ntdll.dll

2010-07-13 08:39:26 ----A---- C:\Windows\system32\kernel32.dll

2010-07-13 08:39:26 ----A---- C:\Windows\system32\apphelp.dll

2010-07-07 14:48:42 ----A---- C:\Windows\vbaddin.ini

2010-07-07 14:48:25 ----A---- C:\Windows\ODBC.INI

2010-07-07 09:58:37 ----D---- C:\Program Files\XML Spy Suite

2010-07-07 09:58:37 ----D---- C:\Program Files\Altova

2010-07-07 09:57:35 ----D---- C:\Program Files\XML Spy Suite 4.4

2010-07-06 19:02:56 ----D---- C:\Users\****\AppData\Roaming\vlc

2010-07-06 19:02:44 ----D---- C:\Program Files\VideoLAN

 

======List of files/folders modified in the last 1 months======

 

2010-08-03 19:04:18 ----D---- C:\Windows\Prefetch

2010-08-03 19:04:07 ----D---- C:\Windows\Temp

2010-08-03 19:02:55 ----D---- C:\Windows\system32\drivers

2010-08-03 19:02:55 ----D---- C:\Windows\Offline Web Pages

2010-08-03 19:00:40 ----A---- C:\Windows\UEDIT32.INI

2010-08-03 18:47:27 ----RD---- C:\Program Files

2010-08-03 18:29:34 ----HD---- C:\ProgramData

2010-08-03 18:16:08 ----D---- C:\Eclipse3.5

2010-08-03 17:49:45 ----SHD---- C:\Windows\Installer

2010-08-03 17:49:45 ----D---- C:\Windows\system32\Tasks

2010-08-03 17:49:04 ----SHD---- C:\System Volume Information

2010-08-03 17:28:50 ----D---- C:\Windows\System32

2010-08-03 17:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI

2010-08-03 17:28:49 ----D---- C:\Windows\inf

2010-08-03 17:07:43 ----D---- C:\Windows

2010-08-03 12:28:26 ----D---- C:\Windows\system32\drivers\Avg

2010-08-02 18:57:55 ----D---- C:\Windows\system32\config

2010-07-30 17:46:14 ----D---- C:\Users\****\AppData\Roaming\uTorrent

2010-07-29 09:40:46 ----D---- C:\Program Files\Safari

2010-07-29 08:43:59 ----D---- C:\Windows\system32\catroot2

2010-07-28 11:28:12 ----D---- C:\ProgramData\Apple Computer

2010-07-26 14:58:29 ----D---- C:\Program Files\Mozilla Firefox

2010-07-23 12:22:15 ----D---- C:\Program Files\Common Files

2010-07-23 12:21:03 ----D---- C:\Program Files\Corel

2010-07-23 12:20:49 ----RSD---- C:\Windows\assembly

2010-07-23 12:20:48 ----D---- C:\Windows\Microsoft.NET

2010-07-23 12:20:40 ----D---- C:\Windows\winsxs

2010-07-23 12:15:36 ----D---- C:\Windows\Tasks

2010-07-22 16:50:05 ----D---- C:\SVN

2010-07-21 11:53:44 ----D---- C:\Program Files\Mozilla Thunderbird

2010-07-21 09:27:14 ----HD---- C:\Program Files\InstallShield Installation Information

2010-07-16 10:51:58 ----SD---- C:\Users\****\AppData\Roaming\Microsoft

2010-07-16 09:27:24 ----D---- C:\Windows\system32\Macromed

2010-07-16 08:22:59 ----D---- C:\Windows\system32\wdi

2010-07-13 08:39:52 ----D---- C:\Windows\system32\en-US

2010-07-13 08:39:51 ----D---- C:\Program Files\Microsoft.NET

2010-07-13 08:39:38 ----D---- C:\Windows\AppPatch

2010-07-13 08:39:25 ----D---- C:\Windows\system32\catroot

2010-07-09 12:32:35 ----D---- C:\Windows\system32\NDF

2010-07-07 14:49:22 ----D---- C:\ProgramData\Microsoft Help

2010-07-07 14:48:34 ----D---- C:\Program Files\Common Files\microsoft shared

2010-07-07 14:48:33 ----SD---- C:\ProgramData\Microsoft

 

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R0 amdxata;amdxata; C:\Windows\system32\DRIVERS\amdxata.sys [2009-07-14 23616]

R0 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys [2010-06-03 52872]

R0 CNG;CNG; C:\Windows\System32\Drivers\cng.sys [2009-07-14 369568]

R0 fvevol;@%SystemRoot%\system32\drivers\fvevol.sys,-100; C:\Windows\System32\DRIVERS\fvevol.sys [2009-09-26 194488]

R0 hwpolicy;@%systemroot%\system32\drivers\hwpolicy.sys,-101; C:\Windows\System32\drivers\hwpolicy.sys [2009-07-14 13904]

R0 KSecPkg;KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [2009-12-11 133720]

R0 pcw;Performance Counters for Windows Driver; C:\Windows\System32\drivers\pcw.sys [2009-07-14 43088]

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-06-03 691696]

R0 storflt;@%SystemRoot%\system32\vmstorfltres.dll,-1000; C:\Windows\system32\DRIVERS\vmstorfl.sys [2009-07-14 40896]

R0 vdrvroot;Microsoft Virtual Drive Enumerator Driver; C:\Windows\system32\DRIVERS\vdrvroot.sys [2009-07-14 32832]

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-06-23 216400]

R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-06-03 29584]

R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-06-23 243024]

R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]

R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]

R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]

R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]

R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2008-04-25 5120]

R3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]

R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]

R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]

R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]

R3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 20992]

R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]

R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]

R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]

R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]

S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys []

S3 a04no0rb;a04no0rb; C:\Windows\system32\drivers\a04no0rb.sys []

S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]

S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]

S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]

S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]

S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]

S3 AsrCDDrv;AsrCDDrv; \??\C:\Windows\system32\Drivers\AsrCDDrv.sys []

S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-14 430080]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]

S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2010-05-01 14336]

S3 drmkaud;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]

S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-14 3100160]

S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]

S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]

S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-14 26624]

S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]

S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]

S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]

S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]

S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]

S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]

S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]

S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]

S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]

S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]

S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]

S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]

S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]

S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]

S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]

S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]

S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]

S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]

S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]

S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]

S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]

 

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]

R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-21 921952]

R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-06-23 308136]

R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]

R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]

S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]

S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2010-05-11 271728]

S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]

S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]

S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-01 1343400]

S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]

 

-----------------EOF-----------------

 

 

Encore merci pour ton aide

Modifié par maxr397
Lien vers le commentaire
Partager sur d’autres sites

Windows 7 Pack 2? Ca existe ça?

 

Télécharge systemsr4.pngOTM de OldTimer sur ton Bureau en cliquant sur ce lien:

 

OTM

 

Ou ici: http://ottools.noahdfear.net/OTM.exe

 

  • Double-clique sur OTM.exe pour le lancer (l'extension .exe peut ne pas apparaître)
     
    ---> sous VISTA/7: clic droit: exécuter en temps qu'administrateur.
     
  • Copie l'entièreté du code ci-dessous.
    Go
    
    :Files
    C:\Windows\tasks\At1.job
    
    
    :Services
    
    :Reg
    
    :Commands
    
    [purity]
    [emptytemp]
    [start explorer]
    
    


     

  • Colle ce code dans la partie jaune de OtMoveIt3 intitulée:
    "Paste Instructions for Items to be Moved" img-025804xb055.png
     
  • Clique sur le bouton Moveit! pour lancer le nettoyage: img-025919bxiq4.png
     
  • Copie-colle dans ta prochaine réponse tout ce qui se trouve dans la fenêtre Results img-030027q93ue.png
    --> Un rapport sera généré dans le dossier C:\ _OTMoveIt\MovedFiles avec la date et l'heure du passage de l'outil (mmddyyyy_hhmmss.log)
  • Ferme OTM en cliquant sur Exit: img-030110c5gvf.png

Note : Si un fichier ou un dossier ne peut être supprimé directement, l'outil peut demander un redémarrage pour terminer le processus. Clique alors sur "Yes" pour accepter.

