Infection Bagle
Résolu/Fermé
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
-
6 janv. 2009 à 04:32
Utilisateur anonyme - 6 janv. 2009 à 19:54
Utilisateur anonyme - 6 janv. 2009 à 19:54
A voir également:
- Infection Bagle
- [Pnkbstra]infection ✓ - Forum Virus
- Infection: URL:Mal !!!???? - Forum Virus
- Infection virus ✓ - Forum Virus
- Infection Bloom ? ✓ - Forum Virus
- Techscam...infection ✓ - Forum Virus
50 réponses
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 19:53
6 janv. 2009 à 19:53
ok et bien ça me parait bon cette fois ci. mille merci pour ton aide Chiquitine. A chi.ki.chi.ki.chi.HaïHaïHaï.
Bye.
Bye.
sam3341
Messages postés
100
Date d'inscription
jeudi 9 octobre 2008
Statut
Membre
Dernière intervention
24 février 2016
11
6 janv. 2009 à 04:33
6 janv. 2009 à 04:33
moi sa m'est arrivé sauvegarde formatage systeme tout neuf
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 04:34
6 janv. 2009 à 04:34
là ou cela a bloquer, c'est l'opération 2 de FyndiKill's qui ne se fini pas (le 2eme démarrage ne se fait pas)
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 04:35
6 janv. 2009 à 04:35
j'ai envisager de le faire mais jne pense pas que ça défonce le Bagle.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
sam3341
Messages postés
100
Date d'inscription
jeudi 9 octobre 2008
Statut
Membre
Dernière intervention
24 février 2016
11
6 janv. 2009 à 04:37
6 janv. 2009 à 04:37
oui je me souviens sa ma fait pareil c'est pour sa j'ai formater mais sur google ya plein d'explication pour eradiquer cette me***
sam3341
Messages postés
100
Date d'inscription
jeudi 9 octobre 2008
Statut
Membre
Dernière intervention
24 février 2016
11
6 janv. 2009 à 04:38
6 janv. 2009 à 04:38
sisi je t'assure que moi apres le formatage plus rien !
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 04:41
6 janv. 2009 à 04:41
j'ai bien pris soin de lire les post concernés mais il me faudrait une personne sachant lire les rapports pour faire ça proprement. Et puis je n'est plus le cd original windows si jamais je doit réparer certain fichier corrompu.
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 04:53
6 janv. 2009 à 04:53
Elibagla ne veut même pas se lancer
Utilisateur anonyme
6 janv. 2009 à 09:23
6 janv. 2009 à 09:23
Salut,
Telecharge FindyKill sur ton bureau :
--> Lance l installation avec les parametres par default
--> Double clic sur le raccourci FindyKill sur ton bureau
--> Au menu principal,choisi l option 1 (Recherche)
--> Post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Tuto : malekal
Tuto : 01net
Telecharge FindyKill sur ton bureau :
--> Lance l installation avec les parametres par default
--> Double clic sur le raccourci FindyKill sur ton bureau
--> Au menu principal,choisi l option 1 (Recherche)
--> Post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Tuto : malekal
Tuto : 01net
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 15:45
6 janv. 2009 à 15:45
je précise que je suis en Guadeloupe du coup ya 5h de décalage.Si je suis long à répondre c'est normal.
le rapport arrive.
le rapport arrive.
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 15:47
6 janv. 2009 à 15:47
----------------- FindyKill V4.711 ------------------
* User : Florian - YAMYCORP-4D6A34
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 05/01/09 par Chiquitine29
* Recherche effectuée à 15:43:13 le 06/01/2009
* Windows XP - Internet Explorer 7.0.5730.11
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\DISKDUR\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\documents and settings\florian\local settings\application data\uiimgko.exe
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\msiexec.exe
E:\Firefox\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
--------------- [ Processus infectieux stoppés ] ----------------
"C:\WINDOWS\system32\wintems.exe" (1256)
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans C:
Found ! [06/01/2009 04:52] - C:\InfoSat.txt
»»»» Presence des fichiers dans C:\WINDOWS
»»»» Presence des fichiers dans C:\WINDOWS\Prefetch
Found ! - C:\WINDOWS\prefetch\105156.EXE-11C89353.pf
Found ! - C:\WINDOWS\prefetch\107234.EXE-37667EE3.pf
Found ! - C:\WINDOWS\prefetch\110625.EXE-12F6A8C1.pf
Found ! - C:\WINDOWS\prefetch\121843.EXE-19D57224.pf
Found ! - C:\WINDOWS\prefetch\126015.EXE-1E86E4A0.pf
Found ! - C:\WINDOWS\prefetch\128656.EXE-02B69EDD.pf
Found ! - C:\WINDOWS\prefetch\132734.EXE-359993C3.pf
Found ! - C:\WINDOWS\prefetch\135812.EXE-351A83E4.pf
Found ! - C:\WINDOWS\prefetch\14899796.EXE-06C17A22.pf
Found ! - C:\WINDOWS\prefetch\14968484.EXE-273F9134.pf
Found ! - C:\WINDOWS\prefetch\156687.EXE-2630A3F6.pf
Found ! - C:\WINDOWS\prefetch\157718.EXE-001A90FC.pf
Found ! - C:\WINDOWS\prefetch\159609.EXE-27EF3C42.pf
Found ! - C:\WINDOWS\prefetch\180500.EXE-2EF1878F.pf
Found ! - C:\WINDOWS\prefetch\182812.EXE-2AFD5148.pf
Found ! - C:\WINDOWS\prefetch\195812.EXE-3253FE4E.pf
Found ! - C:\WINDOWS\prefetch\196312.EXE-17041FDA.pf
Found ! - C:\WINDOWS\prefetch\206109.EXE-2458539E.pf
Found ! - C:\WINDOWS\prefetch\209359.EXE-298554FB.pf
Found ! - C:\WINDOWS\prefetch\215484.EXE-30D11119.pf
Found ! - C:\WINDOWS\prefetch\252281.EXE-0F4ED336.pf
Found ! - C:\WINDOWS\prefetch\286093.EXE-02EEE27D.pf
Found ! - C:\WINDOWS\prefetch\287859.EXE-1F97CF11.pf
Found ! - C:\WINDOWS\prefetch\309265.EXE-0AF7D673.pf
Found ! - C:\WINDOWS\prefetch\316671.EXE-1F99D35A.pf
Found ! - C:\WINDOWS\prefetch\324484.EXE-0B46879B.pf
Found ! - C:\WINDOWS\prefetch\335218.EXE-2F0031D0.pf
Found ! - C:\WINDOWS\prefetch\342312.EXE-0EED8580.pf
Found ! - C:\WINDOWS\prefetch\353359.EXE-03F53753.pf
Found ! - C:\WINDOWS\prefetch\353765.EXE-3B390ABE.pf
Found ! - C:\WINDOWS\prefetch\364000.EXE-2B473FEF.pf
Found ! - C:\WINDOWS\prefetch\372765.EXE-2785AE51.pf
Found ! - C:\WINDOWS\prefetch\378343.EXE-08C4D575.pf
Found ! - C:\WINDOWS\prefetch\383906.EXE-3A041A52.pf
Found ! - C:\WINDOWS\prefetch\405312.EXE-130948E9.pf
Found ! - C:\WINDOWS\prefetch\450343.EXE-24FE5D8C.pf
Found ! - C:\WINDOWS\prefetch\518671.EXE-15168845.pf
Found ! - C:\WINDOWS\prefetch\587312.EXE-0A543075.pf
Found ! - C:\WINDOWS\prefetch\58937.EXE-375AA9B9.pf
Found ! - C:\WINDOWS\prefetch\621906.EXE-2C13A522.pf
Found ! - C:\WINDOWS\prefetch\694703.EXE-26D06062.pf
Found ! - C:\WINDOWS\prefetch\70484.EXE-213BF380.pf
Found ! - C:\WINDOWS\prefetch\711078.EXE-0315AE00.pf
Found ! - C:\WINDOWS\prefetch\822234.EXE-2D85ECD2.pf
Found ! - C:\WINDOWS\prefetch\84515.EXE-046A7138.pf
Found ! - C:\WINDOWS\prefetch\857875.EXE-2AD2252A.pf
Found ! - C:\WINDOWS\prefetch\95343.EXE-07BCB028.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-050E21FC.pf
Found ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
Found ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-101AF362.pf
Found ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-1FE9A009.pf
»»»» Presence des fichiers dans C:\WINDOWS\system32
Found ! [06/01/2009 04:08] - C:\WINDOWS\system32\mdelk.exe
Found ! [06/01/2009 04:08] - C:\WINDOWS\system32\wintems.exe
Found ! [06/01/2009 15:32] - C:\WINDOWS\system32\ban_list.txt
Found ! [24/05/2007 08:55] - C:\WINDOWS\system32\AutoRun.inf
»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers
Found ! [04/01/2009 23:43] - C:\WINDOWS\system32\drivers\srosa.sys
Found ! [04/01/2009 23:43] - C:\WINDOWS\system32\drivers\srosa2.sys
»»»» Presence des fichiers dans C:\Documents and Settings\Florian\Application Data
Found ! [06/01/2009 04:10] - "C:\Documents and Settings\Florian\Application Data\m\flec006.exe"
Found ! [06/01/2009 04:13] - "C:\Documents and Settings\Florian\Application Data\m\shared"
Found ! [06/01/2009 04:51] - "C:\Documents and Settings\Florian\Application Data\m"
Found ! [04/01/2009 22:07] - "C:\Documents and Settings\Florian\Application Data\drivers"
Found ! [06/01/2009 04:07] - "C:\Documents and Settings\Florian\Application Data\drivers\srosa.sys"
