Virus TR/Dropper.gen

Résolu/Fermé
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009 - 12 mai 2009 à 18:50
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 - 15 mai 2009 à 21:26
bonjour,
voila je suis infecté par ce virus, il se met dans mon repertoire system32/drivers et empèche mes ports usb et carte memoire de marcher
chaque fois que je le supprime il revient et ca ne marche toujours pas

si quelqu'un pourrait m'aider
merci d'avance

59 réponses

sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
13 mai 2009 à 09:02
Salut,


dans l'ordre :


1- Nettoyage AD-Remover :

! Déconnecte toi et ferme toutes application en cours ( navigarteur compris ) !

* Relance "Ad-remover" : au menu principal choisis l'option "B" .

* A l'écran de sélection :

> choisis le(s) chiffre(s) suivant pour nettoyer les traces de :


1 - "Adwares connus" puis [entrée]


Une fois la sélection faite, tape S puis [entrée] pour lancer la suppression .

--> le programme va travailler , ne touche à rien ...


* Poste le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...

( le rapport est sauvegardé aussi sous C:\Ad-report.log )

/!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide ) /!\


===========================

2- Télécharge GenProc (de Jean-Chretien1 et Narco4) sur ton bureau (et pas ailleur !) :
http://www.genproc.com/GenProc.exe

!!Déconnecte toi et ferme tes applications en cours !!


* double-clique sur GenProc.exe pour lancer le scan et laisse faire ...

* A la question "faites vous aidez sur un forum..." > clique sur " oui " .

-> poste le contenu du rapport qui s'ouvre ...


Aide en images ici : http://www.alt-shift-return.org/Info/GenProc-HowTo.html

IMPORTANT : poste le rapport et ne fais rien d'autre pour l'instant ( souvant il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement ) .


0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:35
salut
le rapport AD-remover


------- LOGFILE OF AD-REMOVER 1.1.3.7 | ONLY XP/VISTA -------

Updated by C_XX on 11/05/2009 at 16:00
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

**** LIMITED TO ****

Known Adwares

********************

Start at: 10:58:45, 13/05/2009 | Boot mode: Normal Boot
Option: Clean | Executed from: C:\Program Files\Ad-remover\
Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
Computer Name: PIERRE
Current User: Pierrot - Administrator
Drive(s):
- C:\ (File System: FAT32)
- D:\ (File System: NTFS)
- E:\ (File System: CDFS)

(!) ---- C:\Documents and Settings\Administrateur\Ntuser.dat Loaded as: 'HKU\Administrateur'
(!) ---- C:\Documents and Settings\autre\Ntuser.dat Loaded as: 'HKU\autre'

(!) ---- IE start pages/Tabs reset

============ Known Adwares Deleted ============

.
HKLM\Software\Trymedia Systems
.

(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.



+-----------------| Added Scan:

---- Mozilla FireFox Version [Unable to get version] ----

ProfilePath: bbrhzjaq.default (Pierrot)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.netvibes.com/");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.6");
.

---- Internet Explorer Version 7.0.5730.11 ----

[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.google.com
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

[HKEY_USERS\S-1-5-21-86003536-2852020299-55118337-1005\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.google.com
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

=========== Suspicious ==========


+---------------------------------------------------------------------------+

2733 Byte(s) - C:\Ad-Report-Scan-13.05.2009.log
3067 Byte(s) - C:\Ad-Report-Clean-13.05.2009.log

19 File(s) - C:\Program Files\Ad-remover\BACKUP
0 File(s) - C:\Program Files\Ad-remover\QUARANTINE

End at: 11:33:38 | 13/05/2009
.
+-----------------| E.O.F
.
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
13 mai 2009 à 11:42
bien ....

genproc maintenant ...

0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:44
le hijack :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:35, on 13/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\WINDOWS\System32\alg.exe
C:\DOCUME~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\Pierrot\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:46
la suite du HiJAck


Management.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IDMan] d:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Télécharger avec IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:48
la modération est trop sensible ou quoi ?

suite du HiJack

\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.n9ws.com/webscanner/kavwebscan_unicode.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:50
en core le HiJack

O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/...
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c98718c422d7a5) (gupdate1c98718c422d7a5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:52
elle deconne la moderation !

encore le Hijack

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:53
la suite

Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:57
Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 11:59
le genproc

Rapport GenProc 2.560 [2]
@ 13/05/2009 à 11:59:02
@ Windows XP Service Pack 3

# Etape 1/ Télécharge :

- CCleaner https://www.ccleaner.com/ccleaner/download (FileHippo). Ce logiciel va permettre de supprimer tous les fichiers temporaires. Lance-le et clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. Ferme le programme.

