Help rapport hijackthis !! J'comprends pas =(
Fermé
Moi
-
13 mars 2009 à 21:24
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 - 18 mars 2009 à 18:06
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 - 18 mars 2009 à 18:06
A voir également:
- Help rapport hijackthis !! J'comprends pas =(
- Hijackthis windows 10 - Télécharger - Antivirus & Antimalwares
- Plan rapport de stage - Guide
- Impossible d'afficher le rapport de tableau croisé dynamique sur un rapport existant ✓ - Forum Excel
- Problém affichage du tableau croisé dynamique - Forum Excel
- Rapport erreur windows - Guide
37 réponses
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 21:28
13 mars 2009 à 21:28
bonjour je fais des recherches consernant certaine lignes et je reviens
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 21:40
13 mars 2009 à 21:40
bonjour, tu as encore le service symantec " norton " qui est actif il faudra l'arrêter on vèra après , la tu vas faire otmoveit et puis passer malwarebytes , Merci
1) Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
Double-clique sur OTMoveIt3.exe pour le lancer.
Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.
Copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".
:processes
explorer.exe
:files
c:\windows\system32\nss128.dll
c:\windows\system32\nsx10c.dll
c:\windows\system32\spads.dll
c:\windows\system32\rlai.dll
c:\windows\system32\rlls.dll
:Commands
[purity]
[emptytemp]
[start explorer]
[reboot]
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur "Exit" pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .
Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
2) Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
. sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
. enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
. Il va se mettre à jour une fois faite
. rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, cliques sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés)
. cliques sur Supprimer la sélection
. Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. redemarre le pc
. une fois redémarré double-cliques sur malwarebytes
. rends toi dans l'onglet rapport/log
. tu cliques dessus pour l'afficher une fois affiché
. tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
. tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller
1) Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
Double-clique sur OTMoveIt3.exe pour le lancer.
Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.
Copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".
:processes
explorer.exe
:files
c:\windows\system32\nss128.dll
c:\windows\system32\nsx10c.dll
c:\windows\system32\spads.dll
c:\windows\system32\rlai.dll
c:\windows\system32\rlls.dll
:Commands
[purity]
[emptytemp]
[start explorer]
[reboot]
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur "Exit" pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .
Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
2) Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
. sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
. enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
. Il va se mettre à jour une fois faite
. rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, cliques sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés)
. cliques sur Supprimer la sélection
. Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. redemarre le pc
. une fois redémarré double-cliques sur malwarebytes
. rends toi dans l'onglet rapport/log
. tu cliques dessus pour l'afficher une fois affiché
. tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
. tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
(J'en suis au scan de la partie 2) Sinon pour la partie 1 je crois avoir compris, tu veux que je poste ça ? :
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\windows\system32\nss128.dll not found.
File/Folder c:\windows\system32\nsx10c.dll not found.
File/Folder c:\windows\system32\spads.dll not found.
File/Folder c:\windows\system32\rlai.dll not found.
File/Folder c:\windows\system32\rlls.dll not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_215455
Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl moved successfully.
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\windows\system32\nss128.dll not found.
File/Folder c:\windows\system32\nsx10c.dll not found.
File/Folder c:\windows\system32\spads.dll not found.
File/Folder c:\windows\system32\rlai.dll not found.
File/Folder c:\windows\system32\rlls.dll not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_215455
Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl moved successfully.
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 22:27
13 mars 2009 à 22:27
C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log est le chemin pour retrouver le rapport de otmoveit tu vas dans ton disque dur système qui est généralement C et tu cherches le dossier otmoveit que tu ouvres , et puis le dossier MovedFiles dans celui-ci tu dois avoir un document format texte "blocs notes" les xxxxxx_xxxxxxxxxx normalement correspondent à la date et heure de la création du rapport
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 22:32
13 mars 2009 à 22:32
ok , je vois qu tu as trouvé le rapport donc ne tient pas compte de mon dernier message fais malwarebytes, car la je comprend pas le résultat
cela veut dire qu'il n'a rien trouver si malwarebytes ne les trouve pas ou si il ne les vire pa non plus on refera otmoveit mais en mode sans echec
File/Folder c:\windows\system32\nss128.dll not found. File/Folder c:\windows\system32\nsx10c.dll not found. File/Folder c:\windows\system32\spads.dll not found. File/Folder c:\windows\system32\rlai.dll not found. File/Folder c:\windows\system32\rlls.dll not found.
