Précédent
- 1
- 2
- 3
1ere eta¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.2.7 ¤¤¤¤¤¤¤¤¤¤
User : Flavie (Administrateurs)
Update on 12/08/2010 by g3n-h@ckm@n ::::: 00.40
Start at: 23:01:55 | 12/08/2010
Genuine Intel(R) CPU T2130 @ 1.86GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18943
Windows Firewall Status : Enabled
C:\ -> Disque fixe local | 141,04 Go (45,62 Go free) [HDD] | NTFS
D:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)
C:\Windows\System32\smss.exe ----704 Ko
C:\Windows\system32\csrss.exe ----4968 Ko
C:\Windows\system32\csrss.exe ----6016 Ko
C:\Windows\system32\wininit.exe ----3864 Ko
C:\Windows\system32\winlogon.exe ----5588 Ko
C:\Windows\system32\services.exe ----6680 Ko
C:\Windows\system32\lsass.exe ----7888 Ko
C:\Windows\system32\lsm.exe ----3872 Ko
C:\Windows\system32\svchost.exe ----5592 Ko
C:\Windows\system32\svchost.exe ----5908 Ko
C:\Windows\System32\svchost.exe ----17008 Ko
C:\Windows\system32\Ati2evxx.exe ----3860 Ko
C:\Windows\System32\svchost.exe ----11288 Ko
C:\Windows\System32\svchost.exe ----52028 Ko
C:\Windows\system32\svchost.exe ----21216 Ko
C:\Windows\system32\svchost.exe ----4532 Ko
C:\Windows\system32\SLsvc.exe ----7552 Ko
C:\Windows\system32\svchost.exe ----8560 Ko
C:\Windows\system32\Ati2evxx.exe ----5760 Ko
C:\Windows\system32\svchost.exe ----14272 Ko
C:\Program Files\ATK Hotkey\ASLDRSrv.exe ----3180 Ko
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe ----24096 Ko
C:\Windows\system32\Dwm.exe ----33832 Ko
C:\Windows\Explorer.EXE ----8080 Ko
C:\Windows\system32\runonce.exe ----4496 Ko
C:\Program Files\ATK Hotkey\Hcontrol.exe ----7480 Ko
C:\Windows\system32\cmd.exe ----2676 Ko
C:\Program Files\ATK Hotkey\ATKOSD.exe ----4788 Ko
C:\Windows\System32\spoolsv.exe ----11032 Ko
C:\Windows\system32\taskeng.exe ----10028 Ko
C:\Windows\system32\svchost.exe ----10656 Ko
C:\Windows\system32\PresentationSettings.exe ----3752 Ko
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE ----3028 Ko
C:\Windows\system32\svchost.exe ----5248 Ko
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe ----9032 Ko
C:\Windows\system32\svchost.exe ----15712 Ko
C:\Windows\System32\svchost.exe ----1984 Ko
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE ----9328 Ko
C:\Windows\system32\SearchIndexer.exe ----9420 Ko
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe ----2656 Ko
C:\Windows\system32\wbem\wmiprvse.exe ----8584 Ko
C:\Program Files\Alwil Software\Avast5\setup\avast.setup ----8404 Ko
C:\Program Files\List_Kill'em\ERUNT.EXE ----5632 Ko
C:\Program Files\List_Kill'em\pv.exe ----5516 Ko
C:\Windows\system32\taskeng.exe ----3664 Ko
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\Windows\System32\pmsbfn32.dll
Quarantined & Deleted !! : C:\Windows\Temp\DMI20BA.tmp
Quarantined & Deleted !! : C:\Windows\Temp\DMI54A1.tmp
Quarantined & Deleted !! : C:\Windows\Temp\DMIAFC4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\HxB97A.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET199D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET1C4D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET1F46.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET1F5A.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET23EE.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET26DD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET2C4B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3624.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3BDB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3C87.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3F46.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3F94.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3FF2.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET40AD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET410B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET430F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET44B5.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4512.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4551.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET458F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4699.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET46D7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4754.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET47C2.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4810.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET48DB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET48EB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4958.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4959.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET49B6.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET49F4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4AA0.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4B3C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4B6B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4BC9.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4C46.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4D40.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4D7F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4D9E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4DDC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4E0B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4EB7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4ED6.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4FE0.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET506D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5203.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5212.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5270.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5271.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET52BE.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET53E7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET554F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET559D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET55AC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET55DB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5752.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET57CF.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET57D0.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET583D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET586B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET59A4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5ACD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5B79.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5C34.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5D2E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5F61.