- USBFix http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe (Chiquitine29) sur le Bureau, et procède simplement à son installation.


Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** Pierrot *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[2]" sur ton bureau).


# Etape 2/

Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir, puis double-clique sur le raccourci UsbFix présent sur ton Bureau : choisis l' option 2 (Suppression), ton bureau disparaitra et le pc redémarrera. Au redémarrage, UsbFix scannera ton pc, laisse travailler l'outil.

# Etape 3/

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

# Etape 4/

Redémarre normalement et poste, dans la même réponse :

- Le contenu du rapport UsbFix.txt situé dans C:\ ;
- Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;
- Un nouveau rapport GenProc ;

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------

~~ Arguments de la procédure ~~


# Détections [1] GenProc 2.560 13/05/2009 à 11:38:18
USBFix:le 13/05/2009 à 11:38:40 "C:\WINDOWS\System32\tmp.reg"

# Détections [2] GenProc 2.560 13/05/2009 à 11:58:15
USBFix:le 13/05/2009 à 11:58:46 "C:\WINDOWS\System32\tmp.reg"
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
13 mai 2009 à 12:14
bien ...

pas mal de bug sur le site en se moment


On va réutiliser OTMoveIT :


1- ! Déconnecte toi et ferme toutes tes applications en cours !

Double clique sur "OTMoveIt3.exe" pour ouvrir le prg .
Puis copie ce qui se trouve en citation ci-dessous,


:processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\System32\tmp.reg

:Commands
[purity]
[emptytemp]
[Reboot]



et colle le dans le cadre de gauche de OTMoveIt3 :
Paste Instructions for items to be moved.
(ne touche à rien d'autre !)

-> clique sur MoveIt! pour lancer la suppression.
-> laisse travailler l'outil ...

-> une fois finis , un petite fenêtre s'ouvre : clique sur " Yes " .

Ton PC va redémarrer de lui même pour finir la suppression ...

Lors du redémarrage , si on te demande d'autoriser l'exécution d' OTMoveIt , accepte ( pour que l'outil finisse son boulot ... ).

-->Poste le contenu du rapport qui se trouve dans le dossier "C:\_OTMoveIt\MovedFiles"
( " xxxx2008_xxxxxx.log " où les "x" correspondent au jour et à l'heure de l'utilisation ).



2- refais un scan RSIT , poste le nouveau rapport Log.txt obtenu et attends la suite ...

