Prob bagle df et jo et trojan download URGENT

Fermé
rollin - 12 sept. 2007 à 15:36
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 - 28 sept. 2007 à 14:47
Bonjour

Encore un problème avec bagle, je m'appercois que cela est à la "mode" en ce moment.Avant d'utiliser une aide ici, je préfère préciser mon infection spécifique, avant de recevoir une aide, cela fait maintenant 2 semaines que j'ai bien sur tout tenté en vain (scan on line, outils specifique bagle ..) rien, toujours pas possible d 'installer le mondre fichier . exe, et encore moins un anti virus bien sur. Démarrage mode sans échec impossible, seul le mode VGA possible, est le même ?? voila donc apres scan on line KASPERSKY, ce que j'ai découvert:
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000064.exe Infecté : Email-Worm.Win32.Bagle.jo ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000065.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000066.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000067.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000068.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000069.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000070.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000071.exe Infecté : Trojan-Downloader.Win32.Bagle.df ignoré

C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP1\A0000072.exe Infecté : Email-Worm.Win32.Bagle.jo ignoré
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ConnectMFCApplication.zip/uninstall.exe Suspect : Password-protected-EXE ignoré

J'attends vos indications pour avoir mon pc de mon travail en parfait état, merci encore de votre rapidité.

Dominique BON de Nantes
A voir également:

42 réponses

O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
12 sept. 2007 à 15:39
Salut,

- Télécharge HiJackThis de Merijn http://www.merijn.org/files/HiJackThis_v2.exe sur ton bureau
- Renomme "HiJackThis.exe" en "scanner.exe"
- Double cliques dessus et choisis l'option "Do a scan and Save a logfile"
- Copie Colle le log généré ci-dessous.

ET

- Télécharge Diaghelp.zip de Malekal_Morte http://www.malekal.com/download/DiagHelp.zip
- Cliques droit dessus et choisis extraire tout.
- Un nouveau dossier va être créé: DiagHelp
- Ouvre le et double cliques sur Go.cmd
- Choisis l'option 1
- Suis les instructions qui apparaissent, et appuies bien sur une touche quand demandé, après le rapport CatchMe.
- Peut-etre que tu devras redémarrer ton ordinateur.
- Copie colle le rapport se trouve dans C:Resultat.txt ici.

0
Salut,
Je pense qu'au point ou tu en es il faut formaté ton ordinateur car même si tu remplace ces fichiers par d'autre non corompu tu sera surrement réinfecté vu que ton virus dois trainer sur ton pc...
Bon courage
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
12 sept. 2007 à 15:46
Salut

Je ne sui pas d'accord.. Bagle se résoud
0
RESPONSE A O VERTIGO


merci de ta réponse rapide.

Je prends en note cela (copier:coller of course !) et réalise cela demain, la o boulot. A mon compte mais pas trop le temps. Je reprends la discussion avec toi demain, ainsi que le rapport demandé, pour éradiquer cela, en tout cas, déjà merci, bonne fin de journée et à demain pour le résultat de tes consignes.

Dominique BON
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
12 sept. 2007 à 16:02
Ok, je t'attends pour la suite
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
... je te recontacte demain vers 13h ici cela te convient Vertigo ? avec bien sur le résultat demandé.
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
12 sept. 2007 à 16:21
Je peux difficilement venir a cette heure car je reprends les cours demain.. mais sans aucun doute je serai la en soirée, donc je te donnerai les consignes en fonction de ce que tu m'auras répondu vers 13h... pas de problème ;o)

On va essayer de l'avoir ce bagle
0
ok j ai bien noté que toi aussi en tant qu étudiant apparement tu as un planning chargé, j ai eu le temps de m occuper de tes consignes pour hijacksthis je te l ai donne ci dessous:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 16:29:18, on 12/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
D:\TEXTURE\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\RDS\RsiSvc.exe
C:\Program Files\RDS\srscandr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RDS\ddsschednt.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\MSTMON_J.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\MindSoft\MindSoft Utilities XP 9\FreeRAM.exe
D:\TEXTURE\AAWTray.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RDS\dds.exe
C:\PROGRA~1\IncrediMail\bin\IMApp.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\RDS\spooler.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Compaq_Propriétaire\Bureau\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://speedsaisie.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = SPEED SAISIE La Micro Service Nantaise
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {2520BA45-3D97-4864-82FF-F47F951727BA} - (no file)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9B053E00-78D3-47AE-B763-60FF36FF2886} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\RegistrySmart.exe" -boot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [magicolor 2300WStatusDisplay] C:\WINDOWS\system32\MSTMON_J.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\Fix-It\MemCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [MindSoft FreeRAM] C:\Program Files\MindSoft\MindSoft Utilities XP 9\FreeRAM.exe
O4 - HKLM\..\Run: [AAWTray] D:\TEXTURE\AAWTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Démarrer les services de distribution.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: http://*.secuser.com
O16 - DPF: {2472DCCC-68CE-49DA-AA81-E7E6D83C1DFA} - http://acces.blonde.com/package/PackageHtmlCab.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5113/mcfscan.cab
O16 - DPF: {EFB23983-5803-4914-ADA3-C0EA2CFBDC37} - https://www.afternic.com/domains/downloadv3.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C8FADFE-EBE8-447A-A34F-DC5772DD7232}: NameServer = 80.10.246.134 80.10.246.7
O17 - HKLM\System\CS3\Services\Tcpip\..\{5C8FADFE-EBE8-447A-A34F-DC5772DD7232}: NameServer = 80.10.246.134 80.10.246.7
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\TEXTURE\aawservice.exe
O23 - Service: Dds Scheduler Deamon (DdsSched) - RICOH Company Ltd. - C:\Program Files\RDS\ddsschednt.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: Fix-It Task Manager - V Communications, Inc. - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Ridoc Server Information Service (RsiSvc) - RICOH Company Ltd. - C:\Program Files\RDS\RsiSvc.exe
O23 - Service: ScanRouterDriverV2 - Ricoh Co.,Ltd. - C:\Program Files\RDS\srscandr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SOption - RICOH Company Ltd. - C:\Program Files\RDS\SOption.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
0
... voila autant pour moi la suite de ce que tu m'as demandé avec diaghelp.zip:

DiagHelp version v1.2 - http://www.malekal.com
excute le 12/09/2007 à 17:01:42,92


Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CMD.EXE-034B0549.pf -->12/09/2007 17:01:20
C:\WINDOWS\prefetch\CHCP.COM-17EDBDC9.pf -->12/09/2007 17:01:17
C:\WINDOWS\prefetch\ACRODIST.EXE-2B804A15.pf -->12/09/2007 17:01:04
C:\WINDOWS\prefetch\WINRAR.EXE-0AA31BB9.pf -->12/09/2007 16:59:51
C:\WINDOWS\prefetch\HPGS2WNF.EXE-37EAA714.pf -->12/09/2007 16:59:10
C:\WINDOWS\prefetch\WMIPRVSE.EXE-0D449B4F.pf -->12/09/2007 16:53:11
C:\WINDOWS\prefetch\IEXPLORE.EXE-2D97EBE6.pf -->12/09/2007 16:52:05
C:\WINDOWS\prefetch\NOTEPAD.EXE-2F2D61E1.pf -->12/09/2007 16:29:28
C:\WINDOWS\prefetch\SCANNER.EXE.EXE-1D57EBB6.pf -->12/09/2007 16:29:16
C:\WINDOWS\prefetch\QTTASK.EXE-1876A1A1.pf -->12/09/2007 16:24:11