 

*** L'outil va terminer son travail après le redémarrage du pc puis fournira son rapport; copie/colle le dans ta réponse stp.

 

-----------------

Il semblerait qu'il y a d'anciennes versions de Java sur la machine.

Il faudra utiliser JavaRa pour supprimer leurs traces.

 

Assure toi que la console Java est bien la plus récente; pour le savoir rends-toi sur cette page et clique sur Vérifier la version de Java -> Vérification de l'installation de Java -> Il te sera indiqué si tu dois installer la dernière version.

Si tu installes une nouvelle version Java, désinstalle toutes les plus anciennes via ajout/suppr de programmes.

 

JavaRa ou désinstaller proprement les anciennes versions de la console Java

 

Fais un scan en ligne avec Kaspersky.

 

Va dans outils/options internet et sous l'onglet sécurité, clique sur "par défaut".

 

TUTO: Comment faire un scan en ligne avec Kaspersky : Aide pour supprimer les virus

 

Désactive ton antivirus le temps d'installation et de mises à jour du webscanner Kaspersky.

 


  • Fais un scan en ligne Kaspersky
  • Clique sur Accept
  • Patiente le temps d'installation du Webscanner.
  • Les bases de mises à jour vont s'installer, patiente un moment
  • Clique sur Next.
  • Clique sur My Computer, le scan se met en route; attends la fin du scan sans fermer la fenêtre sinon il s'arrêtera.

 

A la fin du scan, si des objets infectés sont découverts, clique sur Save report as... Choisis bureau et nomme le rapport "rapport Kaspersky" et dans le champ d'enregistrement, choisis "fichiers texte" enregistre alors le rapport.

 

Copie l'entièreté du fichier texte ouvert, par clic droit dessus, sélectionner tout/copier.

 

Colle ce rapport dans ta réponse sur le forum.

 

@++

Modifié par Apollo
Lien vers le commentaire
Partager sur d’autres sites

effectivement, le Windows 7 Professional Service Pack 2 est assez étonnant. Quand je fait clique droit sur le poste de travail puis propriété il m'indique bien Windows 7 Professional.

 

Voici le rapport OTM

All processes killed

Error: Unable to interpret <Go> in the current context!

========== FILES ==========

C:\Windows\tasks\At1.job moved successfully.

========== SERVICES/DRIVERS ==========

========== REGISTRY ==========

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: Administrator

->Temp folder emptied: 50465 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: ****

->Temp folder emptied: 54213 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->FireFox cache emptied: 7510902 bytes

->Flash cache emptied: 434 bytes

 

User: ****

->Temp folder emptied: 354137515 bytes

->Temporary Internet Files folder emptied: 1992263 bytes

->FireFox cache emptied: 50763330 bytes

 

User: ****

->Temp folder emptied: 1187009808 bytes

->Temporary Internet Files folder emptied: 87022172 bytes

->Java cache emptied: 455194 bytes

->FireFox cache emptied: 72443365 bytes

->Apple Safari cache emptied: 16463872 bytes

->Opera cache emptied: 13384627 bytes

->Flash cache emptied: 18348 bytes

 

User: Public

 

User: tmp

->Temp folder emptied: 35201 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 9327136 bytes

RecycleBin emptied: 178285469 bytes

 

Total Files Cleaned = 1'887.00 mb

 

 

OTM by OldTimer - Version 3.1.15.0 log created on 08052010_084155

 

 

et le rapport Kaspersky (assez fourni)

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7.0: scan report

Thursday, August 5, 2010

Operating system: Microsoft Professional (build 7600)

Kaspersky Online Scanner version: 7.0.26.13

Last database update: Thursday, August 05, 2010 02:32:08

Records in database: 4149482

--------------------------------------------------------------------------------

 

Scan settings:

scan using the following database: extended

Scan archives: yes

Scan e-mail databases: yes

 

Scan area - My Computer:

C:\

D:\

 

Scan statistics:

Objects scanned: 224945

Threats found: 91

Infected objects found: 1122

Suspicious objects found: 6

Scan duration: 02:21:02

 

 

File name / Threat / Threats count

C:\Program Files\UltraVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.gc 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Backdoor.Win32.Bredolab.bmi 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Packed.Win32.Krap.x 122

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Backdoor.Win32.Bredolab.btd 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Suspicious: Trojan-Spy.HTML.Fraud.gen 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Piker.brn 6

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Agent.dadz 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Genome.agbv 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Backdoor.Win32.Bredolab.cbb 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Genome.agcz 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Dropper.Win32.Agent.blhj 7

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Genome.agft 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Genome.agqa 6

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan.Win32.Pakes.nwx 7

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan.Win32.Pakes.nxe 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Backdoor.Win32.Small.iul 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan.Win32.Pakes.nxg 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan.Win32.Refroso.amdh 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Genome.ahet 14

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Downloader.Win32.Genome.ahoo 9

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Dropper.Win32.Agent.blua 9

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Dropper.Win32.Agent.bluf 10

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Backdoor.Win32.Bredolab.cfq 5

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX Infected: Trojan-Dropper.Win32.Agent.blwl 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Tdss.belr 17

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Tdss.beln 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Tdss.belo 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Agent.eefi 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.VBKrypt.zd 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Net-Worm.Win32.Koobface.gsu 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Worm.Win32.Mabezat.h 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.VBKrypt.yk 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Oficla.ak 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Agent.bmw 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.dz 55

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.ed 29

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.ek 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.JS.Pegel.g 72

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Oficla.bf 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.TDSS.bhjg 10

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.TDSS.bhkv 25

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.go 5

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.i 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.e 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Genome.kfpb 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.JS.Agent.flx 18

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.fj 21

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Agent.eihj 5

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Oficla.br 10

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.HTML.Agent.de 19

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.HTML.Agent.dc 31

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Zapchast.ef 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.jr 18

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.js 19

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.t 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.JS.Pegel.bk 24

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.u 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.JS.Pegel.bn 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.JS.Pegel.bm 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.HTML.Meta.d 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.HTML.Meta.g 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.jy 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.jx 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.jz 15

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.Win32.Small.kop 28

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.aj 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.ka 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.kb 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.kc 8

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.kd 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.kg 9

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Packed.Win32.Krap.hm 5

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.ki 7

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.JS.Redirector.kf 60

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.am 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.Win32.FraudLoad.gxk 52

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.Jorik.Oficla.as 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.Win32.FraudLoad.xeer 21

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Spy.Win32.Zbot.aloy 3

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Spy.Win32.Zbot.alpm 5

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan.Win32.FraudPack.bcet 2

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Backdoor.Win32.Bredolab.gii 6

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Spy.Win32.Zbot.alyp 1

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Backdoor.Win32.Bredolab.gmh 8

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.Win32.Genome.axwz 5

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Backdoor.Win32.Bredolab.gni 58

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Dropper.Win32.HDrop.jo 4

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Dropper.Win32.HDrop.jt 6

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Backdoor.Win32.Bredolab.gsg 12

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\Junk-2 Infected: Trojan-Downloader.Win32.Murlo.gxw 15

C:\Users\****\AppData\Roaming\Thunderbird\Profiles\yx6sk3ow.default\ImapMail\mail.****\INBOX.sbd\log Infected: Trojan.Win32.FakeAV.qq 1

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Backdoor.Win32.Bredolab.bmi 2

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Packed.Win32.Krap.x 67

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Backdoor.Win32.Bredolab.btd 4

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Suspicious: Trojan-Spy.HTML.Fraud.gen 3

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Downloader.Win32.Piker.brn 6

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Downloader.Win32.Agent.dadz 4

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Downloader.Win32.Genome.agbv 2

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Backdoor.Win32.Bredolab.cbb 2

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Downloader.Win32.Genome.agcz 3

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Dropper.Win32.Agent.blhj 7

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Downloader.Win32.Genome.agft 3

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan-Downloader.Win32.Genome.agqa 6

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan.Win32.Pakes.nwx 7

C:\Users\****\Documents\Thunderbird 3.0.4 (en-US) - 2010-06-03_2.pcv Infected: Trojan.Win32.Pakes.nxe 3

 

Selected area has been SCANNed.