0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 12:23
le OT moveIT

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\System32\tmp.reg moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\#)#R !R".c scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âäŧéâçå.╝┐å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cddm▒Â.¥│▒ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\36C43ECF.9BB scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\?EA33210.e33 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Åëêìê g.a scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ôö¿¼s scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ϻСнõÒ.µµô scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢╝╩¥╗▒ý¯.ÈËý scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ËóÐánj.j& scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Çå(*-\(,.+/_ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ýøÙÚÿ£uu.syy scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ྩ┐­â¶ü.æþÓ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ ä■¸╩═░╝.┴ã░ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À┴┬Áb[\.`g scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢└╝╔┴╝╦╚.#$[ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\9cr !"#.v p scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\xGB4@CD.fd2 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æÉ»¿öÕôò.ùÒÒ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âàǶéïèé.±¾z scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¯Ö
vw.vwq scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\lmna{. y
scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µþËÈÝþ¯Þ.Úþ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\iif\[c.õµÓ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\KML6KIò£.õµù scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\å븶┐│ãÀ.┐▒┬ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\â¸é‗ØÜıË.óºñ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÞÙÔÞ݃ØÔ.ÍÐd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ihl%(.&v' scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\à¾‗¶§Å‗­.åÅg scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÍÍÎí᪺¦.¹¨Å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\trs tv scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\}
{zF2.D6D scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ecfe÷³.±³¶ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\║¢‗¶àÇââ.‗§w scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\£×p w#v&.oh' scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ççå­±¸÷î.±¾
scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æûæþss.r scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\÷±┬╚║┐─Â.├╠À scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\5<tu}wt.}wr scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¹¹·îìï?e.8:l scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îè¹■`g.`c scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ebe`cc. scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\üüj`.i scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\onno.¨ ■ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¶¶àéefd. scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\'!á┌ºÑË┌.óáÐ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\klíÎóáÍÍ.Îíá scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┐¢╠╝╦┐÷å.¤╚ç scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!U !\$]T.\p┼ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ï¨ÞõÓÚÆß.ÓÞÔ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ssLKåDZ¶.¸¸å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\tªÊ.ºª█ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!.PS."W&.:4g scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À░±åâüç­.¶¶å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³Å░Àë■¹¨. êâ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\chWP.åâÇ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³ëáÎáðÿƒ.ΡΠscheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Äë³·ïëëî.Á▓º scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µÉæùûýæô.Õýñ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦¦▄¬½¡¼Í.ÿÜý scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ƵÁÀ┼└┼├.À┼┤ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cdW_+X│▒.ÀÃÁ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\3B4EADC3.¢║à scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÓÆö´ÒÉù´.¯þß scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\▒┬│▒ã┤y.}z scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\t`.e scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îŨ°éÅÄ■.¨ëÙ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┬┼è¨Ä¹è³.å⸠scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ð┘õÒ▄ð╗╝.╩¢¢ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bognbfo.د´ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ â‗§üàç.åàà scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\´ø£þ£µÊı.c0g scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\°ëÅì‗³■².e scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\febj.ce2 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ohk88kj>.dg scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\,U!,R!&R."%T scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\_xeeke.k6 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\c20e9cba.
7 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦┌Õßûô-$.,Q% scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\2D
Ðıóº.¦È▄ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf_X.d`6 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\&%,&#QS,._xg scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kDF09AC.2b5 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kbk.2 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\a``.aD scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\åâÇDZ÷P&.SQ' scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\f_Xadab.kb3 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ $P-PV.`ef scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\6F1E0@.SU$ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bk`.g4 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\``a.kd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`eff.af scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\SU$!"". scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf._xe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Pierrot\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2d8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05132009_121758

