Virus TR/Spy.1037824.7
Résolu
joks
-
joks -
joks -
Bonjour,
J'ai un virus qui me bloque mon pc depuis quelque jours, en suivant les differents topics j'ai generer un rapport malwarebytes(examen rapide) et un rapport hijackthis que vous trouverez ci dessous.
Que dois je faire ensuite?
merci d'avance
rapport malwarebytes :
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Version de la base de données: 4638
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
17/09/2010 15:37:29
mbam-log-2010-09-17 (15-37-29).txt
Type d'examen: Examen rapide
Elément(s) analysé(s): 185940
Temps écoulé: 21 minute(s), 6 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cyurwtuh (Rootkit.Agent.BO) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ZE18MW23GY (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\JRMX9X1GML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yxe7dxcq37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\Drivers\cyurwtuh.sys (Rootkit.Agent.BO) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
rapport hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:50:14, on 17/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PVSW\Bin\WGE_SRV.exe
C:\WINDOWS\system32\svchost.exe
C:\PVSW\BIN\W3dbsmgr.EXE
c:\ServeurHF\Manta.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Serveur HF\MantaManager.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Rivalis\AutoBackupRivalis\RivalisAutoBackup.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnp2std.exe
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ACT\Act for Windows\Act.Scheduler.UI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4CDBD57A-9A79-4278-8B6F-97931E4C52F0} - c:\windows\system32\dlo116.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [HPPQVideo] "C:\Program Files\HP\ScheduledLaunch\HP Color LaserJet CM1312 MFP Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\CLJ_CM1312_MFP_Series -f PQOptimizerVideo.xml -o remindLater
O4 - HKLM\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe"
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\Act for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ACTSchedulerUI] "C:\Program Files\ACT\Act for Windows\Act.Scheduler.UI.exe" -Dfalse
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O9 - Extra button: Joindre la page Web au contact ACT! - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Joindre la page Web au contact ACT!... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O15 - Trusted Zone: http://saas.ibizasoftware.com
O16 - DPF: {9FFA5747-4FDB-4221-A61E-4CAC0E5095A5} (CUtils Object) - http://saas.ibizasoftware.com/6.2.8.1/dlls/iBiZaCL.dll
O23 - Service: ACT! Scheduler - Sage Software, Inc. - C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hyper File Server : BUREAU - PC SOFT - c:\ServeurHF\Manta.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MantaManager - PC SOFT - C:\Serveur HF\MantaManager.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Rivalis4NetServiceClient - Unknown owner - C:\Program Files\Rivalis\Rivalis4NetServiceClient.exe
O23 - Service: RivalisAutoBackup - Unknown owner - C:\Program Files\Rivalis\AutoBackupRivalis\RivalisAutoBackup.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/JRMYPI~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/JRMYPI~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
J'ai un virus qui me bloque mon pc depuis quelque jours, en suivant les differents topics j'ai generer un rapport malwarebytes(examen rapide) et un rapport hijackthis que vous trouverez ci dessous.
Que dois je faire ensuite?
merci d'avance
rapport malwarebytes :
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Version de la base de données: 4638
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
17/09/2010 15:37:29
mbam-log-2010-09-17 (15-37-29).txt
Type d'examen: Examen rapide
Elément(s) analysé(s): 185940
Temps écoulé: 21 minute(s), 6 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cyurwtuh (Rootkit.Agent.BO) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ZE18MW23GY (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\JRMX9X1GML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yxe7dxcq37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\Drivers\cyurwtuh.sys (Rootkit.Agent.BO) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
rapport hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:50:14, on 17/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PVSW\Bin\WGE_SRV.exe
C:\WINDOWS\system32\svchost.exe
C:\PVSW\BIN\W3dbsmgr.EXE
c:\ServeurHF\Manta.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Serveur HF\MantaManager.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Rivalis\AutoBackupRivalis\RivalisAutoBackup.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnp2std.exe
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ACT\Act for Windows\Act.Scheduler.UI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4CDBD57A-9A79-4278-8B6F-97931E4C52F0} - c:\windows\system32\dlo116.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [HPPQVideo] "C:\Program Files\HP\ScheduledLaunch\HP Color LaserJet CM1312 MFP Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\CLJ_CM1312_MFP_Series -f PQOptimizerVideo.xml -o remindLater
O4 - HKLM\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe"
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\Act for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ACTSchedulerUI] "C:\Program Files\ACT\Act for Windows\Act.Scheduler.UI.exe" -Dfalse
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O9 - Extra button: Joindre la page Web au contact ACT! - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Joindre la page Web au contact ACT!... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O15 - Trusted Zone: http://saas.ibizasoftware.com
O16 - DPF: {9FFA5747-4FDB-4221-A61E-4CAC0E5095A5} (CUtils Object) - http://saas.ibizasoftware.com/6.2.8.1/dlls/iBiZaCL.dll
O23 - Service: ACT! Scheduler - Sage Software, Inc. - C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hyper File Server : BUREAU - PC SOFT - c:\ServeurHF\Manta.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MantaManager - PC SOFT - C:\Serveur HF\MantaManager.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Rivalis4NetServiceClient - Unknown owner - C:\Program Files\Rivalis\Rivalis4NetServiceClient.exe
O23 - Service: RivalisAutoBackup - Unknown owner - C:\Program Files\Rivalis\AutoBackupRivalis\RivalisAutoBackup.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/JRMYPI~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/JRMYPI~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
A voir également:
- Virus TR/Spy.1037824.7
- Virus mcafee - Accueil - Piratage
- Spy bot - Télécharger - Antivirus & Antimalwares
- Virus facebook demande d'amis - Accueil - Facebook
- Tr signification - Forum Mail
- Faux message virus iphone ✓ - Forum Virus
30 réponses
voici le rapport Kill'em.txt :
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.6 ¤¤¤¤¤¤¤¤¤¤
User : Jérémy PIAU (Administrateurs)
Update on 17/09/2010 by g3n-h@ckm@n ::::: 14.00
Start at: 09:14:24 | 20/09/2010
Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Disabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Disque fixe local | 88,96 Go (31,97 Go free) [Preload] | NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque CD-ROM | 194,45 Mo (0 Mo free) [e-secure] | CDFS
X:\ -> Connexion réseau | 232,75 Go (171,23 Go free) [OS] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)
C:\WINDOWS\System32\smss.exe ----420 Ko
C:\WINDOWS\system32\csrss.exe ----4772 Ko
