Trojan.downloader.small.wv

Résolu
ISA -  
 NAEGELEN -
Bonsoir,

Depuis quelques jours, j'ai un message de biddefender8 pro qui me dit que le trojan downloader.small.wv est bloqué et que mon micro n' est pas infecté. Malgré la suppression dans temporary internet files de tous les fichiers j'ai toujours le même message. Que dois-je faire ?
ci-dessous le compte rendu de bitdefender :

c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm=>(IFRAME) suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm=>(IFRAME) suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm=>(IFRAME) suspect: Trojan.Downloader.Small.WV.
Merci d'avance de votre aide.

19 réponses

Kristopher Messages postés 3752 Statut Contributeur 106
 
Hello,

- Télécharge CCLEANER et nettoie ton PC avec : http://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
Tutorial là : http://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
(Copyright © Kristopher)

Ensuite


-Télécharge HijackThis : http://www.01net.com/telecharger/windows/Internet/internet_utlitaire/fiches/29061.html
-Installe le dans son propre dossier.
Par exemple, C:\HijackThis
Choisis l'option "do a scan and a logfile", il va te générer un rapport, copie et colle sur le forum.
Regarde la démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

Bonne chance

++
0
ISA
 
Merci de me répondre aussi vite

j'ai nettoyé mon micro avec Ccleaner

Voici le compte rendu de hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 20:26:18, on 21/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\HPPAVI~1\Pavilion\XPHWWBP4\plugin\bin\pchbutton.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender8\vsserv.exe
c:\progra~1\softwin\bitdef~1\bdmcon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\Z11VAM29\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.free.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.50.166.13 google.com
O1 - Hosts: 69.50.166.13 google.co.uk
O1 - Hosts: 69.50.166.13 google.ca
O1 - Hosts: 69.50.166.13 google.es
O1 - Hosts: 69.50.166.13 google.de
O1 - Hosts: 69.50.166.13 google.fr
O1 - Hosts: 69.50.166.13 google.com.au
O1 - Hosts: 69.50.166.12 yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDMCon] c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPPAVI~1\Pavilion\XPHWWBP4\plugin\bin\pchbutton.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.virustraq.com/img/scan_virus/webscan.cab
O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.5 Combo Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
0
Kristopher Messages postés 3752 Statut Contributeur 106
 
Hello,

- Fixe ces lignes avec HijackThis :

O1 - Hosts: 69.50.166.13 google.com
O1 - Hosts: 69.50.166.13 google.co.uk
O1 - Hosts: 69.50.166.13 google.ca
O1 - Hosts: 69.50.166.13 google.es
O1 - Hosts: 69.50.166.13 google.de
O1 - Hosts: 69.50.166.13 google.fr
O1 - Hosts: 69.50.166.13 google.com.au
O1 - Hosts: 69.50.166.12 yahoo.com

O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.5 Combo Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab

- Télécharge et scanne ton PC avec Ewido Security Suite : http://www.01net.com/telecharger/windows/Utilitaire/antivirus/fiches/31851.html
Copie/colle le rapport sur le forum.

Bon courage :)

++
0
ISA
 
--Voilà le résultat du scan
-----------------------------------------------------
ewido anti-malware - Rapport de scan
---------------------------------------------------------

+ Créé le: 21:20:25, 21/01/2006
+ Somme de contrôle: E251A148

+ Résultats du scan:

C:\Documents and Settings\Propriétaire\Cookies\propriétaire@estat[1].txt -> Spyware.Cookie.Estat : Nettoyer et sauvegarder
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@wreport.weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder


::Fin du rapport



pendant le scan, j'ai eu un message de bitdefender comme le trojan downloader.small.wv.
Apparement, il est toujours là.

Merci de me donner une solution si possible
0
Kristopher Messages postés 3752 Statut Contributeur 106
 
Hello,

As-tu fixé les lignes que je t'ai indiqué au poste < 3 > ?

- Scannes ton PC avec cet antivirus en ligne : http://www.pandasoftware.com/activescan/fr/activescan_principal.htm
Copie/colle le rapport sur le forum.

Bon courage.

++
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
ISA
 
Bonjour,

J'ai bien fixé les lignes que tu m'as dit.

