NTSB/bagle

Fermé
fanny - 29 déc. 2008 à 15:58
 dready76 - 31 déc. 2008 à 19:35
Bonjour,
j'ai eu un gros probleme...En effet, mon ordinateur c'est éteint tout d'un coup et au démarrage avast ne fonctionné plus..."avast n'est pas une application Win32"..de plus quand l'ordinateur redémarre il y a une fenetre qui s'ouvre:NTSB
QUELQU'UN POURRAIT IL M'AIDER SVP...

65 réponses

Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 18:11
Tape 1 puis Entrée, tape 2 puis Entrée, ...
0
ha oui pardon
voici le rapport

--------- Logfile of AD-Remover 1.0.8.1 by C_XX ---------

*** Limited to ***

Boonty/BoontyGames
Eorezo
Everest Poker
Funwebproduct/MyWay/MyWebsearch
It's TV
Sweetim

******************

# START at: 18:11:56 | Lun 29/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal

# OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat

# PC: ALAIN | USER: couturier ( Current user is an administrator)

# DRIVE(S):
- C:\ (File System: NTFS)

# Internet Explorer v7.0.5730.13

--------- [ RUNNING PROCESSES: 22 ] ---------

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe

-----------------------------------

(!) ---- IE start pages reset

+-----------------------| Boonty/Boonty Games Elements Deleted :

.

+-----------------------| Eorezo Elements Deleted :

"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1"
.
[29/12/2008 17:54|d--------] C:\Program Files\EoRezo
[29/12/2008 17:44|d--------] C:\Documents and Settings\couturier\Application Data\EoRezo
[29/12/2008 11:20|--a------] C:\DOCUME~1\COUTUR~1\Cookies\COF832~1.TXT
[12/11/2008 21:56|--a------] C:\DOCUME~1\COUTUR~1\Cookies\CO3EA2~1.TXT

+-----------------------| Everest Poker Elements Deleted :

.

+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :

.

+-----------------------| It's TV Elements Deleted :

.

+-----------------------| Sweetim Elements Deleted :

.

(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.


+-----------------------| ADDED SCAN :


+---------------------------------------------------------------------------+

+--[HKEY_CURRENT_USER\..\Run]

ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

+--[HKEY_LOCAL_MACHINE\..\Run]

mgsxlybzqwgil REG_SZ C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\coviokgwkc.dll"
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

+--[HKEY_USERS\.DEFAULT\..\Run]


+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]

Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]

Start Page : hxxp://fr.msn.com/

+---------------------------------------------------------------------------+

- "C:\AD-report-Clean-29.12.2008.log" (~3833 bytes)

- "C:\AD-report-Scan-29.12.2008.log" (~7182 bytes)

# END at: 18:13:38 | 29/12/2008 - Time elapsed: 1 minute, 42 seconds

+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 83 lines ]
+---------------------------------------------------------------------------+
0
que me reste t-il a faire maintenant?!
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 18:24
---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:services
eac_notifysvc
eac_productsvc

:files
C:\Documents and Settings\All Users\Application Data\Solt Lake Software
C:\Program Files\Fichiers communs\eAcceleration
C:\PROGRA~1\eAcceleration

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"mgsxlybzqwgil"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"drvsyskit"=-
"german.exe"=-
"mule_st_key"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\DOCUME~1\COUTUR~1\LOCALS~1\Temp\services.exe"=-
"C:\Documents and Settings\couturier\Application Data\m\flec006.exe"=-

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]






---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service eac_notifysvc stopped successfully.
Service eac_notifysvc deleted successfully.
Service eac_productsvc stopped successfully.
Service eac_productsvc deleted successfully.
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009 moved successfully.
C:\Documents and Settings\All Users\Application Data\Solt Lake Software moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\SysSnap moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer\resources\js moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer\resources\images moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer\resources\icons moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer\resources\html moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer\resources\css moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer\resources moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\Installer moved successfully.
C:\Program Files\Fichiers communs\eAcceleration\eAnthComponents moved successfully.
C:\Program Files\Fichiers communs\eAcceleration moved successfully.
C:\PROGRA~1\eAcceleration\Framework moved successfully.
C:\PROGRA~1\eAcceleration moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mgsxlybzqwgil deleted successfully.
Unable to delete registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\drvsyskit .
Unable to delete registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\german.exe .
Unable to delete registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mule_st_key .
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\DOCUME~1\COUTUR~1\LOCALS~1\Temp\services.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\couturier\Application Data\m\flec006.exe deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12292008_182720
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 18:38
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.

A la fin de l'analyse, un message s'affiche :

L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
0
apparament tout n'a pas été supprimés, cela sera fait au redémarrage...


Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1568
Windows 5.1.2600 Service Pack 2

29/12/2008 18:47:14
mbam-log-2008-12-29 (18-47-14).txt

Type de recherche: Examen rapide
Eléments examinés: 52567
Temps écoulé: 3 minute(s), 50 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 8
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 27

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{018b7ec3-eeca-11d3-8e71-0000e82c6c0d} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Solt Lake Software (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020Search) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Delete on reboot.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\dynamic toolbar (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2 (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache (Adware.2020search) -> Quarantined and deleted successfully.
C:\Documents and Settings\couturier\Application Data\m (Trojan.Agent) -> Delete on reboot.

Fichier(s) infecté(s):
C:\Program Files\dynamic toolbar\PBFRV2\Cache\ErrorLog.txt (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\go.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\home.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\logo_pb.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\parent_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\parent_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\pbfrv2tb0200.cfg (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\popup_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\popup_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\search.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\services.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin1.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin2.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin3.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin4.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin5.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\store.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\style.css (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\support.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\ticker.xml (Adware.2020search) -> Quarantined and deleted successfully.
C:\Documents and Settings\couturier\Application Data\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\couturier\Application Data\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\couturier\Application Data\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot.
C:\Documents and Settings\couturier\Application Data\m\flec006.exe (Trojan.Agent) -> Delete on reboot.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 18:52
Bizarre ton histoire.

--> Télécharge FindyKill (par Chiquitine29) sur ton Bureau.

--> Lance l'installation avec les paramètres par défaut.

--> Double-clique sur le raccourci FindyKill sur ton Bureau.

--> Au menu principal, choisis l'option 1 (Recherche).

--> Poste le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
0
----------------- FindyKill V4.710 ------------------

* User : couturier - ALAIN
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 21/12/08 par Chiquitine29
* Recherche effectuée à 18:55:38 le 29/12/2008
* Windows XP - Internet Explorer 7.0.5730.13

((((((((((((((((( *** Recherche *** ))))))))))))))))))


--------------- [ Processus actifs ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

--------------- [ Processus infectieux stoppés ] ----------------


"C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe" (208)


--------------- [ Fichiers/Dossiers infectieux ] ----------------


»»»» Presence des fichiers dans C:


»»»» Presence des fichiers dans C:\WINDOWS


»»»» Presence des fichiers dans C:\WINDOWS\Prefetch

Found ! - C:\WINDOWS\prefetch\70203.EXE-29824ACE.pf
Found ! - C:\WINDOWS\prefetch\MDELK.EXE-0EF461CE.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-377E42D4.pf

»»»» Presence des fichiers dans C:\WINDOWS\system32

Found ! [29/12/2008 18:54] - C:\WINDOWS\system32\mdelk.exe
Found ! [29/12/2008 18:54] - C:\WINDOWS\system32\wintems.exe
Found ! [29/12/2008 18:55] - C:\WINDOWS\system32\ban_list.txt

»»»» Presence des fichiers dans C:\WINDOWS\system32\config\systemprofile\AppData\Roaming


»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers


»»»» Presence des fichiers dans C:\Documents and Settings\couturier\Application Data

Found ! [29/12/2008 17:27] - "C:\Documents and Settings\couturier\Application Data\drivers"
Found ! [29/12/2008 18:54] - "C:\Documents and Settings\couturier\Application Data\drivers\srosa.sys"
Found ! [29/12/2008 18:54] - "C:\Documents and Settings\couturier\Application Data\drivers\srosa2.sys"
Found ! [18/05/2005 09:03] - "C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe"
Found ! [29/12/2008 18:55] - "C:\Documents and Settings\couturier\Application Data\drivers\downld"
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\110296.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\111015.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\111546.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\112062.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\112828.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\113421.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\200718.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\266140.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\266968.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\267109.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\296625.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\297234.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\297703.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\372703.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\41984.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\42765.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\43109.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\443578.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\444531.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\447625.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\465515.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\466718.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\467343.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\468187.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\470390.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\472281.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\493203.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\493921.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\494546.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\502828.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\517906.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\518515.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\518968.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\53593.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\550875.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\551375.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\551468.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\612781.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\65406.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\65937.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\66125.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\673500.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\674406.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\683921.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\699500.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\701109.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\701781.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\70203.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\723843.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\724968.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\725578.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\732718.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\761015.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\761593.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\762125.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\788968.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\789843.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\790203.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\79500.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\79765.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\80015.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\80265.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\81828.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\83218.exe
Found ! [29/12/2008 18:55] - C:\Documents and Settings\couturier\Application Data\drivers\downld\88187.exe

»»»» Presence des fichiers dans C:\DOCUME~1\COUTUR~1\LOCALS~1\Temp


»»»» Presence des fichiers dans C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5

Found ! [29/12/2008 18:34] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\5N2YINOE\b64[1].jpg
Found ! [29/12/2008 18:34] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\5N2YINOE\mxd[1].jpg
Found ! [29/12/2008 18:36] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\MYC3R8D6\b64_1[1].jpg
Found ! [29/12/2008 18:29] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\MYC3R8D6\b64_3[1].jpg

--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
Installed=1
NoChange=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1

[HKEY_CURRENT_USER\software\local appwizard-generated applications\qttask]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]

--------------- [ Registre / Clés infectieuses ] ----------------


Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s

--------------- [ Etat / Services ] ----------------

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

- sans echec non fonctionnel !!