C:\WINDOWS\system32\winlogon.exe ----3356 Ko
C:\WINDOWS\system32\services.exe ----3952 Ko
C:\WINDOWS\system32\lsass.exe ----2144 Ko
C:\WINDOWS\system32\svchost.exe ----5484 Ko
C:\WINDOWS\system32\svchost.exe ----4544 Ko
C:\WINDOWS\System32\svchost.exe ----31928 Ko
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe ----11840 Ko
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe ----10400 Ko
C:\WINDOWS\system32\svchost.exe ----3724 Ko
C:\WINDOWS\system32\svchost.exe ----4060 Ko
C:\WINDOWS\system32\spoolsv.exe ----7536 Ko
C:\Program Files\Avira\AntiVir Desktop\sched.exe ----792 Ko
C:\WINDOWS\system32\svchost.exe ----3884 Ko
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe ----1652 Ko
C:\Program Files\Avira\AntiVir Desktop\avguard.exe ----15796 Ko
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe ----29456 Ko
C:\PVSW\Bin\WGE_SRV.exe ----3652 Ko
C:\WINDOWS\system32\svchost.exe ----5784 Ko
c:\ServeurHF\Manta.exe ----7416 Ko
C:\PVSW\BIN\W3dbsmgr.EXE ----10724 Ko
C:\Program Files\Java\jre6\bin\jqs.exe ----1384 Ko
C:\Program Files\LogMeIn\x86\RaMaint.exe ----3692 Ko
C:\Program Files\LogMeIn\x86\LogMeIn.exe ----12648 Ko
C:\Program Files\LogMeIn\x86\LMIGuardian.exe ----2564 Ko
C:\Serveur HF\MantaManager.exe ----2476 Ko
C:\Program Files\MozyHome\mozybackup.exe ----34176 Ko
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe ----11544 Ko
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe ----47208 Ko
C:\WINDOWS\System32\svchost.exe ----3000 Ko
C:\WINDOWS\system32\nvsvc32.exe ----3624 Ko
C:\WINDOWS\System32\svchost.exe ----2968 Ko
C:\Program Files\Lenovo\PM Driver\PMSveH.exe ----1276 Ko
C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe ----2944 Ko
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe ----3088 Ko
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe ----2376 Ko
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe ----3608 Ko
C:\WINDOWS\system32\svchost.exe ----5932 Ko
C:\WINDOWS\system32\wdfmgr.exe ----1848 Ko
C:\Program Files\Rivalis\AutoBackupRivalis\RivalisAutoBackup.exe ----20136 Ko
C:\WINDOWS\Explorer.EXE ----32484 Ko
C:\WINDOWS\vsnp2std.exe ----3744 Ko
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe ----988 Ko
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe ----1456 Ko
C:\Program Files\ACT\Act for Windows\Act.Scheduler.UI.exe ----12256 Ko
C:\Program Files\MozyHome\mozystat.exe ----11204 Ko
C:\WINDOWS\system32\wscntfy.exe ----2304 Ko
C:\WINDOWS\system32\wbem\wmiapsrv.exe ----4608 Ko
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe ----7364 Ko
C:\WINDOWS\System32\alg.exe ----3636 Ko
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe ----2608 Ko
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ----44608 Ko
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ----35208 Ko
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ----18532 Ko
C:\WINDOWS\system32\cmd.exe ----2960 Ko
C:\WINDOWS\system32\wbem\wmiprvse.exe ----7436 Ko
C:\Program Files\List_Kill'em\ERUNT.EXE ----3428 Ko
C:\Program Files\List_Kill'em\pv.exe ----2832 Ko
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\WINDOWS\002636_.tmp
¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤
127.0.0.1 localhost
¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
FirstRunDisabled = 1 ()
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 0 (0x0)
FirewallOverride = 0 (0x0)
¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
FEATURE_BROWSER_EMULATION | svchost :
====================================
Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION : svchost.exe
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.6 ¤¤¤¤¤¤¤¤¤¤
User : Jérémy PIAU (Administrateurs)
Update on 17/09/2010 by g3n-h@ckm@n ::::: 14.00
Start at: 09:14:24 | 20/09/2010
Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Disabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Disque fixe local | 88,96 Go (31,97 Go free) [Preload] | NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque CD-ROM | 194,45 Mo (0 Mo free) [e-secure] | CDFS
X:\ -> Connexion réseau | 232,75 Go (171,23 Go free) [OS] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)
C:\WINDOWS\System32\smss.exe ----420 Ko
C:\WINDOWS\system32\csrss.exe ----4772 Ko
C:\WINDOWS\system32\winlogon.exe ----3356 Ko
C:\WINDOWS\system32\services.exe ----3952 Ko
C:\WINDOWS\system32\lsass.exe ----2144 Ko
C:\WINDOWS\system32\svchost.exe ----5484 Ko
C:\WINDOWS\system32\svchost.exe ----4544 Ko
C:\WINDOWS\System32\svchost.exe ----31928 Ko
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe ----11840 Ko
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe ----10400 Ko
C:\WINDOWS\system32\svchost.exe ----3724 Ko
C:\WINDOWS\system32\svchost.exe ----4060 Ko
C:\WINDOWS\system32\spoolsv.exe ----7536 Ko
C:\Program Files\Avira\AntiVir Desktop\sched.exe ----792 Ko
C:\WINDOWS\system32\svchost.exe ----3884 Ko
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe ----1652 Ko
C:\Program Files\Avira\AntiVir Desktop\avguard.exe ----15796 Ko
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe ----29456 Ko
C:\PVSW\Bin\WGE_SRV.exe ----3652 Ko
C:\WINDOWS\system32\svchost.exe ----5784 Ko
c:\ServeurHF\Manta.exe ----7416 Ko
C:\PVSW\BIN\W3dbsmgr.EXE ----10724 Ko
C:\Program Files\Java\jre6\bin\jqs.exe ----1384 Ko
C:\Program Files\LogMeIn\x86\RaMaint.exe ----3692 Ko
C:\Program Files\LogMeIn\x86\LogMeIn.exe ----12648 Ko
C:\Program Files\LogMeIn\x86\LMIGuardian.exe ----2564 Ko
C:\Serveur HF\MantaManager.exe ----2476 Ko
C:\Program Files\MozyHome\mozybackup.exe ----34176 Ko
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe ----11544 Ko
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe ----47208 Ko
C:\WINDOWS\System32\svchost.exe ----3000 Ko
C:\WINDOWS\system32\nvsvc32.exe ----3624 Ko
C:\WINDOWS\System32\svchost.exe ----2968 Ko
C:\Program Files\Lenovo\PM Driver\PMSveH.exe ----1276 Ko
C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe ----2944 Ko
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe ----3088 Ko
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe ----2376 Ko
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe ----3608 Ko
C:\WINDOWS\system32\svchost.exe ----5932 Ko
C:\WINDOWS\system32\wdfmgr.exe ----1848 Ko
C:\Program Files\Rivalis\AutoBackupRivalis\RivalisAutoBackup.exe ----20136 Ko
C:\WINDOWS\Explorer.EXE ----32484 Ko
C:\WINDOWS\vsnp2std.exe ----3744 Ko
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe ----988 Ko
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe ----1456 Ko
C:\Program Files\ACT\Act for Windows\Act.Scheduler.UI.exe ----12256 Ko
C:\Program Files\MozyHome\mozystat.exe ----11204 Ko
C:\WINDOWS\system32\wscntfy.exe ----2304 Ko
C:\WINDOWS\system32\wbem\wmiapsrv.exe ----4608 Ko
C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe ----7364 Ko
C:\WINDOWS\System32\alg.exe ----3636 Ko
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe ----2608 Ko
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ----44608 Ko
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ----35208 Ko
C:\Documents and Settings\Jérémy PIAU\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ----18532 Ko
C:\WINDOWS\system32\cmd.exe ----2960 Ko
C:\WINDOWS\system32\wbem\wmiprvse.exe ----7436 Ko
C:\Program Files\List_Kill'em\ERUNT.EXE ----3428 Ko
C:\Program Files\List_Kill'em\pv.exe ----2832 Ko
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\WINDOWS\002636_.tmp
¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤
127.0.0.1 localhost
¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
FirstRunDisabled = 1 ()
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 0 (0x0)
