bonjour marie
concernant AVG au démarrage : g simplement répondu à une question posé par le logicile "voulez vous que avg s'execute au démarrage de window et g répondu non" (g fait pour éviter de ralentir encore plus le démarrage de vista)
g donc fait ms config est g une plus d'une vingtaine de lignes cochées à la fin de la fenetre se trouve les fichiers décochés (itunes messenger..)
et voici de rapport de gmer
GMER 1.0.12.12244 -
http://www.gmer.net
Rootkit scan 2007-06-15 07:44:54
Windows 6.0.6000
---- System - GMER 1.0.12 ----
SSDT 8AB5DAE8 ZwAlertResumeThread
SSDT 8AB5DBC8 ZwAlertThread
SSDT 8AB78678 ZwAllocateVirtualMemory
SSDT 8AB3BA78 ZwConnectPort
SSDT 8AB71E88 ZwCreateMutant
SSDT 8AB78808 ZwCreateThread
SSDT 8AB75F90 ZwFreeVirtualMemory
SSDT 8AB5D808 ZwImpersonateAnonymousToken
SSDT 8AB5DA08 ZwImpersonateThread
SSDT 8AB75EB0 ZwMapViewOfSection
SSDT 8AB5A230 ZwOpenEvent
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT 8AB78748 ZwOpenProcessToken
SSDT 8AB75C10 ZwOpenThreadToken
SSDT 8AB796C0 ZwResumeThread
SSDT 8AB75B30 ZwSetContextThread
SSDT 8AB75CF0 ZwSetInformationProcess
SSDT 8AB75A50 ZwSetInformationThread
SSDT 8ABA27F8 ZwSuspendProcess
SSDT 8AB5DD10 ZwSuspendThread
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT 8AB5DDD0 ZwTerminateThread
SSDT 8AB75DD0 ZwUnmapViewOfSection
SSDT 8AB78588 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.12 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 77E 82080AFA 6 Bytes [ B7, 8A, 50, 5A, B7, 8A ]
---- User code sections - GMER 1.0.12 ----
.text C:\Windows\system32\taskeng.exe[500] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 01EC200E
.text C:\Windows\system32\taskeng.exe[500] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 01EC1DAF
.text C:\Windows\system32\taskeng.exe[500] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 01EC1CF2
.text C:\Windows\system32\taskeng.exe[500] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 01EC191B
.text C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE[836] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 00E4200E
.text C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE[836] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 00E41DAF
.text C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE[836] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 00E41CF2
.text C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE[836] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 00E4191B
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 028C200E
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 028C1DAF
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 028C1CF2
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 028C191B
.text C:\Windows\Explorer.EXE[1860] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 031C200E
.text C:\Windows\Explorer.EXE[1860] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 031C1DAF
.text C:\Windows\Explorer.EXE[1860] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 031C1CF2
.text C:\Windows\Explorer.EXE[1860] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 031C191B
.text C:\Users\CATHY&~1\AppData\Local\Temp\RtkBtMnt.exe[1916] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 013B200E
.text C:\Users\CATHY&~1\AppData\Local\Temp\RtkBtMnt.exe[1916] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 013B1DAF
.text C:\Users\CATHY&~1\AppData\Local\Temp\RtkBtMnt.exe[1916] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 013B1CF2
.text C:\Users\CATHY&~1\AppData\Local\Temp\RtkBtMnt.exe[1916] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 013B191B
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[2004] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 012D200E
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[2004] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 012D1DAF
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[2004] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 012D1CF2
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[2004] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 012D191B
.text C:\Windows\ehome\ehmsas.exe[2020] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0011200E
.text C:\Windows\ehome\ehmsas.exe[2020] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 00111DAF
.text C:\Windows\ehome\ehmsas.exe[2020] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 00111CF2
.text C:\Windows\ehome\ehmsas.exe[2020] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0011191B
.text C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe[2028] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 012B200E
.text C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe[2028] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 012B1DAF
.text C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe[2028] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 012B1CF2
.text C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe[2028] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 012B191B
.text C:\Program Files\Internet Explorer\ieuser.exe[2052] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 01F0200E
.text C:\Program Files\Internet Explorer\ieuser.exe[2052] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 01F01DAF
.text C:\Program Files\Internet Explorer\ieuser.exe[2052] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 01F01CF2
.text C:\Program Files\Internet Explorer\ieuser.exe[2052] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 01F0191B
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.exe[2140] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 003D200E
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.exe[2140] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 003D1DAF
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.exe[2140] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 003D1CF2
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.exe[2140] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 003D191B
.text C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE[2184] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 043E200E
.text C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE[2184] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 043E1DAF
.text C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE[2184] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 043E1CF2
.text C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE[2184] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 043E191B
.text C:\Program Files\Launch Manager\LManager.exe[2612] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 015F200E
.text C:\Program Files\Launch Manager\LManager.exe[2612] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 015F1DAF
.text C:\Program Files\Launch Manager\LManager.exe[2612] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 015F1CF2
.text C:\Program Files\Launch Manager\LManager.exe[2612] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 015F191B
.text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2912] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 003B200E
.text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2912] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 003B1DAF
.text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2912] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 003B1CF2