+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

/!\ Ndisuio - Type de démarrage = 4

/!\ Ip6Fw - Type de démarrage = 4

/!\ SharedAccess - Type de démarrage = 4

/!\ wuauserv - Type de démarrage = 4

/!\ wscsvc - Type de démarrage = 4



--------------- [ Recherche dans supports amovibles] ----------------


+- Informations :

C: - Lecteur fixe


+- presence des fichiers :



--------------- [ Registre / Mountpoint2 ] ----------------


-> Not found !


------------------- ! Fin du rapport ! --------------------
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 18:59
--> Double-clique sur le raccourci FindyKill sur ton Bureau.

--> Au menu principal, choisis l'option 2 (Suppression).

/!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\

--> Ensuite, poste le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
0
----------------- FindyKill V4.710 ------------------

* User : couturier - ALAIN
* executed from : C:\Program Files\FindyKill
* Update on 21/12/08 par Chiquitine29
* Start at 19:03:08 the 29/12/2008
* Windows XP - Internet Explorer 7.0.5730.13


((((((((((((((( *** deleting *** ))))))))))))))))))


--------------- [ Active Processes ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Userinit.exe

--------------- [ Infected files / folders ] ----------------


»»»» Supression files in C:


»»»» Supression files in C:\WINDOWS


»»»» Supression files in C:\WINDOWS\Prefetch

Deleted ! - C:\WINDOWS\prefetch\70203.EXE-29824ACE.pf
Deleted ! - C:\WINDOWS\prefetch\MDELK.EXE-0EF461CE.pf
Deleted ! - C:\WINDOWS\prefetch\WINTEMS.EXE-377E42D4.pf

»»»» Supression files in C:\WINDOWS\system32

Deleted ! - C:\WINDOWS\system32\mdelk.exe
Deleted ! - C:\WINDOWS\system32\wintems.exe
Deleted ! - C:\WINDOWS\system32\ban_list.txt

»»»» Supression files in C:\WINDOWS\system32\config\systemprofile\AppData\Roaming


»»»» Supression files in C:\WINDOWS\system32\drivers

Deleted ! - C:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - C:\WINDOWS\system32\drivers\srosa2.sys

»»»» Supression files in C:\Documents and Settings\couturier\Application Data

Deleted ! - "C:\Documents and Settings\couturier\Application Data\drivers\srosa.sys"
Deleted ! - "C:\Documents and Settings\couturier\Application Data\drivers\srosa2.sys"
Deleted ! - "C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe"
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\110296.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\111015.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\111546.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\112062.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\112828.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\113421.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\200718.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\266140.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\266968.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\267109.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\296625.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\297234.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\297703.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\372703.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\41984.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\42765.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\43109.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\443578.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\444531.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\447625.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\465515.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\466718.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\467343.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\468187.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\470390.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\472281.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\493203.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\493921.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\494546.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\502828.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\517906.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\518515.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\518968.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\53593.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\550875.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\551375.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\551468.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\612781.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\65406.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\65937.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\66125.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\673500.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\674406.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\683921.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\699500.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\701109.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\701781.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\70203.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\723843.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\724968.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\725578.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\732718.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\761015.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\761593.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\762125.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\788968.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\789843.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\790203.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\79500.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\79765.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\80015.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\80265.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\81828.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\83218.exe
Deleted ! - C:\Documents and Settings\couturier\Application Data\drivers\downld\88187.exe
Deleted ! - "C:\Documents and Settings\couturier\Application Data\drivers\downld"
Deleted ! - "C:\Documents and Settings\couturier\Application Data\drivers"

»»»» Supression files in C:\DOCUME~1\COUTUR~1\LOCALS~1\Temp


»»»» Supression files in C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5

Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\9LQ2GAOU\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64[2].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BGQMO8VR\b64_3[3].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BZLRRJYH\b64[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BZLRRJYH\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\BZLRRJYH\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\LO3J0NY7\b64[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\LO3J0NY7\mxd[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\RVFJVS8P\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\RVFJVS8P\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\RVFJVS8P\mxd[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\TWKWJ9S3\mxd[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\Y6OMF339\b64[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\Y6OMF339\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\Y6OMF339\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\YCZF3EJD\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\YCZF3EJD\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\YCZF3EJD\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\YCZF3EJD\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\YCZF3EJD\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\YCZF3EJD\mxd[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\5N2YINOE\b64[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\5N2YINOE\mxd[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\MYC3R8D6\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\MYC3R8D6\b64_3[1].jpg

--------------- [ Registry / Infected keys ] ----------------

Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\Local AppWizard-Generated Applications\winupgro

--------------- [ States / Restarting of services ] ----------------

+- Safe boot mode restored !