FirewallOverride = 0 (0x0)
¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
FEATURE_BROWSER_EMULATION | svchost :
====================================
Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION : svchost.exe
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
rapport Usbfix.txt :
############################## | UsbFix 7.025 | [Suppression]
Utilisateur: Jérémy PIAU (Administrateur) # BUREAU [ ]
Mis à jour le 15/09/10 par El Desaparecido / C_XX
Lancé à 09:33:45 | 20/09/2010
Site Web: http://www.teamxscript.org
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
CPU 2: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Pare-feu Windows: Désactivé /!\
Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
RAM -> 2046 Mo
C:\ (%systemdrive%) -> Disque fixe # 89 Go (32 Go libre(s) - 36%) [Preload] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
################## | Éléments infectieux |
Non supprimé ! E:\Autorun.inf
Non supprimé ! X:\image.jpg
Non supprimé ! X:\test.exe
################## | Registre |
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cleanup.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divxdec.ax
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DJSMAR00.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRMINST.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncodeDivXExt.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncryptPatchVer.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\front.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fullsoft.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GBROWSER.DLL
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmarq.ocx
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmm.ocx
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ishscan.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ISSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm_g.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\main123w.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mngreg32.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msci_uno.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvr.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mso.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVOPTRF.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeVideoFX.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPMLIC.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSWSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photohse.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PMSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppw32hlp.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\printhse.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prwin8.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ps80.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psdmt.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qfinder.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qpw.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\salwrap.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup32.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sevinst.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcnet.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcore_ebook.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TFDTCTT8.DLL
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ua80.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\udtapi.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ums.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vb40032.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbe6.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpwin8.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xlmlEN.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xwsetup.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
################## | Mountpoints2 |
################## | Listing |
[27/07/2010 - 19:50:00 | A | 1024] C:\.rnd
[18/08/2009 - 19:37:43 | D ] C:\90fa146bf70292f9d4
[20/08/2010 - 18:42:18 | A | 47304] C:\abc.txt
[20/09/2010 - 09:31:59 | A | 4] C:\AUTOEXEC.BAT
[17/09/2010 - 13:45:14 | A | 216] C:\Boot.bak
[17/09/2010 - 20:14:45 | RASH | 332] C:\boot.ini
[05/08/2004 - 13:00:00 | RSH | 4952] C:\bootfont.bin
[17/09/2010 - 20:14:45 | RASHD ] C:\cmdcons
[03/08/2004 - 23:00:08 | RASH | 263488] C:\cmldr
[18/09/2010 - 13:37:16 | A | 19818] C:\ComboFix.txt
[01/02/2006 - 01:34:05 | N | 0] C:\CONFIG.SYS
[16/08/2010 - 15:24:45 | A | 92431] C:\ContactTable.htm
[08/07/2002 - 06:04:24 | N | 4608] C:\CRVsPackageLib.dll
[17/07/2002 - 06:23:10 | N | 475136] C:\CrystalDecisions.CrystalReports.Engine.dll
[08/07/2002 - 06:00:42 | N | 8192] C:\CrystalDecisions.CrystalReports.TemplateEngine.dll
[08/07/2002 - 05:45:42 | N | 32768] C:\CrystalDecisions.Enterprise.Framework.dll
[08/07/2002 - 05:45:44 | N | 53248] C:\CrystalDecisions.Enterprise.InfoStore.dll
[08/07/2002 - 05:45:44 | N | 9216] C:\CrystalDecisions.Enterprise.PluginManager.dll
[08/07/2002 - 05:45:44 | N | 49152] C:\CrystalDecisions.Enterprise.Report.dll
[08/07/2002 - 06:00:40 | N | 57344] C:\CrystalDecisions.ReportAppServer.ClientDoc.dll
[08/07/2002 - 05:58:06 | N | 49152] C:\CrystalDecisions.ReportAppServer.CommLayer.dll
[08/07/2002 - 05:57:52 | N | 126976] C:\CrystalDecisions.ReportAppServer.CommonControls.dll
[08/07/2002 - 05:57:32 | N | 36864] C:\CrystalDecisions.ReportAppServer.CommonObjectModel.dll
[08/07/2002 - 06:00:26 | N | 184320] C:\CrystalDecisions.ReportAppServer.Controllers.dll
[08/07/2002 - 05:58:54 | N | 36864] C:\CrystalDecisions.ReportAppServer.CubeDefModel.dll
[08/07/2002 - 05:58:48 | N | 212992] C:\CrystalDecisions.ReportAppServer.DataDefModel.dll
[08/07/2002 - 07:06:32 | N | 8704] C:\CrystalDecisions.ReportAppServer.DataSetConversion.dll
[08/07/2002 - 05:59:50 | N | 274432] C:\CrystalDecisions.ReportAppServer.ReportDefModel.dll
[08/07/2002 - 05:57:56 | N | 15360] C:\CrystalDecisions.ReportAppServer.XmlSerialize.dll
[11/07/2002 - 06:21:46 | N | 135168] C:\CrystalDecisions.ReportSource.dll
[08/07/2002 - 07:06:28 | N | 557056] C:\CrystalDecisions.Shared.dll
[08/07/2002 - 07:06:30 | N | 204800] C:\CrystalDecisions.Web.dll
[08/07/2002 - 07:06:30 | N | 53248] C:\CrystalDecisions.Web.Mobile.dll
[16/07/2002 - 13:56:48 | N | 237568] C:\CrystalDecisions.Windows.Forms.dll
[15/07/2002 - 05:16:56 | N | 18944] C:\CrystalKeyCodeLib.dll
[07/01/2010 - 14:25:35 | D ] C:\Database
[17/09/2010 - 12:33:40 | D ] C:\Documents and Settings
[27/01/2009 - 17:59:22 | D ] C:\Données Ciel
[27/01/2009 - 22:08:26 | AD ] C:\DRIVERS
[27/01/2009 - 14:33:59 | N | 1911] C:\drivez.log
[02/02/2010 - 18:40:20 | D ] C:\HebeLog
[18/09/2010 - 16:35:16 | ASH | 2145570816] C:\hiberfil.sys
[27/01/2009 - 17:57:29 | D ] C:\HSF
[27/01/2009 - 16:19:28 | AD ] C:\I386
[14/11/2009 - 17:40:02 | D ] C:\Icons
[01/02/2006 - 01:34:05 | RSH | 0] C:\IO.SYS
[17/09/2010 - 20:32:34 | D ] C:\JOKS
[18/09/2010 - 13:37:20 | D ] C:\JOKS11252J
[18/09/2010 - 11:31:06 | D ] C:\JOKS16125J
[17/09/2010 - 20:55:46 | D ] C:\JOKS16613J
[18/09/2010 - 13:01:06 | D ] C:\JOKS8212J
[20/09/2010 - 09:14:27 | D ] C:\Kill'em
[08/06/2009 - 12:28:31 | D ] C:\Kiss
[17/09/2010 - 18:19:18 | A | 41669] C:\List'em.txt
[01/02/2006 - 01:34:05 | RSH | 0] C:\MSDOS.SYS
[27/01/2009 - 16:47:21 | RD ] C:\MSOCache
[05/08/2004 - 13:00:00 | RSH | 47564] C:\NTDETECT.COM
[28/01/2009 - 12:14:45 | RSH | 252240] C:\NTLDR
[30/07/2009 - 16:43:52 | D ] C:\Numérisation
[18/09/2010 - 16:35:14 | ASH | 1610612736] C:\pagefile.sys
[23/12/2009 - 16:46:14 | D ] C:\PowerACT
[17/09/2010 - 17:57:30 | RD ] C:\Program Files