Files moved on Reboot...
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\#)#R !R".c not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âäŧéâçå.╝┐å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cddm▒Â.¥│▒ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\36C43ECF.9BB not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\?EA33210.e33 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Åëêìê g.a not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ôö¿¼s not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ϻСнõÒ.µµô not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢╝╩¥╗▒ý¯.ÈËý not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ËóÐánj.j& not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Çå(*-\(,.+/_ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ýøÙÚÿ£uu.syy not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ྩ┐­â¶ü.æþÓ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ ä■¸╩═░╝.┴ã░ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À┴┬Áb[\.`g not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢└╝╔┴╝╦╚.#$[ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\9cr !"#.v p not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\xGB4@CD.fd2 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æÉ»¿öÕôò.ùÒÒ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âàǶéïèé.±¾z not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¯Ö
vw.vwq not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\lmna{. y
not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µþËÈÝþ¯Þ.Úþ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\iif\[c.õµÓ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\KML6KIò£.õµù not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\å븶┐│ãÀ.┐▒┬ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\â¸é‗ØÜıË.óºñ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÞÙÔÞ݃ØÔ.ÍÐd not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ihl%(.&v' not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\à¾‗¶§Å‗­.åÅg not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÍÍÎí᪺¦.¹¨Å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\trs tv not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\}
{zF2.D6D not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ecfe÷³.±³¶ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\║¢‗¶àÇââ.‗§w not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\£×p w#v&.oh' not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ççå­±¸÷î.±¾
not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æûæþss.r not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\÷±┬╚║┐─Â.├╠À not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\5<tu}wt.}wr not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¹¹·îìï?e.8:l not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îè¹■`g.`c not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ebe`cc. not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\üüj`.i not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\onno.¨ ■ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¶¶àéefd. not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\'!á┌ºÑË┌.óáÐ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\klíÎóáÍÍ.Îíá not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┐¢╠╝╦┐÷å.¤╚ç not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!U !\$]T.\p┼ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ï¨ÞõÓÚÆß.ÓÞÔ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ssLKåDZ¶.¸¸å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\tªÊ.ºª█ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!.PS."W&.:4g not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À░±åâüç­.¶¶å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³Å░Àë■¹¨. êâ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\chWP.åâÇ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³ëáÎáðÿƒ.ΡΠnot found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Äë³·ïëëî.Á▓º not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µÉæùûýæô.Õýñ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦¦▄¬½¡¼Í.ÿÜý not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ƵÁÀ┼└┼├.À┼┤ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cdW_+X│▒.ÀÃÁ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\3B4EADC3.¢║à not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÓÆö´ÒÉù´.¯þß not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\▒┬│▒ã┤y.}z not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\t`.e not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îŨ°éÅÄ■.¨ëÙ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┬┼è¨Ä¹è³.å⸠not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ð┘õÒ▄ð╗╝.╩¢¢ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bognbfo.د´ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ â‗§üàç.åàà not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\´ø£þ£µÊı.c0g not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\°ëÅì‗³■².e not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\febj.ce2 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ohk88kj>.dg not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\,U!,R!&R."%T not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\_xeeke.k6 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\c20e9cba.
7 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦┌Õßûô-$.,Q% not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\2D
Ðıóº.¦È▄ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf_X.d`6 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\&%,&#QS,._xg not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kDF09AC.2b5 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kbk.2 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\a``.aD not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\åâÇDZ÷P&.SQ' not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\f_Xadab.kb3 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ $P-PV.`ef not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\6F1E0@.SU$ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bk`.g4 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\``a.kd not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`eff.af not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\SU$!"". not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf._xe not found!
C:\DOCUME~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_2d8.dat moved successfully.
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 12:24
le OT moveIT

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\System32\tmp.reg moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\#)#R !R".c scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âäŧéâçå.╝┐å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cddm▒Â.¥│▒ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\36C43ECF.9BB scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\?EA33210.e33 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Åëêìê g.a scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ôö¿¼s scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ϻСнõÒ.µµô scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢╝╩¥╗▒ý¯.ÈËý scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ËóÐánj.j& scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Çå(*-\(,.+/_ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ýøÙÚÿ£uu.syy scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ྩ┐­â¶ü.æþÓ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ ä■¸╩═░╝.┴ã░ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À┴┬Áb[\.`g scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢└╝╔┴╝╦╚.#$[ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\9cr !"#.v p scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\xGB4@CD.fd2 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æÉ»¿öÕôò.ùÒÒ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âàǶéïèé.±¾z scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¯Ö
vw.vwq scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\lmna{. y
scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µþËÈÝþ¯Þ.Úþ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\iif\[c.õµÓ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\KML6KIò£.õµù scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\å븶┐│ãÀ.┐▒┬ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\â¸é‗ØÜıË.óºñ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÞÙÔÞ݃ØÔ.ÍÐd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ihl%(.&v' scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\à¾‗¶§Å‗­.åÅg scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÍÍÎí᪺¦.¹¨Å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\trs tv scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\}
{zF2.D6D scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ecfe÷³.±³¶ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\║¢‗¶àÇââ.‗§w scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\£×p w#v&.oh' scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ççå­±¸÷î.±¾
scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æûæþss.r scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\÷±┬╚║┐─Â.├╠À scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\5<tu}wt.}wr scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¹¹·îìï?e.8:l scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îè¹■`g.`c scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ebe`cc. scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\üüj`.i scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\onno.¨ ■ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¶¶àéefd. scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\'!á┌ºÑË┌.óáÐ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\klíÎóáÍÍ.Îíá scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┐¢╠╝╦┐÷å.¤╚ç scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!U !\$]T.\p┼ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ï¨ÞõÓÚÆß.ÓÞÔ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ssLKåDZ¶.¸¸å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\tªÊ.ºª█ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!.PS."W&.:4g scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À░±åâüç­.¶¶å scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³Å░Àë■¹¨. êâ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\chWP.åâÇ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³ëáÎáðÿƒ.ΡΠscheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Äë³·ïëëî.Á▓º scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µÉæùûýæô.Õýñ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦¦▄¬½¡¼Í.ÿÜý scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ƵÁÀ┼└┼├.À┼┤ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cdW_+X│▒.ÀÃÁ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\3B4EADC3.¢║à scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÓÆö´ÒÉù´.¯þß scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\▒┬│▒ã┤y.}z scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\t`.e scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îŨ°éÅÄ■.¨ëÙ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┬┼è¨Ä¹è³.å⸠scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ð┘õÒ▄ð╗╝.╩¢¢ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bognbfo.د´ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ â‗§üàç.åàà scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\´ø£þ£µÊı.c0g scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\°ëÅì‗³■².e scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\febj.ce2 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ohk88kj>.dg scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\,U!,R!&R."%T scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\_xeeke.k6 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\c20e9cba.
7 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦┌Õßûô-$.,Q% scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\2D
Ðıóº.¦È▄ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf_X.d`6 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\&%,&#QS,._xg scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kDF09AC.2b5 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kbk.2 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\a``.aD scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\åâÇDZ÷P&.SQ' scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\f_Xadab.kb3 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ $P-PV.`ef scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\6F1E0@.SU$ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bk`.g4 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\``a.kd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`eff.af scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\SU$!"". scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf._xe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Pierrot\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2d8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05132009_121758