+- Services : [ Auto=2 / Request=3 / Disable=4 ]

Ndisuio - Type of startup = 3

Ip6Fw - Type of startup = 2

SharedAccess - Type of startup = 2

wuauserv - Type of startup = 2

wscsvc - Type of startup = 2


--------------- [ Cleaning removable drives ] ----------------

+- Informations :

C: - Lecteur fixe


+- deleting files :


--------------- [ Registry / Mountpoint2 ] ----------------


-> Not found !


--------------- [ Searching Cracks / Keygen ] ----------------

C:\Documents and Settings\couturier\Application Data\Macromedia\Flash Player\#SharedObjects\5M4Q9AXV\crackle.com
C:\Documents and Settings\couturier\Application Data\Macromedia\Flash Player\#SharedObjects\5M4Q9AXV\crackle.com\crackleSettings.sol
C:\Documents and Settings\couturier\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#crackle.com
C:\Documents and Settings\couturier\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#crackle.com\settings.sol


---------------- ! End of report ! ------------------
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 19:07
1/

---> Désinstalle FindyKill et AD-Remover.

---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).


2/

---> Refais un scan avec MBAM et poste le rapport.
0
[ Rapport ToolsCleaner version 2.2.9 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\FindyKill.txt: trouvé !
C:\UsbFix.txt: trouvé !
C:\avenger: trouvé !
C:\Qoobox: trouvé !
C:\_OtMoveIt: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\couturier\Bureau\UsbFix.exe: trouvé !
C:\Documents and Settings\couturier\Bureau\UsbFix.lnk: trouvé !
C:\Documents and Settings\couturier\Bureau\OTMoveIt3.exe: trouvé !
C:\Documents and Settings\couturier\Bureau\Rsit.exe: trouvé !
C:\Documents and Settings\couturier\Menu Démarrer\Programmes\UsbFix: trouvé !
C:\Documents and Settings\couturier\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: trouvé !
C:\Program Files\UsbFix: trouvé !
C:\Program Files\FindyKill: trouvé !
C:\Program Files\Acceleration Software\Anti-Virus\LSPFix.exe: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !
C:\Program Files\UsbFix\Tools\NIRCMD.exe: trouvé !

---------------------------------
-->- Suppression:

C:\Program Files\Acceleration Software\Anti-Virus\LSPFix.exe: ERREUR DE SUPPRESSION !!
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\FindyKill.txt: supprimé !
C:\UsbFix.txt: supprimé !
C:\Documents and Settings\couturier\Bureau\UsbFix.exe: supprimé !
C:\Documents and Settings\couturier\Bureau\UsbFix.lnk: supprimé !
C:\Documents and Settings\couturier\Bureau\OTMoveIt3.exe: supprimé !
C:\Documents and Settings\couturier\Bureau\Rsit.exe: supprimé !
C:\Documents and Settings\couturier\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\Program Files\UsbFix\Tools\NIRCMD.exe: supprimé !
C:\avenger: supprimé !
C:\Qoobox: supprimé !
C:\_OtMoveIt: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\couturier\Menu Démarrer\Programmes\UsbFix: supprimé !
C:\Program Files\UsbFix: supprimé !
C:\Program Files\FindyKill: ERREUR DE SUPPRESSION !!
0
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1568
Windows 5.1.2600 Service Pack 2

29/12/2008 19:13:49
mbam-log-2008-12-29 (19-13-49).txt

Type de recherche: Examen rapide
Eléments examinés: 52266
Temps écoulé: 3 minute(s), 15 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Documents (Trojan.Agent) -> Quarantined and deleted successfully.
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 19:15
---> Relance MBAM, va dans Quarantaine et supprime tout.

- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

- Double-clique sur RSIT.exe afin de lancer le programme.

- Clique sur Continue à l'écran Disclaimer.

- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
0
Logfile of random's system information tool 1.05 (written by random/random)
Run by couturier at 2008-12-29 19:16:30
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 163 GB (88%) free of 185 GB
Total RAM: 511 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:16:55, on 29/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\couturier\Bureau\RSIT.exe
C:\Program Files\trend micro\couturier.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [drvsyskit] C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe
O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
0
fanny > fanny
29 déc. 2008 à 19:18
info.txt logfile of random's system information tool 1.05 2008-12-29 19:16:56

======Uninstall list======

-->"c:\apps\skype\phone\unins000.exe"
-->"C:\Program Files\Acceleration Software\Anti-Virus\ws_uninst.exe" -s
-->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
-->C:\PROGRA~1\ACCELE~1\ANTI-V~1\regsvr32.exe /u /s C:\PROGRA~1\ACCELE~1\ANTI-V~1\ssupload.dll
-->C:\PROGRA~1\ACCELE~1\ANTI-V~1\regsvr32.exe /u /s C:\PROGRA~1\ACCELE~1\ANTI-V~1\vclnr.dll
-->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
-->C:\PROGRA~1\FICHIE~1\EACCEL~1\SysSnap\syssnap.exe -UnregServer
-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
-->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
-->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AFA4872-16B2-419E-ADCA-8E96E739115D}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A32C786-85DE-48F8-9E54-848B3E34A90C}\setup.exe" -l0x40c -removeonly
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
6000 Wierder op Lëtzebuergesch-->C:\WINDOWS\uninst.exe -f"C:\Program Files\CTeam\6000W\DeIsL1.isu" -c"C:\Program Files\CTeam\6000W\_ISREG32.DLL"
Adobe Acrobat 4.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 4.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 4.0\NT\Uninst.dll"
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Cosmopolitan Virtual Look-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TLC-Edusoft\Cosmopolitan Virtual Look\UninstCos.isu"
DirectX Media Runtime 5.1-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\DXM51.INF,Uninstall.NT
Electronic Arts Game Updater-->C:\WINDOWS\IsUninst.exe -f"c:\Program Files\EACom\Update\Uninst.isu"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
Encyclopédie Générale Interactive 99-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TLC-Edusoft\Encyclopedie Generale Interactive 99\Uninst.isu"
Feeding Frenzy-->C:\PROGRA~1\GAMEHO~1\FEEDIN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\FEEDIN~1\INSTALL.LOG
Garmin Communicator Plugin-->MsiExec.exe /X{10B3936F-0E93-4431-8E7B-3FEA5DAC88C3}
GdgAnglais5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{239C1CAC-BA05-40B5-A7A0-C86FEFF50304}\Setup.exe"
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Grand Prix 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E4961DB6-A3F3-11D3-BE67-0000B4A81FC5}\setup.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
iTunes-->MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
Java 2 Runtime Environment, SE v1.4.2_05-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
Je chante et je joue avec Lapin Malin-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{075429DA-47AF-43F1-B889-91BAD1942442}\setup.exe"
Lapin Malin Maternelle 1 + Atelier de dessin & de musique-->C:\Program Files\Mindscape\Lapin Malin Maternelle 1 + Atelier de dessin & de musique\uninstall.exe
Lapin Malin Maternelle 2 + Atelier de dessin & de musique-->C:\Program Files\Mindscape\Lapin Malin Maternelle 2 + Atelier de dessin & de musique\uninstall.exe
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
L'Odyssée d'Abe-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\L'Odyssée d'Abe\Uninst.isu"
Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Messenger Plus! Live & Sponsor (CiD)-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Micro Application - Dictionnaire encyclopédique 2001-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Micro Application\Dictionnaire encyclopédique 2001\Uninst.isu"
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Standard Edition 2003-->MsiExec.exe /I{9112040C-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
Mise à jour de licences personnelles-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\drmtool.inf,Uninstall
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Need For Speed - Porsche 2000-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Electronic Arts\Need For Speed - Porsche 2000\uninst.log"
Nokia Connectivity Cable Driver-->RUNDLL32.EXE nsesetup.dll,DoNTUninst
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Packard Bell InfoCentre-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B04AC0A3-7A0F-4E38-9DE7-FD1E4CE47D8C}\setup.exe"
Portable MP3 Player-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19FA2AF9-AEA1-4D7D-8CCE-B292FECA50D8}\Setup.exe" -l0x40c
Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
Rocket Mania Deluxe 1.02-->C:\Program Files\Zone.Com Deluxe Games\Rocket Mania Deluxe\PopUninstall.exe "C:\Program Files\Zone.Com Deluxe Games\Rocket Mania Deluxe\Install.log"
RON Tool Offersfortoday-->C:\WINDOWS\system32\ggdmjmifjnanhu.exe
Samsung Digital Camera-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B79684C-6DAC-438C-8F30-10DF65C2068F}\Setup.exe"
Samsung Master-->C:\Program Files\InstallShield Installation Information\{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}\Setup.exe -runfromtemp -l0x040c -removeonly
Samsung Media Studio-->C:\Program Files\InstallShield Installation Information\{C20CE592-B0F8-4D20-BF31-0151CA6331A6}\Setup.exe -runfromtemp -l0x040c -removeonly
ScanButton 2.4-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ScanButton 2.4\Uninst.isu"
Search Assistant Searchersmart-->C:\WINDOWS\system32\yeiqkudqzenhjmovn.dll-uninst.exe
SimTractor 3.12-->MsiExec.exe /I{AE2E3787-E898-46D7-BFF3-FB1DE516DBE1}
SimTractor 3.66f-->MsiExec.exe /I{989876E6-27B9-4E2C-9873-F599FB52ECF1}
Smart Link 56K Modem-->C:\WINDOWS\Modio\SLAMR2KO\Setup.exe /Remove
Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
StopSign by eAcceleration-->C:\PROGRA~1\FICHIE~1\EACCEL~1\INSTAL~1\eaccelsetup.exe -AddRemove
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Theme Park World-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Bullfrog\Theme Park World\Uninst.isu" -c"C:\Program Files\Bullfrog\Theme Park World\uninst.dll" -BFLANG=1036
Total Immersion Racing-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C2FE0127-0F86-43C7-824E-AA78E6B5F4F3}\setup.exe"
UsbFix-->C:\Program Files\UsbFix\Uninstal.exe
Wanadoo Messager-->C:\PROGRA~1\WANADO~1\UNWISE.EXE C:\PROGRA~1\WANADO~1\INSTALL.LOG
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
XviD MPEG-4 Video Codec-->"C:\Program Files\XviD\unins000.exe"
ZTE ZXDSL852-->"C:\Program Files\ZTE Corporation\ZXDSL852\setup.exe" -u

