Plus de centre de sécurité application win 32

Résolu
prof hao Messages postés 3 Date d'inscription   Statut Membre -  
sKe69 Messages postés 21955 Statut Contributeur sécurité -
Bonjour,
désolé de vous déranger mais en parcourant le forum, je me suis rendu compte de la performance de vos conseils, donc je me lance.

voilà, depuis deux jours, plus d'antivirus (avira), ni de centre de sécurité sur mon pc (windows xp).

d'autre part, des applications ne fonctionnent plus et un message d'erreur tel que "n'est pas une application win 32 valide" apparait.

j'ai essayé kapersky en ligne et au bout de 15 h 00 de scan !!!, il a détecté 5 virus et 49 fichiers infestés, le problème est qu'il n'y a pas de rapport car çà bloque à ce moment.

aucun antivirus en ligne ne s'installe (bitdefender ou avast) car il y a certainement un virus qui les neutralise au moment de l'installation et des messages d'erreurs ou une fermeture de fenêtre intempestive se produit et donc je suis bloqué !!!
je sais donc qu'il y a 5 virus, lesquels ? mystère !
et que ma bécane rame de plus en plus...

a l'aide !

merci de votre patience car je ne suis pas un as de l'informatique ;)
Configuration: Windows XP
Firefox 3.0.5

48 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Le sujet central est l'infection par des malwares sur Windows XP, qui empêche l'installation d'antivirus et produit des messages d'erreur 'n'est pas une application Win32 valide', tout en ralentissant le PC. Plusieurs réponses proposent des outils et procédures pour diagnostiquer et nettoyer le système, notamment FindyKill, GenProc et HijackThis, afin d'extraire des rapports et d'identifier les composants indésirables. Des avis complémentaires évoquent un possible cheval de Troie Bagle, des risques liés à l'exécution d'outils externes et la nécessité de déconnecter le PC et d'analyser les démarrages et services. Des échanges soulignent aussi des limites des outils en ligne et l'importance de privilégier des scans hors ligne et des rapports clairs pour éviter les faux positifs.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. Utilisateur anonyme
     
    ok

    merci

    réinstal le telecharge celui ci :

    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill-prueba.exe

    et passe a l option 2 directement

    et post le rapport stp
    1
    1. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
       
      A l'option 2 je supose :p

      0
  2. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Salut,

    Infection par un Bagle :

    1-IMPORTANT :
    je rappelle que bagle est amené par un crack et qu'il se relance dès que tu te sers de celui ci; même si tu ne sers pas, il peut se relancer de lui même au démarrage de ton PC . En claire :
    Essaye surtout de te rappeler si récemment tu n'as pas cliquer sur un "patch" ou un "keygen" pour installer un logiciel, un jeu cracké ou avoir une version complète d'un soft , et qu'il ne se soit rien passé de particulier ... C'est la que les bagles s'infiltrent ! Si tu retrouves ce crack en particulier ,scratch tout ( le crack, le soft ou encore les zip concernés). Si tu ne te rappelles plus trop , je te conseille fortement de supprimer tous les cracks qui sont sur ton PC ... ;)

    2-Télécharge FindyKill de Chiquitine29 :

    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

    ->Enregistre le sur ton bureau et pas ailleurs !

    !! Déconnecte toi et ferme toutes applications en cours !!

    ( Si ton anti-virus s'affolle au moment de l'enregistrement ou de l'utilisation de l'outil ,
    ignore l'alerte *.)

    -> Clique sur "FindyKill.exe" pour lancer l'installe de l'outil . Ne touche surtout pas aux paramètres d'installation.

    Notes importantes :
    > si tu as le prg Elibagla sur ton PC , supprime le ( risque de conflit entre les deux outils ) .

    --> Double clique sur le raccourci " FindyKill " qui est sur ton bureau .
    ( sur la 1er fenêtre , tapes f puis [entrèe] pour la version en français ).

    -->choisis l'option 1 ( recherche ) . Puis laisse travailler l'outil sans rien toucher ...

    Une fois terminé, poste le rapport FindyKill.txt qui est généré ...

    ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

    * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    Tuto : https://www.malekal.com/tutorial-findykill/

    0
    1. prof hao Messages postés 3 Date d'inscription   Statut Membre
       
      merci de cette réponse rapide.
      en effet, il est probable que mon fils ai télécharger un crack (ha la jeunesse !!) et donc je vais essayé la solution que vous préconisez même si je n'ai pas la moitié de ce que vous décrivez et mon antivirus ne risque pas de se déclencher puisqu'il est HS !
      0
  3. Utilisateur anonyme
     
    Bonsoir , juste pour suivre merci
    0
  4. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    voici le rapport :

    bonsoir chiquitine 29 (vive la bretagne !?)

    ----------------- FindyKill V4.711 ------------------

    * User : Audiger - BUREAU
    * Emplacement : C:\Program Files\FindyKill
    * Outils Mis a jours le 05/01/09 par Chiquitine29
    * Recherche effectuée à 20:03:07 le 12/01/2009
    * Windows XP - Internet Explorer 7.0.5730.13

    ((((((((((((((((( *** Recherche *** ))))))))))))))))))

    --------------- [ Processus actifs ] ----------------

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Documents and Settings\Audiger\Application Data\drivers\winupgro.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\LXBLPSWX.EXE
    C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\LXBLJSWX.EXE
    C:\WINDOWS\system32\SearchFilterHost.exe

    --------------- [ Processus infectieux stoppés ] ----------------

    "C:\Documents and Settings\Audiger\Application Data\drivers\winupgro.exe" (2460)

    --------------- [ Fichiers/Dossiers infectieux ] ----------------

    »»»» Presence des fichiers dans C:

    »»»» Presence des fichiers dans C:\WINDOWS

    »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

    Found ! - C:\WINDOWS\prefetch\224125.EXE-34B4C238.pf
    Found ! - C:\WINDOWS\prefetch\263625.EXE-1B3E9228.pf
    Found ! - C:\WINDOWS\prefetch\450796.EXE-04DAE54E.pf
    Found ! - C:\WINDOWS\prefetch\540062.EXE-234584E9.pf
    Found ! - C:\WINDOWS\prefetch\568093.EXE-2D8C2123.pf
    Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-122C31B2.pf
    Found ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
    Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
    Found ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-2E335536.pf

    »»»» Presence des fichiers dans C:\WINDOWS\system32

    Found ! [12/01/2009 12:22] - C:\WINDOWS\system32\mdelk.exe
    Found ! [12/01/2009 12:22] - C:\WINDOWS\system32\wintems.exe
    Found ! [12/01/2009 19:26] - C:\WINDOWS\system32\ban_list.txt

    »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

    »»»» Presence des fichiers dans C:\Documents and Settings\Audiger\Application Data

    Found ! [12/01/2009 16:28] - "C:\Documents and Settings\Audiger\Application Data\m\flec006.exe"
    Found ! [12/01/2009 16:28] - "C:\Documents and Settings\Audiger\Application Data\m\list.oct"
    Found ! [12/01/2009 16:28] - "C:\Documents and Settings\Audiger\Application Data\m\data.oct"
    Found ! [12/01/2009 16:28] - "C:\Documents and Settings\Audiger\Application Data\m\srvlist.oct"
    Found ! [12/01/2009 16:29] - "C:\Documents and Settings\Audiger\Application Data\m\shared"
    Found ! [10/01/2009 23:58] - "C:\Documents and Settings\Audiger\Application Data\m"
    Found ! [10/01/2009 23:54] - "C:\Documents and Settings\Audiger\Application Data\drivers"
    Found ! [12/01/2009 12:20] - "C:\Documents and Settings\Audiger\Application Data\drivers\srosa.sys"
    Found ! [12/01/2009 12:20] - "C:\Documents and Settings\Audiger\Application Data\drivers\srosa2.sys"
    Found ! [20/10/2005 01:01] - "C:\Documents and Settings\Audiger\Application Data\drivers\winupgro.exe"
    Found ! [12/01/2009 16:31] - "C:\Documents and Settings\Audiger\Application Data\drivers\downld"

    »»»» Presence des fichiers dans C:\DOCUME~1\Audiger\LOCALS~1\Temp

    »»»» Presence des fichiers dans C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5

    Found ! [11/01/2009 23:16] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64[1].jpg
    Found ! [12/01/2009 03:20] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64[2].jpg
    Found ! [11/01/2009 15:03] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64_1[1].jpg
    Found ! [11/01/2009 23:18] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64_1[2].jpg
    Found ! [11/01/2009 19:14] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64_2[1].jpg
    Found ! [12/01/2009 07:29] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64_2[2].jpg
    Found ! [11/01/2009 15:00] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64_3[1].jpg
    Found ! [11/01/2009 19:04] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\7PVRO0MO\b64_3[2].jpg
    Found ! [12/01/2009 12:24] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\EVAEB7QF\b64_1[1].jpg
    Found ! [12/01/2009 16:28] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\EVAEB7QF\mxd[1].jpg
    Found ! [12/01/2009 16:28] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\I37NZFWX\b64_1[1].jpg
    Found ! [12/01/2009 16:30] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\I37NZFWX\b64_2[1].jpg
    Found ! [12/01/2009 12:23] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\SG75AU41\b64[1].jpg
    Found ! [12/01/2009 16:28] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\SG75AU41\b64[2].jpg
    Found ! [12/01/2009 19:26] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\SG75AU41\file[1].txt
    Found ! [12/01/2009 16:28] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\SG75AU41\servernames[1].htm
    Found ! [12/01/2009 16:30] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\TH3UU3NV\b64_1[1].jpg
    Found ! [12/01/2009 12:26] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\TH3UU3NV\b64_2[1].jpg
    Found ! [12/01/2009 12:22] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\TH3UU3NV\b64_3[1].jpg
    Found ! [12/01/2009 12:23] - C:\Documents and Settings\Audiger\Local Settings\Temporary Internet Files\Content.IE5\TH3UU3NV\mxd[1].jpg
    Found ! [23/07/2002 16:00] - C:\DVD PROGRAMMES\Office 2003\FILES\PFILES\MSOFFICE\OFFICE11\1036\FILTERS.TXT

    --------------- [ Registre / Startup ] ----------------

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
    DWQueuedReporting="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
    swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
    SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    AudioDeck=C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    LXBLKsk=C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
    avgnt="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    MemoryCardManager=C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup
    adiras=adiras.exe
    SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
    Windows Defender="C:\Program Files\Windows Defender\MSASCui.exe" -hide
    Adobe Photo Downloader="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    Canal Widget="C:\Program Files\Canal\Canal Widget\Launcher.exe"
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    <NO NAME>=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
    Installed=1
    <NO NAME>=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
    NoChange=1
    Installed=1
    <NO NAME>=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
    Installed=1
    <NO NAME>=

    [HKEY_CURRENT_USER\software\local appwizard-generated applications\dwtrig20]
    [HKEY_CURRENT_USER\software\local appwizard-generated applications\run]
    [HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]

    --------------- [ Registre / Clés infectieuses ] ----------------

    Found ! - HKEY_USERS\S-1-5-21-1606980848-515967899-839522115-1006\Software\Local AppWizard-Generated Applications\winupgro
    Found ! - HKEY_USERS\S-1-5-21-1606980848-515967899-839522115-1006\Software\bisoft
    Found ! - HKEY_USERS\S-1-5-21-1606980848-515967899-839522115-1006\Software\DateTime4
    Found ! - HKEY_USERS\S-1-5-21-1606980848-515967899-839522115-1006\Software\FFC
    Found ! - HKEY_USERS\S-1-5-21-1606980848-515967899-839522115-1006\Software\FirtR
    Found ! - HKEY_USERS\S-1-5-21-1606980848-515967899-839522115-1006\Software\MuleAppData
    Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
    Found ! - HKEY_CURRENT_USER\Software\bisoft
    Found ! - HKEY_CURRENT_USER\Software\DateTime4
    Found ! - HKEY_CURRENT_USER\Software\FirtR

    /!\ Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
    /!\ Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1

    --------------- [ Etat / Services ] ----------------

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

    /!\ Mode sans echec non fonctionnel !!