Voilà le rapport de Panda
Incident Statut Analyse

Adware:adware/startpage.amb No Désinfecté C:\Documents and Settings\Propritaire\Favoris\internet
Adware:adware/azesearch No Désinfecté Registre Windows
Outil indésirable:application/myway No Désinfecté HKEY_CLASSES_ROOT\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}
Adware:adware/ist.istbar No Désinfecté Registre Windows
Spyware:Cookie/fe.lea.lycos No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@fe.lea.lycos[1].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@xiti[1].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Propriétaire\Cookies\propriétaire@serving-sys[2].txt
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Propriétaire\Cookies\propriétaire@weborama[2].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\Propriétaire\Cookies\propriétaire@xiti[1].txt
Outil indésirable:Application/HideWindow.A No Désinfecté C:\hp\bin\FondleWindow.exe
Outil indésirable:Application/KillApp.B No Désinfecté C:\hp\bin\KillIt.exe
Merci de bien vouloir donner les instructions pour éradiquer
ces indésirables.
0
ISA
 
Bonjour,

Personne n'a d'idée pour mon problème ???
0
Kristopher Messages postés 3752 Statut Contributeur 106
 
hello

- Passe un coup de CCleaner

- Ensuite : Scanne ton PC avec cet antispyware en ligne : http://www.trendmicro.com/spyware-scan/
Copie/colle le rapport sur le forum.

Good luck.

++
0
zabo93 Messages postés 2 Statut Membre
 
Me revoilà,

j'ai nettoyé mon micro avec ccleaner, puis j'ai scanner avec trend micro, par contre j'ai fait une erreur de manipulation lors du copié/collé, il m'avait trouvé des spywares. Enfin, j'ai tout supprimé, puis j'ai rescanné là,le message était

no found spyware

J'ai refait un scan avec bitdefendeur, qui me trouve toujours le même trojan
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm Suspects avec Trojan.Downloader.Small.WV

Je suis en train de refaire un scan avec panda
dès que j'ai le résultat je le copie et le coller
0
zabo93 Messages postés 2 Statut Membre
 
rebonjour,

Le compte rendu de panda Adware:adware/startpage.amb No Désinfecté C:\Documents and Settings\Propritaire\Favoris\internet
Outil indésirable:application/myway No Désinfecté HKEY_CLASSES_ROOT\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}
Adware:adware/azesearch No Désinfecté Registre Windows
Spyware:Cookie/fe.lea.lycos No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@fe.lea.lycos[1].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@xiti[1].txt
Outil indésirable:Application/HideWindow.A No Désinfecté C:\hp\bin\FondleWindow.exe
Outil indésirable:Application/KillApp.B No Désinfecté C:\hp\bin\KillIt.exe
Que faut -il que je fasse, maintenant merci pour votre aide
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
salut utilise ce prog
cleanup (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
section virus/logiciel de securite demo animée sur la meme page
voir demo
http://pageperso.aol.fr/balltrap34/democleanup.htm
0
ISA
 
