J'ai chopé winupgro
Résolu/Fermé
A voir également:
- J'ai chopé winupgro
- Photo chope gratuit - Télécharger - Montage photo
42 réponses
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:00:09, on 03/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\Mixer.exe
D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
D:\Program Files\Vista Drive Icon\DrvIcon.exe
D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
D:\Documents and Settings\Xavier\Application Data\drivers\downld\367875.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\HiJackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] D:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] D:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VadeRetro Outlook] D:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [Shockwave Updater] D:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; Creative ZENcast v2.00.13)" -"https://www.miniclip.com/games/china-2008/en/"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: RocketDock.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Scan saved at 21:00:09, on 03/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\Mixer.exe
D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
D:\Program Files\Vista Drive Icon\DrvIcon.exe
D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
D:\Documents and Settings\Xavier\Application Data\drivers\downld\367875.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\HiJackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] D:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] D:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VadeRetro Outlook] D:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [Shockwave Updater] D:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; Creative ZENcast v2.00.13)" -"https://www.miniclip.com/games/china-2008/en/"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: RocketDock.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 21:17
3 janv. 2009 à 21:17
Salut,
Pourquoi tu dis winupgro ?
Pourquoi tu dis winupgro ?
----------------- FindyKill V4.710 ------------------
* User : Xavier - ADMIN-6S9ZHHX6R
* executed from : D:\Program Files\FindyKill
* Update on 21/12/08 par Chiquitine29
* Start at 22:06:12 the 03/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\logonui.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\userinit.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in D:
»»»» Supression files in D:\WINDOWS
»»»» Supression files in D:\WINDOWS\Prefetch
Deleted ! - D:\WINDOWS\prefetch\CRAC.EXE-0E890010.pf
»»»» Supression files in D:\WINDOWS\system32
Deleted ! - D:\WINDOWS\system32\ban_list.txt
»»»» Supression files in D:\WINDOWS\system32\config\systemprofile\AppData\Roaming
»»»» Supression files in D:\WINDOWS\system32\drivers
Deleted ! - D:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - D:\WINDOWS\system32\drivers\srosa2.sys
»»»» Supression files in D:\Documents and Settings\Xavier\Application Data
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa2.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe"
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\112421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\114828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\118234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12446015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12465640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12479125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\127031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\142781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\175812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\180562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\197453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\199281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\206937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\209203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\217171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\220437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\222140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\224562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\238609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239531.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\243453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\256281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\257171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\259468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\260000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\266937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\269484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283500.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\285000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\290546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\296234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\298093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\299140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\300718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\308937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\316921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\330859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\335546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\337015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\339203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\341593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\346625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\347828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\348812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\354906.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\360921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\369250.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\370687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\371890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\372406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\373546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\374125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\375078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\378890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\382859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\392328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\393546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\395562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\396015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\399843.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\414921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\416515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\417359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\423421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\432640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\449593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\459687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\472203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\476734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\60890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\64796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\65859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\659000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\67109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\75562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\77562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\79156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\85187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\86093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\93421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\98718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\99437.exe
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\downld"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers"
»»»» Supression files in D:\DOCUME~1\Xavier\LOCALS~1\Temp
Deleted ! - D:\DOCUME~1\Xavier\LOCALS~1\Temp\PatchByFile.tmp
»»»» Supression files in D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\G6I4BTCT\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\d0a7ab64d7399db61bbf4a853acb9605[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\D3FFAFDB6414C3E2453CE2289386[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_5[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\ADQTRPW6\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_3[1].jpg
--------------- [ Other deleting ] ----------------
Infected ! - "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> Deleted !
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\msnmsgr
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
EapHost - Type of startup = 2
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur de CD-ROM
G: - Lecteur de CD-ROM
H: - Lecteur amovible
I: - Lecteur fixe
+- deleting files :
Not deleted !! - G:\autorun.inf
--------------- [ Registry / Mountpoint2 ] ----------------
-> Not found !