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

    /!\ Mode sans echec non fonctionnel !!

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

    /!\ Mode sans echec non fonctionnel !!

    +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

    /!\ Ndisuio - Type de démarrage = 4

    EapHost - Type de démarrage = 3

    /!\ Ip6Fw - Type de démarrage = 4

    /!\ SharedAccess - Type de démarrage = 4

    /!\ wuauserv - Type de démarrage = 4

    /!\ wscsvc - Type de démarrage = 4

    /!\ WinDefend - Type de démarrage = 4

    --------------- [ Recherche dans supports amovibles] ----------------

    +- Informations :

    C: - Lecteur fixe

    +- presence des fichiers :

    --------------- [ Registre / Mountpoint2 ] ----------------

    -> Not found !

    ------------------- ! Fin du rapport ! --------------------
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    bien ...

    voilà la suite :

    1- Important :
    Branche toutes tes unités externes au PC ( DD externes , clé USB , lecteur mp3, ect...) mais sans les ouvrir !
    Tu les retireras après la manipe ...

    2- ! Ferme toutes applications en cours !

    Relance FindyKill :

    -> choisis cette fois-ci l'option 2 .

    /!\ ton PC va redémarrer de lui même , c'est normal !... Laisse travailler l'outil jusqu' à l'apparition du message :
    "nettoyage terminé" .

    Note : lors du message d'avertissement , clique sur " Ok " .

    --> ensuite poste le nouveau rapport FindyKill.txt qui est généré et attends la suite ...

    ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

    PS : Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier"-> "Nouvelle tâche":
    tape explorer.exe et valide .
    0
  7. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    bon ben là, problème !

    en fait après le message d'avertissement, j'appuie sur entrée et l'écran devient vleu avec ce message :

    windows est arrété par sécurité suite à un problème avec
    srosa.sys driver_unloaded_without_cancelling_pending_operations
    puis un message disant que si c'est la première fois, il faut éteindre puis redemarré et bla bla bla

    puis ceci

    stop:0x000000ce (0xf6457cco , 0x00000000 , 0xf6457cc0 , 0,0000000
    srosa.sys

    puis début de vidage de la mémoire physique

    comptage jusqu'a 100 puis il redeùmarre et sur le bureau, pas de rapport si ce n'est un message de récuperation d'erreur sérieuse par microsoft.

    après une recherche du fichier pas de C:\FindyKill.txt trouvé !!

    serais je maudit ???
    0
  8. Utilisateur anonyme
     
    Salut prof hao

    réouvre findykill et fais l option 3 afin de le désinstaller

    ensuite je te passe une autre version ...si ske69 me permet
    0
    1. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
       
      No problemo Chiki ! ;)

      je te laisse poursuivre ... ^^

      0
  9. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    voilà il est désinstallé.
    0
  10. Utilisateur anonyme
     
    trop tard ...
    0
    1. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
       
      :)))
      0
  11. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    bon ben c'est exactement pareil, il commence a travailler puis au bout de deux seconde, pchitt !!

    ecran bleu avec le fameux problème au fichier SROSA.SYS

    et donc plantage totale, vidage de mémoire physique puis redemarage seul de la becane.

    voilà, voilà, voilà ;))
    0
  12. Utilisateur anonyme
     
    ok

    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau

    -> Double clique sur killbagle.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    Une fois fait, sur ton bureau double-clic sur killbagle.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
    0
  13. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    voici le rapport de combofix