 

Concernant Java, j'ai en effet le sdk 1.4 car je travaille sur une appli nécessitant cette version.

Modifié par maxr397
Lien vers le commentaire
Partager sur d’autres sites

Bonjour,

 

Il ne vaut rien AVG à ce que je constate.

 

Je te conseille tout d'abord de compacter tous les dossiers dans Thunderbird.

http://www.geckozone.org/articles/2006/07/22/119-le-compactage-dans-mozilla-thunderbird-et-seamonkey

 

Installe une version d'évaluation de 30 jours de Kaspersky Antivirus 2011.

 

Versions d'évaluation

 

Enregistre l'exécutable sur ton bureau.

 

Désinstalle ton antivirus ou ta suite de sécurité présente actuellement, de même que tous les antimachins divers tels Spybot, Ad-Aware, etc. (Incompatibles).

 

Tu pourras réinstaller ton logiciel dès la désinfection terminée.(Il faudra désinstaller Kaspersky, mais autant le laisser courir pendant les 30 jours.)

Ou alors, tu décideras à la fin de la période d'essai, si tu achètes une licence ou non, selon que tu en es satisfait ou non.

 

Installe Kaspersky, valide la licence d'évaluation puis fais les mises à jour.

 

Lance alors une analyse complète du pc.

 

Poste le rapport stp.

 

Tuto: Tutoriel - Kaspersky Internet Security 2010 c'est pour Internet Security mais cela comprend bien sûr les paramétrages de l'antivirus. ;)

 

@++

Lien vers le commentaire
Partager sur d’autres sites

J'ai donc compacté tous les dossiers mais je suis assez surpris par le comportement de Thunderbird (merci du conseil).

 

Je viens de terminer le scan avec Kaspersky dont voici le rapport (il n'a rien trouvé)

 

Analyse Complète: terminée : il y a 16 minutes (événements : 426, objets : 1138932, durée : 00:33:07)

05.08.2010 13:52:09 Fin de la tâche

05.08.2010 13:44:17 Compacté: Com2Exe C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_share.exe_bbb4488d/ExePack

05.08.2010 13:44:17 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_share.exe_bbb4488d

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_nlsfunc.exe_68d576d3

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_mem.exe_e5748c01

05.08.2010 13:44:16 Compacté: Com2Exe C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_fastopen.exe_34b8aa0e/ExePack

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_fastopen.exe_34b8aa0e

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_exe2bin.exe_584b170f

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_edlin.exe_420aa87c

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_edit.com_fc89ce91

05.08.2010 13:44:16 Compacté: ExePack C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d_debug.exe_bdafe3af

05.08.2010 13:40:32 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\netnvmx.inf_x86_neutral_7af3f06863f3b983\nvm60x32.sys

05.08.2010 13:40:32 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\netefe32.inf_x86_neutral_9590f3b23d1d64f3\e100b325.sys

05.08.2010 13:40:32 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\net8185.inf_x86_neutral_20a13cfe2956ed8a\RTL85n86.sys

05.08.2010 13:40:31 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\net44x32.inf_x86_neutral_70a6663fd52fa256\bcm4sbxp.sys

05.08.2010 13:40:27 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\VSTVIA3.SYS

05.08.2010 13:40:27 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\VSTSIS3.SYS

05.08.2010 13:40:27 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\VSTICH3.SYS

05.08.2010 13:40:26 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\VSTATI3.SYS

05.08.2010 13:40:26 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\VSTALI3.SYS

05.08.2010 13:40:25 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\mdmagrm.inf_x86_neutral_8ff94c5737626019\ltmdmnt.sys

05.08.2010 13:40:19 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\djsvs.inf_x86_neutral_836a3a3240941631\djsvs.sys

05.08.2010 13:40:19 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\divacx86.inf_x86_neutral_d9558f410186db36\dimaint.sys

05.08.2010 13:40:19 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\divacx86.inf_x86_neutral_d9558f410186db36\dicowan.sys

05.08.2010 13:40:18 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\divacx86.inf_x86_neutral_d9558f410186db36\dicapi.sys

05.08.2010 13:40:16 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\dc21x4vm.inf_x86_neutral_8887242a56ee027e\dc21x4vm.sys

05.08.2010 13:40:13 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\brmfcwia.inf_x86_neutral_2d38149df9cd17c4\BrUsbScn.sys

05.08.2010 13:40:13 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\brmfcwia.inf_x86_neutral_2d38149df9cd17c4\BrParImg.sys

05.08.2010 13:40:12 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\brmfcmf.inf_x86_neutral_33717b093227cd8c\BrParwdm.sys

05.08.2010 13:40:12 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\brmfcmf.inf_x86_neutral_33717b093227cd8c\BrFilt.sys

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fxusbase.sys

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fus2base.sys

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fpcmbase.sys

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fpcibase.sys

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\b1cbase.sys

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\avmcowan.sys

05.08.2010 13:40:11 Compacté: MIME.Broken C:\Windows\System32\DriverStore\FileRepository\atiriolh.inf_x86_neutral_cdb610d99bcbc631\CTRL.s3

05.08.2010 13:40:11 Compacté: PE_Patch C:\Windows\System32\DriverStore\FileRepository\atiriolh.inf_x86_neutral_cdb610d99bcbc631\atinavrr.sys

05.08.2010 13:40:00 Compacté: VBSComment C:\Windows\Installer\ca7136.msi/Data1.cab/test_errno.py.0160FC08_F3D9_4869_9D41_C611C16F42D5

05.08.2010 13:39:53 Compacté: PECompact C:\Windows\System32\Adobe\Shockwave 11\gt.exe/PE_Patch.PECompact/PecBundle

05.08.2010 13:39:53 Compacté: PecBundle C:\Windows\System32\Adobe\Shockwave 11\gt.exe/PE_Patch.PECompact

05.08.2010 13:39:53 Compacté: PE_Patch.PECompact C:\Windows\System32\Adobe\Shockwave 11\gt.exe

05.08.2010 13:39:52 Compacté: PECompact C:\Windows\Installer\ca714b.msi/ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:39:52 Compacté: PecBundle C:\Windows\Installer\ca714b.msi/ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:39:52 Compacté: PE_Patch.PECompact C:\Windows\Installer\ca714b.msi/ISSetup.dll

