Trojan.downloader.small.wv

Résolu
ISA -  
 NAEGELEN -
Bonsoir,

Depuis quelques jours, j'ai un message de biddefender8 pro qui me dit que le trojan downloader.small.wv est bloqué et que mon micro n' est pas infecté. Malgré la suppression dans temporary internet files de tous les fichiers j'ai toujours le même message. Que dois-je faire ?
ci-dessous le compte rendu de bitdefender :

c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm=>(IFRAME) suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm=>(IFRAME) suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm suspect: Trojan.Downloader.Small.WV
c:\documents and settings\propriétaire\local settings\temporary internet files\content.ie5\yvlzpurh\index[1].htm=>(IFRAME) suspect: Trojan.Downloader.Small.WV.
Merci d'avance de votre aide.
Configuration: xp pack2

19 réponses

  1. Kristopher Messages postés 3752 Statut Contributeur 106
     
    Hello,

    - Télécharge CCLEANER et nettoie ton PC avec : http://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    Tutorial là : http://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
    (Copyright © Kristopher)

    Ensuite


    -Télécharge HijackThis : http://www.01net.com/telecharger/windows/Internet/internet_utlitaire/fiches/29061.html
    -Installe le dans son propre dossier.
    Par exemple, C:\HijackThis
    Choisis l'option "do a scan and a logfile", il va te générer un rapport, copie et colle sur le forum.
    Regarde la démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bonne chance

    ++
    0
  2. ISA
     
    Merci de me répondre aussi vite

    j'ai nettoyé mon micro avec Ccleaner

    Voici le compte rendu de hijackthis
    Logfile of HijackThis v1.99.1
    Scan saved at 20:26:18, on 21/01/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
    C:\HP\KBD\KBD.EXE
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
    C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe
    C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\PROGRA~1\HPPAVI~1\Pavilion\XPHWWBP4\plugin\bin\pchbutton.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
    C:\Program Files\Softwin\BitDefender8\vsserv.exe
    c:\progra~1\softwin\bitdef~1\bdmcon.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\WINDOWS\notepad.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Microsoft Works\WkDStore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\Z11VAM29\HijackThis[1].exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr10.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr10.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.free.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr10.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.free.fr/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: 69.50.166.13 google.com
    O1 - Hosts: 69.50.166.13 google.co.uk
    O1 - Hosts: 69.50.166.13 google.ca
    O1 - Hosts: 69.50.166.13 google.es
    O1 - Hosts: 69.50.166.13 google.de
    O1 - Hosts: 69.50.166.13 google.fr
    O1 - Hosts: 69.50.166.13 google.com.au
    O1 - Hosts: 69.50.166.12 yahoo.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe
    O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe"
    O4 - HKLM\..\Run: [BDMCon] c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPPAVI~1\Pavilion\XPHWWBP4\plugin\bin\pchbutton.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
    O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
    O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.virustraq.com/img/scan_virus/webscan.cab
    O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.5 Combo Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab
    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
    O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe" /service (file missing)
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
    0
  3. Kristopher Messages postés 3752 Statut Contributeur 106
     
    Hello,

    - Fixe ces lignes avec HijackThis :

    O1 - Hosts: 69.50.166.13 google.com
    O1 - Hosts: 69.50.166.13 google.co.uk
    O1 - Hosts: 69.50.166.13 google.ca
    O1 - Hosts: 69.50.166.13 google.es
    O1 - Hosts: 69.50.166.13 google.de
    O1 - Hosts: 69.50.166.13 google.fr
    O1 - Hosts: 69.50.166.13 google.com.au
    O1 - Hosts: 69.50.166.12 yahoo.com

    O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
    O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.5 Combo Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab

    - Télécharge et scanne ton PC avec Ewido Security Suite : http://www.01net.com/telecharger/windows/Utilitaire/antivirus/fiches/31851.html
    Copie/colle le rapport sur le forum.

