Bonsoir,
Il y a eu un problème et j’ai eu 9 rapports.
Premier :
Mode: Recherche – Date : 23/06/2011 01:16:41
Processus malicieux: 0
Entrees de registre: 16
[SUSP PATH] HKCU[…]\Run : cacaoweb (“C:\Users\giai\AppData\Roaming\cacaoweb\cacaoweb.exe” -noplayer) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-2936724674-3419763982-3789971728-1000[…]\Run : cacaoweb (“C:\Users\giai\AppData\Roaming\cacaoweb\cacaoweb.exe” -noplayer) -> FOUND
[SUSP PATH] {03FE7846-2C15-455E-9923-EAEEE94E2121}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> FOUND
[SUSP PATH] {182845B4-9862-4475-94B7-534602441ED5}.job : c:\users\giai\desktop\aequitas\aequitas.exe -> FOUND
[SUSP PATH] {2C388E79-EF01-49DB-BBD4-679AC4A012F8}.job : c:\users\giai\desktop\aoe\aoeinst.exe -> FOUND
[SUSP PATH] {345C56C3-4B5D-4E18-8282-D85D14D66640}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> FOUND
[SUSP PATH] {3EFBFBDF-366E-4891-B55E-0B1C32BA4298}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> FOUND
[SUSP PATH] {85BA2260-52F9-4C5C-AF63-8ED96AFD674D}.job : c:\users\giai\desktop\wlan optimizer\wlan optimizer.exe -> FOUND
[SUSP PATH] {C7A8D0B2-5DF3-4EF6-9AC8-1BCB86AFF794}.job : c:\users\giai\desktop\usbmrs11.exe -> FOUND
[SUSP PATH] {E538C1FF-4F32-4405-BE0D-F9F899DDEBDD}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> FOUND
[SUSP PATH] {F405B50A-B308-4D17-93C9-3E88CCAE66AC}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> FOUND
[PROXY IE] HKCU[…]\Internet Settings : ProxyServer (
-> FOUND
[HJ] HKLM[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ] HKCU[…]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ] HKCU[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
Fichier HOSTS:
78.47.251.150 easyanticheat.se # misleading site
78.47.251.150 www.easyanticheat.se # misleading site
78.47.251.150 easyanticheat.com # misleading site
78.47.251.150 www.easyanticheat.com # misleading site
78.47.251.150 easyanticheat.org # misleading site
78.47.251.150 www.easyanticheat.org # misleading site
Deuxième :
Mode: Suppression – Date : 23/06/2011 01:17:36
Processus malicieux: 0
Entrees de registre: 15
[SUSP PATH] HKCU[…]\Run : cacaoweb (“C:\Users\giai\AppData\Roaming\cacaoweb\cacaoweb.exe” -noplayer) -> DELETED
[SUSP PATH] {03FE7846-2C15-455E-9923-EAEEE94E2121}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> DELETED
[SUSP PATH] {182845B4-9862-4475-94B7-534602441ED5}.job : c:\users\giai\desktop\aequitas\aequitas.exe -> DELETED
[SUSP PATH] {2C388E79-EF01-49DB-BBD4-679AC4A012F8}.job : c:\users\giai\desktop\aoe\aoeinst.exe -> DELETED
[SUSP PATH] {345C56C3-4B5D-4E18-8282-D85D14D66640}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> DELETED
[SUSP PATH] {3EFBFBDF-366E-4891-B55E-0B1C32BA4298}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> DELETED
[SUSP PATH] {85BA2260-52F9-4C5C-AF63-8ED96AFD674D}.job : c:\users\giai\desktop\wlan optimizer\wlan optimizer.exe -> DELETED
[SUSP PATH] {C7A8D0B2-5DF3-4EF6-9AC8-1BCB86AFF794}.job : c:\users\giai\desktop\usbmrs11.exe -> DELETED
[SUSP PATH] {E538C1FF-4F32-4405-BE0D-F9F899DDEBDD}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> DELETED
[SUSP PATH] {F405B50A-B308-4D17-93C9-3E88CCAE66AC}.job : c:\users\giai\desktop\android-sdk-windows\tools\emulator.exe -> DELETED
[PROXY IE] HKCU[…]\Internet Settings : ProxyServer (
-> NOT REMOVED, USE PROXYFIX
[HJ] HKLM[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU[…]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
Fichier HOSTS:
78.47.251.150 easyanticheat.se # misleading site
78.47.251.150 www.easyanticheat.se # misleading site
78.47.251.150 easyanticheat.com # misleading site
78.47.251.150 www.easyanticheat.com # misleading site
78.47.251.150 easyanticheat.org # misleading site
78.47.251.150 www.easyanticheat.org # misleading site
Troisième :
Mode: HOSTS RAZ – Date : 23/06/2011 01:18:10
Processus malicieux: 0
Fichier HOSTS:
78.47.251.150 easyanticheat.se # misleading site
78.47.251.150 www.easyanticheat.se # misleading site
78.47.251.150 easyanticheat.com # misleading site
78.47.251.150 www.easyanticheat.com # misleading site
78.47.251.150 easyanticheat.org # misleading site
78.47.251.150 www.easyanticheat.org # misleading site
Nouveau fichier HOSTS:
127.0.0.1 localhost
Quatrième :
Mode: DNS RAZ – Date : 23/06/2011 01:24:58
Processus malicieux: 0
Entrees de registre: 0
Cinquième :
Mode: Raccourcis RAZ – Date : 23/06/2011 01:22:45
Processus malicieux: 0
Attributs de fichiers restaures:
Bureau: Success 1 / Fail 0
Lancement rapide: Success 1 / Fail 0
Programmes: Success 9 / Fail 0
Menu demarrer: Success 2 / Fail 0
Dossier utilisateur: Success 264 / Fail 0
Mes documents: Success 13 / Fail 0
Mes favoris: Success 0 / Fail 0
Mes images: Success 0 / Fail 0
Ma musique: Success 1680 / Fail 0
Mes videos: Success 0 / Fail 0
Disques locaux: Success 70 / Fail 0
Sauvegarde: [NOT FOUND]
Lecteurs:
[A:] \Device\Floppy0 – 0x2 --> Skipped
[C:] \Device\HarddiskVolume2 – 0x3 --> Restored
[D:] \Device\CdRom0 – 0x5 --> Skipped
[E:] \Device\CdRom1 – 0x5 --> Skipped
[Q:] \Device\SftVol – 0x3 --> Restored
Le dernier reste introuvable :(.
Merci encore, Quartz.