Virus
mariedevls
Messages postés
106
Statut
Membre
-
mariedevls Messages postés 106 Statut Membre -
mariedevls Messages postés 106 Statut Membre -
Bonjour,
slt a tous je vien ici car je croi que je sui infectè je doi avoir quelques virus car mon ordi me fai des chose pa normal :il s eteind tt seul il rame etc etc ....quelqun pourrait il maider a y voir plus clair mon anti virus ètan microsft sècurity essentials en vs remercians ts d avance<code>Configuration: Windows Vista / Internet Explorer
slt a tous je vien ici car je croi que je sui infectè je doi avoir quelques virus car mon ordi me fai des chose pa normal :il s eteind tt seul il rame etc etc ....quelqun pourrait il maider a y voir plus clair mon anti virus ètan microsft sècurity essentials en vs remercians ts d avance<code>Configuration: Windows Vista / Internet Explorer
A voir également:
- Virus
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
74 réponses
List'em by g3n-h@ckm@n 1.6.0.2
User : Marie (Administrateurs)
Update on 18/03/2010 by g3n-h@ckm@n ::::: 12.30
Start at: 19:41:57 | 19/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7
AMD Sempron(tm) Processor 3000+
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-bit) #
Internet Explorer 8.0.6001.18882
Windows Firewall Status : Disabled
AV : Microsoft Security Essentials 2.1.6519.0 [ Enabled | Updated ]
C:\ -> Disque fixe local | 149,05 Go (72,39 Go free) | NTFS
D:\ -> Disque CD-ROM
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\RelevantKnowledge\rlservice.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Microsoft Default Manager REG_SZ "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
Bing Bar REG_SZ "C:\Program Files\MSN Toolbar\Platform\5.0.1051.0\mswinext.exe"
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Google Quick Search Box REG_SZ "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
MSSE REG_SZ "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<NO NAME> REG_SZ
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
EnableInstallerDetection REG_DWORD 1 (0x1)
EnableLUA REG_DWORD 0 (0x0)
EnableSecureUIAPaths REG_DWORD 1 (0x1)
EnableVirtualization REG_DWORD 1 (0x1)
PromptOnSecureDesktop REG_DWORD 1 (0x1)
ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
scforceoption REG_DWORD 0 (0x0)
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
FilterAdministratorToken REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
Userinit REG_SZ C:\Windows\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 1 (0x1)
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 1 (0x1)
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD -2147483609 (0x80000027)
AutoAdminLogon REG_SZ 0
===============
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{2E4A92AB-F2C0-456A-9935-B715439790D7}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{32C3FEAE-0877-4767-8C20-62A5829A0945}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{8AA6CB35-67D7-45A2-B1F4-C87EC19E4522}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{13615073-0551-1729-FC63-A2398C5F5DAB}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1E88CF7D-78A3-3E22-25FA-FD0FE318C0F8}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C660F46-AE56-D35F-F8F2-A218D7F51FE4}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D992902D-BA83-EBA1-EB25-6803FFEDF5CE}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DE5EABAF-492E-BC75-4E24-1C1E2CEA5DED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{905502AB-1987-46cd-9EC5-42B1E087D319}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{abba5619-7774-4cbc-b0bd-bbb69708dd9c}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{2B88A1EF-5BCB-4437-9AC2-0EB841C54D31}: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS1\Services\Tcpip\..\{2B88A1EF-5BCB-4437-9AC2-0EB841C54D31}: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS2\Services\Tcpip\..\{2B88A1EF-5BCB-4437-9AC2-0EB841C54D31}: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://troner.net/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.fr/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x3 ( OK = 2 )
Wlansvc : 0x2 ( OK = 2 )
SharedAccess : 0x3 ( OK = 2 )
windefend : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
wscsvc : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\System32\drivers\atapi.sys
##
21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\System32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
##
21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
##
19048,4f4fcb8b6ea06784fb6d475b7ec7300f,6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
##
21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
##
21560,e03e8c99d15d0381e02743c36afc7c6f,8217348674fc4d0c6d567ffc95b14dfd507f47c5a4728c2ba93d72c412e8527b,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
=======
D'fragmenteur de disque Windows
Copyright (c) 2006 Microsoft Corp.
Rapport d'analyse pour le volume C:
Taille du volume = 149 Go
Espace libre = 72.40 Go
tendue d'espace libre la plus grande = 46.49 Go
Pourcentage de fragmentation des fichiers = 1 %
Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.
Il n'est pas n'cessaire de d'fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\ProgramData\Trymedia
Present !! : C:\Program Files\RelevantKnowledge
Present !! : C:\Windows\DUMP21a1.tmp
Present !! : C:\Windows\DUMP3a98.tmp
Present !! : C:\Windows\DUMP3b63.tmp
Present !! : C:\Windows\tasks\Registry_Doktor.job
Present !! : C:\Users\Marie\Local Settings\Temp\C84.tmp
Present !! : C:\Users\Marie\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
Present !! : C:\Users\Marie\LOCAL Settings\Temp\bfguni.exe
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
Present !! : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Present !! : "HKLM\Software\Trymedia Systems"
Present !! : HKCR\urlsearchhook.toolbarurlsearchhook
Present !! : HKCR\urlsearchhook.toolbarurlsearchhook.1
Present !! : HKCU\SOFTWARE\fcn
Present !! : HKCU\Software\mc
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8bcb5337-ec01-4e38-840c-a964f174255b}
Present !! : HKLM\Software\aedgency
Present !! : HKLM\Software\Classes\Interface\{90F62EF7-58D1-4E8E-BB3E-CFB10BA9E47B}
Present !! : HKLM\Software\Classes\Interface\{B2B92BC9-E149-4EE8-A93E-0B8CFB329808}
Present !! : HKLM\Software\Classes\TypeLib\{022C671F-6CBA-4A03-A8F9-3B3A361B235A}
Present !! : HKLM\Software\Classes\TypeLib\{8AD815FC-607B-419F-8B70-D345A507A54E}
Present !! : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar
Present !! : HKLM\SOFTWARE\Smart-Shopper
Present !! : HKLM\SYSTEM\ControlSet002\Services\RelevantKnowledge
Present !! : HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-19 20:02:30
Windows 6.0.6000 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys tcpip.sys NETIO.SYS rdbss.sys dxgkrnl.sys nvlddmkm.sys
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 20:03:25,54
User : Marie (Administrateurs)
Update on 18/03/2010 by g3n-h@ckm@n ::::: 12.30
Start at: 19:41:57 | 19/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7
AMD Sempron(tm) Processor 3000+
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-bit) #
Internet Explorer 8.0.6001.18882
Windows Firewall Status : Disabled
AV : Microsoft Security Essentials 2.1.6519.0 [ Enabled | Updated ]
C:\ -> Disque fixe local | 149,05 Go (72,39 Go free) | NTFS
D:\ -> Disque CD-ROM
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\RelevantKnowledge\rlservice.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Microsoft Default Manager REG_SZ "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
Bing Bar REG_SZ "C:\Program Files\MSN Toolbar\Platform\5.0.1051.0\mswinext.exe"
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Google Quick Search Box REG_SZ "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
MSSE REG_SZ "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<NO NAME> REG_SZ
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
EnableInstallerDetection REG_DWORD 1 (0x1)
EnableLUA REG_DWORD 0 (0x0)
EnableSecureUIAPaths REG_DWORD 1 (0x1)
EnableVirtualization REG_DWORD 1 (0x1)
PromptOnSecureDesktop REG_DWORD 1 (0x1)
ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
scforceoption REG_DWORD 0 (0x0)
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
FilterAdministratorToken REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
Userinit REG_SZ C:\Windows\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 1 (0x1)
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 1 (0x1)
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD -2147483609 (0x80000027)
AutoAdminLogon REG_SZ 0
===============
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{2E4A92AB-F2C0-456A-9935-B715439790D7}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{32C3FEAE-0877-4767-8C20-62A5829A0945}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{8AA6CB35-67D7-45A2-B1F4-C87EC19E4522}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{13615073-0551-1729-FC63-A2398C5F5DAB}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1E88CF7D-78A3-3E22-25FA-FD0FE318C0F8}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C660F46-AE56-D35F-F8F2-A218D7F51FE4}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D992902D-BA83-EBA1-EB25-6803FFEDF5CE}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DE5EABAF-492E-BC75-4E24-1C1E2CEA5DED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{905502AB-1987-46cd-9EC5-42B1E087D319}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{abba5619-7774-4cbc-b0bd-bbb69708dd9c}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{2B88A1EF-5BCB-4437-9AC2-0EB841C54D31}: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS1\Services\Tcpip\..\{2B88A1EF-5BCB-4437-9AC2-0EB841C54D31}: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS2\Services\Tcpip\..\{2B88A1EF-5BCB-4437-9AC2-0EB841C54D31}: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://troner.net/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.fr/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x3 ( OK = 2 )
Wlansvc : 0x2 ( OK = 2 )
SharedAccess : 0x3 ( OK = 2 )
windefend : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
wscsvc : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\System32\drivers\atapi.sys
##
21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\System32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
##
21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
##
19048,4f4fcb8b6ea06784fb6d475b7ec7300f,6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
##
21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
##
21560,e03e8c99d15d0381e02743c36afc7c6f,8217348674fc4d0c6d567ffc95b14dfd507f47c5a4728c2ba93d72c412e8527b,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
=======
D'fragmenteur de disque Windows
Copyright (c) 2006 Microsoft Corp.
Rapport d'analyse pour le volume C:
Taille du volume = 149 Go
Espace libre = 72.40 Go
tendue d'espace libre la plus grande = 46.49 Go
Pourcentage de fragmentation des fichiers = 1 %
Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.
Il n'est pas n'cessaire de d'fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\ProgramData\Trymedia
Present !! : C:\Program Files\RelevantKnowledge
Present !! : C:\Windows\DUMP21a1.tmp
Present !! : C:\Windows\DUMP3a98.tmp
Present !! : C:\Windows\DUMP3b63.tmp
Present !! : C:\Windows\tasks\Registry_Doktor.job
Present !! : C:\Users\Marie\Local Settings\Temp\C84.tmp
Present !! : C:\Users\Marie\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
Present !! : C:\Users\Marie\LOCAL Settings\Temp\bfguni.exe
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
Present !! : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Present !! : "HKLM\Software\Trymedia Systems"
Present !! : HKCR\urlsearchhook.toolbarurlsearchhook
Present !! : HKCR\urlsearchhook.toolbarurlsearchhook.1
Present !! : HKCU\SOFTWARE\fcn
Present !! : HKCU\Software\mc
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8bcb5337-ec01-4e38-840c-a964f174255b}
Present !! : HKLM\Software\aedgency
Present !! : HKLM\Software\Classes\Interface\{90F62EF7-58D1-4E8E-BB3E-CFB10BA9E47B}
Present !! : HKLM\Software\Classes\Interface\{B2B92BC9-E149-4EE8-A93E-0B8CFB329808}
Present !! : HKLM\Software\Classes\TypeLib\{022C671F-6CBA-4A03-A8F9-3B3A361B235A}
Present !! : HKLM\Software\Classes\TypeLib\{8AD815FC-607B-419F-8B70-D345A507A54E}
Present !! : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar
Present !! : HKLM\SOFTWARE\Smart-Shopper
Present !! : HKLM\SYSTEM\ControlSet002\Services\RelevantKnowledge
Present !! : HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-19 20:02:30
Windows 6.0.6000 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys tcpip.sys NETIO.SYS rdbss.sys dxgkrnl.sys nvlddmkm.sys
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 20:03:25,54
▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'option 2 = Mode Suppression
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
▶ colle le contenu dans ta reponse
mais cette fois-ci :
▶ choisis l'option 2 = Mode Suppression
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
▶ colle le contenu dans ta reponse
desolé :
option clean , et c'est juste le prog que tu dois relancer en tant qu'adminidtrateur , pour la touche "clean , clique juste dessus
option clean , et c'est juste le prog que tu dois relancer en tant qu'adminidtrateur , pour la touche "clean , clique juste dessus
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Kill'em by g3n-h@ckm@n 1.6.0.2
User : Marie (Administrateurs)
Update on 18/03/2010 by g3n-h@ckm@n ::::: 12.30
Start at: 19:33:06 | 21/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7
AMD Sempron(tm) Processor 3000+
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-bit) #
Internet Explorer 8.0.6001.18882
Windows Firewall Status : Enabled
AV : Microsoft Security Essentials 2.1.6519.0 [ Enabled | Updated ]
C:\ -> Disque fixe local | 149,05 Go (76,67 Go free) | NTFS
D:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Search Guard Plus\SearchGuardPlus.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\RelevantKnowledge\rlservice.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Calendar\WinCal.exe
C:\Windows\system32\OGAExec.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\ProgramData\Trymedia
Quarantined & Deleted !! : C:\Program Files\RelevantKnowledge
Quarantined & Deleted !! : C:\Windows\DUMP21a1.tmp
Quarantined & Deleted !! : C:\Windows\DUMP3a98.tmp
Quarantined & Deleted !! : C:\Windows\DUMP3b63.tmp
Quarantined & Deleted !! : C:\Windows\tasks\Registry_Doktor.job
Quarantined & Deleted !! : C:\Users\Marie\Local Settings\Temp\C84.tmp
Quarantined & Deleted !! : C:\Users\Marie\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
Quarantined & Deleted !! : C:\Users\Marie\LOCAL Settings\Temp\bfguni.exe
==============
host file OK !