C:\WINDOWS\System32\drivers\AWRTRD.sys -->07/08/2007 13:58:08
C:\WINDOWS\System32\drivers\NSDriver.sys -->07/08/2007 13:56:58
C:\WINDOWS\System32\drivers\aswRdr.sys -->28/07/2007 00:00:39
C:\WINDOWS\System32\drivers\AWRTPD.sys -->11/07/2007 14:37:26
C:\WINDOWS\System32\drivers\AFS2K.SYS -->28/02/2007 11:33:40
C:\WINDOWS\System32\drivers\ntfs.sys -->09/02/2007 13:10:35
C:\WINDOWS\System32\drivers\fltmgr.sys -->21/08/2006 11:14:58

C:\WINDOWS\System32\KGyGaAvL.sys -->12/09/2007 12:57:40
C:\WINDOWS\System32\wpa.dbl -->12/09/2007 08:52:50
C:\WINDOWS\System32\tmp.txt -->11/09/2007 17:00:37
C:\WINDOWS\System32\tmp.reg -->11/09/2007 17:00:37
C:\WINDOWS\System32\settings.aaw -->11/09/2007 16:52:28
C:\WINDOWS\System32\history.aaw -->11/09/2007 16:52:28
C:\WINDOWS\System32\Uninstall.ico -->06/09/2007 12:42:54
C:\WINDOWS\System32\Help.ico -->06/09/2007 12:42:54
C:\WINDOWS\System32\pavas.ico -->06/09/2007 12:42:53
C:\WINDOWS\System32\FNTCACHE.DAT -->05/09/2007 13:26:13
C:\WINDOWS\System32\CONFIG.NT -->03/09/2007 16:56:32
C:\WINDOWS\System32\MRT.exe -->03/08/2007 06:34:10
C:\WINDOWS\System32\wuaucpl.cpl.mui -->30/07/2007 19:20:06
C:\WINDOWS\System32\wuapi.dll.mui -->30/07/2007 19:19:52
C:\WINDOWS\System32\wuaueng.dll -->30/07/2007 19:19:42
C:\WINDOWS\System32\wuapi.dll -->30/07/2007 19:19:36
C:\WINDOWS\System32\wucltui.dll -->30/07/2007 19:19:32
C:\WINDOWS\System32\wuweb.dll -->30/07/2007 19:19:28
C:\WINDOWS\System32\wuaucpl.cpl -->30/07/2007 19:19:28
C:\WINDOWS\System32\cdm.dll -->30/07/2007 19:19:20
C:\WINDOWS\System32\wuauclt.exe -->30/07/2007 19:19:16
C:\WINDOWS\System32\wups2.dll -->30/07/2007 19:19:12
C:\WINDOWS\System32\wucltui.dll.mui -->30/07/2007 19:19:04
C:\WINDOWS\System32\wuaueng.dll.mui -->30/07/2007 19:18:48
C:\WINDOWS\System32\wups.dll -->30/07/2007 19:18:40

C:\WINDOWS\ModemLog_Agere Systems PCI Soft Modem.txt -->12/09/2007 16:45:36
C:\WINDOWS\WindowsUpdate.log -->12/09/2007 15:53:41
C:\WINDOWS\wiadebug.log -->12/09/2007 12:57:43
C:\WINDOWS\0.log -->12/09/2007 08:49:21
C:\WINDOWS\wiaservc.log -->12/09/2007 08:48:33
C:\WINDOWS\bootstat.dat -->12/09/2007 08:48:21
C:\WINDOWS\SchedLgU.Txt -->11/09/2007 18:04:55
C:\WINDOWS\win.ini -->10/09/2007 09:28:16
C:\WINDOWS\system.ini -->10/09/2007 09:28:16
C:\WINDOWS\TSC.INI -->07/09/2007 11:56:28
C:\WINDOWS\GetServer.ini -->07/09/2007 11:20:30
C:\WINDOWS\UNZIP.DLL -->07/09/2007 11:20:22
C:\WINDOWS\TMUPDATE.DLL -->07/09/2007 11:20:22
C:\WINDOWS\PATCH.EXE -->07/09/2007 11:20:21
C:\WINDOWS\UnHookExec.inf -->07/09/2007 09:18:29


MD5 des fichiers sensibles
tcpip.sys 1dbf125862891817f374f407626967f4
ndis.sys 558635d3af1c7546d26067d5d9b6959e
null.sys 73c1e1f395918bc2c6dd67af7591a3ad
svchost.exe 1bd6c2f707a275cb7c16fd99fe0f31ca


Le volume dans le lecteur C s'appelle DD PROGRAMMES
Le numéro de série du volume est ECBF-4FB6

Répertoire de C:\WINDOWS\system

07/05/1998 18:04 52 736 hpsysdrv.exe
10/09/1999 12:06 4 672 WOWPOST.EXE
2 fichier(s) 57 408 octets
0 Rép(s) 133 777 707 008 octets libres
Le volume dans le lecteur C s'appelle DD PROGRAMMES
Le numéro de série du volume est ECBF-4FB6

Répertoire de C:\WINDOWS\system32

05/08/2004 20:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 133 777 702 912 octets libres

Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle DD PROGRAMMES
Le numéro de série du volume est ECBF-4FB6

Répertoire de C:\WINDOWS\Downloaded Program Files

11/09/2007 17:01 <REP> .
11/09/2007 17:01 <REP> ..
23/11/2004 23:20 65 desktop.ini
25/07/2002 19:13 24 576 dwusplay.dll
25/07/2002 19:13 196 608 dwusplay.exe
13/01/2005 15:34 282 EasyPack.inf
05/12/2005 12:27 259 EGDACCESS.inf
24/01/2005 12:38 1 249 erma.inf
11/08/2005 16:30 417 792 isusweb.dll
18/12/2006 11:02 882 mcfscan.inf
06/09/2007 14:49 3 121 152 vet._at
13/07/2007 06:11 1 353 016 vete.dll
10 fichier(s) 5 115 881 octets

Total des fichiers listés :
10 fichier(s) 5 115 881 octets
2 Rép(s) 133 777 702 912 octets libres

Recherche de rootkit! (Merci S!Ri)

Recherche d'infections connues

Export des clefs sensibles..

Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Mindscape\\Web Creator 2\\FTPCopyDir.exe"="C:\\Program Files\\Mindscape\\Web Creator 2\\FTPCopyDir.exe:*:Enabled:FTPCopyDir"
"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"="C:\\Program Files\\IncrediMail\\bin\\ImLc.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImPackr.exe"="C:\\Program Files\\IncrediMail\\bin\\ImPackr.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Corel\\Bryce Lightning\\Bryce Lightning.exe"="C:\\Program Files\\Corel\\Bryce Lightning\\Bryce Lightning.exe:*:Disabled:Bryce5"
"C:\\Program Files\\RDS\\DdsLaunch.exe"="C:\\Program Files\\RDS\\DdsLaunch.exe:*:Enabled:Démarrer les services de distribution"
"C:\\Program Files\\RDS\\DdsAdmin.exe"="C:\\Program Files\\RDS\\DdsAdmin.exe:*:Enabled:ScanRouter V2 Administration Utility"
"C:\\Program Files\\Mindscape\\Web Creator Pro 3\\FTPCopyDir.exe"="C:\\Program Files\\Mindscape\\Web Creator Pro 3\\FTPCopyDir.exe:*:Enabled:FTPCopyDir"
"C:\\Documents and Settings\\Compaq_Propriétaire\\Application Data\\m\\flec006.exe"="C:\\Documents and Settings\\Compaq_Propriétaire\\Application Data\\m\\flec006.exe:*:Disabled:flec006"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"



exports des policies
REGEDIT4

[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001



Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
12 sept. 2007 à 22:06
En fait, le rapport DiagHelp n'est pas complet.. Faut appuyer sur une touche après le rapport CatchMe. Ce qui m'interesse est juste après en fait...
0
SALUT, sorry, je te fais cela ce matin arrivé a ma boutique et te complete cela, merci encore a bientot.
0
Voila le rapport complet il me semble ! :