Files moved on Reboot...
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\#)#R !R".c not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âäŧéâçå.╝┐å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cddm▒Â.¥│▒ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\36C43ECF.9BB not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\?EA33210.e33 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Åëêìê g.a not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ôö¿¼s not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ϻСнõÒ.µµô not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢╝╩¥╗▒ý¯.ÈËý not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ËóÐánj.j& not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Çå(*-\(,.+/_ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ýøÙÚÿ£uu.syy not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ྩ┐­â¶ü.æþÓ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ ä■¸╩═░╝.┴ã░ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À┴┬Áb[\.`g not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¢└╝╔┴╝╦╚.#$[ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\9cr !"#.v p not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\xGB4@CD.fd2 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æÉ»¿öÕôò.ùÒÒ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\âàǶéïèé.±¾z not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¯Ö
vw.vwq not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\lmna{. y
not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µþËÈÝþ¯Þ.Úþ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\iif\[c.õµÓ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\KML6KIò£.õµù not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\å븶┐│ãÀ.┐▒┬ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\â¸é‗ØÜıË.óºñ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÞÙÔÞ݃ØÔ.ÍÐd not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ihl%(.&v' not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\à¾‗¶§Å‗­.åÅg not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÍÍÎí᪺¦.¹¨Å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\trs tv not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\}
{zF2.D6D not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ecfe÷³.±³¶ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\║¢‗¶àÇââ.‗§w not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\£×p w#v&.oh' not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ççå­±¸÷î.±¾
not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\æûæþss.r not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\÷±┬╚║┐─Â.├╠À not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\5<tu}wt.}wr not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¹¹·îìï?e.8:l not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îè¹■`g.`c not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ebe`cc. not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\üüj`.i not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\onno.¨ ■ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¶¶àéefd. not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\'!á┌ºÑË┌.óáÐ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\klíÎóáÍÍ.Îíá not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┐¢╠╝╦┐÷å.¤╚ç not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!U !\$]T.\p┼ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ï¨ÞõÓÚÆß.ÓÞÔ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ssLKåDZ¶.¸¸å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\tªÊ.ºª█ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\!.PS."W&.:4g not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\À░±åâüç­.¶¶å not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³Å░Àë■¹¨. êâ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\chWP.åâÇ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\³ëáÎáðÿƒ.ΡΠnot found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\Äë³·ïëëî.Á▓º not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\µÉæùûýæô.Õýñ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦¦▄¬½¡¼Í.ÿÜý not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ƵÁÀ┼└┼├.À┼┤ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\cdW_+X│▒.ÀÃÁ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\3B4EADC3.¢║à not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ÓÆö´ÒÉù´.¯þß not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\▒┬│▒ã┤y.}z not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\t`.e not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\îŨ°éÅÄ■.¨ëÙ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\┬┼è¨Ä¹è³.å⸠not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ð┘õÒ▄ð╗╝.╩¢¢ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bognbfo.د´ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ â‗§üàç.åàà not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\´ø£þ£µÊı.c0g not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\°ëÅì‗³■².e not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\febj.ce2 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ohk88kj>.dg not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\,U!,R!&R."%T not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\_xeeke.k6 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\c20e9cba.
7 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\¦┌Õßûô-$.,Q% not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\2D
Ðıóº.¦È▄ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf_X.d`6 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\&%,&#QS,._xg not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kDF09AC.2b5 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\kbk.2 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\a``.aD not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\åâÇDZ÷P&.SQ' not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\f_Xadab.kb3 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\ $P-PV.`ef not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\6F1E0@.SU$ not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\bk`.g4 not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\``a.kd not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`eff.af not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\SU$!"". not found!
File C:\DOCUME~1\Pierrot\LOCALS~1\Temp\Rar$DR01.719\`gf._xe not found!
C:\DOCUME~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_2d8.dat moved successfully.
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 12:28
le RSIT

