Bagle (winupgro.exe) comment le supprimé? - Page 2

Précédent
  • 1
  • 2
  1. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    re

    faut pas s'etonné de choper bagle avec des keygen et crack d'antivirus et companie !!!! aujourd'hui 99% des cracks et keygen sont infecté !!!

    clic sur le parapluie rouge
    - puis a gauche clic sur administration
    - dessous sur quarantaine
    - et supprime toutes les lignes presente dans la quarantaine en les selectionnant et mets supprimer

    ensuite

    tu as toujours Findykill sur ton Bureau ? (si non voir l'explication dans le poste 1)

    si oui réexecute le en option 1 en controle et poste le rapport
    0
    1. atonkena
       
      ############################## | FindyKill V6.002 |

      # User : Moi (Administrateurs) # HOME-A33DA08042
      # Update on 03/07/09 by Chiquitine29 & C_XX
      # Start at: 21:32:45 | 19/03/2009
      # Website : http://pagesperso-orange.fr/NosTools/index.html

      # Intel(R) Pentium(R) 4 CPU 3.20GHz
      # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
      # Internet Explorer 7.0.5730.13
      # Windows Firewall Status : Enabled
      # AV : Rising Internet Security [ Enabled | (!) Outdated ]
      # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
      # AV : Kaspersky Internet Security 8.0.0.454 [ Enabled | (!) Outdated ]
      # FW : Rising Internet Security [ Enabled ]rfw7.0
      # FW : Kaspersky Internet Security[ Enabled ]8.0.0.454

      # C:\ # Disque fixe local # 24,95 Go (7,02 Go free) # FAT32
      # D:\ # Disque fixe local # 34,72 Go (32,71 Go free) # NTFS
      # E:\ # Disque fixe local # 34,72 Go (996,5 Mo free) # NTFS
      # F:\ # Disque fixe local # 54,65 Go (39,35 Go free) # NTFS
      # G:\ # Disque CD-ROM

      ############################## | Processus actifs |

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      D:\Rising\Ris\CCENTER.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      D:\Rising\Ris\RavMonD.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      D:\Rising\Ris\RsTray.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\system32\PnkBstrB.exe
      D:\Rising\Ris\RavTask.exe
      D:\Rising\Ris\ScanFrm.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\ooVoo\oovoo.exe
      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      C:\Program Files\DAP\DAP.EXE
      D:\Rising\Ris\rsnetsvr.exe
      C:\WINDOWS\System32\alg.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Program Files\Windows Media Player\wmplayer.exe
      c:\program files\avira\antivir desktop\avcenter.exe
      C:\Program Files\Free Download Manager\fdm.exe
      C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## | Registre Startup |

      HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
      HKCU_Main: "Start Page"="http://search.orbitdownloader.com"
      HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      HKLM_logon: "DefaultUserName"="Moi"
      HKLM_logon: "AltDefaultUserName"="Moi"
      HKLM_logon: "LegalNoticeCaption"=""
      HKLM_logon: "LegalNoticeText"=""
      HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      HKLM_Run: nwiz=nwiz.exe /install
      HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      HKLM_Run: HDAudDeck=C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
      HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      HKLM_Run: NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
      HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      HKLM_Run: ISUSPM Startup=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      HKLM_Run: ISUSScheduler="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      HKLM_Run: BluetoothAuthenticationAgent=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      HKLM_Run: RisTray="D:\Rising\Ris\RsTray.exe" -system
      HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
      HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      HKCU_Run: oovoo.exe=C:\Program Files\ooVoo\oovoo.exe /minimized
      HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
      HKCU_Run: Google Update="C:\Documents and Settings\Moi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      HKCU_Run: DownloadAccelerator="C:\Program Files\DAP\DAP.EXE" /STARTUP
      HKCU_Run: fsm=
      HKCU_Run: Free Download Manager="C:\Program Files\Free Download Manager\fdm.exe" -autorun

      ################## | Fichiers # Dossiers infectieux |


      ################## | C:\Documents and Settings\Moi\Temporary Internet Files |


      ################## | All Drives ... |


      ################## | Registre # Clés Run infectieuses |

      Présent ! HKLM\software\microsoft\security center "UpdatesDisableNotify" ( 0x1 )

      ################## | Registre # Mountpoints2 |


      ################## | Etat / Services / Informations |

      # Affichage des fichiers cachés : OK

      # Mode sans echec : OK

      # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
      # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
      # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
      # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
      # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

      ################## | Cracks / Keygens / Serials |


      ################## | ! Fin du rapport # FindyKill V6.002 ! |
      0
  2. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    salut

    relance en option 2 et poste le rapport
    0
Précédent
  • 1
  • 2