--------------- [ Searching Cracks / Keygen ] ----------------
D:\Documents and Settings\Xavier\Favoris\Tutorial crack cle wep.url
---------------- ! End of report ! ------------------
* User : Xavier - ADMIN-6S9ZHHX6R
* executed from : D:\Program Files\FindyKill
* Update on 21/12/08 par Chiquitine29
* Start at 22:06:12 the 03/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\logonui.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\userinit.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in D:
»»»» Supression files in D:\WINDOWS
»»»» Supression files in D:\WINDOWS\Prefetch
Deleted ! - D:\WINDOWS\prefetch\CRAC.EXE-0E890010.pf
»»»» Supression files in D:\WINDOWS\system32
Deleted ! - D:\WINDOWS\system32\ban_list.txt
»»»» Supression files in D:\WINDOWS\system32\config\systemprofile\AppData\Roaming
»»»» Supression files in D:\WINDOWS\system32\drivers
Deleted ! - D:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - D:\WINDOWS\system32\drivers\srosa2.sys
»»»» Supression files in D:\Documents and Settings\Xavier\Application Data
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa2.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe"
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\112421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\114828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\118234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12446015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12465640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12479125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\127031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\142781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\175812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\180562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\197453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\199281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\206937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\209203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\217171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\220437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\222140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\224562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\238609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239531.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\243453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\256281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\257171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\259468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\260000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\266937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\269484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283500.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\285000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\290546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\296234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\298093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\299140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\300718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\308937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\316921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\330859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\335546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\337015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\339203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\341593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\346625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\347828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\348812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\354906.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\360921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\369250.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\370687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\371890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\372406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\373546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\374125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\375078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\378890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\382859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\392328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\393546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\395562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\396015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\399843.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\414921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\416515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\417359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\423421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\432640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\449593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\459687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\472203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\476734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\60890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\64796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\65859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\659000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\67109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\75562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\77562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\79156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\85187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\86093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\93421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\98718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\99437.exe
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\downld"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers"
»»»» Supression files in D:\DOCUME~1\Xavier\LOCALS~1\Temp
Deleted ! - D:\DOCUME~1\Xavier\LOCALS~1\Temp\PatchByFile.tmp
»»»» Supression files in D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\G6I4BTCT\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\d0a7ab64d7399db61bbf4a853acb9605[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\D3FFAFDB6414C3E2453CE2289386[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_5[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\ADQTRPW6\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_3[1].jpg
--------------- [ Other deleting ] ----------------
Infected ! - "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> Deleted !
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\msnmsgr
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
EapHost - Type of startup = 2
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur de CD-ROM
G: - Lecteur de CD-ROM
H: - Lecteur amovible
I: - Lecteur fixe
+- deleting files :
Not deleted !! - G:\autorun.inf
--------------- [ Registry / Mountpoint2 ] ----------------
-> Not found !
--------------- [ Searching Cracks / Keygen ] ----------------
D:\Documents and Settings\Xavier\Favoris\Tutorial crack cle wep.url
---------------- ! End of report ! ------------------
parceque je le vois tourner dans mes processus et que j'ai vu que c'es tun virus ... donc je pense que c'est lui la source de tous mes problèmes
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 21:33
3 janv. 2009 à 21:33
1/
--> Démarre Spybot, clique sur Mode, coche Mode avancé.
--> A gauche, clique sur Outils, puis sur Résident.
--> Décoche la case devant Résident "TeaTimer" :
http://apu.mabul.org/up/5/apu-5-gpdx9e06cwz2dypom2q7n6nc.jpg
--> Quitte Spybot.
2/
--> Télécharge FindyKill (par Chiquitine29) sur ton Bureau.
--> Lance l'installation avec les paramètres par défaut.
--> Double-clique sur le raccourci FindyKill sur ton Bureau.
--> Au menu principal, choisis l'option 1 (Recherche).
--> Poste le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
--> Démarre Spybot, clique sur Mode, coche Mode avancé.
--> A gauche, clique sur Outils, puis sur Résident.
--> Décoche la case devant Résident "TeaTimer" :
http://apu.mabul.org/up/5/apu-5-gpdx9e06cwz2dypom2q7n6nc.jpg
--> Quitte Spybot.
2/
--> Télécharge FindyKill (par Chiquitine29) sur ton Bureau.
--> Lance l'installation avec les paramètres par défaut.
--> Double-clique sur le raccourci FindyKill sur ton Bureau.
--> Au menu principal, choisis l'option 1 (Recherche).
--> Poste le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
déjà avec malwarebytes j'ai ça :
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1414
Windows 5.1.2600 Service Pack 3
03/01/2009 21:44:58
mbam-log-2009-01-03 (21-44-58).txt
Type de recherche: Examen rapide
Eléments examinés: 60154
Temps écoulé: 22 minute(s), 26 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
D:\Documents and Settings\Xavier\Application Data\m (Trojan.Agent) -> Delete on reboot.
Fichier(s) infecté(s):
D:\Documents and Settings\Xavier\Application Data\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Xavier\Application Data\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Xavier\Application Data\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot.