Found ! [06/01/2009 04:07] - "C:\Documents and Settings\Florian\Application Data\drivers\srosa2.sys"
Found ! [22/09/2004 06:03] - "C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe"
Found ! [06/01/2009 04:14] - "C:\Documents and Settings\Florian\Application Data\drivers\downld"
»»»» Presence des fichiers dans f:\Temp
»»»» Presence des fichiers dans C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5
Found ! [04/01/2009 20:34] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[1].jpg
Found ! [05/01/2009 18:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[2].jpg
Found ! [05/01/2009 20:29] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[3].jpg
Found ! [05/01/2009 21:18] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[4].jpg
Found ! [06/01/2009 04:12] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[5].jpg
Found ! [05/01/2009 11:44] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[1].jpg
Found ! [05/01/2009 13:58] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[2].jpg
Found ! [05/01/2009 20:42] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[3].jpg
Found ! [05/01/2009 19:25] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_5[1].jpg
Found ! [05/01/2009 12:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\file[1].txt
Found ! [05/01/2009 20:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[1].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[2].jpg
Found ! [05/01/2009 21:34] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[1].jpg
Found ! [05/01/2009 11:38] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[2].jpg
Found ! [05/01/2009 11:49] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[3].jpg
Found ! [05/01/2009 21:48] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[4].jpg
Found ! [06/01/2009 15:32] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\file[1].txt
Found ! [05/01/2009 20:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\mxd[3].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\servernames[1].htm
Found ! [05/01/2009 13:59] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64[2].jpg
Found ! [04/01/2009 20:37] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[1].jpg
Found ! [05/01/2009 21:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[2].jpg
Found ! [03/01/2009 22:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[1].jpg
Found ! [05/01/2009 14:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[2].jpg
Found ! [05/01/2009 19:26] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64[1].jpg
Found ! [05/01/2009 20:31] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64_1[1].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64[1].jpg
Found ! [04/01/2009 22:40] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[1].jpg
Found ! [05/01/2009 19:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[2].jpg
Found ! [05/01/2009 20:46] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[3].jpg
Found ! [05/01/2009 11:35] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[1].jpg
Found ! [05/01/2009 14:21] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[2].jpg
Found ! [05/01/2009 13:59] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_1[1].jpg
Found ! [06/01/2009 04:13] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_2[1].jpg
Found ! [05/01/2009 14:20] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_3[1].jpg
Found ! [05/01/2009 21:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64[1].jpg
Found ! [05/01/2009 11:32] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[2].jpg
Found ! [05/01/2009 13:59] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[4].jpg
Found ! [05/01/2009 14:21] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[5].jpg
Found ! [05/01/2009 21:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\mxd[1].jpg
Found ! [05/01/2009 19:47] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[1].jpg
Found ! [05/01/2009 14:23] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[2].jpg
Found ! [05/01/2009 18:27] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[3].jpg
Found ! [05/01/2009 21:16] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[4].jpg
Found ! [05/01/2009 18:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_2[1].jpg
Found ! [05/01/2009 19:24] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[1].jpg
Found ! [05/01/2009 21:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[2].jpg
Found ! [05/01/2009 20:27] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\file[1].txt
Found ! [05/01/2009 21:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64[1].jpg
Found ! [05/01/2009 11:37] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[1].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[2].jpg
Found ! [05/01/2009 19:48] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_2[1].jpg
Found ! [04/01/2009 21:33] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SGZ2649M\file[1].txt
Found ! [05/01/2009 20:29] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64[2].jpg
Found ! [05/01/2009 14:23] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_1[1].jpg
Found ! [04/01/2009 20:33] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[1].jpg
Found ! [05/01/2009 11:31] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[4].jpg
Found ! [04/01/2009 01:12] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[1].jpg
Found ! [05/01/2009 19:26] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[2].jpg
Found ! [05/01/2009 21:31] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[3].jpg
Found ! [05/01/2009 12:51] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_1[1].jpg
Found ! [04/01/2009 20:37] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[1].jpg
Found ! [05/01/2009 20:32] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[2].jpg
Found ! [05/01/2009 21:43] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[1].jpg
Found ! [06/01/2009 04:08] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[2].jpg
Found ! [05/01/2009 19:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[1].jpg
Found ! [05/01/2009 21:16] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[2].jpg
Found ! [05/01/2009 19:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_1[1].jpg
Found ! [05/01/2009 14:24] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[1].jpg
Found ! [05/01/2009 20:47] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[2].jpg
Found ! [05/01/2009 20:27] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_3[1].jpg
--------------- [ Registre / Startup ] ----------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
NBJ="E:\Ahead\Nero BackItUp\NBJ.exe"
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
uiimgko="c:\documents and settings\florian\local settings\application data\uiimgko.exe" uiimgko
drvsyskit=C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe
mule_st_key=C:\Documents and Settings\Florian\Application Data\m\flec006.exe
german.exe=C:\WINDOWS\system32\wintems.exe
SpybotSD TeaTimer=E:\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
MaxMenuMgr="E:\DISKDUR\FreeAgent Status\StxMenuMgr.exe"
[HKEY_CURRENT_USER\software\local appwizard-generated applications\hprbui]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\install_crack]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\NBJ]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]
--------------- [ Registre / Clés infectieuses ] ----------------
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\install_crack
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\install_crack
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
Found ! - [HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
--------------- [ Etat / Services ] ----------------
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
/!\ Mode sans echec non fonctionnel !!