05.08.2010 13:39:47 Compacté: Com2Exe C:\Windows\System32\share.exe/ExePack

05.08.2010 13:39:47 Compacté: ExePack C:\Windows\System32\share.exe

05.08.2010 13:39:43 Compacté: ExePack C:\Windows\System32\nlsfunc.exe

05.08.2010 13:39:40 Compacté: ExePack C:\Windows\System32\mem.exe

05.08.2010 13:39:35 Compacté: Com2Exe C:\Windows\System32\fastopen.exe/ExePack

05.08.2010 13:39:35 Compacté: ExePack C:\Windows\System32\fastopen.exe

05.08.2010 13:39:35 Compacté: ExePack C:\Windows\System32\exe2bin.exe

05.08.2010 13:39:35 Compacté: ExePack C:\Windows\System32\edlin.exe

05.08.2010 13:39:34 Compacté: ExePack C:\Windows\System32\debug.exe

05.08.2010 13:39:34 Compacté: PECompact C:\Windows\Installer\ca7147.msi/ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:39:34 Compacté: PecBundle C:\Windows\Installer\ca7147.msi/ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:39:34 Compacté: PE_Patch.PECompact C:\Windows\Installer\ca7147.msi/ISSetup.dll

05.08.2010 13:39:00 Compacté: PECompact C:\Windows\Installer\ca7136.msi/ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:38:59 Compacté: PecBundle C:\Windows\Installer\ca7136.msi/ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:38:59 Compacté: PE_Patch.PECompact C:\Windows\Installer\ca7136.msi/ISSetup.dll

05.08.2010 13:38:59 Compacté: PECompact C:\Windows\Installer\ca6e9b.msi/ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:38:59 Compacté: PecBundle C:\Windows\Installer\ca6e9b.msi/ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:38:59 Compacté: PE_Patch.PECompact C:\Windows\Installer\ca6e9b.msi/ISSetup.dll

05.08.2010 13:38:57 Compacté: Swf2Swc C:\Windows\Installer\28de48.msi/Data1.cab/MEDIAPLAYER_UA_FILE_ID/public_html/soundmanager2_flash9.swf

05.08.2010 13:38:57 Compacté: Swf2Swc C:\Windows\Installer\28de48.msi/Data1.cab/MEDIAPLAYER_UA_FILE_ID/public_html/soundmanager2wii.swf

05.08.2010 13:38:57 Compacté: Swf2Swc C:\Windows\Installer\28de48.msi/Data1.cab/MEDIAPLAYER_UA_FILE_ID/public_html/soundmanager2.swf

05.08.2010 13:38:57 Compacté: Swf2Swc C:\Windows\Installer\28de48.msi/Data1.cab/MEDIAPLAYER_UA_FILE_ID/public_html/MessageProxy.swf

05.08.2010 13:38:53 Compacté: ASPack C:\Windows\Installer\28de48.msi/Data1.cab/NETSCAPE_EXE_FILE_ID

05.08.2010 13:38:53 Compacté: UPX C:\Windows\Installer\28de48.msi/Data1.cab/OUNIANSI_DLL_FILE_ID/PE_Patch.UPX

05.08.2010 13:38:53 Compacté: PE_Patch.UPX C:\Windows\Installer\28de48.msi/Data1.cab/OUNIANSI_DLL_FILE_ID

05.08.2010 13:38:51 Compacté: UPX C:\Windows\Installer\28de48.msi/Data1.cab/OPERA_DLL_FILE_ID/PE_Patch.UPX

05.08.2010 13:38:50 Compacté: PE_Patch.UPX C:\Windows\Installer\28de48.msi/Data1.cab/OPERA_DLL_FILE_ID

05.08.2010 13:38:48 Compacté: PECompact C:\Windows\Installer\1fe3414b.msi/ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:38:48 Compacté: PecBundle C:\Windows\Installer\1fe3414b.msi/ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:38:48 Compacté: PE_Patch.PECompact C:\Windows\Installer\1fe3414b.msi/ISSetup.dll

05.08.2010 13:37:45 Compacté: Swf2Swc C:\Users\****\workspace\****\****\images\.svn\text-base\open-flash-chart.swf.svn-base

05.08.2010 13:37:45 Compacté: Swf2Swc C:\Users\****\workspace\****\****\images\open-flash-chart.swf

05.08.2010 13:36:28 Compacté: UPX C:\Users\****\Downloads\HJTInstall.exe/#/PE_Patch.UPX

05.08.2010 13:36:28 Compacté: PECompact C:\Users\****\Downloads\Shockwave_Installer_Slim.exe/data0022/PE_Patch.PECompact/PecBundle

05.08.2010 13:36:28 Compacté: PE_Patch.UPX C:\Users\****\Downloads\HJTInstall.exe/#

05.08.2010 13:36:28 Compacté: PecBundle C:\Users\****\Downloads\Shockwave_Installer_Slim.exe/data0022/PE_Patch.PECompact

05.08.2010 13:36:28 Compacté: PE_Patch.PECompact C:\Users\****\Downloads\Shockwave_Installer_Slim.exe/data0022

05.08.2010 13:36:27 Compacté: UPX C:\Users\****\Downloads\HJTInstall.exe/data0000.res/PE_Patch.UPX

05.08.2010 13:36:27 Compacté: PE_Patch.UPX C:\Users\****\Downloads\HJTInstall.exe/data0000.res

05.08.2010 13:35:19 Compacté: ASProtect C:\Users\****\Documents\Plateforme_JAVA.zip/Plateforme_JAVA/EMS/PostgreSQL Manager 3 Lite/Upgrade.exe/PE_Patch

05.08.2010 13:35:19 Compacté: PE_Patch C:\Users\****\Documents\Plateforme_JAVA.zip/Plateforme_JAVA/EMS/PostgreSQL Manager 3 Lite/Upgrade.exe

05.08.2010 13:35:18 Compacté: ASProtect C:\Users\****\Documents\Plateforme_JAVA.zip/Plateforme_JAVA/EMS/PostgreSQL Manager 3 Lite/PgManager.exe/PE_Patch

05.08.2010 13:35:18 Compacté: ASProtect C:\Users\****\Documents\Plateforme_JAVA\EMS\PostgreSQL Manager 3 Lite\PgManager.exe/PE_Patch

05.08.2010 13:35:17 Compacté: PE_Patch C:\Users\****\Documents\Plateforme_JAVA.zip/Plateforme_JAVA/EMS/PostgreSQL Manager 3 Lite/PgManager.exe

05.08.2010 13:35:17 Compacté: ASProtect C:\Users\****\Documents\Plateforme_JAVA\EMS\PostgreSQL Manager 3 Lite\Upgrade.exe/PE_Patch

05.08.2010 13:35:17 Compacté: PE_Patch C:\Users\****\Documents\Plateforme_JAVA\EMS\PostgreSQL Manager 3 Lite\PgManager.exe

05.08.2010 13:35:17 Compacté: PE_Patch C:\Users\****\Documents\Plateforme_JAVA\EMS\PostgreSQL Manager 3 Lite\Upgrade.exe

05.08.2010 13:31:53 Compacté: VBSComment C:\Users\****\Desktop\SPSS 17\SPSS 17 Setup.exe/WWD.cab/script_with_parameter.wwd

05.08.2010 13:31:51 Compacté: PE_Patch C:\Users\****\Desktop\SPSS 17\SPSS 17 Setup.exe/WindowsInstaller-KB893803-x86.exe

05.08.2010 13:31:51 Compacté: PECompact C:\Users\****\Desktop\SPSS 17\SPSS 17 Setup.exe/SPSS Statistics 17.0.msi/ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:31:51 Compacté: PecBundle C:\Users\****\Desktop\SPSS 17\SPSS 17 Setup.exe/SPSS Statistics 17.0.msi/ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:31:51 Compacté: PE_Patch.PECompact C:\Users\****\Desktop\SPSS 17\SPSS 17 Setup.exe/SPSS Statistics 17.0.msi/ISSetup.dll

05.08.2010 13:31:09 Compacté: UPX C:\Users\****\Documents\Downloads\utorrent.exe

05.08.2010 13:31:07 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/tools/ubcd2iso/mkisofs.exe

05.08.2010 13:31:06 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/gwscn511/GWSCAN.EXE

05.08.2010 13:31:06 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/gwscn315/gwscan.exe