D:\Documents and Settings\Xavier\Application Data\m\flec006.exe (Trojan.Agent) -> Delete on reboot.
et je n'arive pas à supprimer les infections
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1414
Windows 5.1.2600 Service Pack 3
03/01/2009 21:44:58
mbam-log-2009-01-03 (21-44-58).txt
Type de recherche: Examen rapide
Eléments examinés: 60154
Temps écoulé: 22 minute(s), 26 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
D:\Documents and Settings\Xavier\Application Data\m (Trojan.Agent) -> Delete on reboot.
Fichier(s) infecté(s):
D:\Documents and Settings\Xavier\Application Data\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Xavier\Application Data\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Xavier\Application Data\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot.
D:\Documents and Settings\Xavier\Application Data\m\flec006.exe (Trojan.Agent) -> Delete on reboot.
et je n'arive pas à supprimer les infections
----------------- FindyKill V4.710 ------------------
* User : Xavier - ADMIN-6S9ZHHX6R
* Emplacement : D:\Program Files\FindyKill
* Outils Mis a jours le 21/12/08 par Chiquitine29
* Recherche effectuée à 21:54:17 le 03/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\Mixer.exe
D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
D:\Program Files\Vista Drive Icon\DrvIcon.exe
D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
D:\Program Files\Internet Explorer\iexplore.exe
--------------- [ Processus infectieux stoppés ] ----------------
"D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe" (1156)
"D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe" (1588)
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans D:
»»»» Presence des fichiers dans D:\WINDOWS
»»»» Presence des fichiers dans D:\WINDOWS\Prefetch
Found ! - D:\WINDOWS\Prefetch\CRAC.EXE-0E890010.pf
»»»» Presence des fichiers dans D:\WINDOWS\system32
Found ! [03/01/2009 21:21] - D:\WINDOWS\system32\wintems.exe
Found ! [03/01/2009 21:23] - D:\WINDOWS\system32\ban_list.txt
»»»» Presence des fichiers dans D:\WINDOWS\system32\config\systemprofile\AppData\Roaming
»»»» Presence des fichiers dans D:\WINDOWS\system32\drivers
»»»» Presence des fichiers dans D:\Documents and Settings\Xavier\Application Data
Found ! [03/01/2009 21:25] - "D:\Documents and Settings\Xavier\Application Data\m\flec006.exe"
Found ! [03/01/2009 21:27] - "D:\Documents and Settings\Xavier\Application Data\m\shared"
Found ! [03/01/2009 21:44] - "D:\Documents and Settings\Xavier\Application Data\m"
Found ! [03/01/2009 20:33] - "D:\Documents and Settings\Xavier\Application Data\drivers"
Found ! [03/01/2009 21:21] - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa.sys"
Found ! [03/01/2009 21:21] - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa2.sys"
Found ! [09/03/2004 08:07] - "D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe"
Found ! [03/01/2009 21:27] - "D:\Documents and Settings\Xavier\Application Data\drivers\downld"
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101296.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102187.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103078.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104765.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\112421.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113046.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113984.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\114828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\118234.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439437.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439968.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12446015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12465640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466609.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12479125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\127031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130734.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131625.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\142781.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143625.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\175812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\180562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181359.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\197453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\199281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\206937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207796.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207968.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\209203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\217171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\220437.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221296.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\222140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223796.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\224562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\238609.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239531.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\243453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244109.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244437.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253953.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\256281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\257171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258390.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\259468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\260000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265703.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\266937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268703.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\269484.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270265.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283500.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\285000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\290546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291359.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291515.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\296234.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\298093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\299140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\300718.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\308937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310515.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310656.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311390.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311781.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312765.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\316921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317984.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\330859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331578.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334953.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\335546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336109.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336765.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\337015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\339203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\341593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342296.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\346625.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\347828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\348812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\354906.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355781.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\360921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\369250.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\370687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\371890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\372406.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\373546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\374125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\375078.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\378890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379484.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379578.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\382859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\392328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\393546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\395562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\396015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\399843.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\414921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\416515.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\417359.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\423421.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\432640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\449593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\459687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\472203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\476734.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\60890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63656.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\64796.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658578.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\65859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\659000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\67109.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687406.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73484.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\75562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76046.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\77562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\79156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\85187.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\86093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\93421.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97265.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\98718.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\99437.exe
»»»» Presence des fichiers dans D:\DOCUME~1\Xavier\LOCALS~1\Temp
Found ! - D:\DOCUME~1\Xavier\LOCALS~1\Temp\PatchByFile.tmp
* User : Xavier - ADMIN-6S9ZHHX6R
* Emplacement : D:\Program Files\FindyKill
* Outils Mis a jours le 21/12/08 par Chiquitine29
* Recherche effectuée à 21:54:17 le 03/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\Mixer.exe
D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
D:\Program Files\Vista Drive Icon\DrvIcon.exe
D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
D:\Program Files\Internet Explorer\iexplore.exe