DiagHelp version v1.2 - http://www.malekal.com
excute le 13/09/2007 à 8:59:20,10


Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-17EDBDC9.pf -->13/09/2007 08:59:18
C:\WINDOWS\prefetch\SPOOLER.EXE-0C22A119.pf -->13/09/2007 08:57:11
C:\WINDOWS\prefetch\ACRODIST.EXE-2B804A15.pf -->13/09/2007 08:56:54
C:\WINDOWS\prefetch\WUAUCLT.EXE-1360D60A.pf -->13/09/2007 08:56:39
C:\WINDOWS\prefetch\INCMAIL.EXE-2A673D8E.pf -->13/09/2007 08:56:38
C:\WINDOWS\prefetch\IMAPP.EXE-02063928.pf -->13/09/2007 08:56:38
C:\WINDOWS\prefetch\FNPLICENSINGSERVICE.EXE-1F7A5A20.pf -->13/09/2007 08:56:38
C:\WINDOWS\prefetch\BDMTK.EXE-07DB008C.pf -->13/09/2007 08:56:38
C:\WINDOWS\prefetch\ACROBAT_SL.EXE-0E426032.pf -->13/09/2007 08:56:38
C:\WINDOWS\prefetch\WGATRAY.EXE-350D4455.pf -->13/09/2007 08:56:37

C:\WINDOWS\System32\drivers\AWRTRD.sys -->07/08/2007 13:58:08
C:\WINDOWS\System32\drivers\NSDriver.sys -->07/08/2007 13:56:58
C:\WINDOWS\System32\drivers\aswRdr.sys -->28/07/2007 00:00:39
C:\WINDOWS\System32\drivers\AWRTPD.sys -->11/07/2007 14:37:26
C:\WINDOWS\System32\drivers\AFS2K.SYS -->28/02/2007 11:33:40
C:\WINDOWS\System32\drivers\ntfs.sys -->09/02/2007 13:10:35
C:\WINDOWS\System32\drivers\fltmgr.sys -->21/08/2006 11:14:58

C:\WINDOWS\System32\wpa.dbl -->13/09/2007 08:56:15
C:\WINDOWS\System32\KGyGaAvL.sys -->12/09/2007 12:57:40
C:\WINDOWS\System32\tmp.txt -->11/09/2007 17:00:37
C:\WINDOWS\System32\tmp.reg -->11/09/2007 17:00:37
C:\WINDOWS\System32\settings.aaw -->11/09/2007 16:52:28
C:\WINDOWS\System32\history.aaw -->11/09/2007 16:52:28
C:\WINDOWS\System32\Uninstall.ico -->06/09/2007 12:42:54
C:\WINDOWS\System32\Help.ico -->06/09/2007 12:42:54
C:\WINDOWS\System32\pavas.ico -->06/09/2007 12:42:53
C:\WINDOWS\System32\FNTCACHE.DAT -->05/09/2007 13:26:13
C:\WINDOWS\System32\CONFIG.NT -->03/09/2007 16:56:32
C:\WINDOWS\System32\MRT.exe -->03/08/2007 06:34:10
C:\WINDOWS\System32\wuaucpl.cpl.mui -->30/07/2007 19:20:06
C:\WINDOWS\System32\wuapi.dll.mui -->30/07/2007 19:19:52
C:\WINDOWS\System32\wuaueng.dll -->30/07/2007 19:19:42
C:\WINDOWS\System32\wuapi.dll -->30/07/2007 19:19:36
C:\WINDOWS\System32\wucltui.dll -->30/07/2007 19:19:32
C:\WINDOWS\System32\wuweb.dll -->30/07/2007 19:19:28
C:\WINDOWS\System32\wuaucpl.cpl -->30/07/2007 19:19:28
C:\WINDOWS\System32\cdm.dll -->30/07/2007 19:19:20
C:\WINDOWS\System32\wuauclt.exe -->30/07/2007 19:19:16
C:\WINDOWS\System32\wups2.dll -->30/07/2007 19:19:12
C:\WINDOWS\System32\wucltui.dll.mui -->30/07/2007 19:19:04
C:\WINDOWS\System32\wuaueng.dll.mui -->30/07/2007 19:18:48
C:\WINDOWS\System32\wups.dll -->30/07/2007 19:18:40

C:\WINDOWS\WindowsUpdate.log -->13/09/2007 08:55:46
C:\WINDOWS\0.log -->13/09/2007 08:55:07
C:\WINDOWS\wiadebug.log -->13/09/2007 08:54:23
C:\WINDOWS\wiaservc.log -->13/09/2007 08:54:19
C:\WINDOWS\bootstat.dat -->13/09/2007 08:54:07
C:\WINDOWS\SchedLgU.Txt -->12/09/2007 18:02:31
C:\WINDOWS\ModemLog_Agere Systems PCI Soft Modem.txt -->12/09/2007 17:57:11
C:\WINDOWS\win.ini -->10/09/2007 09:28:16
C:\WINDOWS\system.ini -->10/09/2007 09:28:16
C:\WINDOWS\TSC.INI -->07/09/2007 11:56:28
C:\WINDOWS\GetServer.ini -->07/09/2007 11:20:30
C:\WINDOWS\UNZIP.DLL -->07/09/2007 11:20:22
C:\WINDOWS\TMUPDATE.DLL -->07/09/2007 11:20:22
C:\WINDOWS\PATCH.EXE -->07/09/2007 11:20:21
C:\WINDOWS\UnHookExec.inf -->07/09/2007 09:18:29


MD5 des fichiers sensibles
tcpip.sys 1dbf125862891817f374f407626967f4
ndis.sys 558635d3af1c7546d26067d5d9b6959e
null.sys 73c1e1f395918bc2c6dd67af7591a3ad
svchost.exe 1bd6c2f707a275cb7c16fd99fe0f31ca


Le volume dans le lecteur C s'appelle DD PROGRAMMES
Le numéro de série du volume est ECBF-4FB6

Répertoire de C:\WINDOWS\system

07/05/1998 18:04 52 736 hpsysdrv.exe
10/09/1999 12:06 4 672 WOWPOST.EXE
2 fichier(s) 57 408 octets
0 Rép(s) 133 807 058 944 octets libres
Le volume dans le lecteur C s'appelle DD PROGRAMMES
Le numéro de série du volume est ECBF-4FB6

Répertoire de C:\WINDOWS\system32

05/08/2004 20:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 133 807 054 848 octets libres

Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle DD PROGRAMMES
Le numéro de série du volume est ECBF-4FB6

Répertoire de C:\WINDOWS\Downloaded Program Files

11/09/2007 17:01 <REP> .
11/09/2007 17:01 <REP> ..
23/11/2004 23:20 65 desktop.ini
25/07/2002 19:13 24 576 dwusplay.dll
25/07/2002 19:13 196 608 dwusplay.exe
13/01/2005 15:34 282 EasyPack.inf
05/12/2005 12:27 259 EGDACCESS.inf
24/01/2005 12:38 1 249 erma.inf
11/08/2005 16:30 417 792 isusweb.dll
18/12/2006 11:02 882 mcfscan.inf
06/09/2007 14:49 3 121 152 vet._at
13/07/2007 06:11 1 353 016 vete.dll
10 fichier(s) 5 115 881 octets

Total des fichiers listés :
10 fichier(s) 5 115 881 octets
2 Rép(s) 133 807 054 848 octets libres

Recherche de rootkit! (Merci S!Ri)

Recherche d'infections connues

Export des clefs sensibles..

Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Mindscape\\Web Creator 2\\FTPCopyDir.exe"="C:\\Program Files\\Mindscape\\Web Creator 2\\FTPCopyDir.exe:*:Enabled:FTPCopyDir"
"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"="C:\\Program Files\\IncrediMail\\bin\\ImLc.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImPackr.exe"="C:\\Program Files\\IncrediMail\\bin\\ImPackr.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Corel\\Bryce Lightning\\Bryce Lightning.exe"="C:\\Program Files\\Corel\\Bryce Lightning\\Bryce Lightning.exe:*:Disabled:Bryce5"
"C:\\Program Files\\RDS\\DdsLaunch.exe"="C:\\Program Files\\RDS\\DdsLaunch.exe:*:Enabled:Démarrer les services de distribution"
"C:\\Program Files\\RDS\\DdsAdmin.exe"="C:\\Program Files\\RDS\\DdsAdmin.exe:*:Enabled:ScanRouter V2 Administration Utility"
"C:\\Program Files\\Mindscape\\Web Creator Pro 3\\FTPCopyDir.exe"="C:\\Program Files\\Mindscape\\Web Creator Pro 3\\FTPCopyDir.exe:*:Enabled:FTPCopyDir"
"C:\\Documents and Settings\\Compaq_Propriétaire\\Application Data\\m\\flec006.exe"="C:\\Documents and Settings\\Compaq_Propriétaire\\Application Data\\m\\flec006.exe:*:Disabled:flec006"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"



exports des policies
REGEDIT4

[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001



Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-13 08:59:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\system32\drivers\srosa.sys"
"DisplayName"="Megadrv3"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\system32\drivers\srosa.sys"
"DisplayName"="Megadrv3"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\system32\drivers\srosa.sys"
"DisplayName"="Megadrv3"