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET602C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET60B8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET619E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET61E1.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET623F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET62CC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET631A.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET64EF.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET654C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET65F8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET680B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET681B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET6888.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET6B67.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET725C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET74DD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET76A2.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET777D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7AE8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7BB3.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7C6E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7EA1.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET81FC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET8930.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET89B3.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET8B53.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET8F4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET9C3B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETA.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETAA54.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETB11B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETBA90.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETC251.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETC927.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETE1DF.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETFC03.tmp
Quarantined & Deleted !! : C:\Users\Flavie\AppData\Local\d3d9caps.dat
Quarantined & Deleted !! : C:\Users\Flavie\AppData\Local\fusioncache.dat
Quarantined & Deleted !! : C:\Users\Flavie\AppData\Local\GDIPFONTCACHEV1.DAT
=======
Hosts :
=======
127.0.0.1 localhost
========
Registry
========
=================
Internet Explorer
=================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============
Security Center
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval = 1 (0x1)
FirstRunDisabled = 1 (0x1)
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 1 (0x1)
FirewallOverride = 1 (0x1)
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
================
FEATURE_BROWSER_EMULATION | svchost :
====================================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
pe
User : Flavie (Administrateurs)
Update on 12/08/2010 by g3n-h@ckm@n ::::: 00.40
Start at: 23:01:55 | 12/08/2010
Genuine Intel(R) CPU T2130 @ 1.86GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18943
Windows Firewall Status : Enabled
C:\ -> Disque fixe local | 141,04 Go (45,62 Go free) [HDD] | NTFS
D:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)
C:\Windows\System32\smss.exe ----704 Ko
C:\Windows\system32\csrss.exe ----4968 Ko
C:\Windows\system32\csrss.exe ----6016 Ko
C:\Windows\system32\wininit.exe ----3864 Ko
C:\Windows\system32\winlogon.exe ----5588 Ko
C:\Windows\system32\services.exe ----6680 Ko
C:\Windows\system32\lsass.exe ----7888 Ko
C:\Windows\system32\lsm.exe ----3872 Ko
C:\Windows\system32\svchost.exe ----5592 Ko
C:\Windows\system32\svchost.exe ----5908 Ko
C:\Windows\System32\svchost.exe ----17008 Ko
C:\Windows\system32\Ati2evxx.exe ----3860 Ko
C:\Windows\System32\svchost.exe ----11288 Ko
C:\Windows\System32\svchost.exe ----52028 Ko
C:\Windows\system32\svchost.exe ----21216 Ko
C:\Windows\system32\svchost.exe ----4532 Ko
C:\Windows\system32\SLsvc.exe ----7552 Ko
C:\Windows\system32\svchost.exe ----8560 Ko
C:\Windows\system32\Ati2evxx.exe ----5760 Ko
C:\Windows\system32\svchost.exe ----14272 Ko
C:\Program Files\ATK Hotkey\ASLDRSrv.exe ----3180 Ko
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe ----24096 Ko
C:\Windows\system32\Dwm.exe ----33832 Ko
C:\Windows\Explorer.EXE ----8080 Ko
C:\Windows\system32\runonce.exe ----4496 Ko
C:\Program Files\ATK Hotkey\Hcontrol.exe ----7480 Ko
C:\Windows\system32\cmd.exe ----2676 Ko
C:\Program Files\ATK Hotkey\ATKOSD.exe ----4788 Ko
C:\Windows\System32\spoolsv.exe ----11032 Ko
C:\Windows\system32\taskeng.exe ----10028 Ko
C:\Windows\system32\svchost.exe ----10656 Ko
C:\Windows\system32\PresentationSettings.exe ----3752 Ko
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE ----3028 Ko
C:\Windows\system32\svchost.exe ----5248 Ko
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe ----9032 Ko
C:\Windows\system32\svchost.exe ----15712 Ko
C:\Windows\System32\svchost.exe ----1984 Ko
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE ----9328 Ko
C:\Windows\system32\SearchIndexer.exe ----9420 Ko
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe ----2656 Ko
C:\Windows\system32\wbem\wmiprvse.exe ----8584 Ko
C:\Program Files\Alwil Software\Avast5\setup\avast.setup ----8404 Ko
C:\Program Files\List_Kill'em\ERUNT.EXE ----5632 Ko
C:\Program Files\List_Kill'em\pv.exe ----5516 Ko
C:\Windows\system32\taskeng.exe ----3664 Ko
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\Windows\System32\pmsbfn32.dll
Quarantined & Deleted !! : C:\Windows\Temp\DMI20BA.tmp
Quarantined & Deleted !! : C:\Windows\Temp\DMI54A1.tmp
Quarantined & Deleted !! : C:\Windows\Temp\DMIAFC4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\HxB97A.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET199D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET1C4D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET1F46.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET1F5A.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET23EE.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET26DD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET2C4B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3624.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3BDB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3C87.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3F46.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3F94.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET3FF2.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET40AD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET410B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET430F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET44B5.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4512.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4551.