    ComboFix 09-01-11.04 - Audiger 2009-01-12 22:06:23.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.511.314 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Audiger\Bureau\killbagle.exe
    AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Audiger\Application Data\drivers\downld
    c:\documents and settings\Audiger\Application Data\drivers\downld\108843.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\110312.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\110437.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\110578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\111171.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\115921.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\116000.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\124593.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\129218.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\130250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\130453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\130656.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\131734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\133937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\134343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\135546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\135625.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\136265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\136328.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\136640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\136765.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\138265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14712453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14714703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14714890.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14723625.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14752796.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14754328.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14754968.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14793156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14854515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14854937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14854984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14875578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14877031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14877562.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14878671.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14880343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14881906.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14909296.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14910156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14911000.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14920531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14982937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14983843.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\14984468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15007781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15008015.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15008093.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15046703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15049968.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15050265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15061156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15070109.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15127734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15127937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15128000.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15140781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15141921.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15142484.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15143234.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15144250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15144828.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15169703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15170156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15170453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15174671.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15221234.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15221875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\15222296.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\153765.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\155500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\156546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\156562.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\157406.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\158265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\158765.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\167250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\167890.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\168734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\169437.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\169984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\179343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\183812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\184453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\184546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\185078.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\192640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\194984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\199984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\200640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\200718.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\205328.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\205609.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\206515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\206531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\215140.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\216359.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\216765.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\217421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\218062.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\218125.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\218562.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\219734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\221875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\223328.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\224062.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\224125.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\224906.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\225515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\225812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\226500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\227781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\228265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\228390.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\228609.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\229437.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\229484.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\229703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\233578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\236250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\237140.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\237546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\240406.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\243421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\243734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\244265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\244390.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\244671.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\245343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\245484.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\245671.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\245875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\246265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\246328.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\246921.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\247562.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\248265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\248578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\249656.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\250015.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\255406.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\258203.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\258984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\259546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\259875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\263625.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\266265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\266984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\267140.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\267453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\267953.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\268250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\272421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\272500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\277843.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\281734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\281937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\282234.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\284578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\285859.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\285984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29388046.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29388359.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29388515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29395390.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29417515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29418078.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29418703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29441625.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\297203.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29845250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29904968.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29905000.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29905031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29919640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29921296.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29922281.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29923250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29924031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29924515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29945031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29946171.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29946687.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29993500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29994171.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\29994906.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\306750.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\307578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\308421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\308796.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\321359.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\322125.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\327390.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\329625.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\330890.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\331156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\334265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\336640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\337187.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\339625.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\340187.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\340203.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\347234.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\351031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\351531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\354046.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\355359.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\355890.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\356921.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\357781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\358250.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\371703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\377437.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\378468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\379000.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\384500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\407703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\408453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\408500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\423750.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\424984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\425468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\426156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\427265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\427859.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\430234.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\431578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\431781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44399031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44405031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44405218.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44440921.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44442671.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44443890.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44464375.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44477359.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44520640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44521468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44521562.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44536609.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44538906.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44539734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44540687.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44543843.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44544765.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44567656.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44568968.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44569406.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44576703.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44630171.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44631531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\44632343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\446437.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\447062.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\447468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\450796.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\452468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\483781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\484687.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\484859.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\499593.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\501187.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\502421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\503812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\504781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\505421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\528984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\529875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\530640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\540062.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\586031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\587296.