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files\Corel\Graphics10\Draw\Template\"="1"
"C:\Program Files\Corel\Graphics10\Programs\"=""
"C:\Program Files\Corel\Graphics10\Draw\Scripts\Misc\"=""
"C:\Program Files\Corel\Graphics10\Draw\Template\SideFold\"=""
"C:\Program Files\Corel\Graphics10\Draw\Template\Label\"=""
"C:\Program Files\Corel\Graphics10\Draw\Template\FullPage\"=""
"C:\Program Files\Corel\Graphics10\Draw\Template\Booklet\"=""
"C:\Program Files\Corel\Graphics10\Config\DrawBrowser\"=""
"C:\Program Files\Hewlett-Packard\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\Album\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\Album\Filters\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\Album\Art\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\Album\Pages\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\"="1"
"C:\Program Files\Hewlett-Packard\HP Share-to-Web\Files\"="1"
"C:\Program Files\Hewlett-Packard\HP Share-to-Web\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\data\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\hpodcache\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\audio\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Hewlett-Packard\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Hewlett-Packard\Memories Disc\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\prgen\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\SHOW\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\SHOW\STYLE\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\SHOW\JS\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\STYLE\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\JS\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\GRAPHICS\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\BROWSE\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\BROWSE\STYLE\"="1"
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\BROWSE\JS\"="1"
"C:\Program Files\Hewlett-Packard\Digital Imaging\help\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\3500c\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\common\img\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\common\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\common\htc\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\common\css\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\common\js\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\data\bmp\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\data\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\director\img\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\director\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\director\dso\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\director\js\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\director\loc\"=""
"C:\Program Files\Hewlett-Packard\Memories Disc\xslt\"=""
"C:\Program Files\Hewlett-Packard\Memories Disc\graphics\"=""
"C:\Program Files\Hewlett-Packard\Memories Disc\pcgen\VIEW\HTML\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\DocProc\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\scan\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\scan\js\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\scan\css\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\scan\loc\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\scan\img\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\Migrate\"=""
"C:\Program Files\Fichiers communs\Hewlett-Packard\Scanjet\"=""
"C:\Program Files\Fichiers communs\Hewlett-Packard\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\HP Share-to-Web\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Hewlett-Packard\Scanjet 3500c series\"=""
"C:\WINDOWS\Installer\{B8E952E3-A823-443A-8493-39A0CCE0E3EB}\"=""
"C:\Program Files\Canon\PhotoRecord\Program\"=""
"C:\Program Files\Canon\PhotoRecord\"=""
"C:\Program Files\Canon\PhotoRecord\OpPrintCom\"=""
"C:\Program Files\Canon\PhotoRecord\Help\"=""
"C:\Program Files\Canon\PhotoRecord\Help\html\"=""
"C:\Program Files\Canon\PhotoRecord\Help\img\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_English\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_French\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_German\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_Italian\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_Japanese\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_Simplified_Chinese\"=""
"C:\Program Files\Canon\PhotoRecord\Help\Lang_Spanish\"=""
"C:\Program Files\Canon\PhotoRecord\art\"=""
"C:\Program Files\Canon\PhotoRecord\art\baby\"=""
"C:\Program Files\Canon\PhotoRecord\art\baby\Clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\baby\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\beach\"=""
"C:\Program Files\Canon\PhotoRecord\art\beach\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\birthday\"=""
"C:\Program Files\Canon\PhotoRecord\art\birthday\Clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\children\"=""
"C:\Program Files\Canon\PhotoRecord\art\children\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\christmas\"=""
"C:\Program Files\Canon\PhotoRecord\art\christmas\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\christmas\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\classic\"=""
"C:\Program Files\Canon\PhotoRecord\art\classic\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\birds\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\events\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\flowers\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\pets\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\sport\"=""
"C:\Program Files\Canon\PhotoRecord\art\clipart\stickers\"=""
"C:\Program Files\Canon\PhotoRecord\art\crests\"=""
"C:\Program Files\Canon\PhotoRecord\art\floral\"=""
"C:\Program Files\Canon\PhotoRecord\art\frames\border\"=""
"C:\Program Files\Canon\PhotoRecord\art\frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\frames\sketch\"=""
"C:\Program Files\Canon\PhotoRecord\art\frames\tacks\"=""
"C:\Program Files\Canon\PhotoRecord\art\frames\tacks\text\"=""
"C:\Program Files\Canon\PhotoRecord\art\frames\wood\"=""
"C:\Program Files\Canon\PhotoRecord\art\fun\"=""
"C:\Program Files\Canon\PhotoRecord\art\fun\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\fun\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Backgrounds\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\Baby_fun\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\bears\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\birthyday_modern\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\blurs\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\bubbles\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\bugs\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\christmas\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\clouds\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\discs\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\leafs\"=""
"C:\Program Files\Canon\PhotoRecord\art\glorious\Particles\weddings\"=""
"C:\Program Files\Canon\PhotoRecord\art\halloween\"=""
"C:\Program Files\Canon\PhotoRecord\art\halloween\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\halloween\textframe\"=""
"C:\Program Files\Canon\PhotoRecord\art\lines\"=""
"C:\Program Files\Canon\PhotoRecord\art\maple\"=""
"C:\Program Files\Canon\PhotoRecord\art\mask\"=""
"C:\Program Files\Canon\PhotoRecord\art\modern\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nippon1\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nippon1\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nippon1\text_frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nippon2\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nippon2\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nippon2\text_frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\numbers\bold\"=""
"C:\Program Files\Canon\PhotoRecord\art\numbers\"=""
"C:\Program Files\Canon\PhotoRecord\art\numbers\classic\"=""
"C:\Program Files\Canon\PhotoRecord\art\numbers\modern\"=""
"C:\Program Files\Canon\PhotoRecord\art\numbers\stencil\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery1\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery1\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery1\frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery1\text frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery2\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery2\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery2\frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\Nursery2\text frames\"=""
"C:\Program Files\Canon\PhotoRecord\art\oriental\"=""
"C:\Program Files\Canon\PhotoRecord\art\paper\"=""
"C:\Program Files\Canon\PhotoRecord\art\rocks\"=""
"C:\Program Files\Canon\PhotoRecord\art\romance\"=""
"C:\Program Files\Canon\PhotoRecord\art\simple\"=""
"C:\Program Files\Canon\PhotoRecord\art\simple\tacks & pins\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\explosion\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\float\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\float2\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\flourish\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\flourish2\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\note\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\plaque\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\scroll\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\speech\"=""
"C:\Program Files\Canon\PhotoRecord\art\textframes\thought\"=""
"C:\Program Files\Canon\PhotoRecord\art\textures\"=""
"C:\Program Files\Canon\PhotoRecord\art\themes\"=""
"C:\Program Files\Canon\PhotoRecord\art\themes\icons\"=""
"C:\Program Files\Canon\PhotoRecord\art\travel\"=""
"C:\Program Files\Canon\PhotoRecord\art\travel\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\travel\textframes\"=""
"C:\Program Files\Canon\PhotoRecord\art\web_teasers\"=""
"C:\Program Files\Canon\PhotoRecord\art\wedding\"=""
"C:\Program Files\Canon\PhotoRecord\art\wedding\clipart\"=""
"C:\Program Files\Canon\PhotoRecord\art\wood\"=""
"C:\Program Files\Canon\PhotoRecord\art\wood\text\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Canon PhotoRecord\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Proof\1033\"=""
"C:\Program Files\Software Shelf\File Rescue Plus\"=""
"C:\Program Files\Software Shelf\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Application Data\Microsoft\Installer\{52E26953-00EF-42B3-A075-A57E86A38D07}\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Application Data\Microsoft\Installer\"=""
"C:\Program Files\MSN Messenger\"=""
"C:\WINDOWS\Installer\{505AFDC0-5E72-4928-8368-5DEA385E3647}\"=""
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1033\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1036\"=""
"C:\WINDOWS\Installer\{C94E45B0-6AA6-4FB9-9AAE-22085F631880}\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Application Data\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\Musique\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\Sauvegarde\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantAudio\Mayaheditr\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantAudio\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\"="1"
"C:\Program Files\Pinnacle\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantAudio\Components\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\InstantDrive\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantMusic\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantMusic\Example\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\CDDB\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\InstantWrite\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantBackup\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\Mastering\"="1"
"C:\Documents and Settings\Compaq_Propri\xe9taire\Mes documents\InstantCDDVD\Projects\"="1"
"C:\Documents and Settings\Compaq_Propri\xe9taire\Mes documents\InstantCDDVD\"="1"
"C:\Documents and Settings\Compaq_Propri\xe9taire\Mes documents\InstantCDDVD\Labels\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\Audio\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantDisc\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Programs\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\Duplication\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\Outils\"="1"
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\InstantCD+DVD\Vid\xe9o\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantAudio\VstPlugins\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantAudio\Skins\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\InstantAudio\Group\"="1"
"C:\Program Files\Pinnacle\InstantCDDVD\PinnacleMediaCenter\"=""
"C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\"=""
"C:\Program Files\Pinnacle\Shared Files\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\InstantCopy\"=""
"C:\Program Files\Pinnacle\Shared Files\Filter\"=""
"C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\Templates\"=""
"C:\Program Files\Pinnacle\Shared Files\RecordingAPI\"=""
"C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\Pixie\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\Backgrounds\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\Styles\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Mes documents\Pinnacle Expression\Captured Video\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Mes documents\Pinnacle Expression\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\Layouts\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\TextStyles\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\Labels\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Music\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Textures\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Menus\Frames\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Fonts\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Programs\Templates\Papers\"=""
"C:\Program Files\Pinnacle\InstantCDDVD\Pinnacle Expression\Programs\Templates\"=""
"C:\Program Files\Fichiers communs\Fellowes\MediaFace\"=""
"C:\Program Files\Fichiers communs\Fellowes\"=""
"C:\WINDOWS\Installer\{A01872BE-2123-4F1B-B295-E3D1774DC0C9}\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\GMS\"=""
"C:\Program Files\Softwin\BitDefender9\"="1"
"C:\Program Files\Softwin\"="1"
"C:\Program Files\Fichiers communs\Softwin\BitDefender Local Manager\"=""
"C:\Program Files\Ontrack\EasyRecovery Professional\"="1"
"C:\Program Files\Ontrack\"="1"
"C:\Program Files\Ontrack\EasyRecovery Professional\Language\"="1"
"C:\Program Files\Ontrack\SharedFiles\"=""
"C:\WINDOWS\Installer\{A8BB9906-E618-406A-B161-7383AFF46C39}\"=""
"C:\Program Files\MindSoft\MindSoft Utilities XP 9\"=""
"C:\Program Files\MindSoft\"=""
"C:\Program Files\MindSoft\MindSoft Utilities XP 9\lang\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Menu D\xe9marrer\Programmes\MindSoft Utilities XP 9.06\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Menu D\xe9marrer\Programmes\MindSoft Utilities XP 9.06\Utilities\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Application Data\Microsoft\Installer\{ADF1F741-4BBC-4F7E-8C2C-9855D6318185}\"=""
"C:\Program Files\VCOM\Fix-It\"=""
"C:\Program Files\VCOM\"=""
"C:\Program Files\Support Tools\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Windows Support Tools\"=""
"C:\Program Files\MP3 Player Utilities\"="1"
"C:\Program Files\MP3 Player Utilities\RDiskUtility\sys\"=""
"C:\Program Files\MP3 Player Utilities\RDiskUtility\"=""
"C:\Program Files\MP3 Player Utilities\SoundConvert\"=""
"C:\Program Files\MP3 Player Utilities\RDiskUpdate\"=""
"C:\Program Files\MP3 Player Utilities\RDiskUpdate\driver\"=""
"C:\Program Files\MP3 Player Utilities\Windows98Drv\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Menu D\xe9marrer\Programmes\MP3 Player Utilities 1.45\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Application Data\Microsoft\Installer\{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\"=""
"C:\Program Files\Fichiers communs\SYSTEM\OLE DB\resources\1036\"=""
"C:\Program Files\Fichiers communs\SYSTEM\OLE DB\resources\"=""
"C:\Program Files\Microsoft Office\Office12\"=""
"C:\Program Files\Microsoft Office\OFFICE12\1031\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\PROOF\1031\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\VS Runtime\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\1036\"=""