--------------- [ Processus infectieux stoppés ] ----------------
"D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe" (1156)
"D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe" (1588)
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans D:
»»»» Presence des fichiers dans D:\WINDOWS
»»»» Presence des fichiers dans D:\WINDOWS\Prefetch
Found ! - D:\WINDOWS\Prefetch\CRAC.EXE-0E890010.pf
»»»» Presence des fichiers dans D:\WINDOWS\system32
Found ! [03/01/2009 21:21] - D:\WINDOWS\system32\wintems.exe
Found ! [03/01/2009 21:23] - D:\WINDOWS\system32\ban_list.txt
»»»» Presence des fichiers dans D:\WINDOWS\system32\config\systemprofile\AppData\Roaming
»»»» Presence des fichiers dans D:\WINDOWS\system32\drivers
»»»» Presence des fichiers dans D:\Documents and Settings\Xavier\Application Data
Found ! [03/01/2009 21:25] - "D:\Documents and Settings\Xavier\Application Data\m\flec006.exe"
Found ! [03/01/2009 21:27] - "D:\Documents and Settings\Xavier\Application Data\m\shared"
Found ! [03/01/2009 21:44] - "D:\Documents and Settings\Xavier\Application Data\m"
Found ! [03/01/2009 20:33] - "D:\Documents and Settings\Xavier\Application Data\drivers"
Found ! [03/01/2009 21:21] - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa.sys"
Found ! [03/01/2009 21:21] - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa2.sys"
Found ! [09/03/2004 08:07] - "D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe"
Found ! [03/01/2009 21:27] - "D:\Documents and Settings\Xavier\Application Data\drivers\downld"
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101296.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102187.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103078.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104765.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\112421.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113046.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113984.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\114828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\118234.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439437.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439968.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12446015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12465640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466609.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12479125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\127031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130734.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131625.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\142781.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143625.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\175812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\180562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181359.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\197453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\199281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\206937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207796.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207968.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\209203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\217171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\220437.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221296.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\222140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223796.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\224562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\238609.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239531.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\243453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244109.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244437.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253953.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\256281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\257171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258390.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\259468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\260000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265703.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\266937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268703.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\269484.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270265.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283500.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\285000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\290546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291359.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291515.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\296234.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\298093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\299140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\300718.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\308937.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310515.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310656.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311390.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311781.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312765.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\316921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317984.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\330859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331578.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334953.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\335546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336109.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336765.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\337015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\339203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\341593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342296.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\346625.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\347828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\348812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\354906.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355781.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\360921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\369250.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\370687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\371890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\372406.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\373546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\374125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\375078.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\378890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379484.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379578.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\382859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383125.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\392328.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\393546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394031.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394812.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\395562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\396015.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\399843.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400343.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\414921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\416515.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\417359.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\423421.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\432640.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433453.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\449593.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\459687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460218.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\472203.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\476734.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\60890.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63546.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63656.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\64796.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658578.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\65859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658859.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\659000.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\67109.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687140.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687406.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687468.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73171.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73484.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73921.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74281.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74828.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\75562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76046.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76062.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\77562.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\79156.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\85187.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\86093.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87687.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\93421.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97265.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97312.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97375.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\98718.exe
Found ! [03/01/2009 21:27] - D:\Documents and Settings\Xavier\Application Data\drivers\downld\99437.exe
»»»» Presence des fichiers dans D:\DOCUME~1\Xavier\LOCALS~1\Temp
Found ! - D:\DOCUME~1\Xavier\LOCALS~1\Temp\PatchByFile.tmp
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 21:51
3 janv. 2009 à 21:51
FindyKill directement.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 21:57
3 janv. 2009 à 21:57
--> Supprime tes cracks et keygens.
--> Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir.
--> Double-clique sur le raccourci FindyKill sur ton Bureau.
--> Au menu principal, choisis l'option 2 (Suppression).
/!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\
--> Ensuite, poste le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
--> Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir.
--> Double-clique sur le raccourci FindyKill sur ton Bureau.
--> Au menu principal, choisis l'option 2 (Suppression).