==============
========
Registry
========
Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
Deleted : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Deleted : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}"
Deleted : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Deleted : "HKLM\Software\Trymedia Systems"
Deleted : HKCR\urlsearchhook.toolbarurlsearchhook
Deleted : HKCR\urlsearchhook.toolbarurlsearchhook.1
Deleted : HKCU\SOFTWARE\fcn
Deleted : HKCU\Software\mc
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8bcb5337-ec01-4e38-840c-a964f174255b}
Deleted : HKLM\Software\aedgency
Deleted : HKLM\Software\Classes\Interface\{90F62EF7-58D1-4E8E-BB3E-CFB10BA9E47B}
Deleted : HKLM\Software\Classes\Interface\{B2B92BC9-E149-4EE8-A93E-0B8CFB329808}
Deleted : HKLM\Software\Classes\TypeLib\{022C671F-6CBA-4A03-A8F9-3B3A361B235A}
Deleted : HKLM\Software\Classes\TypeLib\{8AD815FC-607B-419F-8B70-D345A507A54E}
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar
Deleted : HKLM\SOFTWARE\Smart-Shopper
Deleted : HKLM\SYSTEM\ControlSet002\Services\RelevantKnowledge
Deleted : HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
============
=================
anti-ver blaster : OK !!
=================
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
User : Marie (Administrateurs)
Update on 18/03/2010 by g3n-h@ckm@n ::::: 12.30
Start at: 19:33:06 | 21/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7
AMD Sempron(tm) Processor 3000+
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-bit) #
Internet Explorer 8.0.6001.18882
Windows Firewall Status : Enabled
AV : Microsoft Security Essentials 2.1.6519.0 [ Enabled | Updated ]
C:\ -> Disque fixe local | 149,05 Go (76,67 Go free) | NTFS
D:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Search Guard Plus\SearchGuardPlus.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\RelevantKnowledge\rlservice.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Calendar\WinCal.exe
C:\Windows\system32\OGAExec.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\ProgramData\Trymedia
Quarantined & Deleted !! : C:\Program Files\RelevantKnowledge
Quarantined & Deleted !! : C:\Windows\DUMP21a1.tmp
Quarantined & Deleted !! : C:\Windows\DUMP3a98.tmp
Quarantined & Deleted !! : C:\Windows\DUMP3b63.tmp
Quarantined & Deleted !! : C:\Windows\tasks\Registry_Doktor.job
Quarantined & Deleted !! : C:\Users\Marie\Local Settings\Temp\C84.tmp
Quarantined & Deleted !! : C:\Users\Marie\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
Quarantined & Deleted !! : C:\Users\Marie\LOCAL Settings\Temp\bfguni.exe
==============
host file OK !
==============
========
Registry
========
Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
Deleted : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Deleted : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}"
Deleted : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Deleted : "HKLM\Software\Trymedia Systems"
Deleted : HKCR\urlsearchhook.toolbarurlsearchhook
Deleted : HKCR\urlsearchhook.toolbarurlsearchhook.1
Deleted : HKCU\SOFTWARE\fcn
Deleted : HKCU\Software\mc
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8bcb5337-ec01-4e38-840c-a964f174255b}
Deleted : HKLM\Software\aedgency
Deleted : HKLM\Software\Classes\Interface\{90F62EF7-58D1-4E8E-BB3E-CFB10BA9E47B}
Deleted : HKLM\Software\Classes\Interface\{B2B92BC9-E149-4EE8-A93E-0B8CFB329808}
Deleted : HKLM\Software\Classes\TypeLib\{022C671F-6CBA-4A03-A8F9-3B3A361B235A}
Deleted : HKLM\Software\Classes\TypeLib\{8AD815FC-607B-419F-8B70-D345A507A54E}
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar
Deleted : HKLM\SOFTWARE\Smart-Shopper
Deleted : HKLM\SYSTEM\ControlSet002\Services\RelevantKnowledge
Deleted : HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
============
=================
anti-ver blaster : OK !!
=================
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
▶ Télécharge :
Malwarebytes
ou :
Malwarebytes
▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
▶ Potasses le Tuto pour te familiariser avec le prg :
( cela dit, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
▶ Lance Malwarebyte's .
Fais un examen dit "Complet" .
▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
▶ Télécharge :
Malwarebytes
ou :
Malwarebytes
▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
▶ Potasses le Tuto pour te familiariser avec le prg :
( cela dit, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
▶ Lance Malwarebyte's .
Fais un examen dit "Complet" .
▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3898
Windows 6.0.6000
Internet Explorer 8.0.6001.18882
22/03/2010 11:43:26
mbam-log-2010-03-22 (11-43-26).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 240865
Temps écoulé: 2 hour(s), 12 minute(s), 38 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 20
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\csetup.setup (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\csetup.setup.1 (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbax (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbax.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbinfoband (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbinfoband.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebutton (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebutton.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttona (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttona.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttonb (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttonb.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.smrt-shprctrl (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.smrt-shprctrl.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79b1445-dfea-4bef-a786-e0c0f33c863b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2e4a92ab-f2c0-456a-9935-b715439790d7} (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{305c6cb1-9d31-4489-881d-5a8e2dc3fe14} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2e4a92ab-f2c0-456a-9935-b715439790d7} (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MStart2Page (Switch.Dialer) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\PermissionResearch (Spyware.PermissionResearch) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Program Files\PermissionResearch\prservice.exe (Spyware.PermissionResearch) -> Quarantined and deleted successfully.
Version de la base de données: 3898
Windows 6.0.6000
Internet Explorer 8.0.6001.18882
22/03/2010 11:43:26
mbam-log-2010-03-22 (11-43-26).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 240865
Temps écoulé: 2 hour(s), 12 minute(s), 38 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 20
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\csetup.setup (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\csetup.setup.1 (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbax (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbax.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbinfoband (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.hbinfoband.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebutton (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebutton.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttona (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttona.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttonb (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.iebuttonb.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.smrt-shprctrl (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smart-shopper.smrt-shprctrl.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79b1445-dfea-4bef-a786-e0c0f33c863b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2e4a92ab-f2c0-456a-9935-b715439790d7} (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{305c6cb1-9d31-4489-881d-5a8e2dc3fe14} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2e4a92ab-f2c0-456a-9935-b715439790d7} (Spyware.MarketScore) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MStart2Page (Switch.Dialer) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\PermissionResearch (Spyware.PermissionResearch) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Program Files\PermissionResearch\prservice.exe (Spyware.PermissionResearch) -> Quarantined and deleted successfully.
bonjour
tu peux faire l'option suppression d'USBFix stp ?
tu peux faire l'option suppression de AD-Remover stp ?
tu peux faire l'option suppression d'USBFix stp ?
tu peux faire l'option suppression de AD-Remover stp ?
.
======= RAPPORT D'AD-REMOVER 2.0.0.0,A | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 17/03/10 à 15:10
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 14:52:57 le 22/03/2010 | Mode normal | Option: CLEAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft® Windows Vista(TM) HomePremium - X86
Nom du PC: MARIE_ONE | Utilisateur actuel: Marie (Administrateur)
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
C:\Program Files\Search Guard Plus
C:\Users\Marie\AppData\Local\eqoumkq.bat
C:\Users\Marie\AppData\Local\gmkuq.bat
C:\Users\Marie\AppData\Local\iauvq.bat
C:\Users\Marie\AppData\Local\mdcifev.bat
C:\Users\Marie\AppData\Local\tydkpv.bat
C:\Users\Marie\AppData\Local\udjpf.bat
C:\Users\Marie\AppData\LocalLow\Kiwee Toolbar
C:\Users\Marie\AppData\LocalLow\Smart-Shopper
C:\Users\Public\MyWebTattoo.exe
(!) -- Fichiers temporaires supprimés.
.
HKCU\Software\FBSearch
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C8AEB260-2075-48DE-950E-EFE20A420E9A}
HKCU\Software\Vegas Red Casino
HKLM\Software\Classes\ComObject.DeskbarEnabler
HKLM\Software\Classes\ComObject.DeskbarEnabler.1
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54CC4A11-1CD5-47a8-BC94-4855758586A9}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\db3ca69f-4f1d-41f2-8997-2a51f0160347
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\e0dcd592-1763-4cd0-8666-09b4cff842bf
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Guard Plus
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
.
============== SCAN ADDITIONNEL ==============
.
* Mozilla FireFox Version 3.6 (fr) *
.
C:\Users\Marie\..\7vz44v9h.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2
.
.
* Internet Explorer Version 8.0.6001.18882 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Enable Browser Extensions: yes
Local Page: C:\Windows\System32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Use Search Asst: no
.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
.
============== SUSPECT(S) ==============
.
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\jeux compresse\Bigfish Games Hidden Expedition - Everest By Crimo Cracked French.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\jeux compresse\Totem Quest Crackeado By Fravacu.rar
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\jeux compresse\[Jeux PC]-Les enquètes de Nancy Drew-La malédiction du manoir de Blackmoor_Fr Crack Soluce-Bon-Testé par Mézigue.zip
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Alice Greenfingers + Crack\Alice.Greenfingers.v1.03-TE-km07\AliceGreenfingersSetup.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Alice Greenfingers + Crack\Alice.Greenfingers.v1.03-TE-km07\CRACK\AliceGreenfingers.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Alice Greenfingers + Crack\Alice.Greenfingers.v1.03-TE-km07\te.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Feeding Frenzy\cRACK\keygen.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Feeding Frenzy\cRACK\tsrh.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Feeding Frenzy\Feeding Frenzy.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Hammer Heads Deluxe\embrace.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Hammer Heads Deluxe\HammerHeadsSetup.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Insaniquarium Deluxe\InsaniquariumDeluxe.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Insaniquarium Deluxe\Insaniquarium_Deluxe_v1[1].0\InsaniquariumDeluxe.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\Crack\keygen.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\Crack\PopCap Zuma Deluxe! v1.0 (crack).exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\Crack\Zuma.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\ZumaSetup.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\F4CG.NFO
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\CRACK\jewelofatlantis.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\CRACK\TNT.NFO
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\Saugstube die beste Emule Seite im Netz. www.saugstube.1a.to www.saugstube.p4.to.url
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\TNT.NFO
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\wichtig lesen !!!.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Svetlograd\patch\Svetlograd.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Svetlograd\patch\svetlograd_100.exe
C:\Users\Marie\Desktop\Mes images\Incoming\sik\[PC-GAME] Bigfish Games - Escape from Paradise + crack.rar
.