    Bon courage :)

    ++
    0
    1. ISA
       
      --Voilà le résultat du scan
      -----------------------------------------------------
      ewido anti-malware - Rapport de scan
      ---------------------------------------------------------

      + Créé le: 21:20:25, 21/01/2006
      + Somme de contrôle: E251A148

      + Résultats du scan:

      C:\Documents and Settings\Propriétaire\Cookies\propriétaire@estat[1].txt -> Spyware.Cookie.Estat : Nettoyer et sauvegarder
      C:\Documents and Settings\Propriétaire\Cookies\propriétaire@weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
      C:\Documents and Settings\Propriétaire\Cookies\propriétaire@wreport.weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder


      ::Fin du rapport



      pendant le scan, j'ai eu un message de bitdefender comme le trojan downloader.small.wv.
      Apparement, il est toujours là.

      Merci de me donner une solution si possible
      0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. ISA
     
    Bonjour,

    J'ai bien fixé les lignes que tu m'as dit.

    Voilà le rapport de Panda
    Incident Statut Analyse

    Adware:adware/startpage.amb No Désinfecté C:\Documents and Settings\Propritaire\Favoris\internet
    Adware:adware/azesearch No Désinfecté Registre Windows
    Outil indésirable:application/myway No Désinfecté HKEY_CLASSES_ROOT\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}
    Adware:adware/ist.istbar No Désinfecté Registre Windows
    Spyware:Cookie/fe.lea.lycos No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@fe.lea.lycos[1].txt
    Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@xiti[1].txt
    Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Propriétaire\Cookies\propriétaire@serving-sys[2].txt
    Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Propriétaire\Cookies\propriétaire@weborama[2].txt
    Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\Propriétaire\Cookies\propriétaire@xiti[1].txt
    Outil indésirable:Application/HideWindow.A No Désinfecté C:\hp\bin\FondleWindow.exe
    Outil indésirable:Application/KillApp.B No Désinfecté C:\hp\bin\KillIt.exe
    Merci de bien vouloir donner les instructions pour éradiquer
    ces indésirables.
    0
  6. ISA
     
    Bonjour,

    Personne n'a d'idée pour mon problème ???
    0
  7. Kristopher Messages postés 3752 Statut Contributeur 106
     
    hello

    - Passe un coup de CCleaner

    - Ensuite : Scanne ton PC avec cet antispyware en ligne : http://www.trendmicro.com/spyware-scan/
    Copie/colle le rapport sur le forum.

    Good luck.

    ++
    0
  8. zabo93 Messages postés 2 Statut Membre
     
    Me revoilà,

    j'ai nettoyé mon micro avec ccleaner, puis j'ai scanner avec trend micro, par contre j'ai fait une erreur de manipulation lors du copié/collé, il m'avait trouvé des spywares. Enfin, j'ai tout supprimé, puis j'ai rescanné là,le message était

    no found spyware

    J'ai refait un scan avec bitdefendeur, qui me trouve toujours le même trojan
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm Suspects avec Trojan.Downloader.Small.WV

    Je suis en train de refaire un scan avec panda
    dès que j'ai le résultat je le copie et le coller
    0
  9. zabo93 Messages postés 2 Statut Membre
     
    rebonjour,

    Le compte rendu de panda Adware:adware/startpage.amb No Désinfecté C:\Documents and Settings\Propritaire\Favoris\internet
    Outil indésirable:application/myway No Désinfecté HKEY_CLASSES_ROOT\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}
    Adware:adware/azesearch No Désinfecté Registre Windows
    Spyware:Cookie/fe.lea.lycos No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@fe.lea.lycos[1].txt
    Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\MICKAEL\Local Settings\Temp\Cookies\mickael@xiti[1].txt
    Outil indésirable:Application/HideWindow.A No Désinfecté C:\hp\bin\FondleWindow.exe
    Outil indésirable:Application/KillApp.B No Désinfecté C:\hp\bin\KillIt.exe
    Que faut -il que je fasse, maintenant merci pour votre aide
    0
  10. ISA
     