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET458F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4699.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET46D7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4754.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET47C2.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4810.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET48DB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET48EB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4958.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4959.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET49B6.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET49F4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4AA0.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4B3C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4B6B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4BC9.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4C46.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4D40.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4D7F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4D9E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4DDC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4E0B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4EB7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4ED6.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET4FE0.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET506D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5203.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5212.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5270.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5271.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET52BE.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET53E7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET554F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET559D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET55AC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET55DB.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5752.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET57CF.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET57D0.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET583D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET586B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET59A4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5ACD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5B79.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5C34.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5D2E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET5F61.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET602C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET60B8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET619E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET61E1.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET623F.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET62CC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET631A.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET64EF.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET654C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET65F8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET680B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET681B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET6888.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET6B67.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET725C.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET74DD.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET76A2.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET777D.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7AE8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7BB3.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7C6E.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET7EA1.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET81FC.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET8930.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET89B3.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET8B53.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET8F4.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JET9C3B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETA.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETAA54.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETB11B.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETBA90.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETC251.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETC927.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETE1DF.tmp
Quarantined & Deleted !! : C:\Windows\Temp\JETFC03.tmp
Quarantined & Deleted !! : C:\Users\Flavie\AppData\Local\d3d9caps.dat
Quarantined & Deleted !! : C:\Users\Flavie\AppData\Local\fusioncache.dat
Quarantined & Deleted !! : C:\Users\Flavie\AppData\Local\GDIPFONTCACHEV1.DAT
=======
Hosts :
=======
127.0.0.1 localhost
========
Registry
========
=================
Internet Explorer
=================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============
Security Center
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval = 1 (0x1)
FirstRunDisabled = 1 (0x1)
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 1 (0x1)
FirewallOverride = 1 (0x1)
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
================
FEATURE_BROWSER_EMULATION | svchost :
====================================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
pe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
je ne vois pas dans tes rapports le problème
je vais siffler un ami pour voir
nous sommes bien d'accord, tu peux télécharger et enregistrer sur ton pc, mais une fois fait, tu ne peux executer l'installation
je vais siffler un ami pour voir
nous sommes bien d'accord, tu peux télécharger et enregistrer sur ton pc, mais une fois fait, tu ne peux executer l'installation
Le truc c'est que je pe pas le telecharger jusqu'au bout.Je m'explique on me dit telechargement terminé mais j'ai 20MO au lieu des 92...Etrange et ca fait depuis le debut
Précédent
- 1
- 2
- 3
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier :
C:\Windows\System32\progress.exe
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Si tu ne trouves pas le fichier alors
Affiche tous les fichiers et dossiers :
Pour cela :
Clique sur démarrer/panneau de configuration/option des dossiers/affichage
Cocher afficher les dossiers cachés
Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher masquer les extensions dont le type est connu
Puis fais «appliquer» pour valider les changements.
Et OK