"C:\Program Files\Fichiers communs\SYSTEM\MSMAPI\1036\"=""
"C:\Program Files\Fichiers communs\SYSTEM\MSMAPI\"=""
"C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\"="1"
"C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\"="1"
"C:\Program Files\Microsoft Office\Office12\STARTUP\"="1"
"C:\Program Files\Fichiers communs\SYSTEM\OLE DB\resources\1033\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\"=""
"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\"=""
"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\"=""
"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\"=""
"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\MSEnv\"=""
"C:\Program Files\Hewlett-Packard\Digital Imaging\bbfe\director\css\"=""
"C:\Program Files\Hewlett-Packard\Memories Disc\sdkgen\"=""
"C:\Program Files\Hewlett-Packard\Memories Disc\coregen\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Plugins\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\MeshWarp\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Draw\Plugins\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Draw\"="1"
"C:\Program Files\Fichiers communs\Corel\Shared\Writing Tools\13\"="1"
"C:\Program Files\Fichiers communs\Corel\Shared\Writing Tools\"="1"
"C:\Program Files\Fichiers communs\Corel\Shared\"="1"
"C:\Program Files\Fichiers communs\Corel\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Filters\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Frames\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Tiles\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Textures\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Tonecrve\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Preflight Styles\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Patterns\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Layouts\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Duotone\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Displace\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Canvas\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Brushes\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Color\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\config\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\Data\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Tutor Files\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\Plugins\TaskManager\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\Plugins\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Draw\GMS\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Plugins\Digimarc\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Draw\Samples\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Draw\Find\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Draw\CustomMediaStrokes\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Filters\Convert\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\CorelDRAW\MS Office\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\CorelDRAW\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\CorelDRAW\Adobe(R)Illustrator(R)\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\CorelDRAW\_BootDefault\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\UIConfig\CorelDRAW\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\UIConfig\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\Samples\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\Presets\Brush\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\Presets\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\Paths\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\ImgLists\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\Net_Fav\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\CorelPHOTO-PAINT\Brushtxr\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Shearmap\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Custom Data\Bumpmap\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\Corel PHOTO-PAINT\_BootDefault\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Workspace\Corel PHOTO-PAINT\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\UIConfig\Corel PHOTO-PAINT\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Suite graphique CorelDRAW X3\"=""
"C:\WINDOWS\Installer\{63218538-4A69-497F-8455-904261B0E9E4}\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\PCUUI\Images\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\PCUUI\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\PCUUI\Images\Button\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Config\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\Contour\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\CorelDRAW Experts\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\CorelDRAW Tutorials\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\Distortion\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\DropShadow\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Template\Envelope\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Template\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\Envelope\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\PHOTO-PAINT\Presets\FileNew\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\PHOTO-PAINT\Presets\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\PHOTO-PAINT\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\PCUUI\Images\Frame\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Template\FullPage\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\HTML Export\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\Images\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Template\Label\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Object Data\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\PHOTO-PAINT Experts\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\PHOTO-PAINT Tutorials\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Tutorials\Sample Files\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Template\SideFold\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\Plugins\TaskManager\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\Plugins\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Userdef\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\VectorExtrude\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Template\Web\"="1"
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Help\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Presets\Blend\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\PHOTO-PAINT\Presets\DropShadow\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Draw\Drawbrowser\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\PHOTO-PAINT\Tables\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Programs\Data\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\RVB\Personnes\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\RVB\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\RVB\Choses\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\RVB\Nature\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\RVB\Divers\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\CMJN\Personnes\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\CMJN\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\CMJN\Choses\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\CMJN\Divers\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\FR\Custom Data\Palettes\CMJN\Nature\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Suite graphique CorelDRAW X3\Documentation (FR)\"=""
"C:\WINDOWS\Installer\{ECE923A3-A411-4494-B6E6-78F13B71BEBF}\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1046\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1046\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1028\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1028\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\2052\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\2052\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1041\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1041\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1043\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1043\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\3082\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\3082\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1040\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1040\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1031\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1031\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1033\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1042\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1042\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\VBA\VBA6\1053\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Office10\1053\"=""
"C:\Program Files\Corel\CorelDRAW Graphics Suite 13\FontNav\"=""
"C:\WINDOWS\Installer\{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}\"=""
"c:\Program Files\MSXML 4.0\"="1"
"c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\"=""
"c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\"=""
"c:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\"="1"
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Demo\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Scan\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Scan\Twain\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Resource\Cmap\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Resource\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Resource\Font\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Support\"=""
"C:\Program Files\ABBYY FineReader 8.0 Professional Edition\Demo\040C\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Menu D\xe9marrer\Programmes\ABBYY FineReader 8.0\"=""
"C:\Documents and Settings\Compaq_Propri\xe9taire\Application Data\Microsoft\Installer\{AAF80000-22B9-4CE9-98D6-2CCF359BAC07}\"=""
"C:\Program Files\Nokia\Connectivity Cable Driver\"=""
"C:\Program Files\Nokia\"=""
"C:\WINDOWS\Installer\{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}\"=""
"C:\Program Files\Fichiers communs\InstallShield\Driver\9\Intel 32\"="1"
"C:\Program Files\Fichiers communs\InstallShield\Driver\9\"="1"
"C:\Program Files\ScanSoft\NaturallySpeaking8\Program\Upgrdmod11\"=""
"C:\Program Files\ScanSoft\NaturallySpeaking8\Program\Upgrdmod7\"=""
"C:\Program Files\ScanSoft\NaturallySpeaking8\Program\Upgrdmod\"=""
"C:\Documents and Settings\All Users\Application Data\ScanSoft\SSBkgdUpdate\"=""
"C:\Documents and Settings\All Users\Menu D\xe9marrer\Programmes\Dragon NaturallySpeaking 8.0\"=""
"C:\WINDOWS\Installer\{DDDD0C4B-57F7-4A85-ACF0-DB3FC8F1DBB4}\"=""
"C:\Program Files\ScanSoft\NaturallySpeaking8\Program\Upgrdmod10\"=""
"C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\"=""
"C:\Program Files\Fichiers communs\Scansoft Shared\"=""
"C:\Program Files\Microsoft Office\Office10\"="1"
"C:\Program Files\Microsoft Office\Office10\AccessWeb\"="1"
"C:\Program Files\Microsoft Office\Office10\Library\"="1"
"C:\Program Files\Microsoft Office\Office10\Queries\"="1"
"C:\Program Files\Microsoft Office\Office10\XLStart\"="1"
"C:\Program Files\Microsoft Office\Office10\1033\webcomp\"="1"
"C:\Program Files\Microsoft Office\Office10\1033\"="1"
"C:\Program Files\Fichiers communs\Microsoft Shared\Grphflt\"="1"
"C:\Program Files\Fichiers communs\Microsoft Shared\Smart Tag\Lists\"="1"
"C:\Program Files\Fichiers communs\Microsoft Shared\Smart Tag\"="1"
"C:\Program Files\Microsoft Office\Templates\Presentation Designs\"="1"
"C:\Program Files\Microsoft Office\Templates\"="1"
"C:\Program Files\Microsoft Office\Office10\Startup\"="1"
"C:\Program Files\Microsoft Office\Office10\Bitmaps\Dbwiz\"=""
"C:\Program Files\Microsoft Office\Office10\Bitmaps\"=""
"C:\Program Files\Microsoft Office\Office10\Bitmaps\Styles\"=""
"C:\Program Files\Microsoft Office\Templates\1033\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\MSClientDataMgr\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Euro\"=""
"C:\Program Files\Microsoft Office\Office10\bots\fpcount\"=""
"C:\Program Files\Microsoft Office\Office10\bots\"=""
"C:\Program Files\Microsoft Office\Office10\1033\botstyle\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Server Extensions\50\bin\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Server Extensions\50\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Server Extensions\50\bin\1033\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\arcs.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\bars.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\blocks.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\blueprnt.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\capsules.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\downtown.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\expeditn.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\highway.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\neon.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\normal.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\poetic.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\street.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\css\sweets.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\DocLibs\doclib1.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\DocLibs\"=""
"C:\Program Files\Microsoft Office\Templates\1033\DocLibs\doclib2.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\bantoc.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\footer.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\footnote.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\header.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\horzsplt.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\navwtoc.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\toc.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\threelev.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\topdown.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Frames\vertsplt.tem\"=""
"C:\Program Files\Microsoft Office\Office10\images\"=""
"C:\Program Files\Microsoft Office\Office10\fpclass\"=""
"C:\Program Files\Microsoft Office\Office10\1033\webcomp\bcentral\"=""
"C:\Program Files\Microsoft Office\Office10\1033\webcomp\expedia\"=""
"C:\Program Files\Microsoft Office\Office10\1033\webcomp\msn\"=""
"C:\Program Files\Microsoft Office\Office10\1033\webcomp\msnbc\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\1center.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\1cheads.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\1cleft.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\1cright.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\2ceven.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\2cmenul.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\2cmenur.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\2cstagr.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\3c2stagl.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\3ceven.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\3cmenuc.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\3cmenul.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\3csidbar.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\4ccenter.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\4cstagc.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\4cstagl.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\biblio.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\confirm.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\faq.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\feedback.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\vtiform.wiz\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\guestbk.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\normal.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\photo.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\reguser.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\search.tem\"=""
"C:\Program Files\Microsoft Office\Templates\1033\Pages\toc.tem\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Server Extensions\50\isapi\_vti_adm\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Server Extensions\50\isapi\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Server Extensions\50\isapi\_vti_aut\"=""
"C:\Program Files\Fichiers communs\Microsoft Shared\Web Serve
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
13 sept. 2007 à 11:53
Ok, on va lui règler son compte...