bonjour,
Merci des tes conseils

le rapport de cleanup
CleanUp! started on 01/22/06 16:01:03.
...
C:\Documents and Settings\AURORE\Local Settings\Temp\~DF9C62.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DF9F9E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DF9FBA.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA02B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA061.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA14A.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA14E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA197.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA2BA.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA473.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA57C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA5C5.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA6B6.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA75F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAA82.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAB5B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAB6F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAB9E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFACCC.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFACCD.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFACF.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAD31.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAD63.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFADA8.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAF47.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAF7.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAF74.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB002.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB081.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB093.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB0F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB11B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB186.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB21F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB232.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB402.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB406.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB437.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB487.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB494.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB641.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB6B6.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB860.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB863.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB926.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB9D5.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBA07.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBA51.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBA8F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBAAF.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBB12.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBB18.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBE56.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC06E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC141.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC216.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC27F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC39E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC43B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC518.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC66F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC688.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC6B9.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC6F9.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC73A.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC7D5.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC824.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC885.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC899.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC8DB.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC9BB.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCA88.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCC17.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCE0C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCEB.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCF5B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD032.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD210.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD25E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD27B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD293.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD34E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD43.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD5D.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD5F3.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD8BC.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD909.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD98.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDC24.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDC26.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDD87.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDEA6.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDFD6.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE08C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE098.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE30C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE56E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE58A.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE5E4.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE60C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE6F2.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE705.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE76C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE97B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEAA.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEB18.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEC08.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFECE.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEDA0.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEE0D.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEE1E.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEE29.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEECC.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF070.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF15.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF1CA.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF2A2.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF3C8.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF3DE.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF3E5.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF408.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF46F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF4F.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF4FD.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF647.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF65D.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF6A7.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFA8C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFACB.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFB7B.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFD50.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFE0D.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFE3D.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFF0D.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFF44.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFF7C.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFFC9.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\~WRF0000.tmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\Adobe\Acrobat\6.0\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\Adobe\Acrobat\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\Adobe\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\Temporary File Cache\MpvFile.pvm - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\Temporary File Cache\PrintJob.xml - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\Temporary File Cache\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\hpodcore\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\hpodwiz\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\hsperfdata_AURORE\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml1\01\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml1\02\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml1\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\radBF75F.tmp\HPSUSelfUpdate.exe - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\radBF75F.tmp\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\Temporary File Cache\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\VBE\MSForms.exd - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\VBE\RefEdit.exd - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\VBE\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\appcompat.txt - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\hpqgalry.exe.hdmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\hpqgalry.exe.mdmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\appcompat.txt - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\hpqgalry.exe.hdmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\hpqgalry.exe.mdmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\appcompat.txt - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\hpqgalry.exe.hdmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\hpqgalry.exe.mdmp - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\ - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\Word8.0\MSForms.exd - deleted
C:\Documents and Settings\AURORE\Local Settings\Temp\Word8.0\ - deleted
C:\Documents and Settings\Administrateur\Cookies\index.dat - deleted
C:\Documents and Settings\Administrateur\locals~1\tempor~1\Content.IE5\index.dat - deleted
C:\WINDOWS\Prefetch\Layout.ini - deleted
C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf - deleted
C:\temp\EmlResize_0.log - deleted
C:\BOOT.BAK - deleted
C:\Documents and Settings\Administrateur\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\All Users\DRM\DRMv1.bak - deleted
C:\Documents and Settings\AURORE\Application Data\Microsoft\Address Book\AURORE.wa~ - deleted
C:\Documents and Settings\AURORE\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\fbc2B.tmp - deleted
C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\Fichiers récents\~$edit agricole.lnk - deleted
C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\Récent\index.dat - deleted
C:\Documents and Settings\AURORE\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012005121920051226\index.dat - deleted
C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012005122620060102\index.dat - deleted
C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012006010220060109\index.dat - deleted
C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012006011420060115\index.dat - deleted
C:\Documents and Settings\AURORE\UserData\index.dat - deleted
C:\Documents and Settings\Default User\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Address Book\MICKAEL.wab~ - deleted
C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Address Book\MICKAEL.wa~ - deleted
C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Office\Récent\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012005122620060102\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006010220060109\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006010920060116\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011520060116\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011620060117\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011720060118\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011820060119\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011920060120\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006012020060121\index.dat - deleted
C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006012120060122\index.dat - deleted
C:\Documents and Settings\MICKAEL\UserData\index.dat - deleted
C:\Documents and Settings\Propriétaire\.limewire\fileurns.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\azureus.config.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\azureus.statistics.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\banips.config.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\downloads.config.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\tracker.config.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\08EA33FCC8EF181E2B42AE840868DD3D43A768E5.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\1B0A240B0CBAB86EA87562FC181718DC923DFA6D.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\1E67D4F143FDD98D3222544119F56FF7831A7525.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\56BFB75D654F390E28674BB602E3AA355ACA9D1C.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\70A9FAD9FC825A0004FECB8E1ED6363DEB352B17.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\8EC9AEC62635237E49FFC9560AA9BEE706753057.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\A0CEEACCABF60C2E316D63C7AC1731E9434ECF48.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\A5294A5F616AA203DAAC16911F45E58DF70D09CA.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\C0BC7F53BD5F12C135B200A101E0465F47177F23.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\D41D5B0404E80C444CE0FB108E8F8EB4A77463D7.dat.bak - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\torrents\AZU41410.tmp - deleted
C:\Documents and Settings\Propriétaire\Application Data\Azureus\torrents\AZU59855.tmp - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Address Book\Propriétaire.wab~ - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Address Book\Propriétaire.wa~ - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Fichiers récents\~DEST.lnk - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Fichiers récents\~e5.lnk - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Récent\index.dat - deleted
C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Incomplete\downloads.bak - deleted
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\MSHist012006012220060123\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF83EF.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFCC90.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF83EF.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFCC90.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak - deleted
C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak - deleted
C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak - deleted
C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak - deleted
C:\Documents and Settings\Propriétaire\UserData\index.dat - deleted
C:\Documents and Settings\PropriÚtaire\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Program Files\Championship Manager 01-02\Data\index.dat - deleted
C:\Program Files\eMule\eMule_Chicane.tmpl - deleted
C:\Program Files\eMule\eMule.tmpl - deleted
C:\Program Files\eMule\config\clients.met.BAK - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil4.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil5.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil55.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil6.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil7.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil75.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil76.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil77.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil8.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\fil9.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\filA.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\filB.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\filC.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\reg1.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\reg2.tmp - deleted
C:\Program Files\ewido anti-malware\Quarantine\reg3.tmp - deleted
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdc.ini.bak - deleted
C:\Program Files\Fichiers communs\Symantec Shared\Firewall.BAK - deleted
C:\Program Files\Fichiers communs\Symantec Shared\Persist.BAK - deleted
C:\Program Files\HP\Digital Imaging\Migrate\hpqgends.tmp - deleted
C:\Program Files\HP\Digital Imaging\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}\drivers\scanner\hpqgends.tmp - deleted
C:\Program Files\InterActual\InterActual Player\itiBF.tmp - deleted
C:\Program Files\Kodak\KODAK Software Updater\7288971\clasid.bak - deleted
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\1ea7\UserProf.bak - deleted
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\1ea7\Stats.tmp - deleted
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\6727\UserProf.bak - deleted
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\6727\Stats.tmp - deleted
C:\Program Files\The Cleaner\cleaner4.cdb.bak - deleted
C:\Program Files\The Cleaner\tcm.log.bak - deleted
C:\RECYCLER\S-1-5-21-992659154-1999999487-2737529250-500\Dc1.IE5\MSHist012004112120041122\index.dat - deleted
C:\WINDOWS\CREATOR\RCDCINI.bak - deleted
C:\WINDOWS\Help\wmplayer.bak - deleted
C:\WINDOWS\inf\mplayer2.bak - deleted
C:\WINDOWS\PCHealth\HelpCtr\Config\Cache\Personal_32_1036.dat.bak - deleted
C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat - deleted
C:\WINDOWS\repair\system.bak - deleted
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
C:\WINDOWS\system32\CatRoot2\edb.chk - deleted
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - deleted
C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat - deleted
C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012004010120040102\index.dat - deleted
C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012005032220050323\index.dat - deleted
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - deleted
C:\WINDOWS\system32\NtmsData\NTMSDATA.BAK - deleted
C:\WINDOWS\twain_32\hpqgends.tmp - deleted
D:\I386\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.Manifest - deleted
D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.Manifest - deleted
D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest - deleted
D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.Manifest - deleted
D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.Manifest - deleted
Emptied Recycle Bin on drive C:
'Run MRU' list - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
WinZip Extract MRU list - removed from the registry.
WinZip File MRU list - removed from the registry.
CleanUp! 4.0 recovered 433.7 MB of disk space from 4658 files.
CleanUp! finished on 01/22/06 16:04:08.
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
c etais pas la peine de mettre le ra^pport
refait un scan defender pour voir si c est ok
0
ISA
 