/!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\
--> Ensuite, poste le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
voila le résultat :
----------------- FindyKill V4.710 ------------------
* User : Xavier - ADMIN-6S9ZHHX6R
* executed from : D:\Program Files\FindyKill
* Update on 21/12/08 par Chiquitine29
* Start at 22:06:12 the 03/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\logonui.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\userinit.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in D:
»»»» Supression files in D:\WINDOWS
»»»» Supression files in D:\WINDOWS\Prefetch
Deleted ! - D:\WINDOWS\prefetch\CRAC.EXE-0E890010.pf
»»»» Supression files in D:\WINDOWS\system32
Deleted ! - D:\WINDOWS\system32\ban_list.txt
»»»» Supression files in D:\WINDOWS\system32\config\systemprofile\AppData\Roaming
»»»» Supression files in D:\WINDOWS\system32\drivers
Deleted ! - D:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - D:\WINDOWS\system32\drivers\srosa2.sys
»»»» Supression files in D:\Documents and Settings\Xavier\Application Data
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa2.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe"
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\112421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\114828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\118234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12446015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12465640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12479125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\127031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\142781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\175812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\180562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\197453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\199281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\206937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\209203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\217171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\220437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\222140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\224562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\238609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239531.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\243453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\256281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\257171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\259468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\260000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\266937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\269484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283500.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\285000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\290546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\296234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\298093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\299140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\300718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\308937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\316921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\330859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\335546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\337015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\339203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\341593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\346625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\347828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\348812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\354906.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\360921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\369250.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\370687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\371890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\372406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\373546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\374125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\375078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\378890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\382859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\392328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\393546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\395562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\396015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\399843.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\414921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\416515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\417359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\423421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\432640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\449593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\459687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\472203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\476734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\60890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\64796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\65859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\659000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\67109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\75562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\77562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\79156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\85187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\86093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\93421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\98718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\99437.exe
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\downld"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers"
»»»» Supression files in D:\DOCUME~1\Xavier\LOCALS~1\Temp
Deleted ! - D:\DOCUME~1\Xavier\LOCALS~1\Temp\PatchByFile.tmp
»»»» Supression files in D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\G6I4BTCT\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\d0a7ab64d7399db61bbf4a853acb9605[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\D3FFAFDB6414C3E2453CE2289386[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_5[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\ADQTRPW6\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_3[1].jpg
--------------- [ Other deleting ] ----------------
Infected ! - "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> Deleted !
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\msnmsgr
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
EapHost - Type of startup = 2
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur de CD-ROM
G: - Lecteur de CD-ROM
H: - Lecteur amovible
I: - Lecteur fixe
+- deleting files :
Not deleted !! - G:\autorun.inf
--------------- [ Registry / Mountpoint2 ] ----------------
-> Not found !
--------------- [ Searching Cracks / Keygen ] ----------------
D:\Documents and Settings\Xavier\Favoris\Tutorial crack cle wep.url
---------------- ! End of report ! ------------------
----------------- FindyKill V4.710 ------------------
* User : Xavier - ADMIN-6S9ZHHX6R
* executed from : D:\Program Files\FindyKill
* Update on 21/12/08 par Chiquitine29
* Start at 22:06:12 the 03/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\logonui.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\userinit.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in D:
»»»» Supression files in D:\WINDOWS
»»»» Supression files in D:\WINDOWS\Prefetch
Deleted ! - D:\WINDOWS\prefetch\CRAC.EXE-0E890010.pf
»»»» Supression files in D:\WINDOWS\system32
Deleted ! - D:\WINDOWS\system32\ban_list.txt
»»»» Supression files in D:\WINDOWS\system32\config\systemprofile\AppData\Roaming
»»»» Supression files in D:\WINDOWS\system32\drivers
Deleted ! - D:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - D:\WINDOWS\system32\drivers\srosa2.sys
»»»» Supression files in D:\Documents and Settings\Xavier\Application Data
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\srosa2.sys"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe"
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\101890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\102593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\103453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\104859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\112421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\113984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\114828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\118234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12439968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12446015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12465640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12466609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\12479125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\127031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\130859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\131625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\142781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\143625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\175812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\180562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\181359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\197453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\199281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\206937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\207968.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\209203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\210171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\217171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\220437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\221828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\222140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\223796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\224562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\225640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\238609.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239531.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\239593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\243453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\244437.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\253953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\254812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\255343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\256281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\257171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\258390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\259468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\260000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\265703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\266937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\268703.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\269484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\270812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\281640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\282812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\283500.