[25/11/2009 - 20:37:53 | D ] C:\PVSW
[18/09/2010 - 13:37:19 | D ] C:\Qoobox
[20/09/2010 - 09:31:50 | SHD ] C:\RECYCLER
[18/09/2010 - 16:36:10 | A | 61] C:\riv4debug.txt
[26/08/2009 - 14:32:18 | RD ] C:\RRbackups
[02/02/2010 - 12:56:00 | D ] C:\Serveur HF
[15/01/2010 - 18:55:30 | D ] C:\Serveur Hyper File - Installation
[02/02/2010 - 12:53:25 | D ] C:\Serveur HyperFileSQL - Installation
[02/02/2010 - 12:56:53 | D ] C:\ServeurHF
[31/01/2006 - 11:54:58 | AD ] C:\SUPPORT
[27/01/2009 - 16:18:18 | D ] C:\SWTOOLS
[27/01/2009 - 22:08:23 | N | 93] C:\syslevel.lgl
[18/09/2010 - 13:31:55 | SHD ] C:\System Volume Information
[17/09/2010 - 17:38:55 | D ] C:\tdsskiller
[17/09/2010 - 17:37:39 | A | 1974] C:\TDSSKiller.2.4.2.1_17.09.2010_17.37.26_log.txt
[17/09/2010 - 17:39:56 | A | 54746] C:\TDSSKiller.2.4.2.1_17.09.2010_17.38.55_log.txt
[17/09/2010 - 17:49:53 | A | 104190] C:\TDSSKiller.2.4.2.1_17.09.2010_17.46.57_log.txt
[24/02/2010 - 19:14:21 | A | 16609280] C:\testpoweract.accdb
[20/08/2010 - 11:32:37 | D ] C:\Transfert
[21/09/2009 - 09:35:39 | N | 922] C:\updatedatfix.log
[20/09/2010 - 09:35:26 | D ] C:\UsbFix
[20/09/2010 - 09:35:25 | A | 815] C:\UsbFix.txt
[31/01/2006 - 11:54:58 | AD ] C:\VALUEADD
[20/09/2010 - 09:14:57 | AD ] C:\WINDOWS
[25/01/2010 - 11:36:21 | RD ] E:\Win32
[25/01/2010 - 11:36:20 | R | 49] E:\autorun.inf
[25/01/2010 - 11:36:24 | RD ] E:\common
[25/01/2010 - 11:36:20 | R | 331776] E:\e-secure.exe
[16/01/2009 - 15:08:22 | A | 39546] X:\#entete_cm.jpg
[15/01/2009 - 16:58:42 | A | 1416836] X:\#entete_cm.rtf
[11/08/2008 - 09:04:28 | A | 333393] X:\accueil.rtf
[27/07/2010 - 14:02:17 | A | 203110379] X:\ACT! ladymoving 2a60a86e4dee4698b5a817fcbeb4d3db 2010-07-27 14-00-00.zip
[19/12/2006 - 15:37:58 | A | 50283] X:\Alarm.mp3
[19/12/2006 - 14:38:16 | A | 57856] X:\AXDLL.DLL
[19/12/2006 - 14:38:16 | A | 197632] X:\AXDLL16.DLL
[19/12/2006 - 14:38:16 | A | 57856] X:\AXDLL32.DLL
[12/08/2009 - 16:23:48 | A | 10361] X:\baspage_tickets.jpg
[05/02/2010 - 17:39:42 | D ] X:\Carré Soleil.wd7
[10/10/2007 - 12:52:34 | A | 8937] X:\cercle.JPG
[02/02/2010 - 14:58:23 | ASH | 102] X:\Connexion new.wx
[01/02/2010 - 00:13:04 | A | 17406163] X:\Connexion.exe
[16/02/2010 - 13:25:40 | A | 16554] X:\Connexion.REP
[02/02/2010 - 19:01:21 | A | 17406315] X:\CxAcces.exe
[02/02/2010 - 19:03:52 | A | 528] X:\CxAcces.REP
[02/02/2010 - 14:58:23 | ASH | 102] X:\CxAgenda new.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxAtr old.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxAtr.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxAtr_Clas.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxCaisse.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxExports.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxImports.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxSuccursale.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxTactile new.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxTactile old.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxTactile.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxVideos new.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxVideos.wx
[24/08/2005 - 11:05:06 | A | 4765] X:\cyan.JPG
[21/07/2010 - 18:24:14 | D ] X:\Doc
[04/10/2009 - 19:08:18 | A | 474151] X:\dos.jpg
[30/09/2009 - 18:23:26 | A | 13316] X:\ellip6.jpg
[12/08/2009 - 16:27:26 | A | 8666] X:\entete_tickets.jpg
[28/10/2009 - 10:30:40 | A | 162] X:\F2000-01.txt
[12/05/2009 - 13:35:28 | A | 70629] X:\fnf.jpg
[16/09/2009 - 17:41:22 | A | 55803] X:\fp.bmp
[29/11/2006 - 10:51:20 | A | 69632] X:\FTD2XX.dll
[02/05/2006 - 20:41:46 | A | 479217] X:\Gmw old.WDD
[17/11/2006 - 17:00:46 | A | 488772] X:\Gmw.WDD
[21/01/2010 - 21:54:52 | A | 919734] X:\graphe.bmp
[06/02/2008 - 09:47:42 | A | 3528151] X:\gt.wmv
[19/12/2006 - 15:38:06 | A | 174838] X:\Happy.wav
[10/06/2008 - 09:28:30 | A | 7397] X:\hebe.gif
[17/11/2008 - 09:27:38 | A | 919206] X:\ico.bmp
[17/11/2008 - 09:27:44 | A | 86358] X:\ico.ico
[02/02/2010 - 16:18:19 | A | 6737] X:\Ident.FIC
[17/01/2008 - 10:51:02 | A | 3603] X:\Ident.NDX
[31/10/2009 - 12:18:44 | A | 56694] X:\image.bmp
[04/08/2009 - 08:44:28 | A | 12761] X:\image.gif
[31/10/2009 - 12:18:44 | A | 5255] X:\image.jpg
[04/08/2009 - 08:45:24 | A | 28771] X:\image.png
[14/02/2007 - 09:58:48 | A | 537906] X:\lm.bmp
[07/10/2008 - 11:12:56 | A | 443718] X:\Logo perroquet.bmp
[10/06/2008 - 09:15:48 | A | 4500] X:\logo.gif
[17/11/2008 - 09:18:54 | A | 86358] X:\Logo.ico
[03/11/2008 - 16:05:00 | A | 13342] X:\logo.jpg
[23/09/2008 - 14:29:38 | A | 349138] X:\Logo2.bmp
[08/08/2003 - 19:56:12 | A | 17999] X:\Logo_atr.jpg
[26/10/2009 - 14:33:20 | A | 411385] X:\logo_atr.rtf
[17/09/2009 - 12:39:04 | A | 166320] X:\log_fitness_park_OK.jpg
[02/02/2010 - 14:55:13 | D ] X:\Master
[11/08/2008 - 09:05:48 | A | 7251] X:\Message.rtf
[02/10/2007 - 13:40:30 | A | 9695] X:\Multi.FIC
[02/10/2007 - 13:13:12 | A | 32934] X:\Multi.NDX
[06/07/2009 - 14:03:12 | A | 928694] X:\Pub.rtf
[15/03/2008 - 14:14:06 | A | 202104] X:\pub1.jpg
[29/04/2007 - 18:36:54 | A | 641811] X:\pub2.jpg
[21/01/2004 - 23:38:26 | A | 4082688] X:\qtintf70.dll
[26/07/2008 - 16:20:32 | A | 896] X:\resa.ini
[30/04/2008 - 12:03:06 | A | 9976] X:\resa_logo.jpg
[19/12/2006 - 14:37:26 | A | 10026] X:\ringin.wav
[25/03/2008 - 13:43:04 | A | 60] X:\sauve.ini
[19/12/2006 - 14:38:20 | A | 52224] X:\SCOMM.DLL
[12/11/2008 - 10:43:20 | A | 194] X:\ServeurHf.ini
[25/03/2008 - 09:40:16 | A | 373] X:\ServeurHFold.ini
[15/06/2007 - 21:26:24 | A | 2699010] X:\sports.wmv
[21/03/2007 - 19:41:12 | A | 89600] X:\SUNDLL.dll
[25/11/2009 - 18:38:34 | A | 16837349] X:\Tactile.exe
[02/02/2010 - 14:58:25 | ASH | 102] X:\Tactile.wx
[21/04/2008 - 15:09:40 | A | 567836] X:\temp.emf
[07/10/2009 - 10:56:10 | A | 16622702] X:\test.exe
[02/02/2010 - 14:58:25 | ASH | 102] X:\test.wx
[31/12/2008 - 16:49:36 | A | 26874] X:\usine.jpg
[15/12/1999 - 16:00:00 | A | 95708] X:\Utopia.WAV
[16/06/2008 - 12:38:06 | A | 264] X:\var.ini
[02/02/2010 - 14:58:25 | ASH | 102] X:\Video1.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\Videos.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\Video_test.wx
[27/02/2006 - 16:13:44 | A | 118784] X:\WD100BARC.DLL
[26/09/2006 - 18:05:58 | A | 458752] X:\WD100COM.DLL
[22/05/2006 - 19:47:48 | A | 491520] X:\WD100DB.DLL
[20/06/2006 - 19:28:54 | A | 344064] X:\WD100ETAT.DLL
[08/06/2006 - 13:17:48 | A | 261120] X:\WD100GRF.DLL
[25/07/2006 - 17:46:26 | A | 2098688] X:\WD100HF.DLL
[29/08/2006 - 19:00:38 | A | 397312] X:\WD100HTML.DLL
[15/06/2006 - 17:50:56 | A | 626688] X:\WD100IMG.DLL
[12/04/2006 - 19:09:00 | A | 94208] X:\WD100MAT.DLL
[28/08/2006 - 13:03:06 | A | 1925120] X:\WD100OBJ.DLL
[15/06/2006 - 15:58:18 | A | 499712] X:\WD100OLDB.DLL
[29/06/2006 - 13:41:50 | A | 106496] X:\WD100OLE.DLL
[18/04/2006 - 00:18:48 | A | 483383] X:\WD100PDF.DLL
[13/06/2006 - 18:52:44 | A | 557056] X:\WD100PRN.DLL
[14/06/2006 - 09:49:34 | A | 528384] X:\WD100RTF.DLL
[07/07/2006 - 15:15:30 | A | 409600] X:\WD100SQL.DLL
[18/07/2006 - 11:43:44 | A | 433152] X:\WD100STD.DLL
[23/10/2006 - 16:39:22 | A | 1307648] X:\WD100VM.DLL
[02/06/2006 - 18:36:56 | A | 143360] X:\WD100XLS.DLL
[11/07/2006 - 14:34:18 | A | 446464] X:\WD100XML.DLL
[07/10/2003 - 14:15:24 | A | 540672] X:\WD553HF.DLL
[29/11/2006 - 10:51:10 | A | 133632] X:\XA_DLL24.dll
[04/03/2009 - 00:14:02 | A | 329] X:\_facture.txt
################## | Vaccin |
C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
################## | Upload |
Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_BUREAU.zip
https://www.ionos.fr/?affiliate_id=77097
Merci de votre contribution.