========================================
.
C:\Users\Marie\AppData\Local\Temp: 3 Fichier(s), 40 Dossier(s)
C:\Windows\temp: 0 Fichier(s), 10 Dossier(s)
C:\Users\Marie\AppData\Roaming\Microsoft\Windows\Cookies: 3 Fichier(s), 2 Dossier(s)
Temporary Internet Files: 7 Fichier(s), 55 Dossier(s)
.
C:\Ad-Remover\Quarantine: 23 Fichier(s)
C:\Ad-Remover\Backup: 16 Fichier(s)
.
C:\Ad-Report-CLEAN[1].txt - 7620 Octet(s)
C:\Ad-Report-SCAN[1].txt - 11984 Octet(s)
.
Fin à: 15:08:30, 22/03/2010
.
============== E.O.F - CLEAN[1] ==============
======= RAPPORT D'AD-REMOVER 2.0.0.0,A | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 17/03/10 à 15:10
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 14:52:57 le 22/03/2010 | Mode normal | Option: CLEAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft® Windows Vista(TM) HomePremium - X86
Nom du PC: MARIE_ONE | Utilisateur actuel: Marie (Administrateur)
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
C:\Program Files\Search Guard Plus
C:\Users\Marie\AppData\Local\eqoumkq.bat
C:\Users\Marie\AppData\Local\gmkuq.bat
C:\Users\Marie\AppData\Local\iauvq.bat
C:\Users\Marie\AppData\Local\mdcifev.bat
C:\Users\Marie\AppData\Local\tydkpv.bat
C:\Users\Marie\AppData\Local\udjpf.bat
C:\Users\Marie\AppData\LocalLow\Kiwee Toolbar
C:\Users\Marie\AppData\LocalLow\Smart-Shopper
C:\Users\Public\MyWebTattoo.exe
(!) -- Fichiers temporaires supprimés.
.
HKCU\Software\FBSearch
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C8AEB260-2075-48DE-950E-EFE20A420E9A}
HKCU\Software\Vegas Red Casino
HKLM\Software\Classes\ComObject.DeskbarEnabler
HKLM\Software\Classes\ComObject.DeskbarEnabler.1
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54CC4A11-1CD5-47a8-BC94-4855758586A9}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\db3ca69f-4f1d-41f2-8997-2a51f0160347
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\e0dcd592-1763-4cd0-8666-09b4cff842bf
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Guard Plus
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
.
============== SCAN ADDITIONNEL ==============
.
* Mozilla FireFox Version 3.6 (fr) *
.
C:\Users\Marie\..\7vz44v9h.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2
.
.
* Internet Explorer Version 8.0.6001.18882 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Enable Browser Extensions: yes
Local Page: C:\Windows\System32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Use Search Asst: no
.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
.
============== SUSPECT(S) ==============
.
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\jeux compresse\Bigfish Games Hidden Expedition - Everest By Crimo Cracked French.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\jeux compresse\Totem Quest Crackeado By Fravacu.rar
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\jeux compresse\[Jeux PC]-Les enquètes de Nancy Drew-La malédiction du manoir de Blackmoor_Fr Crack Soluce-Bon-Testé par Mézigue.zip
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Alice Greenfingers + Crack\Alice.Greenfingers.v1.03-TE-km07\AliceGreenfingersSetup.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Alice Greenfingers + Crack\Alice.Greenfingers.v1.03-TE-km07\CRACK\AliceGreenfingers.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Alice Greenfingers + Crack\Alice.Greenfingers.v1.03-TE-km07\te.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Feeding Frenzy\cRACK\keygen.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Feeding Frenzy\cRACK\tsrh.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Feeding Frenzy\Feeding Frenzy.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Hammer Heads Deluxe\embrace.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Hammer Heads Deluxe\HammerHeadsSetup.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Insaniquarium Deluxe\InsaniquariumDeluxe.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Insaniquarium Deluxe\Insaniquarium_Deluxe_v1[1].0\InsaniquariumDeluxe.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\Crack\keygen.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\Crack\PopCap Zuma Deluxe! v1.0 (crack).exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\Crack\Zuma.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\DELUXE PACK GAMES\Zuma\ZumaSetup.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\7.Wonders.of.the.Ancient.World.v1.0.Cracked-F4CG\F4CG.NFO
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\CRACK\jewelofatlantis.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\CRACK\TNT.NFO
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\Saugstube die beste Emule Seite im Netz. www.saugstube.1a.to www.saugstube.p4.to.url
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\TNT.NFO
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Jewel_of_Atlantis_Deluxe_v1.05_MULTI8_Cracked-TNT\wichtig lesen !!!.nfo
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Svetlograd\patch\Svetlograd.exe
C:\Users\Marie\Desktop\Mes images\Incoming\jeux\JEUX DèCOMPRESSè\Svetlograd\patch\svetlograd_100.exe
C:\Users\Marie\Desktop\Mes images\Incoming\sik\[PC-GAME] Bigfish Games - Escape from Paradise + crack.rar
.
========================================
.
C:\Users\Marie\AppData\Local\Temp: 3 Fichier(s), 40 Dossier(s)
C:\Windows\temp: 0 Fichier(s), 10 Dossier(s)
C:\Users\Marie\AppData\Roaming\Microsoft\Windows\Cookies: 3 Fichier(s), 2 Dossier(s)
Temporary Internet Files: 7 Fichier(s), 55 Dossier(s)
.
C:\Ad-Remover\Quarantine: 23 Fichier(s)
C:\Ad-Remover\Backup: 16 Fichier(s)
.
C:\Ad-Report-CLEAN[1].txt - 7620 Octet(s)
C:\Ad-Report-SCAN[1].txt - 11984 Octet(s)
.
Fin à: 15:08:30, 22/03/2010
.
============== E.O.F - CLEAN[1] ==============
j aurai bien voulu savoir se que donne mes rapport car je rame toujours et mon pc se relance tous seul de temp en temp merci
http://www.cijoint.fr/cjlinkhttp://www.cijoint.fr/cjlink.php?file=cj201003/cijzce0C3C.txt .php?file=cj201003/cijW7hf7bT.txt
http://www.cijoint.fr/cjlink.php?file=cj201003/cijH41y1XI.txt
tien moi au couran si tu la bien recu merci
tien moi au couran si tu la bien recu merci
? clic droit "executer en tant qu'administrateur" sur OTL.exe pour le lancer.
?Copie la liste qui se trouve en gras ci-dessous,
? colle-la dans la zone sous Customs Scans/Fixes :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:Services
boonty games
:OTL
IE - HKU\.DEFAULT\..\URLSearchHook: {88e20c72-8089-469b-8bd9-53f2d2d65554} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {f592709f-ff4a-4862-b659-4afabda56312} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {88e20c72-8089-469b-8bd9-53f2d2d65554} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {f592709f-ff4a-4862-b659-4afabda56312} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {905502AB-1987-46cd-9EC5-42B1E087D319} - No CLSID value found.
O2 - BHO: (no name) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {abba5619-7774-4cbc-b0bd-bbb69708dd9c} - No CLSID value found.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:FC8FFA4E
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:9AA05701
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:880F0FEF
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:59846E5E
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:4A1628E5
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:315B4A13
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:2BC498A4
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:07241935
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:4363DE71
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:9E3E060F
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:459B4633
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:EAFDF1CF
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:A1D3FEF0
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:E895790F
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:DD04902E
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:9ACE4E8E
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:5345C8F6
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:55E1514E
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:3D186293
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:28CDD861
@Alternate Data Stream - 225 bytes -> C:\ProgramData\TEMP:D0DCD8D7
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:B8384DB6
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:7B52659E
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:596E2371
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:101708D3
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:ECFD9449
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:ECC979BD
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:3539CD43
@Alternate Data Stream - 219 bytes -> C:\ProgramData\TEMP:2495D97A
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:A2907225
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:55818279
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:CB16385F
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:7881FECE
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:CF61CE5A
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:C9FD258B
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:270A3983
@Alternate Data Stream - 207 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:C3C72D5F
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:78E0DF72
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:D48500F8
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:61FEC5E3
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:12D2EB9C
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:08D8BB20
@Alternate Data Stream - 202 bytes -> C:\ProgramData\TEMP:F35AE645
@Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:97C4F81F
@Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:8DF68137
@Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:5D351BC6
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:1DEE6B65
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:88B61AC3
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:33EA030E
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:22741C1F
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0DAD93FF
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:69D59C23
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:0D52F295
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E8CB831A
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:A58B27C9
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:CD9109D4
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C0A2E219
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:A4076A3B
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:6710EF08
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:DE9F4320
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:5FA4CB99
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A5FC8FA1
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A00BCDEF
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:23430C4C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:FEEEFFAD
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F69E3A97
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:D8F9D810
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:A6CDBCAC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:93D985FC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3DF63AD7
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:D6A4A911
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:2EA99C48
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:058A7351
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:CA8D6B60
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C10635F6
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:9331E9D2
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:6E86D926
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:6425A235
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:61AF2B29
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:523B97A0
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:32ED8AE7
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:551BED5F
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:1181620C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:B18C4339
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:966CEAE7
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:5025C6E4
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3FD496E1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:17C48B08
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:AA8AD2BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:8944C195
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:3991CD7D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1C6CB897
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:D46D2E5A
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:D2032EBB
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:85A0F6D2
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:405D842B
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:ED2998F5
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D02FBAEC
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A2C4E5BC
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:16C16B18
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:FD000392
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:E7B49FBF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:DC21D414
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A3251D01
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:9F38BF31
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:76A59E49
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:054F0F17
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:92A815D8
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:7CEDF9F3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:561B1D2B
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:6B05AF40
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:4B1195DD
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:1A8BB29B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:CEF2A14E
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:ADE67221
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:0DFE2AE1
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:059167AF
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:F14D1F80
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E945C214
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:BC38C00C
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:B3942462
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:2E49FF93
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:FACB65E7
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:EE39C93C
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D5E0200E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D0668210
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:B845F669
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:603FD11D
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:164FA86E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D2249B7E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D0D17155
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A745DB5D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:943E8182
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:61F0C8FB
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:517B507A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2AFE7797
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:02B823FE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FECEF728
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FB97DB91
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:DB77E2C4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:C928F3BE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:AF54CFFD
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2F384CF4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2CDB9CA3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2B885D7E
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:206470A5
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0C9CD455
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EC855C73
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EB40BC91
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:E027789A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D4BB0AD6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9DF07E8F
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:71FA8B7F
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:5E413CD6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:537E6E55
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:425759C6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:33384BC0
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:FC98D33A
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:D2593961
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8AC7B784
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:89C28CF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:7FD903D7
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:5EF1AD34
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:55C54F7C
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:2832349A
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FC2D0F32
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E4E43015
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DF3CC840
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:CFDE7852
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:A7DA2BCD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:957E9765
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:89CF6F9C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:6AF67671
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5FD47318
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:51F17BB8
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:3A47A0EB
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:38B32B54
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:37994DBE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0C988F7D
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:02BC319B
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:FC2E567F
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:F45F3031
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:EB5BDBB0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:BB71BBA2
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:B1FBA7E1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:918B7566
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:896E1EFF
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5FFC2819
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:0E684AC9
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F0762150
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:D6E29A14
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:BDF08FAF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:9E9A3410
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:8DB31C20
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:6FE17A89
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4C528C86
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:35A81752
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:237E4B91
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F2958F3A
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:80F63EC3
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:6444B424
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:35FAD15D
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:00F7B10F
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:E1CC2D5E
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:9BFB769D
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:59286A3A
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:538B96B5
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:471AD3D0
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:260575F1
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:DFC3B090
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:C36B1175
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:710F4DBF
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:4DCAC4BC
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:177313FB
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:F2AF86D9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:E3CEEC4C
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D92485C9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D4D3884D
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:CB0FEE2B
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:B4980368
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:8F067037
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:7AA6FC81
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:41D1C7CB
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:3BCA993F
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:FBE5FDB9
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A0A7408F
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4CF76F21
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:48977386
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:47A24D4B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:45DDA801
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:2F0007D6
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:F0AB86C0
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:9857FAE3
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:4F8B72C9
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:2F141B68
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:0D3CE40A
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:84CFEE62
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:51E1A4D8
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:3C282BEA
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:3B812EE0
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:D46ECFD5
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:8CCDAB14
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:842B0AED
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:5C6EBC69
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:55BB2521
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0C5BC70E
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:43982D5E
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:385E2CFD
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:25249477
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:1B927722
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:E07EA07E
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:36BC4740
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:2B82C0BB
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:062AF572
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:66AA0486
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:12EA4DC9
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:F7061E5F
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:45F3AD49
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:43C9D140
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:C0A9D0E7
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:79A70C33
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:938EC881
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:53DF59D1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:409A775B
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:FDC41D2C
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:C7F5E798
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:072F1F69
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:6B55B892
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:48081133
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:FDDD8917
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:98AE08EA
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:5363837B
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:52641FBE
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:4FE30352
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:EF4FB3C5
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:DAE3649B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:B2CD146E
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:7B2BB690
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:47FE7AB7
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride"=1
"FirewallOverride"=1
:Files
C:\ProgramData\Ikibago
:commands
[emptytemp]
[start explorer]
[reboot]
? Clique sur RunFix pour lancer la suppression.