05.08.2010 13:31:06 Compacté: Diet C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/gwscn315/gwscan.exe

05.08.2010 13:31:06 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/fprot/FPROT.EXE

05.08.2010 13:31:05 Compacté: PkLite C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/filelink/FILELINK.EXE

05.08.2010 13:31:05 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/fdisk/fdisk.exe/Apack

05.08.2010 13:31:05 Compacté: Apack C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/fdisk/fdisk.exe

05.08.2010 13:31:05 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/dlgdiag5/DLGDIAG5.EXE

05.08.2010 13:31:05 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/dlgdiag4/dlgdiag.exe

05.08.2010 13:31:05 Compacté: Com2Exe C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/diskman4/diskman4.exe/Apack

05.08.2010 13:31:05 Compacté: Apack C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/diskman4/diskman4.exe

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/copyrdma/copyr.exe

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/cmospwd/cmospwd.exe

05.08.2010 13:31:05 Compacté: ExePack C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/cdindex/cdi.exe

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/bughunt/LOCATE.COM

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/bughunt/BUGHUNT.EXE

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/bios/Bios.exe

05.08.2010 13:31:05 Compacté: WWPACK C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/bench/bench.exe

05.08.2010 13:31:05 Compacté: PkLite C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/atainf/scsiping.exe

05.08.2010 13:31:05 Compacté: PkLite C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/atainf/atainf09.exe

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/astra/astra.prg

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/astra/ASTRA32.DLL

05.08.2010 13:31:05 Compacté: Apack C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/astra/ASTRA.EXE

05.08.2010 13:31:05 Compacté: UPX C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/aida16/aida.exe

05.08.2010 13:31:04 Compacté: ExePack C:\Users\****\Documents\Downloads\ubcd411.zip/ubcd411.iso/dosapps/3dbench/3dbench.exe

05.08.2010 13:31:00 Compacté: UPX C:\Users\****\Documents\Downloads\Super_Pi.exe

05.08.2010 13:30:59 Compacté: PE_Patch C:\Users\****\Documents\Downloads\Silverlight.exe

05.08.2010 13:30:58 Compacté: PECompact C:\Users\****\Documents\Downloads\Shockwave_Installer_Slim.exe/data0022/PE_Patch.PECompact/PecBundle

05.08.2010 13:30:57 Compacté: PecBundle C:\Users\****\Documents\Downloads\Shockwave_Installer_Slim.exe/data0022/PE_Patch.PECompact

05.08.2010 13:30:57 Compacté: PE_Patch.PECompact C:\Users\****\Documents\Downloads\Shockwave_Installer_Slim.exe/data0022

05.08.2010 13:30:46 Compacté: PE_Patch C:\Users\****\Documents\Downloads\picasa36-setup.exe/data0000.res/data0000.res/data0022

05.08.2010 13:30:46 Compacté: PE_Patch C:\Users\****\Documents\Downloads\picasa36-setup.exe/data0000.res/data0000.res/data0011

05.08.2010 13:30:45 Compacté: UPX C:\Users\****\Documents\Downloads\pdfediteur!.exe/#

05.08.2010 13:30:44 Compacté: UPX C:\Users\****\Documents\Downloads\pdfediteur!.exe/data0000

05.08.2010 13:30:22 Compacté: UPX C:\Users\****\Desktop\SPSS 17\keygen.exe/PE_Patch.UPX

05.08.2010 13:30:22 Compacté: Swf2Swc C:\Users\****\Documents\4383.swf

05.08.2010 13:30:22 Compacté: PE_Patch.UPX C:\Users\****\Desktop\SPSS 17\keygen.exe

05.08.2010 13:29:57 Compacté: PE_Patch C:\Users\****\Desktop\office 2007\riz-office07sp1fr.iso/Enterpri.WW/EnterWW.cab/GROOVE.EXE

05.08.2010 13:29:51 Compacté: Swf2Swc C:\Users\****\Desktop\old Desktop\inter****-tomcat\images\flash\en\diaryExample.swf

05.08.2010 13:29:51 Compacté: Swf2Swc C:\Users\****\Desktop\old Desktop\inter****-tomcat\images\audio\xspf_player_slim.swf

05.08.2010 13:29:51 Compacté: Swf2Swc C:\Users\****\Desktop\old Desktop\inter****-tomcat\images\audio\mp3player.swf

05.08.2010 13:28:57 Compacté: Swf2Swc C:\Users\****\AppData\Local\Mozilla\Firefox\Profiles\maerialm.default\Cache\DA17B4E5d01

05.08.2010 13:28:55 Compacté: Edit C:\Users\****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EK710QSF\style[1].css

05.08.2010 13:28:55 Compacté: Swf2Swc C:\Users\****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EK710QSF\AE154A2D56898EAB1FD34E82ECD20[1].swf

05.08.2010 13:28:55 Compacté: Swf2Swc C:\Users\****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EK710QSF\1276001317_300x250_Boursorama_sansfrais[1].swf

05.08.2010 13:28:52 Compacté: PE_Patch C:\Users\****\Desktop\office 2007\add-in-odf-pour-microsoft-word_add-in_odf_pour_microsoft_word_francais_31748.exe/data0000.cab/office2003-kb907417sfxcab-ENU.exe

05.08.2010 13:28:51 Compacté: UPX C:\Users\****\Desktop\Mozilla\Thunderbird\Thunderbird Setup 3.0.exe/PE_Patch.UPX

05.08.2010 13:28:51 Compacté: PE_Patch.UPX C:\Users\****\Desktop\Mozilla\Thunderbird\Thunderbird Setup 3.0.exe

05.08.2010 13:28:51 Compacté: UPX C:\Users\****\Desktop\Mozilla\Thunderbird\Thunderbird Setup 2.0.0.23.exe/PE_Patch.UPX

05.08.2010 13:28:51 Compacté: PE_Patch.UPX C:\Users\****\Desktop\Mozilla\Thunderbird\Thunderbird Setup 2.0.0.23.exe

05.08.2010 13:28:47 Compacté: UPX C:\Users\****\Desktop\Mozilla\Sunbird\sunbird-0.9.en-US.win32.installer.exe

05.08.2010 13:28:43 Compacté: UPX C:\Users\****\Desktop\Mozilla\Firefox\Firefox Setup 3.6.3.exe/PE_Patch.UPX

05.08.2010 13:28:43 Compacté: PE_Patch.UPX C:\Users\****\Desktop\Mozilla\Firefox\Firefox Setup 3.6.3.exe

05.08.2010 13:28:41 Compacté: Swf2Swc C:\Users\****\workspace.zip/workspace/****/****/images/open-flash-chart.swf

05.08.2010 13:28:41 Compacté: Swf2Swc C:\Users\****\workspace.zip/workspace/****/****/images/.svn/text-base/open-flash-chart.swf.svn-base

05.08.2010 13:28:39 Compacté: UPX C:\Users\****\Desktop\Mozilla\Firefox\Firefox Setup 3.5.2.exe/PE_Patch.UPX

05.08.2010 13:28:39 Compacté: PE_Patch.UPX C:\Users\****\Desktop\Mozilla\Firefox\Firefox Setup 3.5.2.exe

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0199

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0194

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0188

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0183

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0178

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0174

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0164

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0159

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0154

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0199

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0151

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0141

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0137

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0194

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0188

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0125

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0183

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0178

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0121

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0112

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0174

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0164

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0109

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0159

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0101

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0154

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0151

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0141

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0098

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0137

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0090

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0086

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0125

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0076

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.23-340.zip/cs2_setup.exe/data0069

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0121

05.08.2010 13:28:35 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0112

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0109

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0101

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0098

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0090

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0086

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0076

05.08.2010 13:28:34 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio2.22-335.zip/cs2_setup.exe/data0069