################## | E.O.F |
############################## | UsbFix 7.025 | [Suppression]
Utilisateur: Jérémy PIAU (Administrateur) # BUREAU [ ]
Mis à jour le 15/09/10 par El Desaparecido / C_XX
Lancé à 09:33:45 | 20/09/2010
Site Web: http://www.teamxscript.org
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
CPU 2: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Pare-feu Windows: Désactivé /!\
Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
RAM -> 2046 Mo
C:\ (%systemdrive%) -> Disque fixe # 89 Go (32 Go libre(s) - 36%) [Preload] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
################## | Éléments infectieux |
Non supprimé ! E:\Autorun.inf
Non supprimé ! X:\image.jpg
Non supprimé ! X:\test.exe
################## | Registre |
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cleanup.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divxdec.ax
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DJSMAR00.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRMINST.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncodeDivXExt.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncryptPatchVer.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\front.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fullsoft.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GBROWSER.DLL
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmarq.ocx
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmm.ocx
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ishscan.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ISSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm_g.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\main123w.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mngreg32.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msci_uno.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvr.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mso.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVOPTRF.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeVideoFX.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPMLIC.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSWSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photohse.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PMSTE.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppw32hlp.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\printhse.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prwin8.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ps80.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psdmt.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qfinder.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qpw.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\salwrap.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup32.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sevinst.exe
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcnet.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcore_ebook.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TFDTCTT8.DLL
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ua80.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\udtapi.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ums.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vb40032.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbe6.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpwin8.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xlmlEN.dll
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xwsetup.EXE
Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
################## | Mountpoints2 |
################## | Listing |
[27/07/2010 - 19:50:00 | A | 1024] C:\.rnd
[18/08/2009 - 19:37:43 | D ] C:\90fa146bf70292f9d4
[20/08/2010 - 18:42:18 | A | 47304] C:\abc.txt
[20/09/2010 - 09:31:59 | A | 4] C:\AUTOEXEC.BAT
[17/09/2010 - 13:45:14 | A | 216] C:\Boot.bak
[17/09/2010 - 20:14:45 | RASH | 332] C:\boot.ini
[05/08/2004 - 13:00:00 | RSH | 4952] C:\bootfont.bin
[17/09/2010 - 20:14:45 | RASHD ] C:\cmdcons
[03/08/2004 - 23:00:08 | RASH | 263488] C:\cmldr
[18/09/2010 - 13:37:16 | A | 19818] C:\ComboFix.txt
[01/02/2006 - 01:34:05 | N | 0] C:\CONFIG.SYS
[16/08/2010 - 15:24:45 | A | 92431] C:\ContactTable.htm
[08/07/2002 - 06:04:24 | N | 4608] C:\CRVsPackageLib.dll
[17/07/2002 - 06:23:10 | N | 475136] C:\CrystalDecisions.CrystalReports.Engine.dll
[08/07/2002 - 06:00:42 | N | 8192] C:\CrystalDecisions.CrystalReports.TemplateEngine.dll
[08/07/2002 - 05:45:42 | N | 32768] C:\CrystalDecisions.Enterprise.Framework.dll
[08/07/2002 - 05:45:44 | N | 53248] C:\CrystalDecisions.Enterprise.InfoStore.dll
[08/07/2002 - 05:45:44 | N | 9216] C:\CrystalDecisions.Enterprise.PluginManager.dll
[08/07/2002 - 05:45:44 | N | 49152] C:\CrystalDecisions.Enterprise.Report.dll
[08/07/2002 - 06:00:40 | N | 57344] C:\CrystalDecisions.ReportAppServer.ClientDoc.dll
[08/07/2002 - 05:58:06 | N | 49152] C:\CrystalDecisions.ReportAppServer.CommLayer.dll
[08/07/2002 - 05:57:52 | N | 126976] C:\CrystalDecisions.ReportAppServer.CommonControls.dll
[08/07/2002 - 05:57:32 | N | 36864] C:\CrystalDecisions.ReportAppServer.CommonObjectModel.dll
[08/07/2002 - 06:00:26 | N | 184320] C:\CrystalDecisions.ReportAppServer.Controllers.dll
[08/07/2002 - 05:58:54 | N | 36864] C:\CrystalDecisions.ReportAppServer.CubeDefModel.dll
[08/07/2002 - 05:58:48 | N | 212992] C:\CrystalDecisions.ReportAppServer.DataDefModel.dll
[08/07/2002 - 07:06:32 | N | 8704] C:\CrystalDecisions.ReportAppServer.DataSetConversion.dll
[08/07/2002 - 05:59:50 | N | 274432] C:\CrystalDecisions.ReportAppServer.ReportDefModel.dll
[08/07/2002 - 05:57:56 | N | 15360] C:\CrystalDecisions.ReportAppServer.XmlSerialize.dll
[11/07/2002 - 06:21:46 | N | 135168] C:\CrystalDecisions.ReportSource.dll
[08/07/2002 - 07:06:28 | N | 557056] C:\CrystalDecisions.Shared.dll
[08/07/2002 - 07:06:30 | N | 204800] C:\CrystalDecisions.Web.dll
[08/07/2002 - 07:06:30 | N | 53248] C:\CrystalDecisions.Web.Mobile.dll
[16/07/2002 - 13:56:48 | N | 237568] C:\CrystalDecisions.Windows.Forms.dll
[15/07/2002 - 05:16:56 | N | 18944] C:\CrystalKeyCodeLib.dll
[07/01/2010 - 14:25:35 | D ] C:\Database
[17/09/2010 - 12:33:40 | D ] C:\Documents and Settings
[27/01/2009 - 17:59:22 | D ] C:\Données Ciel
[27/01/2009 - 22:08:26 | AD ] C:\DRIVERS
[27/01/2009 - 14:33:59 | N | 1911] C:\drivez.log
[02/02/2010 - 18:40:20 | D ] C:\HebeLog
[18/09/2010 - 16:35:16 | ASH | 2145570816] C:\hiberfil.sys
[27/01/2009 - 17:57:29 | D ] C:\HSF
[27/01/2009 - 16:19:28 | AD ] C:\I386
[14/11/2009 - 17:40:02 | D ] C:\Icons
[01/02/2006 - 01:34:05 | RSH | 0] C:\IO.SYS
[17/09/2010 - 20:32:34 | D ] C:\JOKS
[18/09/2010 - 13:37:20 | D ] C:\JOKS11252J
[18/09/2010 - 11:31:06 | D ] C:\JOKS16125J
[17/09/2010 - 20:55:46 | D ] C:\JOKS16613J
[18/09/2010 - 13:01:06 | D ] C:\JOKS8212J
[20/09/2010 - 09:14:27 | D ] C:\Kill'em
[08/06/2009 - 12:28:31 | D ] C:\Kiss
[17/09/2010 - 18:19:18 | A | 41669] C:\List'em.txt
[01/02/2006 - 01:34:05 | RSH | 0] C:\MSDOS.SYS
[27/01/2009 - 16:47:21 | RD ] C:\MSOCache
[05/08/2004 - 13:00:00 | RSH | 47564] C:\NTDETECT.COM
[28/01/2009 - 12:14:45 | RSH | 252240] C:\NTLDR
[30/07/2009 - 16:43:52 | D ] C:\Numérisation
[18/09/2010 - 16:35:14 | ASH | 1610612736] C:\pagefile.sys
[23/12/2009 - 16:46:14 | D ] C:\PowerACT
[17/09/2010 - 17:57:30 | RD ] C:\Program Files
[25/11/2009 - 20:37:53 | D ] C:\PVSW
[18/09/2010 - 13:37:19 | D ] C:\Qoobox
[20/09/2010 - 09:31:50 | SHD ] C:\RECYCLER