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\587750.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59035687.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59036453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59036531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59042343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59067859.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59068781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59069578.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59083343.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59110546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59149937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59150265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59150406.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59165937.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59167218.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59167984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59169421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59170828.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59171812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59195734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59196281.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59196812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59204500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59259656.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59260875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\59261656.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\604046.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\604562.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\605062.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\726671.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73665421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73665750.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73665812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73671421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73691812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73692546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73692859.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73707109.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73880281.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73880406.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73880515.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73958125.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73959718.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73961500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73962500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73963421.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73964546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73988921.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73989734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73990781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\73997859.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\74069812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\74070828.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\74071546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\762265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\762750.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\762812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\776031.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\777359.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\778062.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\778968.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\779875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\780609.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\802906.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\803640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\804156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\812265.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88475640.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88476609.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88476734.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88481078.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88502468.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88503531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88504718.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88516656.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88524765.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88562781.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88563812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88563875.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88577500.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88579375.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88580078.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88580953.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88581687.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88582390.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88602890.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88603531.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88603984.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88647125.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88648546.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\88648812.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\914156.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\915453.exe
    c:\documents and settings\Audiger\Application Data\drivers\downld\915937.exe
    c:\documents and settings\Audiger\Application Data\drivers\srosa.sys
    c:\documents and settings\Audiger\Application Data\drivers\srosa2.sys
    c:\documents and settings\Audiger\Application Data\drivers\winupgro.exe
    c:\documents and settings\Audiger\Application Data\m
    c:\documents and settings\Audiger\Application Data\m\data.oct
    c:\documents and settings\Audiger\Application Data\m\flec006.exe
    c:\documents and settings\Audiger\Application Data\m\list.oct
    c:\documents and settings\Audiger\Application Data\m\shared\3D Rocky Reef 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\3D Topicscape Student Edition 1.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\5 Day Class Scheduler for 250 Students 1.3.zip
    c:\documents and settings\Audiger\Application Data\m\shared\646-227 - Lifecycle Services Advanced IP Communications (LCSAIPC) Practice Test Questions 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\ABC [ Yet Another Bittorrent Client ] 3.1 Final.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Acronis True Image Corporate Workstation 9.1 Build 3887.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Agent Red 2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Air and Space Screen Saver.zip
    c:\documents and settings\Audiger\Application Data\m\shared\AirSet Connector 2.0.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\All formats DVD Video Converter 3.29.zip
    c:\documents and settings\Audiger\Application Data\m\shared\anda_1960.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Apollo DVD Creator 5.4.6.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Archive Express 1.4.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Armageddon Regular.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Aster XP 2.5.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Atomic Zip Password Cracker 2.50.zip
    c:\documents and settings\Audiger\Application Data\m\shared\AUAU MOV Converter 4.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Auto Log 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\avast!.v.4.6.Antivirus.zip
    c:\documents and settings\Audiger\Application Data\m\shared\AVG.7.1.serial.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Avira Antivir Personal Pro Plus Edition 8.0 04_06.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Avira.AntiVir.PersonalEdition.Premium.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Birds Screen Saver 1.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Bitdefender.8.0.200.Crack.+.Serial.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Black Knight Caps.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Business Card Studio 2.0 Build 4149.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Cafe Manila 8.7.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Context Style Switcher 1.0.6.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Custom Brushes 5.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\DAC for MySQL 2.6.3.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Date Doctor For Men 1.7.zip
    c:\documents and settings\Audiger\Application Data\m\shared\DIGITAL SHO Professional 2.1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Directory Lister Pro 1.10.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Drive Speed Checker 1.5.5.zip
    c:\documents and settings\Audiger\Application Data\m\shared\DriveImage XML 2.02.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Elecard YUV Viewer 2.1.70710.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Elite Utilities 9 Professional 9.2.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Evidence Nuker 3.00.24.zip
    c:\documents and settings\Audiger\Application Data\m\shared\ExamView 4 Test Player 4.0.8.zip
    c:\documents and settings\Audiger\Application Data\m\shared\ExEinfo PE 0.0.2.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\F-Secure.Antivirus.2006.+.Cracks.&.Super.Infos.2006.fr.zip
    c:\documents and settings\Audiger\Application Data\m\shared\FastView32 2.0 Beta 2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Fowner 1.1.0.6.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Free SQL Compare 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\FT PDF to Image Converter 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Gambling Toolbar 1.0.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Genie Mail Backup 8.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\GIPALS 1.2.5.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Growing Vine Screensaver.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Gyzmo 2.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\HandSim 0.8.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Helpmatic Pro HTML 6.4.3.zip
    c:\documents and settings\Audiger\Application Data\m\shared\HTML Parser 1.6.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Hypnotica 3D Screensaver 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\ICC Batch Converter 1.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\iLead Video Converter 3.3.3.zip
    c:\documents and settings\Audiger\Application Data\m\shared\iOpener 0.3.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Jamendo DewPlayer 1.3.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Linear Interpolation Calculator 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Lossless JPEG Rotator 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\LPDForm 1.31B.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MAGIX Podcast Maker 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MaxDB Code Factory 8.7.0.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\McAfee.VirusScan.Enterprise.v8.0i.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Mehul's Backup 1.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MID Detective 1.0 build 299.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Miracle Service 3.2.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MM Transposer 2.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\mmv2mpg 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MoNooN Spam Killer 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Mp3 File Merger 1.6.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MP3 Splitter & Joiner Pro 4.20.zip
    c:\documents and settings\Audiger\Application Data\m\shared\MS Powerpoint Word Count & Frequency Statistics Software 7.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Music NFO Builder 1.20.zip
    c:\documents and settings\Audiger\Application Data\m\shared\NestedQuote Remover 0.7.18.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Net Monitor 2.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\NHL Teams Analog Clock 2.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\NOD32_All_Versions_v2.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\NOD32_Plug-Ins_de_Maxima_Deteccion.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Notebook Math One 3.0.7.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Object Spy 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\odbc2csv 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\One-to-One Meetings 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Opcion Font Viewer 1.1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\PANDA_TITANIUM_ANTIVIRUS_PLUS_ANTISPYWARE_2006_MULTILANGUAGE_ISO-DVT.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Pivot Pro 8.24.zip
    c:\documents and settings\Audiger\Application Data\m\shared\QMSYS Tolerances and Gauges 3.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\RageRover 1.4.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Registry Winner 3.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Royce PDF Printer 1.0 Build 320.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SeaSideSoft BookStack 1.0.3.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SecondLife Status 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SenseAgent 1.0.6.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SG Big Cats Screensaver 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SimpleGrid1 1.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Skylab.Spot.GPS.for.Mobile.Phone.PDA.Java.with.extern.Bluetooth-GPS.spot_cldc10.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Smtp.NET 3.0.5.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SnowScape 1.04.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Sockter 3.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Softe Video Player 1.0.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Source Code Library 1.9.0.152.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SSE Setup 5.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Sticky Notes 2.0.0.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Super X Desktop virtual Manager 3.4.1229.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SuperICL 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Swiss Rail 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Symantec.Ghost.v8.3.0.1331.4In1集æˆç²¾ç®€ç‰ˆ.zip
    c:\documents and settings\Audiger\Application Data\m\shared\SyvirCom 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\T-Shirt Widget 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Texture Maker 3.02.zip
    c:\documents and settings\Audiger\Application Data\m\shared\TFTPgui 1.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\THBPdf 1.0.3.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\The My Cats Screensaver 3.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Time Control 2.1.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Top1000 Mobile Handy Games (Java) Nokia Siemens Sony Motorola Uvm German Part21.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Tropical Sea Life 1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\U-Download 1.4.2.zip
    c:\documents and settings\Audiger\Application Data\m\shared\USB Flash Drive Recovery 3.0.1.5.zip
    c:\documents and settings\Audiger\Application Data\m\shared\VTE Virus Scanner 2.0.33.7 Beta.zip
    c:\documents and settings\Audiger\Application Data\m\shared\WebLoad 8.0.5.018.00.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Website Layout Maker 2.4.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Wfx Versions 0.19.zip
    c:\documents and settings\Audiger\Application Data\m\shared\WinMatrix XP 2.33.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Writers Project Organizer 2.3.0.23874.zip
    c:\documents and settings\Audiger\Application Data\m\shared\YoGen Vocoder 1.1.0.zip
    c:\documents and settings\Audiger\Application Data\m\shared\Zip Search 1.00.zip
    c:\documents and settings\Audiger\Application Data\m\srvlist.oct
    c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    c:\windows\system32\ban_list.txt
    c:\windows\system32\launcher.exe
    c:\windows\system32\mdelk.exe
    c:\windows\system32\wintems.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_SROSA
    -------\Legacy_SROSA
    -------\Legacy_NPF
    -------\Legacy_SK9OU0S
    -------\Service_sK9Ou0s