- Copie colle le contenu du cadre dans un fichier texte, sur ton bureau, sous le nom Remove.txt
Drivers to unload:
srosa

registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa

Files to delete:
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\drivers\hidr.exe 
C:\Documents and Settings\%USERNAME%\Application Data\hidires\hidr.exe
C:\Documents and Settings\%USERNAME%\Application Data\hidires\srosa.sys

Folders to delete:
C:\WINDOWS\exefld

- Fais bien attention à avoir tout le cadre !
- Télécharge The Avenger de Swandog46 ici: http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/
- Décompresse l'archive et double cliques sur TheAvenger.exe
- Cliques sur OK
- Sélectionne "Load Script from File" et cliques sur l'icone en forme de dossier
- Sélectionne le fichier que tu as créé remove.txt
- Cliques sur le feu vert pour lancer le script
- Cliques sur OUI et redémarre le PC quand demandé.
- Poste le rapport ici.
0
Voila le résultat, merci déjà pour tout cela, car tes consignes sont vraiment trés claire et de plus fonctionne dans leur application, maintenant a toi de me dire si mon pc redevient clean ..., rapport :

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\flmjifmh

*******************

Script file located at: \??\C:\ueupiyol.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver srosa unloaded successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.


Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Status: 0xc0000034

File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\drivers\hidr.exe deleted successfully.


Could not open file C:\Documents and Settings\Compaq_Propriétaire\Application Data\hidires\hidr.exe for deletion
Deletion of file C:\Documents and Settings\Compaq_Propriétaire\Application Data\hidires\hidr.exe failed!

Could not process line:
C:\Documents and Settings\Compaq_Propriétaire\Application Data\hidires\hidr.exe
Status: 0xc000003a



Could not open file C:\Documents and Settings\Compaq_Propriétaire\Application Data\hidires\srosa.sys for deletion
Deletion of file C:\Documents and Settings\Compaq_Propriétaire\Application Data\hidires\srosa.sys failed!

Could not process line:
C:\Documents and Settings\Compaq_Propriétaire\Application Data\hidires\srosa.sys
Status: 0xc000003a

Folder C:\WINDOWS\exefld deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
13 sept. 2007 à 16:08
Bien bien tout çà...

Tu devrais pouvoir installer un antivirus maintenant ! Je te recommande Avira Antivir, il est gratuit et performant. Son seul désavantage est qu'il est en anglais.. C'est pour cela que je t'invite à suivre ce tutoriel fait par Malekal_Morte: https://www.malekal.com/avira-free-security-antivirus-gratuit/

Dis moi, cela a fonctionné ?
0
Ok, je télécharge antivir chez moi ce soir, et tente de l'installer demain matin, et bien sur te donne le résultat de tout cela. J 'aurais un autre prob à te soulever si tu veut bien sur. Un message récurrent quand je ferme windows, message sans incidence apparemment, qui est survenu depuis environ 3 mois, quand un technicien m'a installer le mot de passe de windows obligé, pour pouvoir utiliser un scanner directement a partir de mon copieur laser connecté, je te donnerais le message exact, mais avant tout finissons ce travail bien entammé pour exterminer ce virus. Je te dis à demain, et j'en profite pour te redire un grand merci, car c est la première fois que j'utilise un forum pour règler un prob, pourtant je bosse dans la pao, a mon compte depuis 1989, dont tu t en doute j'en ai connu des virus et prob diverses sur windows, à l'époque version 3.1 !!! Mais là, avec les nouveaux virus qui apparaissent depuis disons 3.4 ans, cela dépasse ma faible connaissance en la matière, alors encore merci et surement bravo je te confirmerais cela demain, car offrir ces compétences ainsi sans arrière pensée mercantile, bravo, d'autant que je le fais aussi, dans mon domaine, pour certains cas bien précis. A demain pour le résultat suite à l'installation d'Antivir

Dominique
0
Salut,

Sorry pour ce retard mais plein de taf. Déjà un grand bravo, car j'ai pu installé antivir, bien sur je préfère Avast, car ses mise a jour sont rapide. Bravo bravo. Maintenant je t'explique la suite car tout apparemment n'est pas vraiment clean. J'ai d abord tenté la mise à jour d antivir, et la au bout d'un long moment de chargement apparemment, il stop, je vérifie dans report de l antivir, et il indique par quatre quatre, que la mise a jour est sans sucès, voila le premier brob, une hypothèse de ma part, mais c est toi le super super pro, qui va me dire cela, le poste sur lequel, tu as reussi a oter bagle, et en basse connection, pas adsl ... adsl chez moi bien sur, peut cela vient de la ?

Ensuite j'ai enfin passé le pc a l antivirus et il a détecte ces trois virus :

w95/blumblebee.1738
bds/vb.alb.2
tr/bable.gen.bque j'ai mis en quarantaine

Voilà, j'attends de tes nouvelles pour peaufiner cela, avant de t expliquer mon dernier prob en fermant le pc.

Si pour la mise à jour cela vient de la basse connection, dis moi comment faire pour récupérer une mise a jour sur un autre poste, qu on a bien sur en adsl, et l'installer ensuite sur ce poste.

Bonne journée, ici à Nantes gros soleil, et 24 ° et toi ?

Dominique
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
14 sept. 2007 à 14:13
Salut,

Je vais essayer de répondre à tout... en allant évidemment du plus agréable au moins agréable ;o)

Donc, chez moi, en Belgique aux alentours de Liège, il fait beau soleil. Pourvu que çà dure !