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\285000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\290546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\291515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\294937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\295453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\296234.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\298093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\299140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\300718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\308937.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\309093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\310656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311390.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\311781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\312765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\316921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\317984.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\319156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\330859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\331921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\332687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\333328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\334953.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\335546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\336765.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\337015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\339203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\341593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342296.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\342468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\346625.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\347828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\348812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\354906.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\355781.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\356218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\360921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\369250.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\370687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\371890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\372406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\373546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\374125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\375078.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\376812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\378890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\379578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\382859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383125.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\383453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\392328.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\393546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394031.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\394812.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\395562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\396015.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\399843.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400343.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\400546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\414921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\416515.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\417359.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\423421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\432640.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\433453.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\449593.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\459687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\460218.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\471890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\472203.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\476734.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\60890.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63546.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\63656.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\64796.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658578.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\65859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\658859.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\659000.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\67109.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687140.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687406.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\687468.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73171.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73484.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\73921.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74281.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\74828.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\75562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76046.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\76062.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\77562.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\79156.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\85187.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\86093.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\87687.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\93421.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97265.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97312.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\97375.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\98718.exe
Deleted ! - D:\Documents and Settings\Xavier\Application Data\drivers\downld\99437.exe
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers\downld"
Deleted ! - "D:\Documents and Settings\Xavier\Application Data\drivers"
»»»» Supression files in D:\DOCUME~1\Xavier\LOCALS~1\Temp
Deleted ! - D:\DOCUME~1\Xavier\LOCALS~1\Temp\PatchByFile.tmp
»»»» Supression files in D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\G6I4BTCT\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\d0a7ab64d7399db61bbf4a853acb9605[1].jpg
Deleted ! - D:\Documents and Settings\Justine\Local Settings\Temporary Internet Files\Content.IE5\VGKXFVYX\D3FFAFDB6414C3E2453CE2289386[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\2ECLYTRI\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\6SKJMD7R\b64_5[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\ADQTRPW6\b64_3[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\44851294E8917D6BB6472DFC6E1DC[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\CCL2E5E3\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[3].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\IO1DUOTY\b64_1[4].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\KQLUZR82\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\b64_2[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\LBGONTYW\mxd[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[1].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_1[2].jpg
Deleted ! - D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\TTZKWANH\b64_3[1].jpg
--------------- [ Other deleting ] ----------------
Infected ! - "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> Deleted !
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\msnmsgr
Deleted ! - HKEY_USERS\S-1-5-21-839522115-854245398-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
EapHost - Type of startup = 2
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur de CD-ROM
G: - Lecteur de CD-ROM
H: - Lecteur amovible
I: - Lecteur fixe
+- deleting files :
Not deleted !! - G:\autorun.inf
--------------- [ Registry / Mountpoint2 ] ----------------
-> Not found !
--------------- [ Searching Cracks / Keygen ] ----------------
D:\Documents and Settings\Xavier\Favoris\Tutorial crack cle wep.url
---------------- ! End of report ! ------------------
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 22:21
3 janv. 2009 à 22:21
---> Désinstalle FindyKill.
---> Réinstalle tes applications infectées (Antivirus...)
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- Clique sur Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
---> Réinstalle tes applications infectées (Antivirus...)
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- Clique sur Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
Logfile of random's system information tool 1.05 (written by random/random)
Run by Xavier at 2009-01-03 22:30:45
Microsoft Windows XP Édition familiale Service Pack 3
System drive D: has 49 GB (62%) free of 79 GB
Total RAM: 1023 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:31:00, on 03/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\System32\msiexec.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\Program Files\AVG\AVG8\avgtray.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\AVG\AVG8\aAvgApi.exe
D:\Documents and Settings\Xavier\Mes documents\Mes fichiers reçus\RSIT.exe
D:\Program Files\trend micro\Xavier.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] D:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] D:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VadeRetro Outlook] D:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [drvsyskit] D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
O4 - HKCU\..\Run: [german.exe] D:\WINDOWS\system32\wintems.exe
O4 - HKCU\..\Run: [mule_st_key] D:\Documents and Settings\Xavier\Application Data\m\flec006.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] D:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; Creative ZENcast v2.00.13)" -"https://www.miniclip.com/games/china-2008/en/"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: RocketDock.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Run by Xavier at 2009-01-03 22:30:45
Microsoft Windows XP Édition familiale Service Pack 3
System drive D: has 49 GB (62%) free of 79 GB
Total RAM: 1023 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:31:00, on 03/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\System32\msiexec.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\Program Files\AVG\AVG8\avgtray.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\AVG\AVG8\aAvgApi.exe
D:\Documents and Settings\Xavier\Mes documents\Mes fichiers reçus\RSIT.exe
D:\Program Files\trend micro\Xavier.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] D:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] D:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VadeRetro Outlook] D:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [drvsyskit] D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
O4 - HKCU\..\Run: [german.exe] D:\WINDOWS\system32\wintems.exe
O4 - HKCU\..\Run: [mule_st_key] D:\Documents and Settings\Xavier\Application Data\m\flec006.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] D:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; Creative ZENcast v2.00.13)" -"https://www.miniclip.com/games/china-2008/en/"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: RocketDock.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 22:47
3 janv. 2009 à 22:47
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1604
Windows 5.1.2600 Service Pack 3
03/01/2009 23:02:32
mbam-log-2009-01-03 (23-02-32).txt
Type de recherche: Examen rapide
Eléments examinés: 59278
Temps écoulé: 9 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
D:\Documents (Trojan.Agent) -> Quarantined and deleted successfully.