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-12-12 au 2009-01-12 ))))))))))))))))))))))))))))))))))))
    .

    2009-01-12 20:02 . 2009-01-12 21:37 <REP> d-------- c:\program files\FindyKill
    2009-01-12 18:56 . 2009-01-12 19:14 <REP> d-------- c:\documents and settings\Audiger\.housecall6.6
    2009-01-12 11:59 . 2009-01-12 11:59 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2009-01-11 11:03 . 2009-01-11 11:03 <REP> d-------- c:\windows\system32\Kaspersky Lab
    2009-01-10 23:42 . 2009-01-12 22:12 <REP> d--h----- c:\documents and settings\Audiger\Application Data\drivers
    2009-01-08 23:07 . 2009-01-08 23:07 <REP> d-------- c:\program files\Canal
    2009-01-08 23:06 . 2009-01-08 23:06 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
    2009-01-07 00:00 . 2009-01-07 00:00 410,984 --a------ c:\windows\system32\deploytk.dll
    2009-01-05 12:27 . 2009-01-05 12:27 <REP> d-------- c:\documents and settings\Audiger\Application Data\Windows Search
    2009-01-04 00:27 . 2009-01-04 00:29 <REP> d-------- c:\documents and settings\Audiger\Application Data\vlc
    2009-01-02 21:32 . 2009-01-02 21:32 <REP> d-------- c:\documents and settings\Audiger\Application Data\Windows Desktop Search
    2009-01-02 21:31 . 2009-01-02 21:31 <REP> d-------- c:\windows\system32\GroupPolicy
    2009-01-02 21:31 . 2009-01-02 21:32 <REP> d-------- c:\program files\Windows Desktop Search
    2009-01-02 21:30 . 2008-03-07 18:02 192,000 -----c--- c:\windows\system32\dllcache\offfilt.dll
    2009-01-02 21:30 . 2008-03-07 18:02 98,304 -----c--- c:\windows\system32\dllcache\nlhtml.dll
    2009-01-02 21:30 . 2008-03-07 18:02 29,696 -----c--- c:\windows\system32\dllcache\mimefilt.dll
    2009-01-02 21:23 . 2009-01-02 21:24 <REP> d-------- c:\windows\system32\URTTemp
    2009-01-02 19:23 . 2008-10-16 21:18 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
    2009-01-02 19:23 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
    2009-01-02 19:23 . 2007-03-08 06:10 1,048,576 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
    2009-01-02 19:23 . 2008-10-16 21:18 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
    2009-01-02 19:23 . 2008-10-16 21:18 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
    2009-01-02 19:23 . 2008-10-16 21:18 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
    2009-01-02 19:23 . 2008-10-16 21:18 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
    2009-01-02 19:23 . 2008-10-16 21:18 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
    2009-01-02 19:23 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
    2009-01-02 19:20 . 2008-09-10 02:15 1,307,648 -----c--- c:\windows\system32\dllcache\msxml6.dll
    2009-01-02 19:20 . 2008-04-14 03:04 93,184 -----c--- c:\windows\system32\dllcache\msxml6r.dll
    2009-01-02 19:18 . 2006-12-28 20:01 19,569 --a------ c:\windows\[u]0/u03094_.tmp
    2009-01-02 18:35 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
    2009-01-02 18:32 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2009-01-02 18:32 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2009-01-02 18:32 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2009-01-02 18:32 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2009-01-02 18:32 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2009-01-02 18:30 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
    2009-01-02 18:29 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
    2009-01-02 18:27 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2009-01-02 18:27 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
    2009-01-02 18:26 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
    2009-01-02 18:26 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2009-01-02 18:13 . 2009-01-02 18:13 <REP> d-------- C:\MesDocuments
    2009-01-02 17:30 . 2009-01-02 17:30 <REP> d--hs---- c:\documents and settings\Audiger\UserData
    2009-01-02 17:12 . 2009-01-12 21:40 536,428,544 --a------ c:\windows\MEMORY.DMP
    2009-01-02 16:47 . 2006-01-05 14:24 <REP> d--h----- c:\documents and settings\Audiger\Voisinage réseau
    2009-01-02 16:47 . 2006-01-05 14:24 <REP> d--h----- c:\documents and settings\Audiger\Voisinage d'impression
    2009-01-02 16:47 . 2009-01-02 16:22 <REP> d--h----- c:\documents and settings\Audiger\Modèles
    2009-01-02 16:47 . 2009-01-12 17:50 <REP> dr------- c:\documents and settings\Audiger\Mes documents
    2009-01-02 16:47 . 2006-01-05 14:24 <REP> dr------- c:\documents and settings\Audiger\Menu Démarrer
    2009-01-02 16:47 . 2009-01-04 14:45 <REP> dr------- c:\documents and settings\Audiger\Favoris
    2009-01-02 16:47 . 2009-01-12 21:53 <REP> d-------- c:\documents and settings\Audiger\Bureau
    2009-01-02 16:47 . 2009-01-12 18:56 <REP> d-------- c:\documents and settings\Audiger
    2009-01-02 16:40 . 2004-08-05 13:00 1,875,968 --a--c--- c:\windows\system32\dllcache\msir3jp.lex
    2009-01-02 16:39 . 2008-04-14 03:31 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
    2009-01-02 16:38 . 2004-08-05 13:00 1,677,824 --a--c--- c:\windows\system32\dllcache\chsbrkr.dll
    2009-01-02 16:36 . 2009-01-02 16:36 488 -rah----- c:\windows\system32\logonui.exe.manifest
    2009-01-02 16:35 . 2004-08-05 13:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
    2009-01-02 16:35 . 2009-01-02 16:35 749 -rah----- c:\windows\WindowsShell.Manifest
    2009-01-02 16:35 . 2009-01-02 16:35 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
    2009-01-02 16:35 . 2009-01-02 16:35 749 -rah----- c:\windows\system32\sapi.cpl.manifest
    2009-01-02 16:35 . 2009-01-02 16:35 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
    2009-01-02 16:30 . 2008-04-14 03:05 14,720 --a------ c:\windows\system32\drivers\kbdhid.sys
    2009-01-02 16:29 . 2001-08-17 20:13 27,165 --a------ c:\windows\system32\drivers\fetnd5.sys
    2008-12-13 09:55 . 2006-01-05 14:24 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
    2008-12-13 09:55 . 2006-01-05 14:24 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
    2008-12-13 09:55 . 2006-01-05 13:32 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
    2008-12-13 09:55 . 2006-01-05 14:24 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
    2008-12-13 09:55 . 2006-01-05 14:24 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
    2008-12-13 09:55 . 2006-01-05 14:24 <REP> d-------- c:\documents and settings\Administrateur\Favoris
    2008-12-13 09:55 . 2006-01-05 14:24 <REP> d-------- c:\documents and settings\Administrateur\Bureau
    2008-12-13 09:55 . 2008-12-13 09:55 <REP> d-------- c:\documents and settings\Administrateur
    2008-12-13 03:02 . 2009-01-02 21:34 1,355 --a------ c:\windows\imsins.BAK