Ensuite, si j'ai bien compris le problème rencontré avec Antivir, tu n'as pas pu faire les mises à jour avec ton PC basse connexion, mais tu as réussi avec ton PC haut débit ? Je sais qu'il y a eut quelques problèmes récemment avec les mises à jour Avira, je vais essayer de jeter un oeil à cela. En attendant, tu peux toujours essayer de refaire les mises à jour de temps en temps et voir si çà marche.. (le problème ne vient de toute façon plus de Bagle).

Enfin, les infections que tu as trouvé en faisant le scan (avec quel antivirus ? Si tu l'as fait avec Antivir, il n'était donc pas à jour ?) sont à mon avis placées dans la restauration système. Pour vérifier, si tu pouvais poster le rapport de l'antivirus, çà m'aiderait (et toi par la même occasion :o)

En espérant avoir répondu à tout,

Bonne journée,
0
Re,

J'ai mon frère qui bosse en Belgique, à Bruxelles, au parement Européen.

Donc pour être plus précis, pas réussis à faire la mise à jour sur ce poste bas débit.
Concernant les trois virus trouvé par antivir sans mise à jour, j'ai fait un deuxième scan après les avoir mis en quarantaine, il détecte plus de virus.
J'ai eu aussi un soucis au démarrage, un soft MINDSOFT activé avec une option d'optimisation de RAM, se lancer tout le temps, je l'ai désinstalé, et j'ai remarqué que deux des virus était en rapport avec MINSOFT, à toi de voir ca de plus près.

Voila, sinon, pour ce prob, de mise, me serait il pas plus cool d'installer comme antivirus, AVAST, bien que j'ai lu sur ton site la démonstration de performance d'Antivir ??

Voila le rapport d'Antivir:



AntiVir PersonalEdition Classic
Report file date: vendredi 14 septembre 2007 11:24

Scanning for 1036370 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Compaq_Propriétaire
Computer name: MAITREVADOR

Version information:
BUILD.DAT : 269 15604 Bytes 10/09/2007 14:31:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 11:32:40
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 11:32:46
ANTIVIR2.VDF : 6.39.1.43 1542656 Bytes 25/08/2007 16:21:02
ANTIVIR3.VDF : 6.39.1.51 29696 Bytes 28/08/2007 06:22:36
AVEWIN32.DLL : 7.6.0.5 2789888 Bytes 29/08/2007 16:09:10
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: vendredi 14 septembre 2007 11:24

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Illustrator.exe' - '1' Module(s) have been scanned
Scan process 'CorelDRW.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned
Scan process 'spooler.exe' - '1' Module(s) have been scanned
Scan process 'FNPLicensingService.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'Dds.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'iwctrl.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'AAWTray.exe' - '1' Module(s) have been scanned
Scan process 'freeram.exe' - '1' Module(s) have been scanned
Scan process 'acrotray.exe' - '1' Module(s) have been scanned
Scan process 'MSTMON_J.EXE' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'MXTASK.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'DdsSchedNT.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SOption.exe' - '1' Module(s) have been scanned
Scan process 'SrScanDr.exe' - '1' Module(s) have been scanned
Scan process 'RsiSvc.exe' - '1' Module(s) have been scanned
Scan process 'imapi.exe' - '1' Module(s) have been scanned
Scan process 'MXTASK.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'incdsrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
44 processes with 44 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[NOTE] No virus was found!
Master boot sector HD1
[NOTE] No virus was found!
[WARNING] The boot sector file could not be read!
[WARNING] Error code: 0x0057
Master boot sector HD2
[NOTE] No virus was found!
[WARNING] The boot sector file could not be read!
[WARNING] Error code: 0x0015
Master boot sector HD3
[NOTE] No virus was found!
[WARNING] The boot sector file could not be read!
[WARNING] Error code: 0x0015
Master boot sector HD4
[NOTE] No virus was found!
[WARNING] The boot sector file could not be read!
[WARNING] Error code: 0x0015
Master boot sector HD5
[NOTE] No virus was found!
[WARNING] The boot sector file could not be read!
[WARNING] Error code: 0x0015
Master boot sector HD6
[NOTE] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!

Starting to scan the registry.
The registry was scanned ( '48' files ).


Starting the file scan:

Begin scan in 'C:\' <DD PROGRAMMES>
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\avenger\backup.zip
[0] Archive type: ZIP
--> avenger/hidr.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was moved to '474d53ce.qua'!
C:\Program Files\MindSoft\MindSoft Utilities XP 9\io.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Vb.ALB.2 Backdoor server programs
[INFO] The file was moved to '47186a71.qua'!
C:\WINDOWS\system32\ActiveScan\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47556eee.qua'!
Begin scan in 'D:\' <DD FICHIERS>


End of the scan: vendredi 14 septembre 2007 13:31
Used time: 2:07:03 min

The scan has been done completely.

7334 Scanning directories
543804 Files were scanned
3 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
3 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
543801 Files not concerned
14392 Archives were scanned
6 Warnings
7 Notes

Voila je préfère qu' on règle tout cela avant d'aborder, le dernier prob déjà cité, celui du message en fermant windows, si tu v bien !

A plus
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
14 sept. 2007 à 18:20
Bonsoir,

Pour le scan d'Antivir, je vais t'expliquer ce que tout çà veut dire pour que tu comprennes bien ce qui se passe.

Ceci est normal:
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened! 
Ceci est ce que The Avenger (le programme que je t'ai fait utiliser pour tuer Bagle) a gardé de Bagle, disons, ce qu'il a emprisonné. Antivir l'a trouvé et l'a mis dans sa propre quarantaine
C:\avenger\backup.zip
[0] Archive type: ZIP
--> avenger/hidr.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was moved to '474d53ce.qua'! 
Pour ceci, je vais me renseigner:
C:\Program Files\MindSoft\MindSoft Utilities XP 9\io.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Vb.ALB.2 Backdoor server programs
[INFO] The file was moved to '47186a71.qua'! 
Et enfin ceci serait un faux positif, ou toute fois ce n'est pas grave:
C:\WINDOWS\system32\ActiveScan\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47556eee.qua'! 


EDIT IMPORTANT: Je ne sais pas comment, mais Antivir EST A JOUR. Donc, tu peux le garder, je te le recommande fortement.

Pour ton problème à la fermeture je vais jeter un oeil.

Cordialement,
0
O VertigO Messages postés 862 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 10 février 2008 32
14 sept. 2007 à 18:43
Voila j'ai fait quelques recherches sur "io.exe", et apparemment c'est pas joli. Je dis apparemment car je ne suis pas toujours d'accord avec ce que disent les antivirus :oP

Enfin, pour ta sécurité, fais ceci:
- Télécharge SpySweeper ici: https://www.webroot.com/us/en en version d'essai (Trial)
- Mets à jour la définition virale
- Dans options, sur la gauche, sous l'onglet option, coches ces cases:
* Sweep Memory
* Sweep Registry
* Sweep Cookies
* Sweep All User Accounts
* Enable Direct Disk Sweeping
* Sweep Contents of Compressed Files
* Sweep for Rootkits
* Décoche Do not Sweep System Restore Folder. (Merci Malekal_Morte)
- Cliques sur SweepNow puis sur start.

Peux tu me confirmer que tu ne veux plus de MindSoft ? (bonne idée tiens çà :-D)
Peux tu aussi supprimer RegistrySmart qui est une arnaque.. Utilise plutot CCleaner comme indiqué ici: https://www.malekal.com/tutoriel-ccleaner/

Amicalement,
0