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0246

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0237

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0231

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0222

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0217

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0209

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0199

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0189

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0184

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0181

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0167

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0163

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0147

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0199

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0194

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0188

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0183

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0178

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0174

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0164

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0159

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0154

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0142

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0129

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0151

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0141

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0137

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0125

05.08.2010 13:28:32 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0125

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0113

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0121

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0112

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0109

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0097

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0093

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0079

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0109

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0101

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.25.zip/cs2_setup.exe/data0072

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0098

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0090

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0086

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0076

05.08.2010 13:28:31 Compacté: Swf2Swc C:\Users\****\Desktop\CaseStudio\casestudio-2.23.1-341.zip/cs2setup.exe/data0069

05.08.2010 13:27:53 Compacté: Edit C:\SVN\****\aes.war/WEB-INF/lib/svg.jar/dtds/svg-20001102.dtd

05.08.2010 13:27:53 Compacté: Edit C:\SVN\****\aes.war/WEB-INF/lib/svg.jar/dtds/svg-20000802.dtd

05.08.2010 13:27:53 Compacté: Edit C:\SVN\****\aes.war/WEB-INF/lib/svg.jar/dtds/svg-20000629.dtd

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\no\sarahStep2.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\no\example1step5a.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\nl\exampleEmotions_nl.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\nl\diaryExample.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\it\sarahStep2.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\fr\diaryExample.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\es\sarahStep2.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\en\diaryExample.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\flash\de\diaryExample.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\audio\xspf_player_slim.swf

05.08.2010 13:27:51 Compacté: Swf2Swc C:\Tomcat-5.0\webapps\****\images\audio\mp3player.swf

05.08.2010 13:27:46 Compacté: Edit C:\SVN\****\shg\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20001102.dtd

05.08.2010 13:27:46 Compacté: Edit C:\SVN\****\shg\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000802.dtd

05.08.2010 13:27:46 Compacté: Edit C:\SVN\****\shg\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000629.dtd

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\sv\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\sv\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\no\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\no\.svn\text-base\example1step5a.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\no\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\nl\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\no\example1step5a.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\nl\.svn\text-base\example1step5a.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\nl\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\it\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\nl\example1step5a.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\it\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\fr\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\fr\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\es\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\es\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\en\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\en\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\de\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\de\sarahStep2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\.svn\text-base\animsun3.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\.svn\text-base\animsun2.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\.svn\text-base\animsun.swf.svn-base

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\animsun3.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\animsun2.swf

05.08.2010 13:27:32 Compacté: Swf2Swc C:\SVN\****\shg\images\flash\animsun.swf

05.08.2010 13:27:27 Compacté: Swf2Swc C:\SVN\****\aes.war/images/flash/en/sarahStep2.swf

05.08.2010 13:27:27 Compacté: Swf2Swc C:\SVN\****\aes.war/images/flash/de/sarahStep2.swf

05.08.2010 13:27:27 Compacté: Swf2Swc C:\SVN\****\aes.war/images/flash/animsun3.swf

05.08.2010 13:27:27 Compacté: Swf2Swc C:\SVN\****\aes.war/images/flash/animsun2.swf

05.08.2010 13:27:27 Compacté: Swf2Swc C:\SVN\****\aes.war/images/flash/animsun.swf

05.08.2010 13:27:16 Compacté: Edit C:\SVN\****_PSH\****\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20001102.dtd

05.08.2010 13:27:16 Compacté: Edit C:\SVN\****_PSH\****\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000802.dtd

05.08.2010 13:27:16 Compacté: Edit C:\SVN\****_PSH\****\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000629.dtd

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\no\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\no\.svn\text-base\example1step5a.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\no\sarahStep2.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\no\example1step5a.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\nl\.svn\text-base\exampleEmotions_nl.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\nl\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\nl\exampleEmotions_nl.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\nl\diaryExample.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\it\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\it\sarahStep2.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\fr\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\es\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\fr\diaryExample.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\es\sarahStep2.swf

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\en\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:27:06 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\flash\en\diaryExample.swf

05.08.2010 13:27:05 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\audio\.svn\text-base\xspf_player_slim.swf.svn-base

05.08.2010 13:27:05 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\audio\.svn\text-base\mp3player.swf.svn-base

05.08.2010 13:27:05 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\audio\xspf_player_slim.swf

05.08.2010 13:27:05 Compacté: Swf2Swc C:\SVN\****_PSH\****\images\audio\mp3player.swf

05.08.2010 13:27:00 Compacté: Edit C:\SVN\****\inter****.war/WEB-INF/lib/svg.jar/dtds/svg-20001102.dtd

05.08.2010 13:27:00 Compacté: Edit C:\SVN\****\inter****.war/WEB-INF/lib/svg.jar/dtds/svg-20000802.dtd

05.08.2010 13:27:00 Compacté: Edit C:\SVN\****\inter****.war/WEB-INF/lib/svg.jar/dtds/svg-20000629.dtd

05.08.2010 13:26:52 Compacté: Edit C:\SVN\****\****\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20001102.dtd

05.08.2010 13:26:52 Compacté: Edit C:\SVN\****\****\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000802.dtd

05.08.2010 13:26:52 Compacté: Edit C:\SVN\****\****\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000629.dtd

05.08.2010 13:26:44 Compacté: Edit C:\SVN\****\jeu\WEB-INF\lib\svg.jar/dtds/svg-20001102.dtd

05.08.2010 13:26:44 Compacté: Edit C:\SVN\****\jeu\WEB-INF\lib\svg.jar/dtds/svg-20000802.dtd

05.08.2010 13:26:44 Compacté: Edit C:\SVN\****\jeu\WEB-INF\lib\svg.jar/dtds/svg-20000629.dtd

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\no\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\no\.svn\text-base\example1step5a.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\no\sarahStep2.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\no\example1step5a.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\nl\.svn\text-base\exampleEmotions_nl.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\nl\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\it\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\nl\exampleEmotions_nl.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\nl\diaryExample.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\it\sarahStep2.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\fr\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\fr\diaryExample.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\es\.svn\text-base\sarahStep2.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\en\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\es\sarahStep2.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\en\diaryExample.swf

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\de\.svn\text-base\diaryExample.swf.svn-base

05.08.2010 13:26:31 Compacté: Swf2Swc C:\SVN\****\****\images\flash\de\diaryExample.swf

05.08.2010 13:26:30 Compacté: Swf2Swc C:\SVN\****\****\images\audio\.svn\text-base\xspf_player_slim.swf.svn-base

05.08.2010 13:26:30 Compacté: Swf2Swc C:\SVN\****\****\images\audio\.svn\text-base\mp3player.swf.svn-base

05.08.2010 13:26:30 Compacté: Swf2Swc C:\SVN\****\****\images\audio\xspf_player_slim.swf

05.08.2010 13:26:30 Compacté: Swf2Swc C:\SVN\****\****\images\audio\mp3player.swf

05.08.2010 13:26:29 Compacté: Swf2Swc C:\SVN\****\inter****.war/images/flash/en/diaryExample.swf

05.08.2010 13:26:29 Compacté: Swf2Swc C:\SVN\****\inter****.war/images/audio/xspf_player_slim.swf

05.08.2010 13:26:29 Compacté: Swf2Swc C:\SVN\****\inter****.war/images/audio/mp3player.swf

05.08.2010 13:26:19 Compacté: Edit C:\SVN\****\jeu\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20001102.dtd

05.08.2010 13:26:19 Compacté: Edit C:\SVN\****\jeu\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000802.dtd

05.08.2010 13:26:19 Compacté: Edit C:\SVN\****\jeu\WEB-INF\lib\.svn\text-base\svg.jar.svn-base/dtds/svg-20000629.dtd