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
/!\ Mode sans echec non fonctionnel !!
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
/!\ Mode sans echec non fonctionnel !!
+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]
/!\ Ndisuio - Type de démarrage = 4
/!\ Ip6Fw - Type de démarrage = 4
SharedAccess - Type de démarrage = 2
wuauserv - Type de démarrage = 2
/!\ wscsvc - Type de démarrage = 4
--------------- [ Recherche dans supports amovibles] ----------------
+- Informations :
C: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur fixe
G: - Lecteur fixe
+- presence des fichiers :
--------------- [ Registre / Mountpoint2 ] ----------------
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ce48e7c-82a7-11dd-beee-fbb3d328bbe8}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a205652-e50b-11db-bd22-88bde0b5dfe8}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ce6e4f5-57ba-11dc-bdb1-eebcfe6f99ea}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf2-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf3-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8595fb2-5425-11dc-bdad-da374e258feb}\Shell\AutoRun\command
------------------- ! Fin du rapport ! --------------------
* User : Florian - YAMYCORP-4D6A34
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 05/01/09 par Chiquitine29
* Recherche effectuée à 15:43:13 le 06/01/2009
* Windows XP - Internet Explorer 7.0.5730.11
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\DISKDUR\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\documents and settings\florian\local settings\application data\uiimgko.exe
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\msiexec.exe
E:\Firefox\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
--------------- [ Processus infectieux stoppés ] ----------------
"C:\WINDOWS\system32\wintems.exe" (1256)
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans C:
Found ! [06/01/2009 04:52] - C:\InfoSat.txt
»»»» Presence des fichiers dans C:\WINDOWS
»»»» Presence des fichiers dans C:\WINDOWS\Prefetch
Found ! - C:\WINDOWS\prefetch\105156.EXE-11C89353.pf
Found ! - C:\WINDOWS\prefetch\107234.EXE-37667EE3.pf
Found ! - C:\WINDOWS\prefetch\110625.EXE-12F6A8C1.pf
Found ! - C:\WINDOWS\prefetch\121843.EXE-19D57224.pf
Found ! - C:\WINDOWS\prefetch\126015.EXE-1E86E4A0.pf
Found ! - C:\WINDOWS\prefetch\128656.EXE-02B69EDD.pf
Found ! - C:\WINDOWS\prefetch\132734.EXE-359993C3.pf
Found ! - C:\WINDOWS\prefetch\135812.EXE-351A83E4.pf
Found ! - C:\WINDOWS\prefetch\14899796.EXE-06C17A22.pf
Found ! - C:\WINDOWS\prefetch\14968484.EXE-273F9134.pf
Found ! - C:\WINDOWS\prefetch\156687.EXE-2630A3F6.pf
Found ! - C:\WINDOWS\prefetch\157718.EXE-001A90FC.pf
Found ! - C:\WINDOWS\prefetch\159609.EXE-27EF3C42.pf
Found ! - C:\WINDOWS\prefetch\180500.EXE-2EF1878F.pf
Found ! - C:\WINDOWS\prefetch\182812.EXE-2AFD5148.pf
Found ! - C:\WINDOWS\prefetch\195812.EXE-3253FE4E.pf
Found ! - C:\WINDOWS\prefetch\196312.EXE-17041FDA.pf
Found ! - C:\WINDOWS\prefetch\206109.EXE-2458539E.pf
Found ! - C:\WINDOWS\prefetch\209359.EXE-298554FB.pf
Found ! - C:\WINDOWS\prefetch\215484.EXE-30D11119.pf
Found ! - C:\WINDOWS\prefetch\252281.EXE-0F4ED336.pf
Found ! - C:\WINDOWS\prefetch\286093.EXE-02EEE27D.pf
Found ! - C:\WINDOWS\prefetch\287859.EXE-1F97CF11.pf
Found ! - C:\WINDOWS\prefetch\309265.EXE-0AF7D673.pf
Found ! - C:\WINDOWS\prefetch\316671.EXE-1F99D35A.pf
Found ! - C:\WINDOWS\prefetch\324484.EXE-0B46879B.pf
Found ! - C:\WINDOWS\prefetch\335218.EXE-2F0031D0.pf
Found ! - C:\WINDOWS\prefetch\342312.EXE-0EED8580.pf
Found ! - C:\WINDOWS\prefetch\353359.EXE-03F53753.pf
Found ! - C:\WINDOWS\prefetch\353765.EXE-3B390ABE.pf
Found ! - C:\WINDOWS\prefetch\364000.EXE-2B473FEF.pf
Found ! - C:\WINDOWS\prefetch\372765.EXE-2785AE51.pf
Found ! - C:\WINDOWS\prefetch\378343.EXE-08C4D575.pf
Found ! - C:\WINDOWS\prefetch\383906.EXE-3A041A52.pf
Found ! - C:\WINDOWS\prefetch\405312.EXE-130948E9.pf
Found ! - C:\WINDOWS\prefetch\450343.EXE-24FE5D8C.pf
Found ! - C:\WINDOWS\prefetch\518671.EXE-15168845.pf
Found ! - C:\WINDOWS\prefetch\587312.EXE-0A543075.pf
Found ! - C:\WINDOWS\prefetch\58937.EXE-375AA9B9.pf
Found ! - C:\WINDOWS\prefetch\621906.EXE-2C13A522.pf
Found ! - C:\WINDOWS\prefetch\694703.EXE-26D06062.pf
Found ! - C:\WINDOWS\prefetch\70484.EXE-213BF380.pf
Found ! - C:\WINDOWS\prefetch\711078.EXE-0315AE00.pf
Found ! - C:\WINDOWS\prefetch\822234.EXE-2D85ECD2.pf
Found ! - C:\WINDOWS\prefetch\84515.EXE-046A7138.pf
Found ! - C:\WINDOWS\prefetch\857875.EXE-2AD2252A.pf
Found ! - C:\WINDOWS\prefetch\95343.EXE-07BCB028.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-050E21FC.pf
Found ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
Found ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-101AF362.pf
Found ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-1FE9A009.pf
»»»» Presence des fichiers dans C:\WINDOWS\system32
Found ! [06/01/2009 04:08] - C:\WINDOWS\system32\mdelk.exe
Found ! [06/01/2009 04:08] - C:\WINDOWS\system32\wintems.exe
Found ! [06/01/2009 15:32] - C:\WINDOWS\system32\ban_list.txt
Found ! [24/05/2007 08:55] - C:\WINDOWS\system32\AutoRun.inf
»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers
Found ! [04/01/2009 23:43] - C:\WINDOWS\system32\drivers\srosa.sys
Found ! [04/01/2009 23:43] - C:\WINDOWS\system32\drivers\srosa2.sys
»»»» Presence des fichiers dans C:\Documents and Settings\Florian\Application Data
Found ! [06/01/2009 04:10] - "C:\Documents and Settings\Florian\Application Data\m\flec006.exe"
Found ! [06/01/2009 04:13] - "C:\Documents and Settings\Florian\Application Data\m\shared"
Found ! [06/01/2009 04:51] - "C:\Documents and Settings\Florian\Application Data\m"
Found ! [04/01/2009 22:07] - "C:\Documents and Settings\Florian\Application Data\drivers"
Found ! [06/01/2009 04:07] - "C:\Documents and Settings\Florian\Application Data\drivers\srosa.sys"
Found ! [06/01/2009 04:07] - "C:\Documents and Settings\Florian\Application Data\drivers\srosa2.sys"
Found ! [22/09/2004 06:03] - "C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe"
Found ! [06/01/2009 04:14] - "C:\Documents and Settings\Florian\Application Data\drivers\downld"
»»»» Presence des fichiers dans f:\Temp
»»»» Presence des fichiers dans C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5
Found ! [04/01/2009 20:34] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[1].jpg
Found ! [05/01/2009 18:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[2].jpg
Found ! [05/01/2009 20:29] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[3].jpg
Found ! [05/01/2009 21:18] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[4].jpg
Found ! [06/01/2009 04:12] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[5].jpg
Found ! [05/01/2009 11:44] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[1].jpg
Found ! [05/01/2009 13:58] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[2].jpg
Found ! [05/01/2009 20:42] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[3].jpg