.text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2912] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 003B191B
.text C:\Windows\System32\mobsync.exe[3188] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0049200E
.text C:\Windows\System32\mobsync.exe[3188] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 00491DAF
.text C:\Windows\System32\mobsync.exe[3188] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 00491CF2
.text C:\Windows\System32\mobsync.exe[3188] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0049191B
.text C:\Program Files\Alwil Software\Avast4\ashDisp.exe[3292] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 01F7200E
.text C:\Program Files\Alwil Software\Avast4\ashDisp.exe[3292] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 01F71DAF
.text C:\Program Files\Alwil Software\Avast4\ashDisp.exe[3292] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 01F71CF2
.text C:\Program Files\Alwil Software\Avast4\ashDisp.exe[3292] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 01F7191B
.text C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE[3372] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 016E200E
.text C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE[3372] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 016E1DAF
.text C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE[3372] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 016E1CF2
.text C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE[3372] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 016E191B
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3428] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0173200E
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3428] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 01731DAF
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3428] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 01731CF2
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3428] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0173191B
.text C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe[3540] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0136200E
.text C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe[3540] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 01361DAF
.text C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe[3540] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 01361CF2
.text C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe[3540] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0136191B
.text C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE[3544] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0531200E
.text C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE[3544] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 05311DAF
.text C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE[3544] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 05311CF2
.text C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE[3544] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0531191B
.text C:\Windows\System32\sflflqdidj.exe[3624] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0212200E
.text C:\Windows\System32\sflflqdidj.exe[3624] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 02121DAF
.text C:\Windows\System32\sflflqdidj.exe[3624] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 02121CF2
.text C:\Windows\System32\sflflqdidj.exe[3624] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0212191B
.text C:\Program Files\Windows Sidebar\sidebar.exe[3832] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 020F200E
.text C:\Program Files\Windows Sidebar\sidebar.exe[3832] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 020F1DAF
.text C:\Program Files\Windows Sidebar\sidebar.exe[3832] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 020F1CF2
.text C:\Program Files\Windows Sidebar\sidebar.exe[3832] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 020F191B
.text C:\Windows\ehome\ehtray.exe[3840] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0025200E
.text C:\Windows\ehome\ehtray.exe[3840] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 00251DAF
.text C:\Windows\ehome\ehtray.exe[3840] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 00251CF2
.text C:\Windows\ehome\ehtray.exe[3840] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0025191B
.text C:\Windows\RtHDVCpl.exe[3964] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 0155200E
.text C:\Windows\RtHDVCpl.exe[3964] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 01551DAF
.text C:\Windows\RtHDVCpl.exe[3964] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 01551CF2
.text C:\Windows\RtHDVCpl.exe[3964] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 0155191B
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3972] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 00CA200E
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3972] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 00CA1DAF
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3972] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 00CA1CF2
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3972] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 00CA191B
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN[4116] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 02AC200E
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN[4116] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 02AC1DAF
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN[4116] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 02AC1CF2
.text C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN[4116] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 02AC191B
.text C:\Windows\System32\rundll32.exe[4620] ntdll.dll!NtEnumerateKey 7799F8A4 5 Bytes JMP 00CD200E
.text C:\Windows\System32\rundll32.exe[4620] ntdll.dll!NtEnumerateValueKey 7799F8D4 5 Bytes JMP 00CD1DAF
.text C:\Windows\System32\rundll32.exe[4620] ntdll.dll!NtQueryDirectoryFile 7799FDF4 5 Bytes JMP 00CD1CF2
.text C:\Windows\System32\rundll32.exe[4620] ntdll.dll!NtQuerySystemInformation 7799FFD4 5 Bytes JMP 00CD191B
---- Registry - GMER 1.0.12 ----
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- Files - GMER 1.0.12 ----
ADS C:\Users\cathy&ste\AppData\Local\Microsoft\Messenger\cathyetste@hotmail.fr\SharingMetadata\yvette_f@hotmail.fr\DFSR\Staging\CS{C5B8CEFC-9556-D47C-701C-FFC09B01886D}\01\10-{C5B8CEFC-9556-D47C-701C-FFC09B01886D}-v1-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Users\cathy&ste\AppData\Local\Microsoft\Messenger\cathyetste@hotmail.fr\SharingMetadata\yvette_f@hotmail.fr\DFSR\Staging\CS{C5B8CEFC-9556-D47C-701C-FFC09B01886D}\11\11-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v11-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Users\cathy&ste\AppData\Local\Microsoft\Messenger\cathyetste@hotmail.fr\SharingMetadata\yvette_f@hotmail.fr\DFSR\Staging\CS{C5B8CEFC-9556-D47C-701C-FFC09B01886D}\11\11-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v11-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Users\cathy&ste\AppData\Local\Microsoft\Messenger\cathyetste@hotmail.fr\SharingMetadata\yvette_f@hotmail.fr\DFSR\Staging\CS{C5B8CEFC-9556-D47C-701C-FFC09B01886D}\11\11-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v11-{99446D37-94E9-48F2-A04D-155A7DB11B62}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
---- EOF - GMER 1.0.12 ----
ENCORE MERCI ET A BIENTOT