? Poste le rapport.
?G3?-?@¢??@?(TM)©®?
?Copie la liste qui se trouve en gras ci-dessous,
? colle-la dans la zone sous Customs Scans/Fixes :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:Services
boonty games
:OTL
IE - HKU\.DEFAULT\..\URLSearchHook: {88e20c72-8089-469b-8bd9-53f2d2d65554} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {f592709f-ff4a-4862-b659-4afabda56312} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {88e20c72-8089-469b-8bd9-53f2d2d65554} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {f592709f-ff4a-4862-b659-4afabda56312} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {905502AB-1987-46cd-9EC5-42B1E087D319} - No CLSID value found.
O2 - BHO: (no name) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {abba5619-7774-4cbc-b0bd-bbb69708dd9c} - No CLSID value found.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:FC8FFA4E
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:9AA05701
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:880F0FEF
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:59846E5E
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:4A1628E5
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:315B4A13
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:2BC498A4
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:07241935
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:4363DE71
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:9E3E060F
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:459B4633
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:EAFDF1CF
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:A1D3FEF0
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:E895790F
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:DD04902E
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:9ACE4E8E
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:5345C8F6
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:55E1514E
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:3D186293
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:28CDD861
@Alternate Data Stream - 225 bytes -> C:\ProgramData\TEMP:D0DCD8D7
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:B8384DB6
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:7B52659E
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:596E2371
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:101708D3
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:ECFD9449
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:ECC979BD
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:3539CD43
@Alternate Data Stream - 219 bytes -> C:\ProgramData\TEMP:2495D97A
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:A2907225
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:55818279
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:CB16385F
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:7881FECE
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:CF61CE5A
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:C9FD258B
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:270A3983
@Alternate Data Stream - 207 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:C3C72D5F
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:78E0DF72
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:D48500F8
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:61FEC5E3
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:12D2EB9C
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:08D8BB20
@Alternate Data Stream - 202 bytes -> C:\ProgramData\TEMP:F35AE645
@Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:97C4F81F
@Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:8DF68137
@Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:5D351BC6
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:1DEE6B65
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:88B61AC3
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:33EA030E
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:22741C1F
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0DAD93FF
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:69D59C23
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:0D52F295
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E8CB831A
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:A58B27C9
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:CD9109D4
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C0A2E219
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:A4076A3B
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:6710EF08
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:DE9F4320
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:5FA4CB99
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A5FC8FA1
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A00BCDEF
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:23430C4C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:FEEEFFAD
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F69E3A97
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:D8F9D810
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:A6CDBCAC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:93D985FC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3DF63AD7
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:D6A4A911
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:2EA99C48
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:058A7351
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:CA8D6B60
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C10635F6
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:9331E9D2
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:6E86D926
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:6425A235
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:61AF2B29
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:523B97A0
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:32ED8AE7
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:551BED5F
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:1181620C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:B18C4339
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:966CEAE7
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:5025C6E4
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3FD496E1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:17C48B08
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:AA8AD2BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:8944C195
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:3991CD7D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1C6CB897
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:D46D2E5A
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:D2032EBB
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:85A0F6D2
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:405D842B
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:ED2998F5
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D02FBAEC
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A2C4E5BC
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:16C16B18
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:FD000392
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:E7B49FBF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:DC21D414
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A3251D01
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:9F38BF31
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:76A59E49
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:054F0F17
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:92A815D8
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:7CEDF9F3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:561B1D2B
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:6B05AF40
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:4B1195DD
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:1A8BB29B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:CEF2A14E
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:ADE67221
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:0DFE2AE1
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:059167AF
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:F14D1F80
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E945C214
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:BC38C00C
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:B3942462
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:2E49FF93
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:FACB65E7
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:EE39C93C
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D5E0200E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D0668210
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:B845F669
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:603FD11D
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:164FA86E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D2249B7E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D0D17155
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A745DB5D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:943E8182
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:61F0C8FB
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:517B507A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2AFE7797
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:02B823FE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FECEF728
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FB97DB91
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:DB77E2C4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:C928F3BE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:AF54CFFD
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2F384CF4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2CDB9CA3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2B885D7E
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:206470A5
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0C9CD455
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EC855C73
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EB40BC91
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:E027789A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D4BB0AD6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9DF07E8F
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:71FA8B7F
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:5E413CD6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:537E6E55
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:425759C6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:33384BC0
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:FC98D33A
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:D2593961
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8AC7B784
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:89C28CF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:7FD903D7
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:5EF1AD34
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:55C54F7C
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:2832349A
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FC2D0F32
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E4E43015
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DF3CC840
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:CFDE7852
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:A7DA2BCD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:957E9765
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:89CF6F9C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:6AF67671
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5FD47318
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:51F17BB8
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:3A47A0EB
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:38B32B54
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:37994DBE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0C988F7D
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:02BC319B
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:FC2E567F
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:F45F3031
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:EB5BDBB0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:BB71BBA2
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:B1FBA7E1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:918B7566
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:896E1EFF
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5FFC2819
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:0E684AC9
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F0762150
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:D6E29A14
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:BDF08FAF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:9E9A3410
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:8DB31C20
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:6FE17A89
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4C528C86
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:35A81752
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:237E4B91
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F2958F3A
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:80F63EC3
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:6444B424
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:35FAD15D
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:00F7B10F
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:E1CC2D5E
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:9BFB769D
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:59286A3A
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:538B96B5
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:471AD3D0
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:260575F1
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:DFC3B090
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:C36B1175
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:710F4DBF
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:4DCAC4BC
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:177313FB
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:F2AF86D9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:E3CEEC4C
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D92485C9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D4D3884D
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:CB0FEE2B
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:B4980368
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:8F067037
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:7AA6FC81
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:41D1C7CB
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:3BCA993F
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:FBE5FDB9
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A0A7408F
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4CF76F21
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:48977386
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:47A24D4B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:45DDA801
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:2F0007D6
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:F0AB86C0
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:9857FAE3
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:4F8B72C9
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:2F141B68
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:0D3CE40A
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:84CFEE62
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:51E1A4D8
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:3C282BEA
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:3B812EE0
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:D46ECFD5
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:8CCDAB14
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:842B0AED
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:5C6EBC69
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:55BB2521
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0C5BC70E
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:43982D5E
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:385E2CFD
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:25249477
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:1B927722
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:E07EA07E
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:36BC4740
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:2B82C0BB
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:062AF572
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:66AA0486
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:12EA4DC9
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:F7061E5F
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:45F3AD49
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:43C9D140
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:C0A9D0E7
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:79A70C33
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:938EC881
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:53DF59D1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:409A775B
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:FDC41D2C
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:C7F5E798
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:072F1F69
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:6B55B892
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:48081133
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:FDDD8917
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:98AE08EA
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:5363837B
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:52641FBE
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:4FE30352
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:EF4FB3C5
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:DAE3649B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:B2CD146E
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:7B2BB690
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:47FE7AB7
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride"=1
"FirewallOverride"=1
:Files
C:\ProgramData\Ikibago
:commands
[emptytemp]
[start explorer]
[reboot]
? Clique sur RunFix pour lancer la suppression.
? Poste le rapport.
?G3?-?@¢??@?(TM)©®?
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
Process iexplore.exe killed successfully!
No active process named firefox.exe was found!
Process msnmsgr.exe killed successfully!
No active process named Teatimer.exe was found!
========== SERVICES/DRIVERS ==========
Error: No service named boonty games was found to stop!
Service\Driver key boonty games not found.
========== OTL ==========
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{88e20c72-8089-469b-8bd9-53f2d2d65554} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88e20c72-8089-469b-8bd9-53f2d2d65554}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f592709f-ff4a-4862-b659-4afabda56312} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f592709f-ff4a-4862-b659-4afabda56312}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{88e20c72-8089-469b-8bd9-53f2d2d65554} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88e20c72-8089-469b-8bd9-53f2d2d65554}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f592709f-ff4a-4862-b659-4afabda56312} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f592709f-ff4a-4862-b659-4afabda56312}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{905502AB-1987-46cd-9EC5-42B1E087D319}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{905502AB-1987-46cd-9EC5-42B1E087D319}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{abba5619-7774-4cbc-b0bd-bbb69708dd9c} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{abba5619-7774-4cbc-b0bd-bbb69708dd9c}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Unable to delete ADS C:\ProgramData\TEMP:FC8FFA4E .
Unable to delete ADS C:\ProgramData\TEMP:9AA05701 .
Unable to delete ADS C:\ProgramData\TEMP:880F0FEF .
Unable to delete ADS C:\ProgramData\TEMP:59846E5E .
Unable to delete ADS C:\ProgramData\TEMP:4A1628E5 .
Unable to delete ADS C:\ProgramData\TEMP:315B4A13 .
Unable to delete ADS C:\ProgramData\TEMP:2BC498A4 .
Unable to delete ADS C:\ProgramData\TEMP:07241935 .
Unable to delete ADS C:\ProgramData\TEMP:4363DE71 .
Unable to delete ADS C:\ProgramData\TEMP:9E3E060F .
Unable to delete ADS C:\ProgramData\TEMP:459B4633 .
Unable to delete ADS C:\ProgramData\TEMP:EAFDF1CF .
Unable to delete ADS C:\ProgramData\TEMP:A1D3FEF0 .
Unable to delete ADS C:\ProgramData\TEMP:F84B8DB5 .
Unable to delete ADS C:\ProgramData\TEMP:E895790F .
Unable to delete ADS C:\ProgramData\TEMP:DD04902E .
Unable to delete ADS C:\ProgramData\TEMP:9ACE4E8E .
Unable to delete ADS C:\ProgramData\TEMP:EEB25EAE .
Unable to delete ADS C:\ProgramData\TEMP:5345C8F6 .
Unable to delete ADS C:\ProgramData\TEMP:55E1514E .
Unable to delete ADS C:\ProgramData\TEMP:3D186293 .
Unable to delete ADS C:\ProgramData\TEMP:32A82570 .
Unable to delete ADS C:\ProgramData\TEMP:28CDD861 .
Unable to delete ADS C:\ProgramData\TEMP:D0DCD8D7 .
Unable to delete ADS C:\ProgramData\TEMP:B8384DB6 .
Unable to delete ADS C:\ProgramData\TEMP:7B52659E .
Unable to delete ADS C:\ProgramData\TEMP:5E9B629B .