Found ! [05/01/2009 19:25] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_5[1].jpg
Found ! [05/01/2009 12:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\file[1].txt
Found ! [05/01/2009 20:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[1].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[2].jpg
Found ! [05/01/2009 21:34] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[1].jpg
Found ! [05/01/2009 11:38] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[2].jpg
Found ! [05/01/2009 11:49] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[3].jpg
Found ! [05/01/2009 21:48] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[4].jpg
Found ! [06/01/2009 15:32] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\file[1].txt
Found ! [05/01/2009 20:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\mxd[3].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\servernames[1].htm
Found ! [05/01/2009 13:59] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64[2].jpg
Found ! [04/01/2009 20:37] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[1].jpg
Found ! [05/01/2009 21:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[2].jpg
Found ! [03/01/2009 22:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[1].jpg
Found ! [05/01/2009 14:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[2].jpg
Found ! [05/01/2009 19:26] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64[1].jpg
Found ! [05/01/2009 20:31] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64_1[1].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64[1].jpg
Found ! [04/01/2009 22:40] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[1].jpg
Found ! [05/01/2009 19:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[2].jpg
Found ! [05/01/2009 20:46] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[3].jpg
Found ! [05/01/2009 11:35] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[1].jpg
Found ! [05/01/2009 14:21] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[2].jpg
Found ! [05/01/2009 13:59] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_1[1].jpg
Found ! [06/01/2009 04:13] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_2[1].jpg
Found ! [05/01/2009 14:20] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_3[1].jpg
Found ! [05/01/2009 21:30] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64[1].jpg
Found ! [05/01/2009 11:32] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[2].jpg
Found ! [05/01/2009 13:59] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[4].jpg
Found ! [05/01/2009 14:21] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[5].jpg
Found ! [05/01/2009 21:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\mxd[1].jpg
Found ! [05/01/2009 19:47] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[1].jpg
Found ! [05/01/2009 14:23] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[2].jpg
Found ! [05/01/2009 18:27] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[3].jpg
Found ! [05/01/2009 21:16] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[4].jpg
Found ! [05/01/2009 18:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_2[1].jpg
Found ! [05/01/2009 19:24] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[1].jpg
Found ! [05/01/2009 21:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[2].jpg
Found ! [05/01/2009 20:27] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\file[1].txt
Found ! [05/01/2009 21:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64[1].jpg
Found ! [05/01/2009 11:37] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[1].jpg
Found ! [06/01/2009 04:10] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[2].jpg
Found ! [05/01/2009 19:48] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_2[1].jpg
Found ! [04/01/2009 21:33] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SGZ2649M\file[1].txt
Found ! [05/01/2009 20:29] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64[2].jpg
Found ! [05/01/2009 14:23] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_1[1].jpg
Found ! [04/01/2009 20:33] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[1].jpg
Found ! [05/01/2009 11:31] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[4].jpg
Found ! [04/01/2009 01:12] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[1].jpg
Found ! [05/01/2009 19:26] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[2].jpg
Found ! [05/01/2009 21:31] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[3].jpg
Found ! [05/01/2009 12:51] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_1[1].jpg
Found ! [04/01/2009 20:37] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[1].jpg
Found ! [05/01/2009 20:32] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[2].jpg
Found ! [05/01/2009 21:43] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[1].jpg
Found ! [06/01/2009 04:08] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[2].jpg
Found ! [05/01/2009 19:45] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[1].jpg
Found ! [05/01/2009 21:16] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[2].jpg
Found ! [05/01/2009 19:28] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_1[1].jpg
Found ! [05/01/2009 14:24] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[1].jpg
Found ! [05/01/2009 20:47] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[2].jpg
Found ! [05/01/2009 20:27] - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_3[1].jpg
--------------- [ Registre / Startup ] ----------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
NBJ="E:\Ahead\Nero BackItUp\NBJ.exe"
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
uiimgko="c:\documents and settings\florian\local settings\application data\uiimgko.exe" uiimgko
drvsyskit=C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe
mule_st_key=C:\Documents and Settings\Florian\Application Data\m\flec006.exe
german.exe=C:\WINDOWS\system32\wintems.exe
SpybotSD TeaTimer=E:\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
MaxMenuMgr="E:\DISKDUR\FreeAgent Status\StxMenuMgr.exe"
[HKEY_CURRENT_USER\software\local appwizard-generated applications\hprbui]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\install_crack]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\NBJ]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]
--------------- [ Registre / Clés infectieuses ] ----------------
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\install_crack
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\install_crack
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
Found ! - [HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
--------------- [ Etat / Services ] ----------------
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
/!\ Mode sans echec non fonctionnel !!
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
/!\ Mode sans echec non fonctionnel !!
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
/!\ Mode sans echec non fonctionnel !!