Logfile of random's system information tool 1.06 (written by random/random)
Run by Pierrot at 2009-05-13 12:27:13
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 10 GB (23%) free of 45 GB
Total RAM: 1022 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:33, on 13/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\rundll32.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\WINDOWS\System32\alg.exe
C:\DOCUME~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Pierrot\Bureau\RSIT.exe
C:\Documents and Settings\Pierrot\Bureau\Pierrot.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IDMan] d:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Télécharger avec IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.n9ws.com/webscanner/kavwebscan_unicode.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/...
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c98718c422d7a5) (gupdate1c98718c422d7a5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O24 - Desktop Component 0: (no name) - http://ic3.deviantart.com/fs12/i/2006/340/4/8/Sasuke_Naruto_by_Ruutus.jpg
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
13 mai 2009 à 12:35
re,


encore quelques chose de louche ... et des reste de Norton que l'on va nettoyer ...



1- Télécharge Norton removal tool sur ton bureau :
ftp://ftp.symantec.com/public/francais/removal_tools/Norton_Removal_Tool.exe

Déconnecte toi .
Ensuite désinstalle Norton avec "Norton removal tool": tu double-cliques dessus et tu te laisses guider ... il faut le désinstaller correctement ( fais la manipe 2 fois si possible ).



==================

2- Télécharge ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


--------------------------------- [ ! ATTENTION ! ] ------------------------------------------
!! Déconnecte toi,ferme tes applications en cours ( ainsi que ton navigateur ) et DESACTIVE TOUTES TES DEFENSES (anti-virus, guarde anti spy-ware, pare-feu) le temps de la manipe :
en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
--->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Note : pour XP, bien installer la Console de Récupération de Windows comme il est indiqué dans le tuto ci-dessus ...
--------------------------------------------------------------------------------------------


Ensuite :
double-clique sur l'icône "combofix.exe" pour lancer l'outil .

Appuie sur la touche Y (Yes) pour démarrer le scan .

Notes importantes :
-> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
-> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisse le faire .
-> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
-> si un message d'erreur windows apparait à un momment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

Le rapport sera crée ici : C:\Combofix.txt

Réactive bien tes défenses .


Poste le rapport Combofix pour analyse ...




0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 14:28
voila :

ComboFix 09-05-12.06 - Pierrot 13/05/2009 14:15.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.644 [GMT 2:00]
Lancé depuis: c:\documents and settings\Pierrot\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\ovfsthgtiqjyiiqootlyrnsiyyuochuhrhdyoh.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\ovfsthgotqtemxhwihyodoswwvbyvpqonatoym.dll
c:\windows\system32\ovfsthnpmbcoppyxpwsecvcaxsxtngdrievwks.dat
c:\windows\system32\ovfsthtqjjhtwmtjqsxdqhxdpnqsravncwuxcn.dat
c:\windows\system32\ovfsthxmkmrvpreycabjfultgaclkbikfaovbl.dll
c:\windows\system32\ovfsthxybwmvwpugrynurylnqssyunvutnmjck.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ovfsthlrpapkhlcskbebxmboeojkcjapfafogi
-------\Legacy_IPRIP
-------\Service_Iprip


((((((((((((((((((((((((((((( Fichiers créés du 2009-04-13 au 2009-05-13 ))))))))))))))))))))))))))))))))))))
.