Version de la base de données: 1604
Windows 5.1.2600 Service Pack 3
03/01/2009 23:02:32
mbam-log-2009-01-03 (23-02-32).txt
Type de recherche: Examen rapide
Eléments examinés: 59278
Temps écoulé: 9 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
D:\Documents (Trojan.Agent) -> Quarantined and deleted successfully.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 23:13
3 janv. 2009 à 23:13
1/
---> Relance MBAM, va dans Quarantaine et supprime tout.
---> Mets à jour Adobe Reader :
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
2/
---> Lance ce fichier : D:\Program Files\trend micro\Xavier.exe
---> Choisis Do a system scan only.
---> Coche les cases qui sont devant les lignes suivantes :
O4 - HKCU\..\Run: [drvsyskit] D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
O4 - HKCU\..\Run: [german.exe] D:\WINDOWS\system32\wintems.exe
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Ferme HijackThis.
3/
---> Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries sur ton Bureau :
* Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Clique sur Search For Updates.
* Sélectionne Update Using jucheck.exe puis clique sur Search.
* Autorise le processus à se connecter s'il le demande, clique sur Install et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Remove Older Versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur Ok, puis une deuxième fois sur Ok.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
---> Relance MBAM, va dans Quarantaine et supprime tout.
---> Mets à jour Adobe Reader :
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
2/
---> Lance ce fichier : D:\Program Files\trend micro\Xavier.exe
---> Choisis Do a system scan only.
---> Coche les cases qui sont devant les lignes suivantes :
O4 - HKCU\..\Run: [drvsyskit] D:\Documents and Settings\Xavier\Application Data\drivers\winupgro.exe
O4 - HKCU\..\Run: [german.exe] D:\WINDOWS\system32\wintems.exe
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Ferme HijackThis.
3/
---> Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries sur ton Bureau :
* Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Clique sur Search For Updates.
* Sélectionne Update Using jucheck.exe puis clique sur Search.
* Autorise le processus à se connecter s'il le demande, clique sur Install et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Remove Older Versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur Ok, puis une deuxième fois sur Ok.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
JavaRa 1.13 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Sat Jan 03 23:29:23 2009
Found and removed: D:\Program Files\Java\jre1.5.0_11
Found and removed: D:\Program Files\Java\jre1.6.0_05
Found and removed: D:\Program Files\Java\jre1.6.0_07
Found and removed: Software\JavaSoft\Java2D\1.5.0_11
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Classes\JavaPlugin.150_11
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_11
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_11
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D511001
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150110}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Classes\JavaPlugin.160_05
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_11
Found and removed: Software\Classes\JavaPlugin.160_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05
Found and removed: Software\JavaSoft\Java2D\1.6.0_05
Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
------------------------------------
Finished reporting.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Sat Jan 03 23:29:23 2009
Found and removed: D:\Program Files\Java\jre1.5.0_11
Found and removed: D:\Program Files\Java\jre1.6.0_05
Found and removed: D:\Program Files\Java\jre1.6.0_07
Found and removed: Software\JavaSoft\Java2D\1.5.0_11
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Classes\JavaPlugin.150_11
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_11
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_11
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D511001
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D511001
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150110}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Classes\JavaPlugin.160_05
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_11
Found and removed: Software\Classes\JavaPlugin.160_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05
Found and removed: Software\JavaSoft\Java2D\1.6.0_05
Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
------------------------------------
Finished reporting.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 23:32
3 janv. 2009 à 23:32
---> Supprime JavaRa.