[18/09/2010 - 16:36:10 | A | 61] C:\riv4debug.txt
[26/08/2009 - 14:32:18 | RD ] C:\RRbackups
[02/02/2010 - 12:56:00 | D ] C:\Serveur HF
[15/01/2010 - 18:55:30 | D ] C:\Serveur Hyper File - Installation
[02/02/2010 - 12:53:25 | D ] C:\Serveur HyperFileSQL - Installation
[02/02/2010 - 12:56:53 | D ] C:\ServeurHF
[31/01/2006 - 11:54:58 | AD ] C:\SUPPORT
[27/01/2009 - 16:18:18 | D ] C:\SWTOOLS
[27/01/2009 - 22:08:23 | N | 93] C:\syslevel.lgl
[18/09/2010 - 13:31:55 | SHD ] C:\System Volume Information
[17/09/2010 - 17:38:55 | D ] C:\tdsskiller
[17/09/2010 - 17:37:39 | A | 1974] C:\TDSSKiller.2.4.2.1_17.09.2010_17.37.26_log.txt
[17/09/2010 - 17:39:56 | A | 54746] C:\TDSSKiller.2.4.2.1_17.09.2010_17.38.55_log.txt
[17/09/2010 - 17:49:53 | A | 104190] C:\TDSSKiller.2.4.2.1_17.09.2010_17.46.57_log.txt
[24/02/2010 - 19:14:21 | A | 16609280] C:\testpoweract.accdb
[20/08/2010 - 11:32:37 | D ] C:\Transfert
[21/09/2009 - 09:35:39 | N | 922] C:\updatedatfix.log
[20/09/2010 - 09:35:26 | D ] C:\UsbFix
[20/09/2010 - 09:35:25 | A | 815] C:\UsbFix.txt
[31/01/2006 - 11:54:58 | AD ] C:\VALUEADD
[20/09/2010 - 09:14:57 | AD ] C:\WINDOWS
[25/01/2010 - 11:36:21 | RD ] E:\Win32
[25/01/2010 - 11:36:20 | R | 49] E:\autorun.inf
[25/01/2010 - 11:36:24 | RD ] E:\common
[25/01/2010 - 11:36:20 | R | 331776] E:\e-secure.exe
[16/01/2009 - 15:08:22 | A | 39546] X:\#entete_cm.jpg
[15/01/2009 - 16:58:42 | A | 1416836] X:\#entete_cm.rtf
[11/08/2008 - 09:04:28 | A | 333393] X:\accueil.rtf
[27/07/2010 - 14:02:17 | A | 203110379] X:\ACT! ladymoving 2a60a86e4dee4698b5a817fcbeb4d3db 2010-07-27 14-00-00.zip
[19/12/2006 - 15:37:58 | A | 50283] X:\Alarm.mp3
[19/12/2006 - 14:38:16 | A | 57856] X:\AXDLL.DLL
[19/12/2006 - 14:38:16 | A | 197632] X:\AXDLL16.DLL
[19/12/2006 - 14:38:16 | A | 57856] X:\AXDLL32.DLL
[12/08/2009 - 16:23:48 | A | 10361] X:\baspage_tickets.jpg
[05/02/2010 - 17:39:42 | D ] X:\Carré Soleil.wd7
[10/10/2007 - 12:52:34 | A | 8937] X:\cercle.JPG
[02/02/2010 - 14:58:23 | ASH | 102] X:\Connexion new.wx
[01/02/2010 - 00:13:04 | A | 17406163] X:\Connexion.exe
[16/02/2010 - 13:25:40 | A | 16554] X:\Connexion.REP
[02/02/2010 - 19:01:21 | A | 17406315] X:\CxAcces.exe
[02/02/2010 - 19:03:52 | A | 528] X:\CxAcces.REP
[02/02/2010 - 14:58:23 | ASH | 102] X:\CxAgenda new.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxAtr old.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxAtr.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxAtr_Clas.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxCaisse.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxExports.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxImports.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxSuccursale.wx
[02/02/2010 - 14:58:24 | ASH | 102] X:\CxTactile new.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxTactile old.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxTactile.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxVideos new.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\CxVideos.wx
[24/08/2005 - 11:05:06 | A | 4765] X:\cyan.JPG
[21/07/2010 - 18:24:14 | D ] X:\Doc
[04/10/2009 - 19:08:18 | A | 474151] X:\dos.jpg
[30/09/2009 - 18:23:26 | A | 13316] X:\ellip6.jpg
[12/08/2009 - 16:27:26 | A | 8666] X:\entete_tickets.jpg
[28/10/2009 - 10:30:40 | A | 162] X:\F2000-01.txt
[12/05/2009 - 13:35:28 | A | 70629] X:\fnf.jpg
[16/09/2009 - 17:41:22 | A | 55803] X:\fp.bmp
[29/11/2006 - 10:51:20 | A | 69632] X:\FTD2XX.dll
[02/05/2006 - 20:41:46 | A | 479217] X:\Gmw old.WDD
[17/11/2006 - 17:00:46 | A | 488772] X:\Gmw.WDD
[21/01/2010 - 21:54:52 | A | 919734] X:\graphe.bmp
[06/02/2008 - 09:47:42 | A | 3528151] X:\gt.wmv
[19/12/2006 - 15:38:06 | A | 174838] X:\Happy.wav
[10/06/2008 - 09:28:30 | A | 7397] X:\hebe.gif
[17/11/2008 - 09:27:38 | A | 919206] X:\ico.bmp
[17/11/2008 - 09:27:44 | A | 86358] X:\ico.ico
[02/02/2010 - 16:18:19 | A | 6737] X:\Ident.FIC
[17/01/2008 - 10:51:02 | A | 3603] X:\Ident.NDX
[31/10/2009 - 12:18:44 | A | 56694] X:\image.bmp
[04/08/2009 - 08:44:28 | A | 12761] X:\image.gif
[31/10/2009 - 12:18:44 | A | 5255] X:\image.jpg
[04/08/2009 - 08:45:24 | A | 28771] X:\image.png
[14/02/2007 - 09:58:48 | A | 537906] X:\lm.bmp
[07/10/2008 - 11:12:56 | A | 443718] X:\Logo perroquet.bmp
[10/06/2008 - 09:15:48 | A | 4500] X:\logo.gif
[17/11/2008 - 09:18:54 | A | 86358] X:\Logo.ico
[03/11/2008 - 16:05:00 | A | 13342] X:\logo.jpg
[23/09/2008 - 14:29:38 | A | 349138] X:\Logo2.bmp
[08/08/2003 - 19:56:12 | A | 17999] X:\Logo_atr.jpg
[26/10/2009 - 14:33:20 | A | 411385] X:\logo_atr.rtf
[17/09/2009 - 12:39:04 | A | 166320] X:\log_fitness_park_OK.jpg
[02/02/2010 - 14:55:13 | D ] X:\Master
[11/08/2008 - 09:05:48 | A | 7251] X:\Message.rtf
[02/10/2007 - 13:40:30 | A | 9695] X:\Multi.FIC
[02/10/2007 - 13:13:12 | A | 32934] X:\Multi.NDX
[06/07/2009 - 14:03:12 | A | 928694] X:\Pub.rtf
[15/03/2008 - 14:14:06 | A | 202104] X:\pub1.jpg
[29/04/2007 - 18:36:54 | A | 641811] X:\pub2.jpg
[21/01/2004 - 23:38:26 | A | 4082688] X:\qtintf70.dll
[26/07/2008 - 16:20:32 | A | 896] X:\resa.ini
[30/04/2008 - 12:03:06 | A | 9976] X:\resa_logo.jpg
[19/12/2006 - 14:37:26 | A | 10026] X:\ringin.wav
[25/03/2008 - 13:43:04 | A | 60] X:\sauve.ini
[19/12/2006 - 14:38:20 | A | 52224] X:\SCOMM.DLL
[12/11/2008 - 10:43:20 | A | 194] X:\ServeurHf.ini
[25/03/2008 - 09:40:16 | A | 373] X:\ServeurHFold.ini
[15/06/2007 - 21:26:24 | A | 2699010] X:\sports.wmv
[21/03/2007 - 19:41:12 | A | 89600] X:\SUNDLL.dll
[25/11/2009 - 18:38:34 | A | 16837349] X:\Tactile.exe
[02/02/2010 - 14:58:25 | ASH | 102] X:\Tactile.wx
[21/04/2008 - 15:09:40 | A | 567836] X:\temp.emf
[07/10/2009 - 10:56:10 | A | 16622702] X:\test.exe
[02/02/2010 - 14:58:25 | ASH | 102] X:\test.wx
[31/12/2008 - 16:49:36 | A | 26874] X:\usine.jpg
[15/12/1999 - 16:00:00 | A | 95708] X:\Utopia.WAV
[16/06/2008 - 12:38:06 | A | 264] X:\var.ini
[02/02/2010 - 14:58:25 | ASH | 102] X:\Video1.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\Videos.wx
[02/02/2010 - 14:58:25 | ASH | 102] X:\Video_test.wx
[27/02/2006 - 16:13:44 | A | 118784] X:\WD100BARC.DLL
[26/09/2006 - 18:05:58 | A | 458752] X:\WD100COM.DLL
[22/05/2006 - 19:47:48 | A | 491520] X:\WD100DB.DLL
[20/06/2006 - 19:28:54 | A | 344064] X:\WD100ETAT.DLL
[08/06/2006 - 13:17:48 | A | 261120] X:\WD100GRF.DLL
[25/07/2006 - 17:46:26 | A | 2098688] X:\WD100HF.DLL
[29/08/2006 - 19:00:38 | A | 397312] X:\WD100HTML.DLL
[15/06/2006 - 17:50:56 | A | 626688] X:\WD100IMG.DLL
[12/04/2006 - 19:09:00 | A | 94208] X:\WD100MAT.DLL
[28/08/2006 - 13:03:06 | A | 1925120] X:\WD100OBJ.DLL
[15/06/2006 - 15:58:18 | A | 499712] X:\WD100OLDB.DLL
[29/06/2006 - 13:41:50 | A | 106496] X:\WD100OLE.DLL
[18/04/2006 - 00:18:48 | A | 483383] X:\WD100PDF.DLL
[13/06/2006 - 18:52:44 | A | 557056] X:\WD100PRN.DLL
[14/06/2006 - 09:49:34 | A | 528384] X:\WD100RTF.DLL
[07/07/2006 - 15:15:30 | A | 409600] X:\WD100SQL.DLL
[18/07/2006 - 11:43:44 | A | 433152] X:\WD100STD.DLL
[23/10/2006 - 16:39:22 | A | 1307648] X:\WD100VM.DLL
[02/06/2006 - 18:36:56 | A | 143360] X:\WD100XLS.DLL
[11/07/2006 - 14:34:18 | A | 446464] X:\WD100XML.DLL
[07/10/2003 - 14:15:24 | A | 540672] X:\WD553HF.DLL
[29/11/2006 - 10:51:10 | A | 133632] X:\XA_DLL24.dll
[04/03/2009 - 00:14:02 | A | 329] X:\_facture.txt
################## | Vaccin |
C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
################## | Upload |
Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_BUREAU.zip
https://www.ionos.fr/?affiliate_id=77097
Merci de votre contribution.