cela veut dire qu'il n'a rien trouver si malwarebytes ne les trouve pas ou si il ne les vire pa non plus on refera otmoveit mais en mode sans echec
Ok ba malwarebytes est en cours, j'en suis à 42300 éléments examinés, ce qui fait 25 minutes, et j'ai pour l'instant 20 éléments infectés.
=(
=(
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 22:38
13 mars 2009 à 22:38
ok sois patient car cela peut prendre près de 2h mais surtout tu clique bien sur supprimer la sélection une fois l'examen terminé et poste le rapport si je te répond pas tout de suite c'est que je serais parti dormir et je regarderais demain
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 22:45
13 mars 2009 à 22:45
on va attendre de voir ce que malwarebytes va nous avoir trouver et supprimé et on avisera les outils à télécharger en proportion
J'ai oublié de préciser qqch qui est peut-être important : j'ai lancé deux fois OTMoveIt3.
Le rapport que j'ai posté vient du deuxième scan car j'ai eu un problème de lag de l'ordinateur avec le premier scan et j'ai donc recommencé une deuxième fois (les deux scans ont été réalisés en entier).
Peut-être que ça n'a aucune importance mais je tiens juste à le préciser.
Le rapport que j'ai posté vient du deuxième scan car j'ai eu un problème de lag de l'ordinateur avec le premier scan et j'ai donc recommencé une deuxième fois (les deux scans ont été réalisés en entier).
Peut-être que ça n'a aucune importance mais je tiens juste à le préciser.
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
13 mars 2009 à 23:13
13 mars 2009 à 23:13
ok la je comprends mieux pourquoi il n'a rien trouvé tu n'as pas le rapport du premier par hazard
Bon voila ça devrait être le premier:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
c:\windows\system32\nss128.dll unregistered successfully.
c:\windows\system32\nss128.dll moved successfully.
c:\windows\system32\nsx10C.dll unregistered successfully.
c:\windows\system32\nsx10C.dll moved successfully.
File/Folder c:\windows\system32\spads.dll not found.
DllUnregisterServer procedure not found in c:\windows\system32\rlai.dll
c:\windows\system32\rlai.dll NOT unregistered.
c:\windows\system32\rlai.dll moved successfully.
File/Folder c:\windows\system32\rlls.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\etilqs_2Id8nnINiLGPQ4ryeYF8 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF147B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7AFC.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7B07.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\01889805d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\1A38215Ed01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\264BB7B7d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\2A229243d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\44CB876Cd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\5C48EFCEd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8845E8EBd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8EFCD9B7d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\9455C282d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BA0F876Dd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BCCCC87Bd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\C0CD8E4Cd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CC76BFA2d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CD01889Bd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\D5FB611Dd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_214422
Files moved on Reboot...
C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe moved successfully.
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\etilqs_2Id8nnINiLGPQ4ryeYF8 not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF147B.tmp not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7AFC.tmp not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7B07.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\01889805d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\1A38215Ed01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\264BB7B7d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\2A229243d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\44CB876Cd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\5C48EFCEd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8845E8EBd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8EFCD9B7d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\9455C282d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BA0F876Dd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BCCCC87Bd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\C0CD8E4Cd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CC76BFA2d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CD01889Bd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\D5FB611Dd01 not found!
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be moved on reboot.
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
c:\windows\system32\nss128.dll unregistered successfully.
c:\windows\system32\nss128.dll moved successfully.
c:\windows\system32\nsx10C.dll unregistered successfully.
c:\windows\system32\nsx10C.dll moved successfully.
File/Folder c:\windows\system32\spads.dll not found.