---> Supprime le dossier RSIT situé dans C:\
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- Clique sur Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
---> Supprime le dossier RSIT situé dans C:\
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- Clique sur Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
Logfile of random's system information tool 1.05 (written by random/random)
Run by Xavier at 2009-01-03 23:38:40
Microsoft Windows XP Édition familiale Service Pack 3
System drive D: has 48 GB (62%) free of 79 GB
Total RAM: 1023 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:38:46, on 03/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\Program Files\AVG\AVG8\avgtray.exe
D:\WINDOWS\System32\msiexec.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\AVG\AVG8\aAvgApi.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\JCHTDAAN\RSIT[1].exe
D:\Program Files\trend micro\Xavier.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] D:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] D:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VadeRetro Outlook] D:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Uninstall getPlus(R) for Adobe] "D:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [Shockwave Updater] D:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; Creative ZENcast v2.00.13)" -"https://www.miniclip.com/games/china-2008/en/"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: RocketDock.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - D:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Run by Xavier at 2009-01-03 23:38:40
Microsoft Windows XP Édition familiale Service Pack 3
System drive D: has 48 GB (62%) free of 79 GB
Total RAM: 1023 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:38:46, on 03/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\CTsvcCDA.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\Program Files\AVG\AVG8\avgtray.exe
D:\WINDOWS\System32\msiexec.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\AVG\AVG8\aAvgApi.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\JCHTDAAN\RSIT[1].exe
D:\Program Files\trend micro\Xavier.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] D:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] D:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VadeRetro Outlook] D:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] D:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Uninstall getPlus(R) for Adobe] "D:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [Shockwave Updater] D:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; Creative ZENcast v2.00.13)" -"https://www.miniclip.com/games/china-2008/en/"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = D:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: RocketDock.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = D:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - D:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 janv. 2009 à 23:41
3 janv. 2009 à 23:41
Pour vérifier :
- Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer).
- En bas à droite, clique sur Démarrer Online-scanner.
- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.
- Accepte les Contrôles ActiveX.
- Choisis Poste de travail pour le scan.
- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.
- Pour t'aider à utiliser le scan en ligne :
https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
- Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer).
- En bas à droite, clique sur Démarrer Online-scanner.
- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.
- Accepte les Contrôles ActiveX.
- Choisis Poste de travail pour le scan.
- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.
- Pour t'aider à utiliser le scan en ligne :
https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
bon je crosi que ça va tourner toute la nuit ...
j'en suis à 4% et 1 virus trouvé + 252 objets infectés !
merci mille fois en tous cas.
je le laisse tourner cette nuit et je posterai demain matin le résultat !
j'en suis à 4% et 1 virus trouvé + 252 objets infectés !
merci mille fois en tous cas.
je le laisse tourner cette nuit et je posterai demain matin le résultat !
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
4 janv. 2009 à 00:11
4 janv. 2009 à 00:11
Ok mais vu que le rapport va être gros, tu peux me l'envoyer par mail (Clique sur mon pseudo).
bonjour :p
alors l'antivirus kaspersky on line a tourné toute la nuit. Il a fini. Mais je ne vois pas où il faut aller pour enregistrer le rapport et ensuite nettoyer les virus trouver ...
[URL=https://imageshack.com/][IMG]http://img508.imageshack.us/img508/4509/sanstitreyj5.jpg[/IMG][/URL]
[URL=http://g.imageshack.us/img508/sanstitreyj5.jpg/1/][IMG]http://img508.imageshack.us/img508/sanstitreyj5.jpg/1/w740.png[/IMG][/URL]
alors l'antivirus kaspersky on line a tourné toute la nuit. Il a fini. Mais je ne vois pas où il faut aller pour enregistrer le rapport et ensuite nettoyer les virus trouver ...
[URL=https://imageshack.com/][IMG]http://img508.imageshack.us/img508/4509/sanstitreyj5.jpg[/IMG][/URL]
[URL=http://g.imageshack.us/img508/sanstitreyj5.jpg/1/][IMG]http://img508.imageshack.us/img508/sanstitreyj5.jpg/1/w740.png[/IMG][/URL]
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
4 janv. 2009 à 11:06
4 janv. 2009 à 11:06
Il ne nettoie pas les virus.
Par contre, la dernière fois, j'avais une option pour le rapport. Je ne le vois pas dans ton screen.
Par contre, la dernière fois, j'avais une option pour le rapport. Je ne le vois pas dans ton screen.