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-12 11:17 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
    2009-01-11 09:02 --------- d-----w c:\program files\Spybot - Search & Destroy
    2009-01-10 22:39 --------- d-----w c:\program files\eMule
    2009-01-08 21:04 --------- d-----w c:\program files\adslTV
    2009-01-06 23:00 --------- d-----w c:\program files\Java
    2008-12-13 00:56 --------- d-----w c:\program files\DesktopEarth
    2008-12-08 20:31 --------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
    2008-12-08 20:31 --------- d-----w c:\program files\SDHelper (Spybot - Search & Destroy)
    2008-12-08 20:05 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-12-08 19:40 --------- d-----w c:\documents and settings\Lorenne\Application Data\OpenOffice.org
    2008-12-08 19:37 --------- d-----w c:\program files\OpenOffice.org 3
    2008-12-08 19:37 --------- d-----w c:\program files\JRE
    2008-11-26 17:58 138,512 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
    2008-11-26 16:46 --------- d-----w c:\program files\Phonetik
    2008-11-16 10:17 --------- d-----w c:\program files\DX-Ball
    2008-11-12 17:54 --------- d-----w c:\program files\Podmailing
    2008-06-22 14:58 1,970,176 ----a-w c:\program files\produits.mdb
    2008-06-22 14:55 369 ----a-w c:\program files\AUCL220080622165553.txt
    2008-06-22 14:55 176 ----a-w c:\program files\AUEC220080622165553.txt
    2008-06-22 14:55 12,225 ----a-w c:\program files\AULC220080622165553.txt
    2008-06-22 14:51 369 ----a-w c:\program files\AUCL220080622165140.txt
    2008-06-22 14:51 176 ----a-w c:\program files\AUEC220080622165140.txt
    2008-06-22 14:51 12,225 ----a-w c:\program files\AULC220080622165140.txt
    2008-06-22 14:50 369 ----a-w c:\program files\AUCL220080622165031.txt
    2008-06-22 14:50 176 ----a-w c:\program files\AUEC220080622165031.txt
    2008-06-22 14:50 12,225 ----a-w c:\program files\AULC220080622165031.txt
    2008-06-22 12:03 6,741 ----a-w c:\program files\ST6UNST.LOG
    2008-04-15 07:20 839,680 ----a-w c:\program files\papeterie.exe
    2008-04-15 07:01 5,064 ----a-w c:\program files\cgv.txt
    2008-04-11 07:35 536,064 ----a-w c:\program files\GIFAnimator.exe
    2008-04-11 07:35 248 ----a-w c:\program files\GIFAnimator.cnt
    2008-04-11 07:35 17,642 ----a-w c:\program files\GIFAnimator.hlp
    2008-04-11 07:35 10,752 ----a-w c:\program files\README.WRI
    2006-01-08 19:47 9,336,520 ----a-w c:\program files\Install_MSN_Messenger.EXE
    2005-03-29 11:50 177 ----a-w c:\program files\boot.syt
    2001-03-27 09:43 1 ----a-w c:\program files\BOOT.ASC
    2001-03-23 15:46 3,495 ----a-w c:\program files\a1.txt
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-12 68856]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-11 1832272]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2005-09-06 450560]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-19 86016]
    "LXBLKsk"="c:\progra~1\Lexmark\PHOTOC~1\LXBLKsk.exe" [2003-03-26 282624]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-06 98304]
    "avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2009-01-12 266497]
    "MemoryCardManager"="c:\program files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe" [2003-04-28 122880]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-07 136600]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 63712]
    "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-20 185896]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "Canal Widget"="c:\program files\Canal\Canal Widget\Launcher.exe" [2008-12-12 105528]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\Lorenne\Menu D‚marrer\Programmes\D‚marrage\
    DesktopEarth AutoStart.lnk - c:\documents and settings\Lorenne\Application Data\Microsoft\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_C1A9BF9D98647632ED5172.exe [2007-06-26 29926]
    OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-908\dslmon.exe [2006-01-09 962663]
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.3iv2"= 3ivxVfWCodec.dll
    "VIDC.HFYU"= huffyuv.dll
    "VIDC.VP31"= vp31vfw.dll
    "VIDC.VP40"= vp4vfw.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\InterVideo WinCinema Manager.lnk
    backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
    backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
    --a------ 2003-04-28 17:29 122880 c:\program files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    --a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2006-01-06 20:38 98304 c:\program files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    --a------ 2003-10-31 19:42 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    --a------ 2008-04-20 17:14 185896 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\InterVideo\\DVD6\\WinDVD.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "c:\\Program Files\\SAGEM\\SAGEM F@st 908-948\\BridgeMon.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Azureus\\Azureus.exe"=
    "c:\\WINDOWS\\system32\\LEXPPS.EXE"=
    "c:\\Program Files\\adslTV\\adsltv.exe"=
    "c:\\Program Files\\Podmailing\\podmailing.exe"=
    "c:\\Program Files\\adslTV\\vlc.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [2006-02-09 22336]
    R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [2006-02-09 45376]
    R3 Camdrv30;Philips ToUcam XS;c:\windows\system32\drivers\camdrv30.sys [2006-01-09 171264]
    R4 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [2008-12-10 61440]
    R4 ppsio2;PPDevice;c:\windows\system32\drivers\PPSIO2.SYS [2006-04-18 22272]
    S3 76de0ff6-89ec-40b8-aef1-43cdf25ce1f8;76de0ff6-89ec-40b8-aef1-43cdf25ce1f8;\??\d:\player\cds300.dll --> d:\player\cds300.dll [?]
    S3 adiusbae;USB ADSL LAN Adapter;c:\windows\system32\DRIVERS\adiusbae.sys --> c:\windows\system32\DRIVERS\adiusbae.sys [?]
    S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    .
    Contenu du dossier 'Tâches planifiées'

    2009-01-12 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

    2009-01-09 c:\windows\Tasks\Norton Security Scan.job
    - c:\program files\Norton Security Scan\Nss.exe []