05.08.2010 13:26:07 Compacté: Swf2Swc C:\SVN\****\jeu\images\flash\fr\.svn\text-base\cerveauArrow.swf.svn-base

05.08.2010 13:26:07 Compacté: Swf2Swc C:\SVN\****\jeu\images\flash\fr\cerveauArrow.swf

05.08.2010 13:26:07 Compacté: Swf2Swc C:\SVN\****\jeu\images\flash\fr\.svn\text-base\intro.swf.svn-base

05.08.2010 13:26:07 Compacté: Swf2Swc C:\SVN\****\jeu\images\flash\fr\intro.swf

05.08.2010 13:25:44 Compacté: UPX C:\Program Files\uTorrent\uTorrent.exe

05.08.2010 13:25:43 Compacté: UPX C:\Program Files\trend micro\****.exe/PE_Patch.UPX

05.08.2010 13:25:43 Compacté: PE_Patch.UPX C:\Program Files\trend micro\****.exe

05.08.2010 13:25:38 Compacté: VBSComment C:\Program Files\SPSSInc\Statistics17\Samples\Script with parameter.wwd

05.08.2010 13:25:20 Compacté: UPX C:\Program Files\SPSSInc\Statistics17\law.exe

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\SimpleBlue\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\SimpleBlue\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\SeptemberIE\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\SeptemberIE\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Printer\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Printer\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Mozilla\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Mozilla\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Fox\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Fox\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Cool\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Cool\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Classic\Yellow\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Classic\Yellow\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Classic\Violet\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Classic\Violet\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Classic\Green\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Classic\Green\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Aqua_yellow\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Aqua_yellow\leftFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Aqua_blue\topFrame.swf

05.08.2010 13:25:19 Compacté: Swf2Swc C:\Program Files\RKSoft\CASEStudio2\Styles\Aqua_blue\leftFrame.swf

05.08.2010 13:25:15 Compacté: Swf2Swc C:\Program Files\Opera\unite\mediaPlayer.ua/public_html/soundmanager2_flash9.swf

05.08.2010 13:25:15 Compacté: Swf2Swc C:\Program Files\Opera\unite\mediaPlayer.ua/public_html/soundmanager2wii.swf

05.08.2010 13:25:15 Compacté: Swf2Swc C:\Program Files\Opera\unite\mediaPlayer.ua/public_html/soundmanager2.swf

05.08.2010 13:25:15 Compacté: Swf2Swc C:\Program Files\Opera\unite\mediaPlayer.ua/public_html/MessageProxy.swf

05.08.2010 13:25:14 Compacté: UPX C:\Program Files\Opera\opera.dll/PE_Patch.UPX

05.08.2010 13:25:14 Compacté: ASPack C:\Program Files\Opera\program\netscape.exe

05.08.2010 13:25:13 Compacté: PE_Patch.UPX C:\Program Files\Opera\opera.dll

05.08.2010 13:25:13 Compacté: UPX C:\Program Files\Opera\OUniAnsi.dll/PE_Patch.UPX

05.08.2010 13:25:13 Compacté: PE_Patch.UPX C:\Program Files\Opera\OUniAnsi.dll

05.08.2010 13:24:12 Compacté: UPX C:\Program Files\InstallShield Installation Information\{F8855CFD-73C1-42E5-A431-78CAE7ACBBF1}\ISSetup.dll

05.08.2010 13:24:11 Compacté: UPX C:\Program Files\InstallShield Installation Information\{CC5EE390-9E19-496E-B776-0238620130D9}\ISSetup.dll

05.08.2010 13:24:11 Compacté: PECompact C:\Program Files\InstallShield Installation Information\{91029ED4-04B8-40EF-A70F-30C9AA538358}\ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:24:11 Compacté: PecBundle C:\Program Files\InstallShield Installation Information\{91029ED4-04B8-40EF-A70F-30C9AA538358}\ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:24:11 Compacté: PE_Patch.PECompact C:\Program Files\InstallShield Installation Information\{91029ED4-04B8-40EF-A70F-30C9AA538358}\ISSetup.dll

05.08.2010 13:24:11 Compacté: PECompact C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISSetup.dll/PE_Patch.PECompact/PecBundle

05.08.2010 13:24:11 Compacté: PecBundle C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISSetup.dll/PE_Patch.PECompact

05.08.2010 13:24:11 Compacté: PE_Patch.PECompact C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISSetup.dll

05.08.2010 13:24:11 Compacté: WiseSFXDropper C:\Program Files\InstallShield Installation Information\{682F7326-6DAF-4088-8313-23E7DA9F78E8}\SM\SPanel\Help\Flash_Shockwave_Full.exe/WiseSFXDropper/SHOCKWAVE_INSTALLER_FULL.EXE

05.08.2010 13:24:11 Compacté: WiseSFXDropper C:\Program Files\InstallShield Installation Information\{682F7326-6DAF-4088-8313-23E7DA9F78E8}\SM\SPanel\Help\Flash_Shockwave_Full.exe

05.08.2010 13:24:10 Compacté: UPX C:\Program Files\InstallShield Installation Information\{682F7326-6DAF-4088-8313-23E7DA9F78E8}\ISSetup.dll

05.08.2010 13:24:09 Compacté: WiseSFXDropper C:\Program Files\DELL\Dell 2335dn MFP\SPanel\Help\Flash_Shockwave_Full.exe/WiseSFXDropper/SHOCKWAVE_INSTALLER_FULL.EXE

05.08.2010 13:24:09 Compacté: WiseSFXDropper C:\Program Files\DELL\Dell 2335dn MFP\SPanel\Help\Flash_Shockwave_Full.exe

05.08.2010 13:24:01 Compacté: VBSComment C:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Python Libraries\Lib\test\test_errno.py

05.08.2010 13:23:31 Compacté: PE_Patch C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\WindowsInstallerKB893803v2x86.exe

05.08.2010 13:21:01 Compacté: Edit C:\Eclipse3.5\plugins\org.eclipse.datatools.sqltools.result.ui_1.0.1.v200908070830.jar/META-INF/ECLIPSEF.SF

05.08.2010 13:21:01 Compacté: Edit C:\Eclipse3.5\plugins\org.eclipse.datatools.sqltools.result.ui_1.0.0.v200906022302.jar/META-INF/ECLIPSEF.SF

05.08.2010 13:20:17 Compacté: PE_Patch C:\Program Files\DAEMON Tools Lite\Engine.dll/data0007.res

05.08.2010 13:20:15 Compacté: UPX C:\Users\****\Desktop\RSIT.exe/PE_Patch.UPX

05.08.2010 13:20:15 Compacté: PE_Patch.UPX C:\Users\****\Desktop\RSIT.exe

05.08.2010 13:20:14 Compacté: PECompact C:\Users\****\Desktop\OTM.exe/PE_Patch.PECompact/PecBundle

05.08.2010 13:20:14 Compacté: PecBundle C:\Users\****\Desktop\OTM.exe/PE_Patch.PECompact

05.08.2010 13:20:14 Compacté: PE_Patch.PECompact C:\Users\****\Desktop\OTM.exe

05.08.2010 13:19:23 Compacté: ExePack C:\Windows\System32\edit.com

05.08.2010 13:19:17 Compacté: PE_Patch C:\Windows\System32\drivers\nfrd960.sys

05.08.2010 13:19:16 Compacté: PE_Patch C:\Windows\System32\drivers\iirsp.sys/PE_Patch