+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]
/!\ Ndisuio - Type de démarrage = 4
/!\ Ip6Fw - Type de démarrage = 4
SharedAccess - Type de démarrage = 2
wuauserv - Type de démarrage = 2
/!\ wscsvc - Type de démarrage = 4
--------------- [ Recherche dans supports amovibles] ----------------
+- Informations :
C: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur fixe
G: - Lecteur fixe
+- presence des fichiers :
--------------- [ Registre / Mountpoint2 ] ----------------
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ce48e7c-82a7-11dd-beee-fbb3d328bbe8}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a205652-e50b-11db-bd22-88bde0b5dfe8}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ce6e4f5-57ba-11dc-bdb1-eebcfe6f99ea}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf2-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf3-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8595fb2-5425-11dc-bdad-da374e258feb}\Shell\AutoRun\command
------------------- ! Fin du rapport ! --------------------
Utilisateur anonyme
6 janv. 2009 à 15:51
6 janv. 2009 à 15:51
ok
Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
--> Double clic sur le raccourci FindyKill sur ton bureau
--> Au menu principal,choisi l option 2 (Suppression)
/!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"
/!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !
-------> ensuite post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides
/!\ A lire dans tons cas 1 : http://www.libellules.ch/...
/!\ A lire dans tons cas 2 : http://forum.malekal.com/ftopic893.php
/!\ A visionner : http://secuboxlabs.fr/archives/computertoday.html
Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
--> Double clic sur le raccourci FindyKill sur ton bureau
--> Au menu principal,choisi l option 2 (Suppression)
/!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"
/!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !
-------> ensuite post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides
/!\ A lire dans tons cas 1 : http://www.libellules.ch/...
/!\ A lire dans tons cas 2 : http://forum.malekal.com/ftopic893.php
/!\ A visionner : http://secuboxlabs.fr/archives/computertoday.html
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 16:18
6 janv. 2009 à 16:18
j'ai bien lu les lignes principales de mes cas. Je comprends pas mal de choses et je sais que j'était dans l'ignorance totale. Que ça me sert de leçon...
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 16:21
6 janv. 2009 à 16:21
je l'ai posté 2 fois il ne s'affiche pas ...
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 16:22
6 janv. 2009 à 16:22
rraport 2
----------------- FindyKill V4.711 ------------------
* User : Florian - YAMYCORP-4D6A34
* executed from : C:\Program Files\FindyKill
* Update on 05/01/09 par Chiquitine29
* Start at 16:04:40 the 06/01/2009
* Windows XP - Internet Explorer 7.0.5730.11
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in C:
Deleted ! - C:\InfoSat.txt
»»»» Supression files in C:\WINDOWS
»»»» Supression files in C:\WINDOWS\Prefetch
Deleted ! - C:\WINDOWS\prefetch\105156.EXE-11C89353.pf
Deleted ! - C:\WINDOWS\prefetch\107234.EXE-37667EE3.pf
Deleted ! - C:\WINDOWS\prefetch\110625.EXE-12F6A8C1.pf
Deleted ! - C:\WINDOWS\prefetch\121843.EXE-19D57224.pf
Deleted ! - C:\WINDOWS\prefetch\126015.EXE-1E86E4A0.pf
Deleted ! - C:\WINDOWS\prefetch\128656.EXE-02B69EDD.pf
Deleted ! - C:\WINDOWS\prefetch\132734.EXE-359993C3.pf
Deleted ! - C:\WINDOWS\prefetch\135812.EXE-351A83E4.pf
Deleted ! - C:\WINDOWS\prefetch\14899796.EXE-06C17A22.pf
Deleted ! - C:\WINDOWS\prefetch\14968484.EXE-273F9134.pf
Deleted ! - C:\WINDOWS\prefetch\156687.EXE-2630A3F6.pf
Deleted ! - C:\WINDOWS\prefetch\157718.EXE-001A90FC.pf
Deleted ! - C:\WINDOWS\prefetch\159609.EXE-27EF3C42.pf
Deleted ! - C:\WINDOWS\prefetch\180500.EXE-2EF1878F.pf
Deleted ! - C:\WINDOWS\prefetch\182812.EXE-2AFD5148.pf
Deleted ! - C:\WINDOWS\prefetch\195812.EXE-3253FE4E.pf
Deleted ! - C:\WINDOWS\prefetch\196312.EXE-17041FDA.pf
Deleted ! - C:\WINDOWS\prefetch\206109.EXE-2458539E.pf
Deleted ! - C:\WINDOWS\prefetch\209359.EXE-298554FB.pf
Deleted ! - C:\WINDOWS\prefetch\215484.EXE-30D11119.pf
Deleted ! - C:\WINDOWS\prefetch\252281.EXE-0F4ED336.pf
Deleted ! - C:\WINDOWS\prefetch\286093.EXE-02EEE27D.pf
Deleted ! - C:\WINDOWS\prefetch\287859.EXE-1F97CF11.pf
Deleted ! - C:\WINDOWS\prefetch\309265.EXE-0AF7D673.pf
Deleted ! - C:\WINDOWS\prefetch\316671.EXE-1F99D35A.pf
Deleted ! - C:\WINDOWS\prefetch\324484.EXE-0B46879B.pf
Deleted ! - C:\WINDOWS\prefetch\335218.EXE-2F0031D0.pf
Deleted ! - C:\WINDOWS\prefetch\342312.EXE-0EED8580.pf
Deleted ! - C:\WINDOWS\prefetch\353359.EXE-03F53753.pf
Deleted ! - C:\WINDOWS\prefetch\353765.EXE-3B390ABE.pf
Deleted ! - C:\WINDOWS\prefetch\364000.EXE-2B473FEF.pf
Deleted ! - C:\WINDOWS\prefetch\372765.EXE-2785AE51.pf
Deleted ! - C:\WINDOWS\prefetch\378343.EXE-08C4D575.pf
Deleted ! - C:\WINDOWS\prefetch\383906.EXE-3A041A52.pf
Deleted ! - C:\WINDOWS\prefetch\405312.EXE-130948E9.pf
Deleted ! - C:\WINDOWS\prefetch\450343.EXE-24FE5D8C.pf
Deleted ! - C:\WINDOWS\prefetch\518671.EXE-15168845.pf
Deleted ! - C:\WINDOWS\prefetch\587312.EXE-0A543075.pf
Deleted ! - C:\WINDOWS\prefetch\58937.EXE-375AA9B9.pf
Deleted ! - C:\WINDOWS\prefetch\621906.EXE-2C13A522.pf
Deleted ! - C:\WINDOWS\prefetch\694703.EXE-26D06062.pf
Deleted ! - C:\WINDOWS\prefetch\70484.EXE-213BF380.pf
Deleted ! - C:\WINDOWS\prefetch\711078.EXE-0315AE00.pf
Deleted ! - C:\WINDOWS\prefetch\822234.EXE-2D85ECD2.pf
Deleted ! - C:\WINDOWS\prefetch\84515.EXE-046A7138.pf
Deleted ! - C:\WINDOWS\prefetch\857875.EXE-2AD2252A.pf
Deleted ! - C:\WINDOWS\prefetch\95343.EXE-07BCB028.pf
Deleted ! - C:\WINDOWS\prefetch\FLEC006.EXE-050E21FC.pf
Deleted ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Deleted ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
Deleted ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-101AF362.pf
Deleted ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-1FE9A009.pf
»»»» Supression files in C:\WINDOWS\system32
Deleted ! - C:\WINDOWS\system32\autorun.inf
Deleted ! - C:\WINDOWS\system32\mdelk.exe
Deleted ! - C:\WINDOWS\system32\wintems.exe
Deleted ! - C:\WINDOWS\system32\ban_list.txt
»»»» Supression files in C:\WINDOWS\system32\drivers
Deleted ! - C:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - C:\WINDOWS\system32\drivers\srosa2.sys
»»»» Supression files in C:\Documents and Settings\Florian\Application Data
Deleted ! - "C:\Documents and Settings\Florian\Application Data\m\flec006.exe"
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\3D A Salute to America 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\642-564 Practice Exam Testing Engine Software 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Active Clock 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Adaeria Today! 0.36.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Admit One R2686.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\AGM View 1.0.3 Beta.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Aimersoft iPod Copy Manager 2.1.22.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Aiseesoft iPhone Movie Converter 3.1.22.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Amadis Apple TV Video Converter 3.7.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Annotea Ubimarks 0.6.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Any Flash Screensaver Maker 1.90.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Arendaine [ FTP
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ASP.NET Documentation Tool 9.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Attachment Security for Microsoft Outlook 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Auction Artist 2.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Bahama Slim 001.000.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Basketball Scoreboard Deluxe 1.0.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\BatchSync FTP 2.1 Build 3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Beautiful Reef - Animated Wallpaper 2.52.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\BlackBerry Database Viewer 2.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\British Isles - Visible Satellite Animation.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CadStd Lite 3.7.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ChatBlocker 2.6.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ChordWizard Music Theory 3.01f.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Classic Menu for Word 2007 3.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ClusterSHISH 0.15.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Contante 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CopyCode 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Cowboy with Keyboard 2.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\cryptlib 3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CSE HTML Validator Lite 9.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CTL 0.9 Build 20080325.