Unable to delete ADS C:\ProgramData\TEMP:596E2371 .
Unable to delete ADS C:\ProgramData\TEMP:101708D3 .
Unable to delete ADS C:\ProgramData\TEMP:ECFD9449 .
Unable to delete ADS C:\ProgramData\TEMP:ECC979BD .
Unable to delete ADS C:\ProgramData\TEMP:3539CD43 .
Unable to delete ADS C:\ProgramData\TEMP:2495D97A .
Unable to delete ADS C:\ProgramData\TEMP:870649A4 .
Unable to delete ADS C:\ProgramData\TEMP:A2907225 .
Unable to delete ADS C:\ProgramData\TEMP:7FCB9D0D .
Unable to delete ADS C:\ProgramData\TEMP:55818279 .
Unable to delete ADS C:\ProgramData\TEMP:CB16385F .
Unable to delete ADS C:\ProgramData\TEMP:C22674B6 .
Unable to delete ADS C:\ProgramData\TEMP:7881FECE .
Unable to delete ADS C:\ProgramData\TEMP:CF61CE5A .
Unable to delete ADS C:\ProgramData\TEMP:C9FD258B .
Unable to delete ADS C:\ProgramData\TEMP:270A3983 .
Unable to delete ADS C:\ProgramData\TEMP:569CEE83 .
Unable to delete ADS C:\ProgramData\TEMP:C3C72D5F .
Unable to delete ADS C:\ProgramData\TEMP:78E0DF72 .
Unable to delete ADS C:\ProgramData\TEMP:737160C1 .
Unable to delete ADS C:\ProgramData\TEMP:D48500F8 .
Unable to delete ADS C:\ProgramData\TEMP:61FEC5E3 .
Unable to delete ADS C:\ProgramData\TEMP:12D2EB9C .
Unable to delete ADS C:\ProgramData\TEMP:08D8BB20 .
Unable to delete ADS C:\ProgramData\TEMP:F35AE645 .
Unable to delete ADS C:\ProgramData\TEMP:97C4F81F .
Unable to delete ADS C:\ProgramData\TEMP:8DF68137 .
Unable to delete ADS C:\ProgramData\TEMP:0AC32449 .
Unable to delete ADS C:\ProgramData\TEMP:5D351BC6 .
Unable to delete ADS C:\ProgramData\TEMP:1DEE6B65 .
Unable to delete ADS C:\ProgramData\TEMP:88B61AC3 .
Unable to delete ADS C:\ProgramData\TEMP:33EA030E .
Unable to delete ADS C:\ProgramData\TEMP:22741C1F .
Unable to delete ADS C:\ProgramData\TEMP:0DAD93FF .
Unable to delete ADS C:\ProgramData\TEMP:69D59C23 .
Unable to delete ADS C:\ProgramData\TEMP:1B7E2022 .
Unable to delete ADS C:\ProgramData\TEMP:69AF9D20 .
Unable to delete ADS C:\ProgramData\TEMP:0D52F295 .
Unable to delete ADS C:\ProgramData\TEMP:E8CB831A .
Unable to delete ADS C:\ProgramData\TEMP:E7B4296D .
Unable to delete ADS C:\ProgramData\TEMP:A58B27C9 .
Unable to delete ADS C:\ProgramData\TEMP:4FE42FFC .
Unable to delete ADS C:\ProgramData\TEMP:3D36932D .
Unable to delete ADS C:\ProgramData\TEMP:CD9109D4 .
Unable to delete ADS C:\ProgramData\TEMP:C0A2E219 .
Unable to delete ADS C:\ProgramData\TEMP:A4076A3B .
Unable to delete ADS C:\ProgramData\TEMP:6710EF08 .
Unable to delete ADS C:\ProgramData\TEMP:DE9F4320 .
Unable to delete ADS C:\ProgramData\TEMP:5FA4CB99 .
Unable to delete ADS C:\ProgramData\TEMP:A5FC8FA1 .
Unable to delete ADS C:\ProgramData\TEMP:A00BCDEF .
Unable to delete ADS C:\ProgramData\TEMP:23430C4C .
Unable to delete ADS C:\ProgramData\TEMP:FEEEFFAD .
Unable to delete ADS C:\ProgramData\TEMP:F69E3A97 .
Unable to delete ADS C:\ProgramData\TEMP:D8F9D810 .
Unable to delete ADS C:\ProgramData\TEMP:A6CDBCAC .
Unable to delete ADS C:\ProgramData\TEMP:93D985FC .
Unable to delete ADS C:\ProgramData\TEMP:3DF63AD7 .
Unable to delete ADS C:\ProgramData\TEMP:D6A4A911 .
Unable to delete ADS C:\ProgramData\TEMP:2EA99C48 .
Unable to delete ADS C:\ProgramData\TEMP:058A7351 .
Unable to delete ADS C:\ProgramData\TEMP:CA8D6B60 .
Unable to delete ADS C:\ProgramData\TEMP:C10635F6 .
Unable to delete ADS C:\ProgramData\TEMP:9331E9D2 .
Unable to delete ADS C:\ProgramData\TEMP:6E86D926 .
Unable to delete ADS C:\ProgramData\TEMP:6425A235 .
Unable to delete ADS C:\ProgramData\TEMP:61AF2B29 .
Unable to delete ADS C:\ProgramData\TEMP:523B97A0 .
Unable to delete ADS C:\ProgramData\TEMP:32ED8AE7 .
Unable to delete ADS C:\ProgramData\TEMP:E91ADC66 .
Unable to delete ADS C:\ProgramData\TEMP:700B9342 .
Unable to delete ADS C:\ProgramData\TEMP:551BED5F .
Unable to delete ADS C:\ProgramData\TEMP:1181620C .
Unable to delete ADS C:\ProgramData\TEMP:B18C4339 .
Unable to delete ADS C:\ProgramData\TEMP:966CEAE7 .
Unable to delete ADS C:\ProgramData\TEMP:5025C6E4 .
Unable to delete ADS C:\ProgramData\TEMP:3FD496E1 .
Unable to delete ADS C:\ProgramData\TEMP:17C48B08 .
Unable to delete ADS C:\ProgramData\TEMP:AA8AD2BF .
Unable to delete ADS C:\ProgramData\TEMP:8944C195 .
Unable to delete ADS C:\ProgramData\TEMP:3991CD7D .
Unable to delete ADS C:\ProgramData\TEMP:1C6CB897 .
Unable to delete ADS C:\ProgramData\TEMP:D46D2E5A .
Unable to delete ADS C:\ProgramData\TEMP:D2032EBB .
Unable to delete ADS C:\ProgramData\TEMP:EDC744FB .
Unable to delete ADS C:\ProgramData\TEMP:85A0F6D2 .
Unable to delete ADS C:\ProgramData\TEMP:405D842B .
Unable to delete ADS C:\ProgramData\TEMP:ED2998F5 .
Unable to delete ADS C:\ProgramData\TEMP:D02FBAEC .
Unable to delete ADS C:\ProgramData\TEMP:A2C4E5BC .
Unable to delete ADS C:\ProgramData\TEMP:16C16B18 .
Unable to delete ADS C:\ProgramData\TEMP:FD000392 .
Unable to delete ADS C:\ProgramData\TEMP:EA701346 .
Unable to delete ADS C:\ProgramData\TEMP:E7B49FBF .
Unable to delete ADS C:\ProgramData\TEMP:DC21D414 .
Unable to delete ADS C:\ProgramData\TEMP:A3251D01 .
Unable to delete ADS C:\ProgramData\TEMP:9F38BF31 .
Unable to delete ADS C:\ProgramData\TEMP:76A59E49 .
Unable to delete ADS C:\ProgramData\TEMP:054F0F17 .
Unable to delete ADS C:\ProgramData\TEMP:92A815D8 .
Unable to delete ADS C:\ProgramData\TEMP:7CEDF9F3 .
Unable to delete ADS C:\ProgramData\TEMP:561B1D2B .
Unable to delete ADS C:\ProgramData\TEMP:6B05AF40 .
Unable to delete ADS C:\ProgramData\TEMP:6017A808 .
Unable to delete ADS C:\ProgramData\TEMP:4B1195DD .
Unable to delete ADS C:\ProgramData\TEMP:1A8BB29B .
Unable to delete ADS C:\ProgramData\TEMP:CEF2A14E .
Unable to delete ADS C:\ProgramData\TEMP:C07A6A6B .
Unable to delete ADS C:\ProgramData\TEMP:ADE67221 .
Unable to delete ADS C:\ProgramData\TEMP:A02025CE .
Unable to delete ADS C:\ProgramData\TEMP:0DFE2AE1 .
Unable to delete ADS C:\ProgramData\TEMP:059167AF .
Unable to delete ADS C:\ProgramData\TEMP:F14D1F80 .
Unable to delete ADS C:\ProgramData\TEMP:E945C214 .
Unable to delete ADS C:\ProgramData\TEMP:BC38C00C .
Unable to delete ADS C:\ProgramData\TEMP:B3942462 .
Unable to delete ADS C:\ProgramData\TEMP:2E49FF93 .
Unable to delete ADS C:\ProgramData\TEMP:FACB65E7 .
Unable to delete ADS C:\ProgramData\TEMP:EE39C93C .
Unable to delete ADS C:\ProgramData\TEMP:E80802C7 .
Unable to delete ADS C:\ProgramData\TEMP:D5E0200E .
Unable to delete ADS C:\ProgramData\TEMP:D0668210 .
Unable to delete ADS C:\ProgramData\TEMP:B845F669 .
Unable to delete ADS C:\ProgramData\TEMP:603FD11D .
Unable to delete ADS C:\ProgramData\TEMP:2B1EA607 .
Unable to delete ADS C:\ProgramData\TEMP:164FA86E .
Unable to delete ADS C:\ProgramData\TEMP:0EC7A545 .
Unable to delete ADS C:\ProgramData\TEMP:D2249B7E .
Unable to delete ADS C:\ProgramData\TEMP:D0D17155 .
Unable to delete ADS C:\ProgramData\TEMP:A745DB5D .
Unable to delete ADS C:\ProgramData\TEMP:943E8182 .
Unable to delete ADS C:\ProgramData\TEMP:61F0C8FB .
Unable to delete ADS C:\ProgramData\TEMP:517B507A .
Unable to delete ADS C:\ProgramData\TEMP:2AFE7797 .
Unable to delete ADS C:\ProgramData\TEMP:02B823FE .
Unable to delete ADS C:\ProgramData\TEMP:FED25C29 .
Unable to delete ADS C:\ProgramData\TEMP:FECEF728 .
Unable to delete ADS C:\ProgramData\TEMP:FB97DB91 .
Unable to delete ADS C:\ProgramData\TEMP:DB77E2C4 .
Unable to delete ADS C:\ProgramData\TEMP:C928F3BE .
Unable to delete ADS C:\ProgramData\TEMP:AF54CFFD .
Unable to delete ADS C:\ProgramData\TEMP:2F384CF4 .
Unable to delete ADS C:\ProgramData\TEMP:2CDB9CA3 .
Unable to delete ADS C:\ProgramData\TEMP:2B885D7E .
Unable to delete ADS C:\ProgramData\TEMP:206470A5 .
Unable to delete ADS C:\ProgramData\TEMP:0C9CD455 .
Unable to delete ADS C:\ProgramData\TEMP:EC855C73 .
Unable to delete ADS C:\ProgramData\TEMP:EB40BC91 .
Unable to delete ADS C:\ProgramData\TEMP:E027789A .
Unable to delete ADS C:\ProgramData\TEMP:D4BB0AD6 .
Unable to delete ADS C:\ProgramData\TEMP:9DF07E8F .
Unable to delete ADS C:\ProgramData\TEMP:71FA8B7F .
Unable to delete ADS C:\ProgramData\TEMP:5E413CD6 .
Unable to delete ADS C:\ProgramData\TEMP:537E6E55 .