======Security center information======

AV: StopSign Antivirus FREE TRIAL diagnostic version (disabled) (outdated)
AS: StopSign Antispyware FREE TRIAL diagnostic version (disabled) (outdated)

System event log

Computer Name: ALAIN
Event Code: 7023
Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
Le module spécifié est introuvable.


Record Number: 55524
Source Name: Service Control Manager
Time Written: 20081130115917.000000+060
Event Type: erreur
User:

Computer Name: ALAIN
Event Code: 7036
Message: Le service Gestion d'applications est entré dans l'état : arrêté.

Record Number: 55523
Source Name: Service Control Manager
Time Written: 20081130115917.000000+060
Event Type: Informations
User:

Computer Name: ALAIN
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Gestion d'applications.

Record Number: 55522
Source Name: Service Control Manager
Time Written: 20081130115917.000000+060
Event Type: Informations
User: ALAIN\couturier

Computer Name: ALAIN
Event Code: 7023
Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
Le module spécifié est introuvable.


Record Number: 55521
Source Name: Service Control Manager
Time Written: 20081130115917.000000+060
Event Type: erreur
User:

Computer Name: ALAIN
Event Code: 7036
Message: Le service Gestion d'applications est entré dans l'état : arrêté.

Record Number: 55520
Source Name: Service Control Manager
Time Written: 20081130115917.000000+060
Event Type: Informations
User:

Application event log

Computer Name: ALAIN
Event Code: 1
Message:
Record Number: 20546
Source Name: SNDSrvc
Time Written: 20071225105114.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: ALAIN
Event Code: 26
Message:
Record Number: 20545
Source Name: SNDSrvc
Time Written: 20071225105114.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: ALAIN
Event Code: 1
Message:
Record Number: 20544
Source Name: ccSetMgr
Time Written: 20071225105113.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: ALAIN
Event Code: 26
Message:
Record Number: 20543
Source Name: ISService
Time Written: 20071225105113.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: ALAIN
Event Code: 26
Message:
Record Number: 20542
Source Name: ccSetMgr
Time Written: 20071225105112.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM;C:\PROGRA~1\FICHIE~1\SONICS~1\;C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=2f00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\j2re1.4.2_05\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\j2re1.4.2_05\lib\ext\QTJava.zip

-----------------EOF-----------------
0
que reste t-il a faire??!!
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 19:26
Redémarre ton PC et repasse un coup de ToolsCleaner.
0
[ Rapport ToolsCleaner version 2.2.9 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\Rsit: trouvé !
C:\Documents and Settings\couturier\Bureau\Rsit.exe: trouvé !
C:\Program Files\FindyKill: trouvé !
C:\Program Files\Acceleration Software\Anti-Virus\LSPFix.exe: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !

---------------------------------
-->- Suppression:

C:\Program Files\Acceleration Software\Anti-Virus\LSPFix.exe: ERREUR DE SUPPRESSION !!
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\Documents and Settings\couturier\Bureau\Rsit.exe: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\Rsit: supprimé !
C:\Program Files\FindyKill: supprimé !
0
quand je redémarre l'ordinateur, une fenetre s'ouvre parfois a propos de "Ntsb investigator"...
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 19:38
1/

---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Outils puis Programmes de désinstallations.
* Sélectionne StopSign by eAcceleration puis clique sur Efface l'Entrée.
* Pareil pour RON Tool Offersfortoday.

---> Désinstalle Java 2 Runtime Environment, SE v1.4.2_05.

---> Mets à jour Adobe Reader :
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

---> Mets à jour Java :
https://www.java.com/fr/download/manual.jsp

---> Désinstalle Avast et installe Antivir :
http://www.commentcamarche.net/telecharger/telecharger 55 antivir


2/

---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"drvsyskit"=-
"german.exe"=-

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]






---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
j'ai bien installer CCleaner mais lorsque je veux double clicer pour l'ouvrir et faire le reste de la manipulation il s'ouvre pedant meme pas 1 seconde et disparait de la barre de tache..
0
rien a faire, l'application ne s'ouvre pas...
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 20:00
Installe Antivir.
0
ok, c'est fait
ensuite je continue avec ce que vous m'avez dit en numéro 2 ??
0
fanny > fanny
29 déc. 2008 à 20:13
lors de l'installation de antivir, un message s'est affiché: la création de certains fichiers à échouer
0
fanny > fanny
29 déc. 2008 à 20:21
je na sais plus quoi faire...
0
fanny > fanny
29 déc. 2008 à 20:32
please!!!!!!!!!!!!!
0
fanny > fanny
29 déc. 2008 à 20:32
please!!!!!!!!!!!!!
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
29 déc. 2008 à 21:08
On va revérifier.

--> Télécharge FindyKill (par Chiquitine29) sur ton Bureau.

--> Lance l'installation avec les paramètres par défaut.

--> Double-clique sur le raccourci FindyKill sur ton Bureau.

--> Au menu principal, choisis l'option 1 (Recherche).

--> Poste le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
0
----------------- FindyKill V4.710 ------------------

* User : couturier - ALAIN
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 21/12/08 par Chiquitine29
* Recherche effectuée à 10:06:56 le 30/12/2008
* Windows XP - Internet Explorer 7.0.5730.13

((((((((((((((((( *** Recherche *** ))))))))))))))))))


--------------- [ Processus actifs ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

--------------- [ Processus infectieux stoppés ] ----------------


"C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe" (1760)


--------------- [ Fichiers/Dossiers infectieux ] ----------------


»»»» Presence des fichiers dans C:


»»»» Presence des fichiers dans C:\WINDOWS


»»»» Presence des fichiers dans C:\WINDOWS\Prefetch

Found ! - C:\WINDOWS\prefetch\239812.EXE-00F88DF2.pf
Found ! - C:\WINDOWS\prefetch\327968.EXE-11034FE4.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-06C898AB.pf

»»»» Presence des fichiers dans C:\WINDOWS\system32

Found ! [30/12/2008 10:04] - C:\WINDOWS\system32\mdelk.exe
Found ! [30/12/2008 10:04] - C:\WINDOWS\system32\wintems.exe
Found ! [30/12/2008 10:05] - C:\WINDOWS\system32\ban_list.txt

»»»» Presence des fichiers dans C:\WINDOWS\system32\config\systemprofile\AppData\Roaming


»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers


»»»» Presence des fichiers dans C:\Documents and Settings\couturier\Application Data

Found ! [29/12/2008 20:49] - "C:\Documents and Settings\couturier\Application Data\m\flec006.exe"
Found ! [30/12/2008 10:04] - "C:\Documents and Settings\couturier\Application Data\m\list.oct"
Found ! [30/12/2008 10:04] - "C:\Documents and Settings\couturier\Application Data\m\data.oct"
Found ! [30/12/2008 10:04] - "C:\Documents and Settings\couturier\Application Data\m\srvlist.oct"
Found ! [30/12/2008 10:05] - "C:\Documents and Settings\couturier\Application Data\m\shared"
Found ! [29/12/2008 20:49] - "C:\Documents and Settings\couturier\Application Data\m"
Found ! [29/12/2008 19:31] - "C:\Documents and Settings\couturier\Application Data\drivers"
Found ! [30/12/2008 10:04] - "C:\Documents and Settings\couturier\Application Data\drivers\srosa.sys"
Found ! [30/12/2008 10:04] - "C:\Documents and Settings\couturier\Application Data\drivers\srosa2.sys"
Found ! [18/05/2005 09:03] - "C:\Documents and Settings\couturier\Application Data\drivers\winupgro.exe"
Found ! [30/12/2008 10:05] - "C:\Documents and Settings\couturier\Application Data\drivers\downld"
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\168171.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\171796.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\222828.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\226796.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\227187.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\239812.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\240031.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\240937.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\242437.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\243140.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\266625.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\267125.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\267625.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\274656.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\276937.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\277531.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\278062.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\278968.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\280031.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\281078.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\284156.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\286781.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\292453.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\293125.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\294234.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\294843.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\295687.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\297515.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\297937.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\299671.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\306734.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\308015.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\308640.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\309406.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\309625.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\310203.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\310546.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\312109.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\314593.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\321125.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\321671.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\322203.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\327968.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\340000.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\340750.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\341312.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\343421.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\344109.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\344500.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\346718.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\358921.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\359515.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\360062.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\362078.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\374250.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\374906.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\375187.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\384859.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\387765.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\398625.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\399265.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\399609.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\44218.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\44734.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\45046.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\45203.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\45718.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\46109.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\46406.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\46890.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\47078.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\50484.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\52843.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\53390.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\53687.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\54484.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\57296.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\59281.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\70718.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\71265.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\71734.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\75796.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\77593.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\79000.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\81031.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\81968.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\82750.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\83234.exe
Found ! [30/12/2008 10:05] - C:\Documents and Settings\couturier\Application Data\drivers\downld\83984.exe