05.08.2010 13:19:16 Compacté: PE_Patch C:\Windows\System32\drivers\iirsp.sys

05.08.2010 13:19:15 Compacté: PE_Patch C:\Windows\System32\drivers\djsvs.sys

05.08.2010 13:19:09 Non réparés: Rootkit.Win32.TDSS.d System Memory Reporté

05.08.2010 13:19:02 Détectés: Rootkit.Win32.TDSS.d System Memory

05.08.2010 13:19:02 Lancement de la tâche

05.08.2010 13:16:23 Tâche arrêtée

05.08.2010 13:16:09 Détectés: Rootkit.Win32.TDSS.d System Memory

05.08.2010 13:16:09 Lancement de la tâche

Réparation des menaces actives: terminée : il y a 51 minutes (événements : 27, objets : 5736, durée : 00:01:01)

05.08.2010 13:17:24 Fin de la tâche

05.08.2010 13:17:11 Compacté: PE_Patch C:\Program Files\DAEMON Tools Lite\Engine.dll/data0007.res

05.08.2010 13:17:09 Compacté: UPX C:\Users\****\Desktop\RSIT.exe/PE_Patch.UPX

05.08.2010 13:17:09 Compacté: PE_Patch.UPX C:\Users\****\Desktop\RSIT.exe

05.08.2010 13:17:08 Compacté: PECompact C:\Users\****\Desktop\OTM.exe/PE_Patch.PECompact/PecBundle

05.08.2010 13:17:08 Compacté: PecBundle C:\Users\****\Desktop\OTM.exe/PE_Patch.PECompact

05.08.2010 13:17:08 Compacté: PE_Patch.PECompact C:\Users\****\Desktop\OTM.exe

05.08.2010 13:17:07 Compacté: UPX C:\Program Files\HijackThis\HijackThis.exe/PE_Patch.UPX

05.08.2010 13:17:07 Compacté: PE_Patch.UPX C:\Program Files\HijackThis\HijackThis.exe

05.08.2010 13:17:02 Compacté: ExePack C:\Windows\System32\edit.com

05.08.2010 13:16:59 Compacté: UPX C:\Program Files\trend micro\hijackthis.exe/PE_Patch.UPX

05.08.2010 13:16:59 Compacté: PE_Patch.UPX C:\Program Files\trend micro\hijackthis.exe

05.08.2010 13:16:55 Compacté: PE_Patch C:\Windows\System32\drivers\secdrv.sys

05.08.2010 13:16:54 Compacté: PE_Patch C:\Windows\System32\drivers\nfrd960.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\iirsp.sys/PE_Patch

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\iirsp.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\BrUsbSer.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\BrUsbMdm.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\BrSerWdm.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\BrSerId.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\BrFiltUp.sys

05.08.2010 13:16:53 Compacté: PE_Patch C:\Windows\System32\drivers\BrFiltLo.sys

05.08.2010 13:16:52 Compacté: PE_Patch C:\Windows\System32\drivers\djsvs.sys

05.08.2010 13:16:23 Non réparés: Rootkit.Win32.TDSS.d System Memory Ignoré par l'utilisateur

05.08.2010 13:16:23 Non réparés: Rootkit.Win32.TDSS.d System Memory Ne peut être réparé

05.08.2010 13:16:23 Détectés: Rootkit.Win32.TDSS.d System Memory

05.08.2010 13:16:23 Lancement de la tâche

Analyse des objets de démarrage: terminée : il y a 12 minutes (événements : 9, objets : 1641, durée : 00:02:48)

05.08.2010 13:56:22 Fin de la tâche

05.08.2010 13:55:10 Compacté: PE_Patch C:\Program Files\DAEMON Tools Lite\Engine.dll/data0007.res

05.08.2010 13:55:09 Compacté: UPX C:\Program Files\Opera\opera.dll/PE_Patch.UPX

05.08.2010 13:55:08 Compacté: PE_Patch.UPX C:\Program Files\Opera\opera.dll

05.08.2010 13:54:53 Compacté: PECompact C:\Users\****\Desktop\OTM.exe/PE_Patch.PECompact/PecBundle

05.08.2010 13:54:53 Compacté: PecBundle C:\Users\****\Desktop\OTM.exe/PE_Patch.PECompact

05.08.2010 13:54:53 Compacté: PE_Patch.PECompact C:\Users\****\Desktop\OTM.exe

05.08.2010 13:53:51 Compacté: PE_Patch C:\Windows\System32\drivers\djsvs.sys

05.08.2010 13:53:34 Lancement de la tâche

Analyse Complète: terminée : il y a 1 minute (événements : 3, objets : 228230, durée : 00:08:10)

05.08.2010 13:59:08 Lancement de la tâche

05.08.2010 14:02:36 Compacté: Swf2Swc C:\Users\****\AppData\Local\Mozilla\Firefox\Profiles\maerialm.default\Cache\E9F24FC0d01

05.08.2010 14:07:18 Fin de la tâche

Modifié par maxr397
Lien vers le commentaire
Partager sur d’autres sites

Re,

 

Thunderbird et Firefox plus sûrs que d'autres, si tu veux mon avis perso, c'est une légende...

 

J'utilise toujours Explorer (8) et Outlook Express 6 sans rencontrer le moindre problème; le tout est d'avoir une protection de pc efficace.

 

Bien sûr, aucune protection ne sera assez sûre si on joue avec des cracks et des keygens.

 

Dans Kaspersky, tu as une fonction d'analyse des applications présentes sur la machine. Fais une analyse.

 

(analyse/ recherche de vulnérabilités) S'il y a des mises à jour à faire, le logiciel te donnera des liens pour appliquer des correctifs ou des mises à jour.

 

rech-vuln-rabilit-s-1efcb58.jpg

 

Comment se comporte le pc?

Lien vers le commentaire
Partager sur d’autres sites

Hello,

j'ai du nouveau: kaspersky m'a détecté un virus, Rootkit.Win32.TDSS.d.

 

J'ai donc fait la procédure spéciale de réparation, réparé et redémarrer, 2 fois de suite, mais cela n'a rien donné. A la troisième détection j'ai donc choisi "Ne pas exécuter" afin de continuer le scan.

 

Voici le rapport kaspersky :

Analyse Complète: arrêtée : il y a 36 minutes (événements : 2, objets : 0, durée : 00:15:40)

06.08.2010 10:14:35 Détectés: Rootkit.Win32.TDSS.d System Memory

06.08.2010 10:19:25 Détectés: Rootkit.Win32.TDSS.d System Memory

Réparation des menaces actives: terminée : il y a 53 minutes (événements : 3, objets : 6374, durée : 00:01:17)

06.08.2010 10:16:24 Détectés: Rootkit.Win32.TDSS.d System Memory

06.08.2010 10:16:24 Non réparés: Rootkit.Win32.TDSS.d System Memory Ne peut être réparé

06.08.2010 10:16:24 Non réparés: Rootkit.Win32.TDSS.d System Memory Ignoré par l'utilisateur

Réparation des menaces actives: terminée : il y a 34 minutes (événements : 3, objets : 6604, durée : 00:01:22)

06.08.2010 10:35:05 Détectés: Rootkit.Win32.TDSS.d System Memory

06.08.2010 10:35:05 Non réparés: Rootkit.Win32.TDSS.d System Memory Ne peut être réparé

06.08.2010 10:35:05 Non réparés: Rootkit.Win32.TDSS.d System Memory Ignoré par l'utilisateur

Analyse Complète: terminée : il y a 1 minute (événements : 2, objets : 1210937, durée : 00:29:34)

06.08.2010 10:39:51 Détectés: Rootkit.Win32.TDSS.d System Memory

06.08.2010 10:39:55 Non réparés: Rootkit.Win32.TDSS.d System Memory Reporté

Modifié par maxr397
Lien vers le commentaire
Partager sur d’autres sites

  • Tonton a modifié le titre en Infection Trojan Horse Crypt. YCS

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...