2009-05-13 12:13 . 2009-05-13 12:13 -------- d-sh--w C:\FOUND.000
2009-05-13 11:22 . 2009-05-13 11:22 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-05-13 09:37 . 2009-05-13 09:37 -------- d-----w C:\GenProc
2009-05-12 22:44 . 2009-05-12 22:44 -------- d-----w c:\program files\Ad-remover
2009-05-12 22:20 . 2009-05-12 22:20 -------- d-----w C:\_OTMoveIt
2009-05-12 17:43 . 2009-05-12 17:43 -------- d-----w C:\UsbFix
2009-05-12 17:01 . 2009-05-12 17:01 -------- d-----w C:\rsit
2009-05-12 10:12 . 2009-05-12 10:12 -------- d-----w c:\documents and settings\Pierrot\Application Data\Malwarebytes
2009-05-12 10:12 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-12 10:12 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-12 10:12 . 2009-05-12 10:12 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-12 10:12 . 2009-05-12 10:12 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-11 21:51 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-11 21:51 . 2009-05-11 21:51 -------- d-----w c:\program files\Avira
2009-04-28 19:27 . 2009-04-28 19:27 -------- d-----w c:\documents and settings\Pierrot\Application Data\Mount&Blade
2009-04-27 13:21 . 2009-04-27 13:21 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-27 13:21 . 2009-04-27 13:21 -------- d-----w c:\program files\iTunes
2009-04-27 13:20 . 2009-04-27 13:20 -------- d-----w c:\program files\Bonjour
2009-04-25 15:05 . 2009-04-25 15:05 -------- d-----w c:\documents and settings\Pierrot\Application Data\IDM
2009-04-25 15:05 . 2009-04-25 15:05 -------- d-----w c:\documents and settings\Pierrot\Application Data\DMCache
2009-04-19 12:45 . 2009-04-19 12:45 -------- d-----w c:\documents and settings\Pierrot\Application Data\Paquet Builder
2009-04-19 12:31 . 2009-04-19 12:31 -------- d-----w c:\program files\7-Zip
2009-04-18 19:13 . 2009-04-18 19:13 -------- d-----w c:\program files\Sierra On-Line
2009-04-15 09:51 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
2009-04-15 09:51 . 2008-04-21 21:15 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 09:50 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 09:50 . 2009-03-06 14:20 286720 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-15 09:50 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-15 09:50 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 09:50 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 09:50 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 09:50 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 09:50 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 09:50 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 12:18 . 2006-08-19 04:41 12 ----a-w c:\windows\bthservsdp.dat
2009-05-13 10:22 . 2006-11-25 20:58 61696 ----a-w c:\documents and settings\Pierrot\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 22:14 . 2006-12-06 18:46 16296 ----a-w c:\documents and settings\Pierrot\Application Data\wklnhst.dat
2009-04-19 09:25 . 2006-08-19 04:21 78346 ----a-w c:\windows\system32\perfc00C.dat
2009-04-19 09:25 . 2006-08-19 04:21 476522 ----a-w c:\windows\system32\perfh00C.dat
2009-03-26 15:35 . 2009-04-02 11:18 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-19 14:32 . 2008-09-23 23:52 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-09 03:19 . 2009-01-05 09:38 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:20 . 2004-08-10 18:00 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:13 . 2006-01-09 18:02 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 17:10 . 2004-08-10 18:00 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-15 17:30 . 2009-02-15 17:30 53248 ----a-w c:\windows\ipuninst.exe
2007-09-04 19:01 . 2007-09-04 19:01 48 --sh--w c:\windows\S83A54D1A.tmp
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-22 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"SuperCopier2.exe"="d:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2009-04-02 2794928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 352256]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-22 3080704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 397312]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"ISUSPM Startup"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-01-01 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-12 7577600]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-12 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-06-28 16248320]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-06-12 1519616]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Pierrot\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Recherche acc‚l‚r‚e.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-12-17 111376]
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\System32\\dplaysvr.exe"=
"d:\\Program Files\\Microsoft Games\\Age of Empires II\\Age2_X1\\age2_x1.Exe"=
"d:\\Program Files\\Microsoft Games\\Freelancer\\EXE\\Freelancer.exe"=
"d:\\Program Files\\eMule\\emule.exe"=
"d:\\Program Files\\Azureus\\Azureus.exe"=
"d:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3587:TCP"= 3587:TCP:Groupement homologue Windows
"3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
"4662:TCP"= 4662:TCP:4662 TCP
"4672:UDP"= 4672:UDP:4672 UDP
"4711:TCP"= 4711:TCP:4711 TCP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [11/05/2009 23:51 108289]
S2 gupdate1c98718c422d7a5;Google Update Service (gupdate1c98718c422d7a5);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2009 23:34 133104]
S2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [24/07/2007 20:59 2560]
S3 asbp2poa;asbp2poa;\??\c:\docume~1\Pierrot\LOCALS~1\Temp\asbp2poa.sys --> c:\docume~1\Pierrot\LOCALS~1\Temp\asbp2poa.sys [?]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - INT15.SYS
*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contenu du dossier 'Tâches planifiées'