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Daniusoft DVD to iPhone Suite 2.0.2.7.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Date Doctor For Women 3.7.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DAudioK 0.1.9 beta.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DKMessenger 4.6.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DocTray 2.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DudeCMS 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Early Learning 5.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ESC-Rental 4.13.7.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\eTeSoft iPod Video Converter 1.00.806.19.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Finale PrintMusic 2007.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FitLife 4.36.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FontMaker 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Franken's-SteinA.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FreshOutline 2.1.1.49.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FTP Shortcut 0.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Gameloft Brain Challenge j2Me Nokia n92 n93 n73 e61 n71 e50 240x320 Symbian s60 v3 Os9.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\GeoLINE 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Glueee Business Wallpapers Set 1024x768 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Groowe Firefox Toolbar 1.6.4.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\GymMaster Lite 2.7.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\HD Photo Plug-in 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Ice Pattern 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Image Grabber 3.0.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Intacros 2.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Investment Analyzer InvAn-4 2008.04.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\JEST INLINE & SOLID 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Kaspersky.Internet.Security.v6.0.0.303.EspaÇñol.by.SashiX.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\KB Piano 2.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\LangPad - German Characters.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\LingvoSoft Learning PhraseBook 2008 English - Turkish 2.3.90.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Math Pal Computer Calculator 1.12.13.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MB Free Tarot Tutor And Glossary 1.40.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MestRe-C 4.8.6.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MiniMinder 8.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Mobile Movie Studio (Sony Ericsson) 1.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MoreMotion AF 4.1.0.106.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\NetSess 2.00.00.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\NTDomain 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\NumberFox 0.3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\o3find 0.8.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Optimaze! 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Panda.Platinum.Internet.Security.2005.Trupevent.(Crack).Hasta.El.(30-12-2020).Funciona.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Panda.Titanium.Antivirus.2005.v4.02.WinALL.Retail-DVT+sn.for.update=.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Pascal Look 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PhotoPulse 1.3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PHP Function Finder mini 1.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Pixelshop 5.2.48.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PolyMorph3D 1.02.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PQ DVD to Apple TV Converter 1.0 build 01.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Program starter 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\QuickGuidePAVFirewalls_es.GUIA.PANDA.FIRARE.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Rainbow 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RDSGroup Animated chat 1.0.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Record (and edit) anything to Mp3 2.6.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\removegoogleadsfromdu 0.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Rescue 911 2.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RGB to CMYK Color Space 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Ringtone Editor 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RSP Encrypt OCX 3.2.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RSS Validator Maxthon Plugin 0.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RTF-to-HTML DLL .Net 2.3.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ScreenNemo 1.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\SecuriKey 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ServiceMP 3.324.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Shark! Yahoo Widget 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\sipcli 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Sketcher Plugin 1.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Snow In The Valley Demo Screensaver 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Software.Avg.Antivirus.Pro.7.0.206.Keygen.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Solid FTP 4.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\SolvoLink Link Exchange Software 1.00.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\SQL-RD 5.6 Build 20080924.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Stay Connected 4.01.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Swiss City 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Symantec.Mobile.Security.4.0.For.Symbian.Phones.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Symantec.Norton.Antivirus.2007.in.italiano.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\System Keylogger 3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Template Phrases for Microsoft Outlook 1.39.103.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\The Great Lake - Animated Wallpaper 5.07.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\The Name Dropper 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\tssSubst 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Tuber Player 1.06.160.171.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Vista Network Icons 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\VS BMI Calculator 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\WDIR 1.54.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Weather Channel Search 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Window Tracker 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Xilisoft iPhone Video Converter 5.1.17.1114.zip
Deleted ! - "C:\Documents and Settings\Florian\Application Data\m\shared"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\m"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\srosa.sys"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\srosa2.sys"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\downld"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers"
»»»» Supression files in f:\Temp
»»»» Supression files in C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[5].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_5[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\mxd[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\servernames[1].htm
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[5].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SGZ2649M\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_3[1].jpg
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_USER\Software\bisoft
Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
Deleted ! - HKEY_CURRENT_USER\Software\FirtR
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flec006.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hldrrr.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfilse.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupgro.exe
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\install_crack
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\FFC
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\MuleAppData
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur fixe
G: - Lecteur fixe
+- deleting files :
--------------- [ Registry / Mountpoint2 ] ----------------
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ce48e7c-82a7-11dd-beee-fbb3d328bbe8}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a205652-e50b-11db-bd22-88bde0b5dfe8}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ce6e4f5-57ba-11dc-bdb1-eebcfe6f99ea}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf2-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf3-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8595fb2-5425-11dc-bdad-da374e258feb}\Shell\AutoRun\command