Unable to delete ADS C:\ProgramData\TEMP:425759C6 .
Unable to delete ADS C:\ProgramData\TEMP:33384BC0 .
Unable to delete ADS C:\ProgramData\TEMP:FC98D33A .
Unable to delete ADS C:\ProgramData\TEMP:D2593961 .
Unable to delete ADS C:\ProgramData\TEMP:8AC7B784 .
Unable to delete ADS C:\ProgramData\TEMP:89C28CF6 .
Unable to delete ADS C:\ProgramData\TEMP:7FD903D7 .
Unable to delete ADS C:\ProgramData\TEMP:5EF1AD34 .
Unable to delete ADS C:\ProgramData\TEMP:55C54F7C .
Unable to delete ADS C:\ProgramData\TEMP:2832349A .
Unable to delete ADS C:\ProgramData\TEMP:FC2D0F32 .
Unable to delete ADS C:\ProgramData\TEMP:E4E43015 .
Unable to delete ADS C:\ProgramData\TEMP:DF3CC840 .
Unable to delete ADS C:\ProgramData\TEMP:CFDE7852 .
Unable to delete ADS C:\ProgramData\TEMP:A7DA2BCD .
Unable to delete ADS C:\ProgramData\TEMP:9E76E7F3 .
Unable to delete ADS C:\ProgramData\TEMP:957E9765 .
Unable to delete ADS C:\ProgramData\TEMP:89CF6F9C .
Unable to delete ADS C:\ProgramData\TEMP:6AF67671 .
Unable to delete ADS C:\ProgramData\TEMP:5FD47318 .
Unable to delete ADS C:\ProgramData\TEMP:51F17BB8 .
Unable to delete ADS C:\ProgramData\TEMP:3A47A0EB .
Unable to delete ADS C:\ProgramData\TEMP:38B32B54 .
Unable to delete ADS C:\ProgramData\TEMP:37994DBE .
Unable to delete ADS C:\ProgramData\TEMP:0C988F7D .
Unable to delete ADS C:\ProgramData\TEMP:02BC319B .
Unable to delete ADS C:\ProgramData\TEMP:FC2E567F .
Unable to delete ADS C:\ProgramData\TEMP:F45F3031 .
Unable to delete ADS C:\ProgramData\TEMP:EB5BDBB0 .
Unable to delete ADS C:\ProgramData\TEMP:BB71BBA2 .
Unable to delete ADS C:\ProgramData\TEMP:B1FBA7E1 .
Unable to delete ADS C:\ProgramData\TEMP:918B7566 .
Unable to delete ADS C:\ProgramData\TEMP:896E1EFF .
Unable to delete ADS C:\ProgramData\TEMP:5FFC2819 .
Unable to delete ADS C:\ProgramData\TEMP:0E684AC9 .
Unable to delete ADS C:\ProgramData\TEMP:F0762150 .
Unable to delete ADS C:\ProgramData\TEMP:D6E29A14 .
Unable to delete ADS C:\ProgramData\TEMP:BDF08FAF .
Unable to delete ADS C:\ProgramData\TEMP:9E9A3410 .
Unable to delete ADS C:\ProgramData\TEMP:8DB31C20 .
Unable to delete ADS C:\ProgramData\TEMP:6FE17A89 .
Unable to delete ADS C:\ProgramData\TEMP:4C528C86 .
Unable to delete ADS C:\ProgramData\TEMP:35A81752 .
Unable to delete ADS C:\ProgramData\TEMP:237E4B91 .
Unable to delete ADS C:\ProgramData\TEMP:F2958F3A .
Unable to delete ADS C:\ProgramData\TEMP:80F63EC3 .
Unable to delete ADS C:\ProgramData\TEMP:6444B424 .
Unable to delete ADS C:\ProgramData\TEMP:35FAD15D .
Unable to delete ADS C:\ProgramData\TEMP:00F7B10F .
Unable to delete ADS C:\ProgramData\TEMP:E1CC2D5E .
Unable to delete ADS C:\ProgramData\TEMP:9BFB769D .
Unable to delete ADS C:\ProgramData\TEMP:59286A3A .
Unable to delete ADS C:\ProgramData\TEMP:538B96B5 .
Unable to delete ADS C:\ProgramData\TEMP:471AD3D0 .
Unable to delete ADS C:\ProgramData\TEMP:260575F1 .
Unable to delete ADS C:\ProgramData\TEMP:DFC3B090 .
Unable to delete ADS C:\ProgramData\TEMP:C36B1175 .
Unable to delete ADS C:\ProgramData\TEMP:710F4DBF .
Unable to delete ADS C:\ProgramData\TEMP:4DCAC4BC .
Unable to delete ADS C:\ProgramData\TEMP:177313FB .
Unable to delete ADS C:\ProgramData\TEMP:F2AF86D9 .
Unable to delete ADS C:\ProgramData\TEMP:E3CEEC4C .
Unable to delete ADS C:\ProgramData\TEMP:D92485C9 .
Unable to delete ADS C:\ProgramData\TEMP:D4D3884D .
Unable to delete ADS C:\ProgramData\TEMP:CB0FEE2B .
Unable to delete ADS C:\ProgramData\TEMP:B4980368 .
Unable to delete ADS C:\ProgramData\TEMP:8F067037 .
Unable to delete ADS C:\ProgramData\TEMP:7AA6FC81 .
Unable to delete ADS C:\ProgramData\TEMP:41D1C7CB .
Unable to delete ADS C:\ProgramData\TEMP:3BCA993F .
Unable to delete ADS C:\ProgramData\TEMP:FBE5FDB9 .
Unable to delete ADS C:\ProgramData\TEMP:A0A7408F .
Unable to delete ADS C:\ProgramData\TEMP:4CF76F21 .
Unable to delete ADS C:\ProgramData\TEMP:48977386 .
Unable to delete ADS C:\ProgramData\TEMP:47A24D4B .
Unable to delete ADS C:\ProgramData\TEMP:45DDA801 .
Unable to delete ADS C:\ProgramData\TEMP:2F0007D6 .
Unable to delete ADS C:\ProgramData\TEMP:F0AB86C0 .
Unable to delete ADS C:\ProgramData\TEMP:9857FAE3 .
Unable to delete ADS C:\ProgramData\TEMP:4F8B72C9 .
Unable to delete ADS C:\ProgramData\TEMP:2F141B68 .
Unable to delete ADS C:\ProgramData\TEMP:0D3CE40A .
Unable to delete ADS C:\ProgramData\TEMP:84CFEE62 .
Unable to delete ADS C:\ProgramData\TEMP:8247A199 .
Unable to delete ADS C:\ProgramData\TEMP:51E1A4D8 .
Unable to delete ADS C:\ProgramData\TEMP:3C282BEA .
Unable to delete ADS C:\ProgramData\TEMP:3B812EE0 .
Unable to delete ADS C:\ProgramData\TEMP:D46ECFD5 .
Unable to delete ADS C:\ProgramData\TEMP:8CCDAB14 .
Unable to delete ADS C:\ProgramData\TEMP:842B0AED .
Unable to delete ADS C:\ProgramData\TEMP:5C6EBC69 .
Unable to delete ADS C:\ProgramData\TEMP:55BB2521 .
Unable to delete ADS C:\ProgramData\TEMP:0C5BC70E .
Unable to delete ADS C:\ProgramData\TEMP:43982D5E .
Unable to delete ADS C:\ProgramData\TEMP:385E2CFD .
Unable to delete ADS C:\ProgramData\TEMP:25249477 .
Unable to delete ADS C:\ProgramData\TEMP:1B927722 .
Unable to delete ADS C:\ProgramData\TEMP:E07EA07E .
Unable to delete ADS C:\ProgramData\TEMP:36BC4740 .
Unable to delete ADS C:\ProgramData\TEMP:2B82C0BB .
Unable to delete ADS C:\ProgramData\TEMP:062AF572 .
Unable to delete ADS C:\ProgramData\TEMP:66AA0486 .
Unable to delete ADS C:\ProgramData\TEMP:12EA4DC9 .
Unable to delete ADS C:\ProgramData\TEMP:F7061E5F .
Unable to delete ADS C:\ProgramData\TEMP:45F3AD49 .
Unable to delete ADS C:\ProgramData\TEMP:43C9D140 .
Unable to delete ADS C:\ProgramData\TEMP:40D8F125 .
Unable to delete ADS C:\ProgramData\TEMP:C0A9D0E7 .
Unable to delete ADS C:\ProgramData\TEMP:79A70C33 .
Unable to delete ADS C:\ProgramData\TEMP:938EC881 .
Unable to delete ADS C:\ProgramData\TEMP:53DF59D1 .
Unable to delete ADS C:\ProgramData\TEMP:409A775B .
Unable to delete ADS C:\ProgramData\TEMP:FDC41D2C .
Unable to delete ADS C:\ProgramData\TEMP:C7F5E798 .
Unable to delete ADS C:\ProgramData\TEMP:072F1F69 .
Unable to delete ADS C:\ProgramData\TEMP:6B55B892 .
Unable to delete ADS C:\ProgramData\TEMP:50636E35 .
Unable to delete ADS C:\ProgramData\TEMP:48081133 .
Unable to delete ADS C:\ProgramData\TEMP:FDDD8917 .
Unable to delete ADS C:\ProgramData\TEMP:98AE08EA .
Unable to delete ADS C:\ProgramData\TEMP:5363837B .
Unable to delete ADS C:\ProgramData\TEMP:52641FBE .
Unable to delete ADS C:\ProgramData\TEMP:4FE30352 .
Unable to delete ADS C:\ProgramData\TEMP:EF4FB3C5 .
Unable to delete ADS C:\ProgramData\TEMP:DAE3649B .
Unable to delete ADS C:\ProgramData\TEMP:B2CD146E .
Unable to delete ADS C:\ProgramData\TEMP:7B2BB690 .
Unable to delete ADS C:\ProgramData\TEMP:47FE7AB7 .
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AntiVirusOverride"|1 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirewallOverride"|1 /E : value set successfully!
========== FILES ==========
File\Folder C:\ProgramData\Ikibago not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Marie
->Temp folder emptied: 570093 bytes
->Temporary Internet Files folder emptied: 3262102 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 434 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 52118 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 4,00 mb
OTL by OldTimer - Version 3.1.37.2 log created on 03232010_212748
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== PROCESSES ==========
No active process named explorer.exe was found!
Process iexplore.exe killed successfully!
No active process named firefox.exe was found!
Process msnmsgr.exe killed successfully!
No active process named Teatimer.exe was found!
========== SERVICES/DRIVERS ==========
Error: No service named boonty games was found to stop!
Service\Driver key boonty games not found.
========== OTL ==========
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{88e20c72-8089-469b-8bd9-53f2d2d65554} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88e20c72-8089-469b-8bd9-53f2d2d65554}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f592709f-ff4a-4862-b659-4afabda56312} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f592709f-ff4a-4862-b659-4afabda56312}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{88e20c72-8089-469b-8bd9-53f2d2d65554} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88e20c72-8089-469b-8bd9-53f2d2d65554}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f592709f-ff4a-4862-b659-4afabda56312} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f592709f-ff4a-4862-b659-4afabda56312}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{905502AB-1987-46cd-9EC5-42B1E087D319}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{905502AB-1987-46cd-9EC5-42B1E087D319}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{abba5619-7774-4cbc-b0bd-bbb69708dd9c} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{abba5619-7774-4cbc-b0bd-bbb69708dd9c}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Unable to delete ADS C:\ProgramData\TEMP:FC8FFA4E .
Unable to delete ADS C:\ProgramData\TEMP:9AA05701 .
Unable to delete ADS C:\ProgramData\TEMP:880F0FEF .
Unable to delete ADS C:\ProgramData\TEMP:59846E5E .
Unable to delete ADS C:\ProgramData\TEMP:4A1628E5 .
Unable to delete ADS C:\ProgramData\TEMP:315B4A13 .