    2009-01-12 c:\windows\Tasks\User_Feed_Synchronization-{62BD6609-9A41-4D87-B340-62589589D728}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKCU-Run-DWQueuedReporting - c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    HKLM-Run-adiras - adiras.exe
    HKU-Default-Run-DWQueuedReporting - c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    MSConfigStartUp-CloneCDElbyCDFL - c:\program files\Elaborate Bytes\CloneCD\ElbyCheck.exe
    MSConfigStartUp-CloneCDTray - c:\program files\Elaborate Bytes\CloneCD\CloneCDTray.exe
    MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.ogame.fr/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    O16 -: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} - hxxp://minitelweb.minitel.com/imin_data/ocx/MDM.cab
    c:\windows\Downloaded Program Files\MDM.inf

    c:\windows\Downloaded Program Files\tra2_2_5.rc - c:\windows\Downloaded Program Files\PIXACODnDUpload.ocx
    O16 -: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA}
    hxxp://www.pixaco.fr/static/download/pixacodndupload.cab
    c:\windows\Downloaded Program Files\PIXACODnDUpload.inf
    FF - ProfilePath - c:\documents and settings\Audiger\Application Data\Mozilla\Firefox\Profiles\4rpfae5h.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.ogame.fr/
    0
  14. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    oups la fin

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-12 22:18:43
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\system32\LEXBCES.EXE
    c:\windows\system32\LEXPPS.EXE
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\PnkBstrA.exe
    c:\windows\system32\searchindexer.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Canal\Canal Widget\Canal Widget.exe
    c:\windows\system32\searchprotocolhost.exe
    c:\windows\system32\searchfilterhost.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-01-12 22:30:57 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-01-12 21:30:49

    Avant-CF: 8,963,719,168 octets libres
    Après-CF: 13,993,168,896 octets libres

    WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

    799 --- E O F --- 2009-01-12 21:21:03

    dois je ouvrir l'antivirus qui est réapparu ou faut il faire autre chose auparavant ?
    0
  15. Utilisateur anonyme
     
    ok ,

    la suite pour ske69

    @++
    0
  16. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    merci de ton aide chiquitine

    j'attends la suite mon cher ske69 :))
    0
  17. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    ben en fait le centre de sécurité est réapparu, mais l'antivirus apparait désactivé.
    lorsque je clique sur start antivir personnaledition classic le message ce n'est pas une application win32 valide réapparait !
    0
  18. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    bon, je vais me coucher.

    j'espère avoir des nouvelles demain.

    je vous souhaite une bonne nuit et vosu remercie pour l'aide déjà apportée, le bout du tunnel n'est peut être plus si loin que cela...

    a demain, donc

    :)
    0
  19. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    mais l'antivirus apparait désactivé.
    lorsque je clique sur start antivir personnaledition classic le message ce n'est pas une application win32 valide réapparait !


    c'est normal ... Bagle l'a définitivement shooter ... ^^

    Dans l'ordre :

    1- Va dans panneau de configuration / ajout et suppression de prg :

    Supprime AntiVir ... On le ré-instalera une fois le PC propre ...

    ==============

    2- Relance Fyndykill et choisi l'option 3 pour le désinstaller proprement ... c'est important !

    ==============

    3- Télécharge CCleaner :
    http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
    ou https://www.pcastuces.com/logitheque/ccleaner.htm
    Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corriger ton registre .
    Lors de l'installation:
    -choisis bien "français" en langue .
    -avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 premières.

    Un tuto ( aide ):
    http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

    ---> Utilisation:
    ! déconnecte toi et ferme toutes applications en cours !
    * va dans "nettoyeur" : fais -analyse- puis -nettoyage-
    * va dans "registre" : fais -chercher les erreurs- et -réparer toutes les erreurs-
    ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

    ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

    ================

    4- Télécharge MalwareByte's :
    ici http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebytes anti malware
    ou ici : http://www.malwarebytes.org/mbam.php

    * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

    * Potasse le tuto pour te familiariser avec le prg :
    https://forum.pcastuces.com/sujet.asp?f=31&s=3
    ( cela dis, il est très simple d'utilisation ).

    ! Déconnecte toi et ferme toutes applications en cours !

    * Lance Malwarebyte's .

    Fais un examen dit "Rapide" .

    --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    --> à la fin tu cliques sur "résultat" .
    --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) pour analyse ...

    ==================

    5- Télécharge et installe le logiciel HijackThis :

    ici http://static.commentcamarche.net/www.commentcamarche.net/download/fichiers/HJTInstall.exe
    ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

    > Clique sur le setup pour lancer l'installe : laisse toi guider et ne modifie pas les paramètres d'installation .
    A la fin de l'installe , le prg ce lance automatiquement : ferme le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

    tuto pour utilisation :
    Regarde ici, c'est parfaitement expliqué en images (merci balltrap34),
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    ( Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement )

    > !! Déconnecte toi et ferme toutes tes applications en cours !!

    Clique sur le raccourci du bureau pour lancer le prg :
    fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

    ---> Poste le rapport généré pour analyse ...

    0
  20. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    merci, je vais cela dans la journée (si j'en ai le temps ) ou ce soir se sera plus simple!

    bonne journée, je te tiens au courant
    merci
    0
  21. prof hao Messages postés 3 Date d'inscription   Statut Membre
     
    voici le rapport de malwarebytes :

    Malwarebytes' Anti-Malware 1.32
    Version de la base de données: 1647
    Windows 5.1.2600 Service Pack 3

    13/01/2009 18:45:23
    mbam-log-2009-01-13 (18-45-23).txt

    Type de recherche: Examen rapide
    Eléments examinés: 57798
    Temps écoulé: 9 minute(s), 5 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    je m'attelle à la suite de ce pas
    a tout de suite
    0
  • 1
  • 2
  • 3