DllUnregisterServer procedure not found in c:\windows\system32\rlai.dll
c:\windows\system32\rlai.dll NOT unregistered.
c:\windows\system32\rlai.dll moved successfully.
File/Folder c:\windows\system32\rlls.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\etilqs_2Id8nnINiLGPQ4ryeYF8 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF147B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7AFC.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7B07.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\01889805d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\1A38215Ed01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\264BB7B7d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\2A229243d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\44CB876Cd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\5C48EFCEd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8845E8EBd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8EFCD9B7d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\9455C282d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BA0F876Dd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BCCCC87Bd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\C0CD8E4Cd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CC76BFA2d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CD01889Bd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\D5FB611Dd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_214422
Files moved on Reboot...
C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe moved successfully.
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\etilqs_2Id8nnINiLGPQ4ryeYF8 not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF147B.tmp not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7AFC.tmp not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7B07.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\01889805d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\1A38215Ed01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\264BB7B7d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\2A229243d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\44CB876Cd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\5C48EFCEd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8845E8EBd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8EFCD9B7d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\9455C282d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BA0F876Dd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BCCCC87Bd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\C0CD8E4Cd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CC76BFA2d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CD01889Bd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\D5FB611Dd01 not found!
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be moved on reboot.
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
14 mars 2009 à 00:48
14 mars 2009 à 00:48
ok merci c'est bien le premier , je vais dormir je regarderais malwarebytes demain @+
Rebonjour jacques !!
Je me suis couché aussi je ne savais pas combien de temps ça allait prendre...
Le scan s'est terminé au bout de 2h45 et voici ce que ça donne:
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1845
Windows 5.1.2600 Service Pack 2
14/03/2009 07:14:13
mbam-log-2009-03-14 (07-14-13).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 215775
Temps écoulé: 2 hour(s), 44 minute(s), 9 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 21
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 5
Fichier(s) infecté(s): 40
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\rotator.gizmo3 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rotator.gizmo3.1 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{733716e1-76d2-4003-ac39-845281c0ef85} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178f3fb-2560-458f-bdee-631e2fe0dfe4} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2cbd1bb3-9ac7-4d7f-9023-8a3e8dfb841a} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\messengerskinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\superiorads (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\AdvRemoteDbg (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MessengerSkinner (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcads (Adware.Dcads) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spa_start (Adware.BHO) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\download (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jules\Application Data\MessengerSkinner\Userdata\defaultPack.cab (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\WINDOWS\WinLockDll.dll (Malware.Tool) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\silc_dll.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\WhoisCL.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03132009_214422\windows\system32\rlai.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\MessengerSkinner.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\download\defaultPack.cab (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\appconfig.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btn.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnBnr.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnIn.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnInNormal.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnInOver.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormal.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormal.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormalBnr.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormalBnr.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOver.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOver.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOverBnr.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOverBnr.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Grégoire\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\model.dat (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\LDPackage.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\rlph.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\uid.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcydarcdh_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcydarcdh_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
Je me suis couché aussi je ne savais pas combien de temps ça allait prendre...
Le scan s'est terminé au bout de 2h45 et voici ce que ça donne:
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1845
Windows 5.1.2600 Service Pack 2
14/03/2009 07:14:13
mbam-log-2009-03-14 (07-14-13).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 215775
Temps écoulé: 2 hour(s), 44 minute(s), 9 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 21
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 5
Fichier(s) infecté(s): 40
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\rotator.gizmo3 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rotator.gizmo3.1 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{733716e1-76d2-4003-ac39-845281c0ef85} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178f3fb-2560-458f-bdee-631e2fe0dfe4} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2cbd1bb3-9ac7-4d7f-9023-8a3e8dfb841a} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\messengerskinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\superiorads (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\AdvRemoteDbg (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MessengerSkinner (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcads (Adware.Dcads) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spa_start (Adware.BHO) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\download (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jules\Application Data\MessengerSkinner\Userdata\defaultPack.cab (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\WINDOWS\WinLockDll.dll (Malware.Tool) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\silc_dll.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\WhoisCL.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03132009_214422\windows\system32\rlai.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\MessengerSkinner.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\download\defaultPack.cab (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\appconfig.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btn.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnBnr.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnIn.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnInNormal.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnInOver.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormal.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormal.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormalBnr.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormalBnr.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOver.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOver.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOverBnr.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOverBnr.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Grégoire\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\model.dat (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\LDPackage.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\rlph.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\uid.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcydarcdh_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcydarcdh_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
14 mars 2009 à 17:53
14 mars 2009 à 17:53
bonjour, il a bien bossé , tu ouvres malwarebytes tu vides la quarantaine, ne retélécharge pas MessengerSkinner c'est une grosse merde .