--------------- [ Searching Other Infections ] ----------------
Références de comparaison Bagle MD5 :
113ac36b77630a2f67dd6cb7844406a4 C:\WINDOWS\system32\mdelk.exe
113ac36b77630a2f67dd6cb7844406a4 C:\WINDOWS\system32\wintems.exe
9c15290ee0d941f08b7ac48a1eaecffb C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe
--------------- [ Searching Cracks / Keygen ] ----------------
---------------- ! End of report ! ------------------
----------------- FindyKill V4.711 ------------------
* User : Florian - YAMYCORP-4D6A34
* executed from : C:\Program Files\FindyKill
* Update on 05/01/09 par Chiquitine29
* Start at 16:04:40 the 06/01/2009
* Windows XP - Internet Explorer 7.0.5730.11
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in C:
Deleted ! - C:\InfoSat.txt
»»»» Supression files in C:\WINDOWS
»»»» Supression files in C:\WINDOWS\Prefetch
Deleted ! - C:\WINDOWS\prefetch\105156.EXE-11C89353.pf
Deleted ! - C:\WINDOWS\prefetch\107234.EXE-37667EE3.pf
Deleted ! - C:\WINDOWS\prefetch\110625.EXE-12F6A8C1.pf
Deleted ! - C:\WINDOWS\prefetch\121843.EXE-19D57224.pf
Deleted ! - C:\WINDOWS\prefetch\126015.EXE-1E86E4A0.pf
Deleted ! - C:\WINDOWS\prefetch\128656.EXE-02B69EDD.pf
Deleted ! - C:\WINDOWS\prefetch\132734.EXE-359993C3.pf
Deleted ! - C:\WINDOWS\prefetch\135812.EXE-351A83E4.pf
Deleted ! - C:\WINDOWS\prefetch\14899796.EXE-06C17A22.pf
Deleted ! - C:\WINDOWS\prefetch\14968484.EXE-273F9134.pf
Deleted ! - C:\WINDOWS\prefetch\156687.EXE-2630A3F6.pf
Deleted ! - C:\WINDOWS\prefetch\157718.EXE-001A90FC.pf
Deleted ! - C:\WINDOWS\prefetch\159609.EXE-27EF3C42.pf
Deleted ! - C:\WINDOWS\prefetch\180500.EXE-2EF1878F.pf
Deleted ! - C:\WINDOWS\prefetch\182812.EXE-2AFD5148.pf
Deleted ! - C:\WINDOWS\prefetch\195812.EXE-3253FE4E.pf
Deleted ! - C:\WINDOWS\prefetch\196312.EXE-17041FDA.pf
Deleted ! - C:\WINDOWS\prefetch\206109.EXE-2458539E.pf
Deleted ! - C:\WINDOWS\prefetch\209359.EXE-298554FB.pf
Deleted ! - C:\WINDOWS\prefetch\215484.EXE-30D11119.pf
Deleted ! - C:\WINDOWS\prefetch\252281.EXE-0F4ED336.pf
Deleted ! - C:\WINDOWS\prefetch\286093.EXE-02EEE27D.pf
Deleted ! - C:\WINDOWS\prefetch\287859.EXE-1F97CF11.pf
Deleted ! - C:\WINDOWS\prefetch\309265.EXE-0AF7D673.pf
Deleted ! - C:\WINDOWS\prefetch\316671.EXE-1F99D35A.pf
Deleted ! - C:\WINDOWS\prefetch\324484.EXE-0B46879B.pf
Deleted ! - C:\WINDOWS\prefetch\335218.EXE-2F0031D0.pf
Deleted ! - C:\WINDOWS\prefetch\342312.EXE-0EED8580.pf
Deleted ! - C:\WINDOWS\prefetch\353359.EXE-03F53753.pf
Deleted ! - C:\WINDOWS\prefetch\353765.EXE-3B390ABE.pf
Deleted ! - C:\WINDOWS\prefetch\364000.EXE-2B473FEF.pf
Deleted ! - C:\WINDOWS\prefetch\372765.EXE-2785AE51.pf
Deleted ! - C:\WINDOWS\prefetch\378343.EXE-08C4D575.pf
Deleted ! - C:\WINDOWS\prefetch\383906.EXE-3A041A52.pf
Deleted ! - C:\WINDOWS\prefetch\405312.EXE-130948E9.pf
Deleted ! - C:\WINDOWS\prefetch\450343.EXE-24FE5D8C.pf
Deleted ! - C:\WINDOWS\prefetch\518671.EXE-15168845.pf
Deleted ! - C:\WINDOWS\prefetch\587312.EXE-0A543075.pf
Deleted ! - C:\WINDOWS\prefetch\58937.EXE-375AA9B9.pf
Deleted ! - C:\WINDOWS\prefetch\621906.EXE-2C13A522.pf
Deleted ! - C:\WINDOWS\prefetch\694703.EXE-26D06062.pf
Deleted ! - C:\WINDOWS\prefetch\70484.EXE-213BF380.pf
Deleted ! - C:\WINDOWS\prefetch\711078.EXE-0315AE00.pf
Deleted ! - C:\WINDOWS\prefetch\822234.EXE-2D85ECD2.pf
Deleted ! - C:\WINDOWS\prefetch\84515.EXE-046A7138.pf
Deleted ! - C:\WINDOWS\prefetch\857875.EXE-2AD2252A.pf
Deleted ! - C:\WINDOWS\prefetch\95343.EXE-07BCB028.pf
Deleted ! - C:\WINDOWS\prefetch\FLEC006.EXE-050E21FC.pf
Deleted ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Deleted ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
Deleted ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-101AF362.pf
Deleted ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-1FE9A009.pf
»»»» Supression files in C:\WINDOWS\system32
Deleted ! - C:\WINDOWS\system32\autorun.inf
Deleted ! - C:\WINDOWS\system32\mdelk.exe
Deleted ! - C:\WINDOWS\system32\wintems.exe
Deleted ! - C:\WINDOWS\system32\ban_list.txt
»»»» Supression files in C:\WINDOWS\system32\drivers
Deleted ! - C:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - C:\WINDOWS\system32\drivers\srosa2.sys
»»»» Supression files in C:\Documents and Settings\Florian\Application Data
Deleted ! - "C:\Documents and Settings\Florian\Application Data\m\flec006.exe"
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\3D A Salute to America 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\642-564 Practice Exam Testing Engine Software 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Active Clock 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Adaeria Today! 0.36.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Admit One R2686.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\AGM View 1.0.3 Beta.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Aimersoft iPod Copy Manager 2.1.22.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Aiseesoft iPhone Movie Converter 3.1.22.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Amadis Apple TV Video Converter 3.7.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Annotea Ubimarks 0.6.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Any Flash Screensaver Maker 1.90.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Arendaine [ FTP
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ASP.NET Documentation Tool 9.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Attachment Security for Microsoft Outlook 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Auction Artist 2.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Bahama Slim 001.000.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Basketball Scoreboard Deluxe 1.0.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\BatchSync FTP 2.1 Build 3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Beautiful Reef - Animated Wallpaper 2.52.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\BlackBerry Database Viewer 2.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\British Isles - Visible Satellite Animation.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CadStd Lite 3.7.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ChatBlocker 2.6.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ChordWizard Music Theory 3.01f.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Classic Menu for Word 2007 3.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ClusterSHISH 0.15.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Contante 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CopyCode 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Cowboy with Keyboard 2.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\cryptlib 3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CSE HTML Validator Lite 9.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\CTL 0.9 Build 20080325.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Daniusoft DVD to iPhone Suite 2.0.2.7.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Date Doctor For Women 3.7.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DAudioK 0.1.9 beta.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DKMessenger 4.6.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DocTray 2.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\DudeCMS 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Early Learning 5.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ESC-Rental 4.13.7.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\eTeSoft iPod Video Converter 1.00.806.19.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Finale PrintMusic 2007.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FitLife 4.36.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FontMaker 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Franken's-SteinA.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FreshOutline 2.1.1.49.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\FTP Shortcut 0.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Gameloft Brain Challenge j2Me Nokia n92 n93 n73 e61 n71 e50 240x320 Symbian s60 v3 Os9.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\GeoLINE 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Glueee Business Wallpapers Set 1024x768 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Groowe Firefox Toolbar 1.6.4.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\GymMaster Lite 2.7.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\HD Photo Plug-in 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Ice Pattern 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Image Grabber 3.0.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Intacros 2.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Investment Analyzer InvAn-4 2008.04.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\JEST INLINE & SOLID 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Kaspersky.Internet.Security.v6.0.0.303.EspaÇñol.by.SashiX.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\KB Piano 2.3.