»»»» Presence des fichiers dans C:\DOCUME~1\COUTUR~1\LOCALS~1\Temp


»»»» Presence des fichiers dans C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5

Found ! [29/12/2008 20:49] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\6YBC9G0U\b64[1].jpg
Found ! [29/12/2008 19:36] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\6YBC9G0U\b64_1[1].jpg
Found ! [29/12/2008 20:46] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\6YBC9G0U\b64_3[1].jpg
Found ! [29/12/2008 19:31] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\M51LBY8V\b64_3[1].jpg
Found ! [29/12/2008 20:11] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\M51LBY8V\b64_3[2].jpg
Found ! [29/12/2008 20:14] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\M51LBY8V\b64_5[1].jpg
Found ! [29/12/2008 19:35] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\M51LBY8V\mxd[1].jpg
Found ! [29/12/2008 20:15] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\R6K12H91\b64_2[1].jpg
Found ! [30/12/2008 10:04] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\R6K12H91\b64_3[1].jpg
Found ! [30/12/2008 10:04] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\R6K12H91\mxd[1].jpg
Found ! [29/12/2008 19:34] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\T7XXP8EK\b64[1].jpg
Found ! [29/12/2008 20:13] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\T7XXP8EK\b64[2].jpg
Found ! [29/12/2008 20:51] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\T7XXP8EK\b64_1[1].jpg
Found ! [29/12/2008 19:36] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\T7XXP8EK\b64_2[1].jpg
Found ! [29/12/2008 20:51] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\T7XXP8EK\b64_2[2].jpg
Found ! [29/12/2008 20:13] - C:\Documents and Settings\couturier\Local Settings\Temporary Internet Files\Content.IE5\T7XXP8EK\mxd[1].jpg

--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
Installed=1
NoChange=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1

[HKEY_CURRENT_USER\software\local appwizard-generated applications\qttask]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]

--------------- [ Registre / Clés infectieuses ] ----------------


Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-2366115807-3377660124-3793208125-1006\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR

--------------- [ Etat / Services ] ----------------

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

- sans echec non fonctionnel !!



+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

/!\ Ndisuio - Type de démarrage = 4

/!\ Ip6Fw - Type de démarrage = 4

/!\ SharedAccess - Type de démarrage = 4

/!\ wuauserv - Type de démarrage = 4

/!\ wscsvc - Type de démarrage = 4



--------------- [ Recherche dans supports amovibles] ----------------


+- Informations :

C: - Lecteur fixe


+- presence des fichiers :



--------------- [ Registre / Mountpoint2 ] ----------------


-> Not found !


------------------- ! Fin du rapport ! --------------------
0
ce matin j'ai rééssayer CCleaner ( sans grande conviction) et par miracle ça a fonctionné.J'ai donc fait ce que vous m'aviez indiqué de faire avec ce logiciel mais toujours pas moyen d'installer antivir.
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
30 déc. 2008 à 14:18
L'infection Bagle revient à chaque fois.

---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"

---> Je te conseille vivement d'installer la Console de récupération.

---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.

/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

Note : Le rapport se trouve également là : C:\Combofix.txt

Tutoriel officiel :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
0
petite question bete...comment installer la console de récupération??
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 297
30 déc. 2008 à 15:39
0
punaise je ne retrouve plus le cd d'installation pr xp, jé que des cd de 97 ou 98...comment faire??
0
pardon, j'ai vu qu'il y a une indication pour les gens qui ont xp sans le cd, je le fais
0