tu vas passer AD-Remover et poster le rapport, Merci
Télécharge AD-Remover de C_XX sur ton Bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
Ferme toutes les applications en cours, y compris ton navigateur *.
Désactive ton antivirus.
Double-clique sur AD-R.exe et installe-le dans le répertoire par défaut. ( C:\Program files )
Double clique sur l'icône Ad-remover
https://i75.servimg.com/u/f75/11/05/93/83/ad-r10.jpg
Au menu principal choisis l'option A
Poste le rapport qui apparait à la fin du scan.
Il est sauvegardé ici : C:\Ad-report(date).log
* Process.exe, un composant de l'outil, est détecté par certains antivirus, (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
C'est pourquoi il faut désactiver provisoirement ton antivirus.
tu vas passer AD-Remover et poster le rapport, Merci
Télécharge AD-Remover de C_XX sur ton Bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
Ferme toutes les applications en cours, y compris ton navigateur *.
Désactive ton antivirus.
Double-clique sur AD-R.exe et installe-le dans le répertoire par défaut. ( C:\Program files )
Double clique sur l'icône Ad-remover
https://i75.servimg.com/u/f75/11/05/93/83/ad-r10.jpg
Au menu principal choisis l'option A
Poste le rapport qui apparait à la fin du scan.
Il est sauvegardé ici : C:\Ad-report(date).log
* Process.exe, un composant de l'outil, est détecté par certains antivirus, (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
C'est pourquoi il faut désactiver provisoirement ton antivirus.
Bon j'ai suivi ce que tu as dis et voici le rapport:
------- LOGFILE OF AD-REMOVER 1.1.1.7 | ONLY XP/VISTA -------
Updated by C_XX on 11/03/2009 at 11:30
Start at: 18:10:07, Sam 14/03/2009 | Boot mode: Normal Boot
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
Computer Name: MINILOUP
Current User: Fabienne - Administrator
Drive(s):
- C:\ (File System: NTFS)
- E:\ (File System: CDFS)
- F:\ (File System: FAT32)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 50
+-----------------| Boonty/Boonty Games Elements Found:
Service: Boonty Games
.
HKCU\Software\Boonty
HKLM\Software\Boonty
HKLM\System\ControlSet001\Services\Boonty Games
HKLM\System\CurrentControlSet\Services\Boonty Games
HKLM\System\ControlSet003\Services\Boonty Games
.
C:\Program Files\Boonty
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY
+-----------------| Eorezo Elements Found:
.
+-----------------| Infected Poker Softwares Elements Found:
.
------- LOGFILE OF AD-REMOVER 1.1.1.7 | ONLY XP/VISTA -------
Updated by C_XX on 11/03/2009 at 11:30
Start at: 18:10:07, Sam 14/03/2009 | Boot mode: Normal Boot
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
Computer Name: MINILOUP
Current User: Fabienne - Administrator
Drive(s):
- C:\ (File System: NTFS)
- E:\ (File System: CDFS)
- F:\ (File System: FAT32)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 50
+-----------------| Boonty/Boonty Games Elements Found:
Service: Boonty Games
.
HKCU\Software\Boonty
HKLM\Software\Boonty
HKLM\System\ControlSet001\Services\Boonty Games
HKLM\System\CurrentControlSet\Services\Boonty Games
HKLM\System\ControlSet003\Services\Boonty Games
.
C:\Program Files\Boonty
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY
+-----------------| Eorezo Elements Found:
.