################## | E.O.F |
lien pour le ZHPdiag.txt :
http://www.cijoint.fr/cjlink.php?file=cj201009/cijNXybAZL.txt
Merci d'avance
http://www.cijoint.fr/cjlink.php?file=cj201009/cijNXybAZL.txt
Merci d'avance
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
ok
on termine proprement
1)
* Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )
[HKCU\Software\20W6RLKX65]
[HKLM\Software\SEC]
Puis Lance ZHPFix depuis le raccourci du bureau .
* Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .
* Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".
Copie/Colle le rapport à l'écran dans ton prochain message
( ce rapport est sauvegardé dans ce dossier C:\Program files\ZHPDiag\ZHPFixReport.txt )
..........................
2)
Mettre à jour la Console Java ? :
https://www.java.com/fr/download/uninstalltool.jsp
et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).
voici pour desinstaller :
JavaRa
http://raproducts.org/click/click.php?id=1
Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Choisis Français puis clique sur Select.
* Clique sur Recherche de mises à jour.
* Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
* Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
.............
3)
Mets à jour Adobe Reader (désinstalle avant la version antérieure)
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
puis
* Lancez Adobe Reader
* Cliquez sur Edition --> Préférences --> JavaScript
* Décochez "Activer Acrobat JavaScript"
* Validez
....................
4)
IMPORTANT
Purger la restauration systeme XP
http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm
.................
5)
Télécharge DelFix sur ton bureau.
http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe
1. Lance le, tape 2 puis valide en appuyant sur [Entrée]
2. Patiente pendant le scan jusqu'à l'ouverture du rapport.
3. Copie/Colle le contenu du rapport dans ta prochaine réponse.
Note : Le rapport se trouve également sous C:\DelFixSearch
...................
Recommandations pour l'avenir
Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
- logiciels non à jour (windows, internet explorer, java, adobe reader etc)
- installation de toolbar
- fréquentation de sites piégés
- P2P
- Application de cracks
- Supports usb
Pour t'aider dans cette tâche, voici quelques pistes
Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
http://www.mozilla-europe.org/fr/firefox/
Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
pour bloquer les publicités
https://addons.mozilla.org/fr/mobile/addon/1865
............................
WOT - Extension pour ton navigateur internet :
Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp
........................
Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker
https://www.commentcamarche.net/telecharger/utilitaires/9771-filehippo-app-manager/
Et particulièrement Internet explorer, même s'il n'est pas ton navigateur, car les MAJ sécurité Windows ne s'opèrent que par ce chemin là
......................................
Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !
..........................
Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
Au menu principal, choisis l'option 3 (Vaccination).
explications ici https://forum.malekal.com/viewtopic.php?t=5544&start=
............................
garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
.......................
Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
..........................
utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html
........................
A lire pour mieux comprendre l'environnement qui t'entoure
http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf
http://www.libellules.ch/...
CONTRIBUTEUR SECURITE
Désinfection = diagnostic + traitement + finalisation
"Restez" jusqu'au bout...merci
on termine proprement
1)
* Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )
[HKCU\Software\20W6RLKX65]
[HKLM\Software\SEC]
Puis Lance ZHPFix depuis le raccourci du bureau .
* Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .
* Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".
Copie/Colle le rapport à l'écran dans ton prochain message
( ce rapport est sauvegardé dans ce dossier C:\Program files\ZHPDiag\ZHPFixReport.txt )
..........................
2)
Mettre à jour la Console Java ? :
https://www.java.com/fr/download/uninstalltool.jsp
et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).
voici pour desinstaller :
JavaRa
http://raproducts.org/click/click.php?id=1
Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Choisis Français puis clique sur Select.
* Clique sur Recherche de mises à jour.
* Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
* Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
.............
3)
Mets à jour Adobe Reader (désinstalle avant la version antérieure)
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
puis
* Lancez Adobe Reader
* Cliquez sur Edition --> Préférences --> JavaScript
* Décochez "Activer Acrobat JavaScript"
* Validez
....................
4)
IMPORTANT
Purger la restauration systeme XP
http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm
.................
5)
Télécharge DelFix sur ton bureau.
http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe
1. Lance le, tape 2 puis valide en appuyant sur [Entrée]
2. Patiente pendant le scan jusqu'à l'ouverture du rapport.
3. Copie/Colle le contenu du rapport dans ta prochaine réponse.
Note : Le rapport se trouve également sous C:\DelFixSearch
...................
Recommandations pour l'avenir
Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
- logiciels non à jour (windows, internet explorer, java, adobe reader etc)
- installation de toolbar
- fréquentation de sites piégés
- P2P
- Application de cracks
- Supports usb
Pour t'aider dans cette tâche, voici quelques pistes
Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
http://www.mozilla-europe.org/fr/firefox/
Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
pour bloquer les publicités
https://addons.mozilla.org/fr/mobile/addon/1865
............................
WOT - Extension pour ton navigateur internet :
Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp
........................
Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker
https://www.commentcamarche.net/telecharger/utilitaires/9771-filehippo-app-manager/
Et particulièrement Internet explorer, même s'il n'est pas ton navigateur, car les MAJ sécurité Windows ne s'opèrent que par ce chemin là
......................................
Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !
..........................
Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
Au menu principal, choisis l'option 3 (Vaccination).
explications ici https://forum.malekal.com/viewtopic.php?t=5544&start=
............................
garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
.......................
Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
..........................
utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html
........................
A lire pour mieux comprendre l'environnement qui t'entoure
http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf
http://www.libellules.ch/...
CONTRIBUTEUR SECURITE
Désinfection = diagnostic + traitement + finalisation
"Restez" jusqu'au bout...merci
Rapport ZHPFix :
Rapport de ZHPFix v1.12.3153 par Nicolas Coolman, Update du 16/09/2010
Fichier d'export Registre : C:\ZHPExportRegistry-20-09-2010-14-02-59.txt
Run by Jérémy PIAU at 20/09/2010 14:02:59
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Clé(s) du Registre ==========
HKCU\Software\20W6RLKX65 => Clé supprimée avec succès
HKLM\Software\SEC => Clé supprimée avec succès
========== Autre ==========
<gras> => Format Non supporté
========== Récapitulatif ==========
2 : Clé(s) du Registre
1 : Autre
End of the scan
Rapport de ZHPFix v1.12.3153 par Nicolas Coolman, Update du 16/09/2010
Fichier d'export Registre : C:\ZHPExportRegistry-20-09-2010-14-02-59.txt
Run by Jérémy PIAU at 20/09/2010 14:02:59
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Clé(s) du Registre ==========
HKCU\Software\20W6RLKX65 => Clé supprimée avec succès
HKLM\Software\SEC => Clé supprimée avec succès
========== Autre ==========
<gras> => Format Non supporté
========== Récapitulatif ==========
2 : Clé(s) du Registre
1 : Autre
End of the scan
rapport Javara :
JavaRa 1.16 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Mon Sep 20 14:09:53 2010
Found and removed: C:\Program Files\Java\jre1.5.0_06
Found and removed: C:\Program Files\Java\jre1.6.0_07
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_07
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_11
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_13
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_14
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_15
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\JRERunOnce.exe
Found and removed: Software\JavaSoft\Java2D\1.5.0_06
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\JavaPlugin.150_06
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Classes\JavaPlugin.160_07
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06
Found and removed: Software\Classes\JavaPlugin.160_07
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_07
Found and removed: Software\JavaSoft\Java2D\1.6.0_07
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
JavaRa 1.16 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Mon Sep 20 15:10:08 2010
------------------------------------
Finished reporting.