2009-05-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-02 21:14]

2009-05-13 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 21:34]

2009-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Télécharger avec IDM - d:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger le contenu de video FLV avec IDM - d:\program files\Internet Download Manager\IEGetVL.htm
IE: Télécharger tous les liens avec IDM - d:\program files\Internet Download Manager\IEGetAll.htm
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game03.zylom.com/activex/zylomgamesplayer.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-13 14:22
Windows 5.1.2600 Service Pack 3 FAT NTAPI

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\Pierrot\LOCALS~1\Temp\mc24.tmp"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):fc,2a,6e,1d,21,80,ad,85,57,cf,1d,68,74,b7,68,8c,82,5c,0e,11,3b,
31,ad,cc,20,cd,86,49,e5,db,b2,b0,76,2e,da,c4,c5,d2,39,44,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{af2ddcb7-a988-49a4-a645-ae9b1516069a}]
@Denied: (Full) (Everyone)
"Model"=dword:00000084
"Therad"=dword:00000013
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(3696)
d:\program files\SuperCopier2\SC2Hook.dll
c:\windows\system32\MSNChatHook.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\MSVCR71.dll
c:\program files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
c:\program files\Fichiers communs\Microsoft Shared\Encarta Search Bar\F\ESBRes.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\acer\Empowering Technology\admServ.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\docume~1\Pierrot\LOCALS~1\Temp\RtkBtMnt.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-05-13 14:25 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-05-13 12:25

Avant-CF: 5 404 983 296 octets libres
Après-CF: 8 338 014 208 octets libres

WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptOut

263 --- E O F --- 2009-04-15 11:42


avira m'a detecté plusieurs virus ou prog malveillant venant de combofix après le redemarage mais je les ai ignorés
0
p59 Messages postés 39 Date d'inscription mardi 12 mai 2009 Statut Membre Dernière intervention 15 mai 2009
13 mai 2009 à 14:32
les ports usb et carte memoire remarchent !
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
13 mai 2009 à 16:30
de retour ...

j'analyse le rapport et te donne la suite ... ;)


0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
13 mai 2009 à 16:43
La suite :


1-Créer un doc texte sur ton bureau :
pointe ta souris sur ton bureau , clique droit : va dans "nouveau" et choisis "document texte" .

Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :


File::
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat

Folder::
c:\documents and settings\All Users\Application Data\NortonInstaller

Driver::
asbp2poa



Puis va dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
CFScript puis valide ...


2-Nettoyage :

!! Déconnecte toi, ferme toutes tes applications et désactive TOUTES TES DEFENSES ( tu les réactiveras après ) !!

--->Sur ton bureau, fais glisser avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

(Regarde ici : http://img.photobucket.com/albums/v666/sUBs/CFScript.gif )

Cette manipulation va relancer combofix .
--> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tape 1 puis valide.

Puis patiente le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

!! Ne touches à rien tant que le scan n'est pas terminé !!

Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : poste le accompagné d' un nouveau rapport RSIT pour analyse ...

( Attention : cette manipe a été fait pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation )

0