Unable to delete ADS C:\ProgramData\TEMP:2BC498A4 .
Unable to delete ADS C:\ProgramData\TEMP:07241935 .
Unable to delete ADS C:\ProgramData\TEMP:4363DE71 .
Unable to delete ADS C:\ProgramData\TEMP:9E3E060F .
Unable to delete ADS C:\ProgramData\TEMP:459B4633 .
Unable to delete ADS C:\ProgramData\TEMP:EAFDF1CF .
Unable to delete ADS C:\ProgramData\TEMP:A1D3FEF0 .
Unable to delete ADS C:\ProgramData\TEMP:F84B8DB5 .
Unable to delete ADS C:\ProgramData\TEMP:E895790F .
Unable to delete ADS C:\ProgramData\TEMP:DD04902E .
Unable to delete ADS C:\ProgramData\TEMP:9ACE4E8E .
Unable to delete ADS C:\ProgramData\TEMP:EEB25EAE .
Unable to delete ADS C:\ProgramData\TEMP:5345C8F6 .
Unable to delete ADS C:\ProgramData\TEMP:55E1514E .
Unable to delete ADS C:\ProgramData\TEMP:3D186293 .
Unable to delete ADS C:\ProgramData\TEMP:32A82570 .
Unable to delete ADS C:\ProgramData\TEMP:28CDD861 .
Unable to delete ADS C:\ProgramData\TEMP:D0DCD8D7 .
Unable to delete ADS C:\ProgramData\TEMP:B8384DB6 .
Unable to delete ADS C:\ProgramData\TEMP:7B52659E .
Unable to delete ADS C:\ProgramData\TEMP:5E9B629B .
Unable to delete ADS C:\ProgramData\TEMP:596E2371 .
Unable to delete ADS C:\ProgramData\TEMP:101708D3 .
Unable to delete ADS C:\ProgramData\TEMP:ECFD9449 .
Unable to delete ADS C:\ProgramData\TEMP:ECC979BD .
Unable to delete ADS C:\ProgramData\TEMP:3539CD43 .
Unable to delete ADS C:\ProgramData\TEMP:2495D97A .
Unable to delete ADS C:\ProgramData\TEMP:870649A4 .
Unable to delete ADS C:\ProgramData\TEMP:A2907225 .
Unable to delete ADS C:\ProgramData\TEMP:7FCB9D0D .
Unable to delete ADS C:\ProgramData\TEMP:55818279 .
Unable to delete ADS C:\ProgramData\TEMP:CB16385F .
Unable to delete ADS C:\ProgramData\TEMP:C22674B6 .
Unable to delete ADS C:\ProgramData\TEMP:7881FECE .
Unable to delete ADS C:\ProgramData\TEMP:CF61CE5A .
Unable to delete ADS C:\ProgramData\TEMP:C9FD258B .
Unable to delete ADS C:\ProgramData\TEMP:270A3983 .
Unable to delete ADS C:\ProgramData\TEMP:569CEE83 .
Unable to delete ADS C:\ProgramData\TEMP:C3C72D5F .
Unable to delete ADS C:\ProgramData\TEMP:78E0DF72 .
Unable to delete ADS C:\ProgramData\TEMP:737160C1 .
Unable to delete ADS C:\ProgramData\TEMP:D48500F8 .
Unable to delete ADS C:\ProgramData\TEMP:61FEC5E3 .
Unable to delete ADS C:\ProgramData\TEMP:12D2EB9C .
Unable to delete ADS C:\ProgramData\TEMP:08D8BB20 .
Unable to delete ADS C:\ProgramData\TEMP:F35AE645 .
Unable to delete ADS C:\ProgramData\TEMP:97C4F81F .
Unable to delete ADS C:\ProgramData\TEMP:8DF68137 .
Unable to delete ADS C:\ProgramData\TEMP:0AC32449 .
Unable to delete ADS C:\ProgramData\TEMP:5D351BC6 .
Unable to delete ADS C:\ProgramData\TEMP:1DEE6B65 .
Unable to delete ADS C:\ProgramData\TEMP:88B61AC3 .
Unable to delete ADS C:\ProgramData\TEMP:33EA030E .
Unable to delete ADS C:\ProgramData\TEMP:22741C1F .
Unable to delete ADS C:\ProgramData\TEMP:0DAD93FF .
Unable to delete ADS C:\ProgramData\TEMP:69D59C23 .
Unable to delete ADS C:\ProgramData\TEMP:1B7E2022 .
Unable to delete ADS C:\ProgramData\TEMP:69AF9D20 .
Unable to delete ADS C:\ProgramData\TEMP:0D52F295 .
Unable to delete ADS C:\ProgramData\TEMP:E8CB831A .
Unable to delete ADS C:\ProgramData\TEMP:E7B4296D .
Unable to delete ADS C:\ProgramData\TEMP:A58B27C9 .
Unable to delete ADS C:\ProgramData\TEMP:4FE42FFC .
Unable to delete ADS C:\ProgramData\TEMP:3D36932D .
Unable to delete ADS C:\ProgramData\TEMP:CD9109D4 .
Unable to delete ADS C:\ProgramData\TEMP:C0A2E219 .
Unable to delete ADS C:\ProgramData\TEMP:A4076A3B .
Unable to delete ADS C:\ProgramData\TEMP:6710EF08 .
Unable to delete ADS C:\ProgramData\TEMP:DE9F4320 .
Unable to delete ADS C:\ProgramData\TEMP:5FA4CB99 .
Unable to delete ADS C:\ProgramData\TEMP:A5FC8FA1 .
Unable to delete ADS C:\ProgramData\TEMP:A00BCDEF .
Unable to delete ADS C:\ProgramData\TEMP:23430C4C .
Unable to delete ADS C:\ProgramData\TEMP:FEEEFFAD .
Unable to delete ADS C:\ProgramData\TEMP:F69E3A97 .
Unable to delete ADS C:\ProgramData\TEMP:D8F9D810 .
Unable to delete ADS C:\ProgramData\TEMP:A6CDBCAC .
Unable to delete ADS C:\ProgramData\TEMP:93D985FC .
Unable to delete ADS C:\ProgramData\TEMP:3DF63AD7 .
Unable to delete ADS C:\ProgramData\TEMP:D6A4A911 .
Unable to delete ADS C:\ProgramData\TEMP:2EA99C48 .
Unable to delete ADS C:\ProgramData\TEMP:058A7351 .
Unable to delete ADS C:\ProgramData\TEMP:CA8D6B60 .
Unable to delete ADS C:\ProgramData\TEMP:C10635F6 .
Unable to delete ADS C:\ProgramData\TEMP:9331E9D2 .
Unable to delete ADS C:\ProgramData\TEMP:6E86D926 .
Unable to delete ADS C:\ProgramData\TEMP:6425A235 .
Unable to delete ADS C:\ProgramData\TEMP:61AF2B29 .
Unable to delete ADS C:\ProgramData\TEMP:523B97A0 .
Unable to delete ADS C:\ProgramData\TEMP:32ED8AE7 .
Unable to delete ADS C:\ProgramData\TEMP:E91ADC66 .
Unable to delete ADS C:\ProgramData\TEMP:700B9342 .
Unable to delete ADS C:\ProgramData\TEMP:551BED5F .
Unable to delete ADS C:\ProgramData\TEMP:1181620C .
Unable to delete ADS C:\ProgramData\TEMP:B18C4339 .
Unable to delete ADS C:\ProgramData\TEMP:966CEAE7 .
Unable to delete ADS C:\ProgramData\TEMP:5025C6E4 .
Unable to delete ADS C:\ProgramData\TEMP:3FD496E1 .
Unable to delete ADS C:\ProgramData\TEMP:17C48B08 .
Unable to delete ADS C:\ProgramData\TEMP:AA8AD2BF .
Unable to delete ADS C:\ProgramData\TEMP:8944C195 .
Unable to delete ADS C:\ProgramData\TEMP:3991CD7D .
Unable to delete ADS C:\ProgramData\TEMP:1C6CB897 .
Unable to delete ADS C:\ProgramData\TEMP:D46D2E5A .
Unable to delete ADS C:\ProgramData\TEMP:D2032EBB .
Unable to delete ADS C:\ProgramData\TEMP:EDC744FB .
Unable to delete ADS C:\ProgramData\TEMP:85A0F6D2 .
Unable to delete ADS C:\ProgramData\TEMP:405D842B .
Unable to delete ADS C:\ProgramData\TEMP:ED2998F5 .
Unable to delete ADS C:\ProgramData\TEMP:D02FBAEC .
Unable to delete ADS C:\ProgramData\TEMP:A2C4E5BC .
Unable to delete ADS C:\ProgramData\TEMP:16C16B18 .
Unable to delete ADS C:\ProgramData\TEMP:FD000392 .
Unable to delete ADS C:\ProgramData\TEMP:EA701346 .
Unable to delete ADS C:\ProgramData\TEMP:E7B49FBF .
Unable to delete ADS C:\ProgramData\TEMP:DC21D414 .
Unable to delete ADS C:\ProgramData\TEMP:A3251D01 .
Unable to delete ADS C:\ProgramData\TEMP:9F38BF31 .
Unable to delete ADS C:\ProgramData\TEMP:76A59E49 .
Unable to delete ADS C:\ProgramData\TEMP:054F0F17 .
Unable to delete ADS C:\ProgramData\TEMP:92A815D8 .
Unable to delete ADS C:\ProgramData\TEMP:7CEDF9F3 .
Unable to delete ADS C:\ProgramData\TEMP:561B1D2B .
Unable to delete ADS C:\ProgramData\TEMP:6B05AF40 .
Unable to delete ADS C:\ProgramData\TEMP:6017A808 .
Unable to delete ADS C:\ProgramData\TEMP:4B1195DD .
Unable to delete ADS C:\ProgramData\TEMP:1A8BB29B .
Unable to delete ADS C:\ProgramData\TEMP:CEF2A14E .
Unable to delete ADS C:\ProgramData\TEMP:C07A6A6B .
Unable to delete ADS C:\ProgramData\TEMP:ADE67221 .
Unable to delete ADS C:\ProgramData\TEMP:A02025CE .
Unable to delete ADS C:\ProgramData\TEMP:0DFE2AE1 .
Unable to delete ADS C:\ProgramData\TEMP:059167AF .
Unable to delete ADS C:\ProgramData\TEMP:F14D1F80 .
Unable to delete ADS C:\ProgramData\TEMP:E945C214 .
Unable to delete ADS C:\ProgramData\TEMP:BC38C00C .
Unable to delete ADS C:\ProgramData\TEMP:B3942462 .
Unable to delete ADS C:\ProgramData\TEMP:2E49FF93 .
Unable to delete ADS C:\ProgramData\TEMP:FACB65E7 .
Unable to delete ADS C:\ProgramData\TEMP:EE39C93C .
Unable to delete ADS C:\ProgramData\TEMP:E80802C7 .
Unable to delete ADS C:\ProgramData\TEMP:D5E0200E .
Unable to delete ADS C:\ProgramData\TEMP:D0668210 .
Unable to delete ADS C:\ProgramData\TEMP:B845F669 .
Unable to delete ADS C:\ProgramData\TEMP:603FD11D .
Unable to delete ADS C:\ProgramData\TEMP:2B1EA607 .
Unable to delete ADS C:\ProgramData\TEMP:164FA86E .
Unable to delete ADS C:\ProgramData\TEMP:0EC7A545 .
Unable to delete ADS C:\ProgramData\TEMP:D2249B7E .
Unable to delete ADS C:\ProgramData\TEMP:D0D17155 .
Unable to delete ADS C:\ProgramData\TEMP:A745DB5D .
Unable to delete ADS C:\ProgramData\TEMP:943E8182 .
Unable to delete ADS C:\ProgramData\TEMP:61F0C8FB .
Unable to delete ADS C:\ProgramData\TEMP:517B507A .