+-----------------| Infected Poker Softwares Elements Found:
.
Je ne suis pas sur d'avoir bien réussi à arrêter l'antivirus, (c'est une version gratuite d'avg) mais je pense l'avoir fait vu que j'ai réussi à obtenir le scan.
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
14 mars 2009 à 18:34
14 mars 2009 à 18:34
bon tu vas relancer ad-remover pour faire la suppression tu postes le rapport suivi d'un nouveau hijackthis pour contrôler et finir le nettoyage , tu pourras en attendant la lecture de ton hijackthis faire la désinstallation de ad-remover
Fermes toutes les applications en cours, y compris ton navigateur
.
Relances "Ad-remover". tu choisis l'option B
et tu coches tout et tu le lances laisses le travailler en appuyant sur S
et postes le rapport générer
Il est sauvegardé ici : C:\Ad-report(date).log
désinstallation de ad-renover:
Via l'Explorateur Windows, ouvre le répertoire C:\Program Files\Ad-remover.
Double-clique sur le fichier Uninstal.exe.
Supprime les fichiers : C:\Ad-report(date).log
Supprime ensuite le répertoire C:\Program Files\AD-Remover qui sera vide.
Fermes toutes les applications en cours, y compris ton navigateur
.
Relances "Ad-remover". tu choisis l'option B
et tu coches tout et tu le lances laisses le travailler en appuyant sur S
et postes le rapport générer
Il est sauvegardé ici : C:\Ad-report(date).log
désinstallation de ad-renover:
Via l'Explorateur Windows, ouvre le répertoire C:\Program Files\Ad-remover.
Double-clique sur le fichier Uninstal.exe.
Supprime les fichiers : C:\Ad-report(date).log
Supprime ensuite le répertoire C:\Program Files\AD-Remover qui sera vide.
Ok, tout est supprimé et voici le rapport: (je dois partir un moment et je reviendrai peut-être dans deux heures ou alors demain matin, encore merci de ton aide! )
------- LOGFILE OF AD-REMOVER 1.1.1.7 | ONLY XP/VISTA -------
Updated by C_XX on 11/03/2009 at 11:30
**** LIMITED TO ****
Boonty/BoontyGames
Eorezo
Infected Poker Softwares
FunWebProduct/MyWay/MyWebSearch
It's TV
Sweetim
Other Adwares
********************
Start at: 18:37:45, Sam 14/03/2009 | Boot mode: Normal Boot
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
Computer Name: MINILOUP
Current User: Fabienne - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 49
(!) ---- IE start pages/Tabs reset
+-----------------| Boonty/Boonty Games Elements Deleted :
Service: "Boonty Games"
.
HKCU\Software\Boonty
HKLM\Software\Boonty
HKLM\System\ControlSet003\Services\Boonty Games
.
C:\Program Files\Boonty
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY
+-----------------| Eorezo Elements Deleted :
.
------- LOGFILE OF AD-REMOVER 1.1.1.7 | ONLY XP/VISTA -------
Updated by C_XX on 11/03/2009 at 11:30
**** LIMITED TO ****
Boonty/BoontyGames
Eorezo
Infected Poker Softwares
FunWebProduct/MyWay/MyWebSearch
It's TV
Sweetim
Other Adwares
********************
Start at: 18:37:45, Sam 14/03/2009 | Boot mode: Normal Boot
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
Computer Name: MINILOUP
Current User: Fabienne - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 49
(!) ---- IE start pages/Tabs reset
+-----------------| Boonty/Boonty Games Elements Deleted :
Service: "Boonty Games"
.
HKCU\Software\Boonty
HKLM\Software\Boonty
HKLM\System\ControlSet003\Services\Boonty Games
.
C:\Program Files\Boonty
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY
+-----------------| Eorezo Elements Deleted :
.
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
14 mars 2009 à 19:17
14 mars 2009 à 19:17
ok je suis ce soir sur le pc jusqua minuit environ sinon demain je ne serais pas sur le pc donc si on fini pas ce soir cela sera pour lundi