le rapport de bitdefender est toujours le même

C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm Suspects avec Trojan.Downloader.Small.WV

Une autre idée ???
0
jean38 Messages postés 2534 Date d'inscription   Statut Contributeur Dernière intervention   47
 
je ne sais si ball trap est là mais tu es sous la session AURORE et visiblement les temp malware se trouve dans la session Propriétaire.

Mets toi sur cette session et relance Cleanup
0
ISA
 
Je suis bien sous la session propriétaire, j'ai vérifiémalgré tout,
J'ai relancé Cleanup,

voilà son rapport

CleanUp! started on 01/22/06 17:28:21.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
'Typed URLs' (Internet Explorer) - removed from the registry.
C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\pcf1.tmp - deleted
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\temp.log - deleted
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\temp\tmp000003b4\ - deleted
C:\WINDOWS\temp\tmp00000761\tmp00000000 currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\locals~1\tempor~1\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\subC.tmp - deleted
C:\Documents and Settings\Propriétaire\Local Settings\Temp\xmlB.tmp - deleted
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
'Run MRU' list - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
WinZip Extract MRU list - removed from the registry.
WinZip File MRU list - removed from the registry.
CleanUp! 4.0 recovered 505.7 KB of disk space from 6 files.
CleanUp! finished on 01/22/06 17:29:27.
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
repasse cleanup en mode sans echec
0
ISA
 
Merci de votre aide à tous !

ça marche, tout va bien !
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
oki
a++
0
abcd
 
Vous n'auriez pas installé la programe HOTBAR par hazard ?
Ci oui c'est peut-etre pour ca car c'est un logiciel espion.
0
NAEGELEN
 
pas du tout !!!
0