Unable to delete ADS C:\ProgramData\TEMP:2AFE7797 .
Unable to delete ADS C:\ProgramData\TEMP:02B823FE .
Unable to delete ADS C:\ProgramData\TEMP:FED25C29 .
Unable to delete ADS C:\ProgramData\TEMP:FECEF728 .
Unable to delete ADS C:\ProgramData\TEMP:FB97DB91 .
Unable to delete ADS C:\ProgramData\TEMP:DB77E2C4 .
Unable to delete ADS C:\ProgramData\TEMP:C928F3BE .
Unable to delete ADS C:\ProgramData\TEMP:AF54CFFD .
Unable to delete ADS C:\ProgramData\TEMP:2F384CF4 .
Unable to delete ADS C:\ProgramData\TEMP:2CDB9CA3 .
Unable to delete ADS C:\ProgramData\TEMP:2B885D7E .
Unable to delete ADS C:\ProgramData\TEMP:206470A5 .
Unable to delete ADS C:\ProgramData\TEMP:0C9CD455 .
Unable to delete ADS C:\ProgramData\TEMP:EC855C73 .
Unable to delete ADS C:\ProgramData\TEMP:EB40BC91 .
Unable to delete ADS C:\ProgramData\TEMP:E027789A .
Unable to delete ADS C:\ProgramData\TEMP:D4BB0AD6 .
Unable to delete ADS C:\ProgramData\TEMP:9DF07E8F .
Unable to delete ADS C:\ProgramData\TEMP:71FA8B7F .
Unable to delete ADS C:\ProgramData\TEMP:5E413CD6 .
Unable to delete ADS C:\ProgramData\TEMP:537E6E55 .
Unable to delete ADS C:\ProgramData\TEMP:425759C6 .
Unable to delete ADS C:\ProgramData\TEMP:33384BC0 .
Unable to delete ADS C:\ProgramData\TEMP:FC98D33A .
Unable to delete ADS C:\ProgramData\TEMP:D2593961 .
Unable to delete ADS C:\ProgramData\TEMP:8AC7B784 .
Unable to delete ADS C:\ProgramData\TEMP:89C28CF6 .
Unable to delete ADS C:\ProgramData\TEMP:7FD903D7 .
Unable to delete ADS C:\ProgramData\TEMP:5EF1AD34 .
Unable to delete ADS C:\ProgramData\TEMP:55C54F7C .
Unable to delete ADS C:\ProgramData\TEMP:2832349A .
Unable to delete ADS C:\ProgramData\TEMP:FC2D0F32 .
Unable to delete ADS C:\ProgramData\TEMP:E4E43015 .
Unable to delete ADS C:\ProgramData\TEMP:DF3CC840 .
Unable to delete ADS C:\ProgramData\TEMP:CFDE7852 .
Unable to delete ADS C:\ProgramData\TEMP:A7DA2BCD .
Unable to delete ADS C:\ProgramData\TEMP:9E76E7F3 .
Unable to delete ADS C:\ProgramData\TEMP:957E9765 .
Unable to delete ADS C:\ProgramData\TEMP:89CF6F9C .
Unable to delete ADS C:\ProgramData\TEMP:6AF67671 .
Unable to delete ADS C:\ProgramData\TEMP:5FD47318 .
Unable to delete ADS C:\ProgramData\TEMP:51F17BB8 .
Unable to delete ADS C:\ProgramData\TEMP:3A47A0EB .
Unable to delete ADS C:\ProgramData\TEMP:38B32B54 .
Unable to delete ADS C:\ProgramData\TEMP:37994DBE .
Unable to delete ADS C:\ProgramData\TEMP:0C988F7D .
Unable to delete ADS C:\ProgramData\TEMP:02BC319B .
Unable to delete ADS C:\ProgramData\TEMP:FC2E567F .
Unable to delete ADS C:\ProgramData\TEMP:F45F3031 .
Unable to delete ADS C:\ProgramData\TEMP:EB5BDBB0 .
Unable to delete ADS C:\ProgramData\TEMP:BB71BBA2 .
Unable to delete ADS C:\ProgramData\TEMP:B1FBA7E1 .
Unable to delete ADS C:\ProgramData\TEMP:918B7566 .
Unable to delete ADS C:\ProgramData\TEMP:896E1EFF .
Unable to delete ADS C:\ProgramData\TEMP:5FFC2819 .
Unable to delete ADS C:\ProgramData\TEMP:0E684AC9 .
Unable to delete ADS C:\ProgramData\TEMP:F0762150 .
Unable to delete ADS C:\ProgramData\TEMP:D6E29A14 .
Unable to delete ADS C:\ProgramData\TEMP:BDF08FAF .
Unable to delete ADS C:\ProgramData\TEMP:9E9A3410 .
Unable to delete ADS C:\ProgramData\TEMP:8DB31C20 .
Unable to delete ADS C:\ProgramData\TEMP:6FE17A89 .
Unable to delete ADS C:\ProgramData\TEMP:4C528C86 .
Unable to delete ADS C:\ProgramData\TEMP:35A81752 .
Unable to delete ADS C:\ProgramData\TEMP:237E4B91 .
Unable to delete ADS C:\ProgramData\TEMP:F2958F3A .
Unable to delete ADS C:\ProgramData\TEMP:80F63EC3 .
Unable to delete ADS C:\ProgramData\TEMP:6444B424 .
Unable to delete ADS C:\ProgramData\TEMP:35FAD15D .
Unable to delete ADS C:\ProgramData\TEMP:00F7B10F .
Unable to delete ADS C:\ProgramData\TEMP:E1CC2D5E .
Unable to delete ADS C:\ProgramData\TEMP:9BFB769D .
Unable to delete ADS C:\ProgramData\TEMP:59286A3A .
Unable to delete ADS C:\ProgramData\TEMP:538B96B5 .
Unable to delete ADS C:\ProgramData\TEMP:471AD3D0 .
Unable to delete ADS C:\ProgramData\TEMP:260575F1 .
Unable to delete ADS C:\ProgramData\TEMP:DFC3B090 .
Unable to delete ADS C:\ProgramData\TEMP:C36B1175 .
Unable to delete ADS C:\ProgramData\TEMP:710F4DBF .
Unable to delete ADS C:\ProgramData\TEMP:4DCAC4BC .
Unable to delete ADS C:\ProgramData\TEMP:177313FB .
Unable to delete ADS C:\ProgramData\TEMP:F2AF86D9 .
Unable to delete ADS C:\ProgramData\TEMP:E3CEEC4C .
Unable to delete ADS C:\ProgramData\TEMP:D92485C9 .
Unable to delete ADS C:\ProgramData\TEMP:D4D3884D .
Unable to delete ADS C:\ProgramData\TEMP:CB0FEE2B .
Unable to delete ADS C:\ProgramData\TEMP:B4980368 .
Unable to delete ADS C:\ProgramData\TEMP:8F067037 .
Unable to delete ADS C:\ProgramData\TEMP:7AA6FC81 .
Unable to delete ADS C:\ProgramData\TEMP:41D1C7CB .
Unable to delete ADS C:\ProgramData\TEMP:3BCA993F .
Unable to delete ADS C:\ProgramData\TEMP:FBE5FDB9 .
Unable to delete ADS C:\ProgramData\TEMP:A0A7408F .
Unable to delete ADS C:\ProgramData\TEMP:4CF76F21 .
Unable to delete ADS C:\ProgramData\TEMP:48977386 .
Unable to delete ADS C:\ProgramData\TEMP:47A24D4B .
Unable to delete ADS C:\ProgramData\TEMP:45DDA801 .
Unable to delete ADS C:\ProgramData\TEMP:2F0007D6 .
Unable to delete ADS C:\ProgramData\TEMP:F0AB86C0 .
Unable to delete ADS C:\ProgramData\TEMP:9857FAE3 .
Unable to delete ADS C:\ProgramData\TEMP:4F8B72C9 .
Unable to delete ADS C:\ProgramData\TEMP:2F141B68 .
Unable to delete ADS C:\ProgramData\TEMP:0D3CE40A .
Unable to delete ADS C:\ProgramData\TEMP:84CFEE62 .
Unable to delete ADS C:\ProgramData\TEMP:8247A199 .
Unable to delete ADS C:\ProgramData\TEMP:51E1A4D8 .
Unable to delete ADS C:\ProgramData\TEMP:3C282BEA .
Unable to delete ADS C:\ProgramData\TEMP:3B812EE0 .
Unable to delete ADS C:\ProgramData\TEMP:D46ECFD5 .
Unable to delete ADS C:\ProgramData\TEMP:8CCDAB14 .
Unable to delete ADS C:\ProgramData\TEMP:842B0AED .
Unable to delete ADS C:\ProgramData\TEMP:5C6EBC69 .
Unable to delete ADS C:\ProgramData\TEMP:55BB2521 .
Unable to delete ADS C:\ProgramData\TEMP:0C5BC70E .
Unable to delete ADS C:\ProgramData\TEMP:43982D5E .
Unable to delete ADS C:\ProgramData\TEMP:385E2CFD .
Unable to delete ADS C:\ProgramData\TEMP:25249477 .
Unable to delete ADS C:\ProgramData\TEMP:1B927722 .
Unable to delete ADS C:\ProgramData\TEMP:E07EA07E .
Unable to delete ADS C:\ProgramData\TEMP:36BC4740 .
Unable to delete ADS C:\ProgramData\TEMP:2B82C0BB .
Unable to delete ADS C:\ProgramData\TEMP:062AF572 .
Unable to delete ADS C:\ProgramData\TEMP:66AA0486 .
Unable to delete ADS C:\ProgramData\TEMP:12EA4DC9 .
Unable to delete ADS C:\ProgramData\TEMP:F7061E5F .
Unable to delete ADS C:\ProgramData\TEMP:45F3AD49 .
Unable to delete ADS C:\ProgramData\TEMP:43C9D140 .
Unable to delete ADS C:\ProgramData\TEMP:40D8F125 .
Unable to delete ADS C:\ProgramData\TEMP:C0A9D0E7 .
Unable to delete ADS C:\ProgramData\TEMP:79A70C33 .
Unable to delete ADS C:\ProgramData\TEMP:938EC881 .
Unable to delete ADS C:\ProgramData\TEMP:53DF59D1 .
Unable to delete ADS C:\ProgramData\TEMP:409A775B .
Unable to delete ADS C:\ProgramData\TEMP:FDC41D2C .
Unable to delete ADS C:\ProgramData\TEMP:C7F5E798 .
Unable to delete ADS C:\ProgramData\TEMP:072F1F69 .
Unable to delete ADS C:\ProgramData\TEMP:6B55B892 .
Unable to delete ADS C:\ProgramData\TEMP:50636E35 .
Unable to delete ADS C:\ProgramData\TEMP:48081133 .
Unable to delete ADS C:\ProgramData\TEMP:FDDD8917 .
Unable to delete ADS C:\ProgramData\TEMP:98AE08EA .
Unable to delete ADS C:\ProgramData\TEMP:5363837B .
Unable to delete ADS C:\ProgramData\TEMP:52641FBE .
Unable to delete ADS C:\ProgramData\TEMP:4FE30352 .
Unable to delete ADS C:\ProgramData\TEMP:EF4FB3C5 .
Unable to delete ADS C:\ProgramData\TEMP:DAE3649B .
Unable to delete ADS C:\ProgramData\TEMP:B2CD146E .
Unable to delete ADS C:\ProgramData\TEMP:7B2BB690 .
Unable to delete ADS C:\ProgramData\TEMP:47FE7AB7 .
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AntiVirusOverride"|1 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirewallOverride"|1 /E : value set successfully!
========== FILES ==========
File\Folder C:\ProgramData\Ikibago not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Marie
->Temp folder emptied: 570093 bytes
->Temporary Internet Files folder emptied: 3262102 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 434 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 52118 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 4,00 mb
OTL by OldTimer - Version 3.1.37.2 log created on 03232010_212748
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...