JavaRa 1.16 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Mon Sep 20 14:09:53 2010
Found and removed: C:\Program Files\Java\jre1.5.0_06
Found and removed: C:\Program Files\Java\jre1.6.0_07
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_07
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_11
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_13
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_14
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\jre1.6.0_15
Found and removed: C:\Documents and Settings\Jérémy PIAU\Application Data\Sun\Java\JRERunOnce.exe
Found and removed: Software\JavaSoft\Java2D\1.5.0_06
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\JavaPlugin.150_06
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Classes\JavaPlugin.160_07
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06
Found and removed: Software\Classes\JavaPlugin.160_07
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_07
Found and removed: Software\JavaSoft\Java2D\1.6.0_07
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
JavaRa 1.16 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Mon Sep 20 15:10:08 2010
------------------------------------
Finished reporting.
rapport DelFix :
Rapport DelFix v3.8
Mis à jour le 18/09/10 à 18h par Xplode
Lancé le 20/09/2010 à 15h28 et 38 seconde(s)
Utilisateur : J'r'my PIAU - BUREAU
Système d'exploitation : Microsoft Windows XP - 32 bits
Internet Explorer : v8.0.6001.18702
Mode de démarrage : Normal
Option [Suppression]
~~~~~~ C:\ ~~~~~~
Dossier Supprimé : C:\Qoobox
Dossier Supprimé : C:\USBFix
Dossier Supprimé : C:\tdsskiller
Fichier Supprimé : C:\ComboFix.txt
Fichier Supprimé : C:\List'em.txt
Fichier Supprimé : C:\UsbFix.txt
Fichier Supprimé : C:\UsbFix_Upload_Me_BUREAU.zip
Fichier Supprimé : C:\TDSSKiller.2.4.2.1_17.09.2010_17.37.26_log.txt
Fichier Supprimé : C:\TDSSKiller.2.4.2.1_17.09.2010_17.38.55_log.txt
Fichier Supprimé : C:\TDSSKiller.2.4.2.1_17.09.2010_17.46.57_log.txt
~~~~~~ C:\WINDOWS ~~~~~~
Dossier Supprimé : C:\WINDOWS\ERDNT
Fichier Supprimé : C:\WINDOWS\grep.exe
Fichier Supprimé : C:\WINDOWS\PEV.exe
Fichier Supprimé : C:\WINDOWS\NIRCMD.exe
Fichier Supprimé : C:\WINDOWS\MBR.exe
Fichier Supprimé : C:\WINDOWS\sed.exe
Fichier Supprimé : C:\WINDOWS\SWREG.exe
Fichier Supprimé : C:\WINDOWS\SWSC.exe
Fichier Supprimé : C:\WINDOWS\SWXCACLS.exe
Fichier Supprimé : C:\WINDOWS\zip.exe
~~~~~~ C:\WINDOWS\System32 ~~~~~~
~~~~~~ C:\Program Files ~~~~~~
Dossier Supprimé : C:\Program Files\List_Kill'em
Dossier Supprimé : C:\Program Files\ZHPDiag
Dossier Supprimé : C:\Program Files\trend micro
~~~~~~ C:\Documents and Settings\J'r'my PIAU ~~~~~~
~~~~~~ C:\Documents and Settings\J'r'my PIAU\Bureau ~~~~~~
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\Othman.JPG
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\MBRCheck_09.17.10_16.56.03.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\MBRCheck_09.20.10_09.40.41.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\More.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\HijackThis.lnk
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\hijackthis.log
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\ZHPDiag.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\ZHPFixReport.txt
~~~~~~ C:\Documents and Settings\All Users\Bureau ~~~~~~
Fichier Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
Fichier Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
~~~~~~ C:\Documents and Settings\All Users\Menu démarrer\Programmes ~~~~~~
Dossier Supprimé : C:\Documents and Settings\All Users\Menu démarrer\Programmes\List_Kill'em
~~~~~~ C:\Documents and Settings\J'r'my PIAU\Mes documents\Téléchargements ~~~~~~
~~~~~~ Registre ~~~~~~
Clé Supprimée : HKLM\Software\swearware
Clé Supprimée : HKLM\Software\TrendMicro
Clé Supprimée : HKCU\SOFTWARE\USBFix
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USBFix
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E88BA4E8-6B36-4D39-9499-C10B439819E1}_is1
########## EOF - "C:\DelFixSuppr.txt" - [3103 octets] ##########
Rapport DelFix v3.8
Mis à jour le 18/09/10 à 18h par Xplode
Lancé le 20/09/2010 à 15h28 et 38 seconde(s)
Utilisateur : J'r'my PIAU - BUREAU
Système d'exploitation : Microsoft Windows XP - 32 bits
Internet Explorer : v8.0.6001.18702
Mode de démarrage : Normal
Option [Suppression]
~~~~~~ C:\ ~~~~~~
Dossier Supprimé : C:\Qoobox
Dossier Supprimé : C:\USBFix
Dossier Supprimé : C:\tdsskiller
Fichier Supprimé : C:\ComboFix.txt
Fichier Supprimé : C:\List'em.txt
Fichier Supprimé : C:\UsbFix.txt
Fichier Supprimé : C:\UsbFix_Upload_Me_BUREAU.zip
Fichier Supprimé : C:\TDSSKiller.2.4.2.1_17.09.2010_17.37.26_log.txt
Fichier Supprimé : C:\TDSSKiller.2.4.2.1_17.09.2010_17.38.55_log.txt
Fichier Supprimé : C:\TDSSKiller.2.4.2.1_17.09.2010_17.46.57_log.txt
~~~~~~ C:\WINDOWS ~~~~~~
Dossier Supprimé : C:\WINDOWS\ERDNT
Fichier Supprimé : C:\WINDOWS\grep.exe
Fichier Supprimé : C:\WINDOWS\PEV.exe
Fichier Supprimé : C:\WINDOWS\NIRCMD.exe
Fichier Supprimé : C:\WINDOWS\MBR.exe
Fichier Supprimé : C:\WINDOWS\sed.exe
Fichier Supprimé : C:\WINDOWS\SWREG.exe
Fichier Supprimé : C:\WINDOWS\SWSC.exe
Fichier Supprimé : C:\WINDOWS\SWXCACLS.exe
Fichier Supprimé : C:\WINDOWS\zip.exe
~~~~~~ C:\WINDOWS\System32 ~~~~~~
~~~~~~ C:\Program Files ~~~~~~
Dossier Supprimé : C:\Program Files\List_Kill'em
Dossier Supprimé : C:\Program Files\ZHPDiag
Dossier Supprimé : C:\Program Files\trend micro
~~~~~~ C:\Documents and Settings\J'r'my PIAU ~~~~~~
~~~~~~ C:\Documents and Settings\J'r'my PIAU\Bureau ~~~~~~
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\Othman.JPG
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\MBRCheck_09.17.10_16.56.03.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\MBRCheck_09.20.10_09.40.41.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\More.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\HijackThis.lnk
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\hijackthis.log
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\ZHPDiag.txt
Fichier Supprimé : C:\Documents and Settings\J'r'my PIAU\Bureau\ZHPFixReport.txt
~~~~~~ C:\Documents and Settings\All Users\Bureau ~~~~~~
Fichier Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
Fichier Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
~~~~~~ C:\Documents and Settings\All Users\Menu démarrer\Programmes ~~~~~~
Dossier Supprimé : C:\Documents and Settings\All Users\Menu démarrer\Programmes\List_Kill'em
~~~~~~ C:\Documents and Settings\J'r'my PIAU\Mes documents\Téléchargements ~~~~~~
~~~~~~ Registre ~~~~~~
Clé Supprimée : HKLM\Software\swearware
Clé Supprimée : HKLM\Software\TrendMicro
Clé Supprimée : HKCU\SOFTWARE\USBFix
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USBFix
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E88BA4E8-6B36-4D39-9499-C10B439819E1}_is1
########## EOF - "C:\DelFixSuppr.txt" - [3103 octets] ##########