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\LangPad - German Characters.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\LingvoSoft Learning PhraseBook 2008 English - Turkish 2.3.90.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Math Pal Computer Calculator 1.12.13.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MB Free Tarot Tutor And Glossary 1.40.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MestRe-C 4.8.6.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MiniMinder 8.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Mobile Movie Studio (Sony Ericsson) 1.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\MoreMotion AF 4.1.0.106.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\NetSess 2.00.00.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\NTDomain 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\NumberFox 0.3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\o3find 0.8.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Optimaze! 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Panda.Platinum.Internet.Security.2005.Trupevent.(Crack).Hasta.El.(30-12-2020).Funciona.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Panda.Titanium.Antivirus.2005.v4.02.WinALL.Retail-DVT+sn.for.update=.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Pascal Look 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PhotoPulse 1.3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PHP Function Finder mini 1.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Pixelshop 5.2.48.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PolyMorph3D 1.02.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\PQ DVD to Apple TV Converter 1.0 build 01.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Program starter 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\QuickGuidePAVFirewalls_es.GUIA.PANDA.FIRARE.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Rainbow 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RDSGroup Animated chat 1.0.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Record (and edit) anything to Mp3 2.6.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\removegoogleadsfromdu 0.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Rescue 911 2.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RGB to CMYK Color Space 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Ringtone Editor 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RSP Encrypt OCX 3.2.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RSS Validator Maxthon Plugin 0.5.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\RTF-to-HTML DLL .Net 2.3.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ScreenNemo 1.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\SecuriKey 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\ServiceMP 3.324.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Shark! Yahoo Widget 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\sipcli 1.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Sketcher Plugin 1.2.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Snow In The Valley Demo Screensaver 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Software.Avg.Antivirus.Pro.7.0.206.Keygen.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Solid FTP 4.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\SolvoLink Link Exchange Software 1.00.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\SQL-RD 5.6 Build 20080924.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Stay Connected 4.01.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Swiss City 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Symantec.Mobile.Security.4.0.For.Symbian.Phones.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Symantec.Norton.Antivirus.2007.in.italiano.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\System Keylogger 3.1.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Template Phrases for Microsoft Outlook 1.39.103.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\The Great Lake - Animated Wallpaper 5.07.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\The Name Dropper 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\tssSubst 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Tuber Player 1.06.160.171.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Vista Network Icons 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\VS BMI Calculator 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\WDIR 1.54.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Weather Channel Search 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Window Tracker 1.0.zip
Deleted ! - C:\Documents and Settings\Florian\Application Data\m\shared\Xilisoft iPhone Video Converter 5.1.17.1114.zip
Deleted ! - "C:\Documents and Settings\Florian\Application Data\m\shared"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\m"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\srosa.sys"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\srosa2.sys"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers\downld"
Deleted ! - "C:\Documents and Settings\Florian\Application Data\drivers"
»»»» Supression files in f:\Temp
»»»» Supression files in C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_1[5].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_3[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\b64_5[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\1EPGF2GD\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\b64_2[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\mxd[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\5QRW5393\servernames[1].htm
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\78U0F4UP\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\7LC3MMKY\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\EAP0JD61\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\FHJQ0JCI\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\b64_1[5].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\HM8UEL4R\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\LOS795CM\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\NR8VM3PD\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SGZ2649M\file[1].txt
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\b64_3[4].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\SKB3UWAC\mxd[3].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\U36BN05R\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Florian\Local Settings\Temporary Internet Files\Content.IE5\WP861SZ5\b64_3[1].jpg
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_USER\Software\bisoft
Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
Deleted ! - HKEY_CURRENT_USER\Software\FirtR
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flec006.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hldrrr.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfilse.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupgro.exe
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\install_crack
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\FFC
Deleted ! - HKEY_USERS\S-1-5-21-299502267-117609710-839522115-1003\Software\MuleAppData
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixe
E: - Lecteur fixe
F: - Lecteur fixe
G: - Lecteur fixe
+- deleting files :
--------------- [ Registry / Mountpoint2 ] ----------------
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ce48e7c-82a7-11dd-beee-fbb3d328bbe8}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a205652-e50b-11db-bd22-88bde0b5dfe8}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ce6e4f5-57ba-11dc-bdb1-eebcfe6f99ea}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf2-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c0b57bf3-56f0-11dc-bdaf-dfbed579eae9}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8595fb2-5425-11dc-bdad-da374e258feb}\Shell\AutoRun\command
--------------- [ Searching Other Infections ] ----------------
Références de comparaison Bagle MD5 :
113ac36b77630a2f67dd6cb7844406a4 C:\WINDOWS\system32\mdelk.exe
113ac36b77630a2f67dd6cb7844406a4 C:\WINDOWS\system32\wintems.exe
9c15290ee0d941f08b7ac48a1eaecffb C:\Documents and Settings\Florian\Application Data\drivers\winupgro.exe
--------------- [ Searching Cracks / Keygen ] ----------------
---------------- ! End of report ! ------------------
Utilisateur anonyme
6 janv. 2009 à 16:23
6 janv. 2009 à 16:23
OK attend j averti
et post le ici en message privé stp
http://www.commentcamarche.net/communaute/profil Chiquitine29
et post le ici en message privé stp
http://www.commentcamarche.net/communaute/profil Chiquitine29
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 16:23
6 janv. 2009 à 16:23
je vien de le posté un 3eme fois il me dit que mon post est arrivé mais en vain..
foxymophan
Messages postés
103
Date d'inscription
lundi 5 janvier 2009
Statut
Membre
Dernière intervention
28 janvier 2012
1
6 janv. 2009 à 16:28
6 janv. 2009 à 16:28
est-il bien arrivé??