    bonjour,
    Merci des tes conseils

    le rapport de cleanup
    CleanUp! started on 01/22/06 16:01:03.
    ...
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DF9C62.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DF9F9E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DF9FBA.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA02B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA061.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA14A.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA14E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA197.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA2BA.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA473.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA57C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA5C5.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA6B6.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFA75F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAA82.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAB5B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAB6F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAB9E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFACCC.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFACCD.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFACF.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAD31.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAD63.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFADA8.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAF47.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAF7.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFAF74.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB002.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB081.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB093.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB0F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB11B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB186.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB21F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB232.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB402.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB406.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB437.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB487.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB494.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB641.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB6B6.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB860.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB863.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB926.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFB9D5.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBA07.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBA51.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBA8F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBAAF.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBB12.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBB18.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFBE56.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC06E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC141.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC216.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC27F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC39E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC43B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC518.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC66F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC688.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC6B9.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC6F9.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC73A.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC7D5.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC824.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC885.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC899.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC8DB.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFC9BB.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCA88.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCC17.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCE0C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCEB.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFCF5B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD032.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD210.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD25E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD27B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD293.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD34E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD43.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD5D.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD5F3.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD8BC.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD909.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFD98.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDC24.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDC26.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDD87.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDEA6.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFDFD6.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE08C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE098.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE30C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE56E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE58A.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE5E4.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE60C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE6F2.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE705.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE76C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFE97B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEAA.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEB18.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEC08.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFECE.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEDA0.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEE0D.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEE1E.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEE29.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFEECC.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF070.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF15.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF1CA.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF2A2.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF3C8.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF3DE.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF3E5.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF408.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF46F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF4F.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF4FD.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF647.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF65D.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFF6A7.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFA8C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFACB.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFB7B.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFD50.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFE0D.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFE3D.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFF0D.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFF44.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFF7C.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~DFFFC9.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\~WRF0000.tmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\Adobe\Acrobat\6.0\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\Adobe\Acrobat\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\Adobe\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\Temporary File Cache\MpvFile.pvm - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\Temporary File Cache\PrintJob.xml - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\Temporary File Cache\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\HP PhotoSmart\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\hpodcore\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\hpodwiz\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\hsperfdata_AURORE\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml1\01\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml1\02\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\msohtml1\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\radBF75F.tmp\HPSUSelfUpdate.exe - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\radBF75F.tmp\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\Temporary File Cache\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\VBE\MSForms.exd - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\VBE\RefEdit.exd - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\VBE\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\appcompat.txt - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\hpqgalry.exe.hdmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\hpqgalry.exe.mdmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WER2378.dir00\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\appcompat.txt - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\hpqgalry.exe.hdmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\hpqgalry.exe.mdmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERa723.dir00\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\appcompat.txt - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\hpqgalry.exe.hdmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\hpqgalry.exe.mdmp - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\WERe75a.dir00\ - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\Word8.0\MSForms.exd - deleted
    C:\Documents and Settings\AURORE\Local Settings\Temp\Word8.0\ - deleted
    C:\Documents and Settings\Administrateur\Cookies\index.dat - deleted
    C:\Documents and Settings\Administrateur\locals~1\tempor~1\Content.IE5\index.dat - deleted
    C:\WINDOWS\Prefetch\Layout.ini - deleted
    C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf - deleted
    C:\temp\EmlResize_0.log - deleted
    C:\BOOT.BAK - deleted
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
    C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\All Users\DRM\DRMv1.bak - deleted
    C:\Documents and Settings\AURORE\Application Data\Microsoft\Address Book\AURORE.wa~ - deleted
    C:\Documents and Settings\AURORE\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
    C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\fbc2B.tmp - deleted
    C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\Fichiers récents\~$edit agricole.lnk - deleted
    C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
    C:\Documents and Settings\AURORE\Application Data\Microsoft\Office\Récent\index.dat - deleted
    C:\Documents and Settings\AURORE\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
    C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012005121920051226\index.dat - deleted
    C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012005122620060102\index.dat - deleted
    C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012006010220060109\index.dat - deleted
    C:\Documents and Settings\AURORE\Local Settings\Historique\History.IE5\MSHist012006011420060115\index.dat - deleted
    C:\Documents and Settings\AURORE\UserData\index.dat - deleted
    C:\Documents and Settings\Default User\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Address Book\MICKAEL.wab~ - deleted
    C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Address Book\MICKAEL.wa~ - deleted
    C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
    C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Application Data\Microsoft\Office\Récent\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012005122620060102\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006010220060109\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006010920060116\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011520060116\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011620060117\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011720060118\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011820060119\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006011920060120\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006012020060121\index.dat - deleted
    C:\Documents and Settings\MICKAEL\Local Settings\Historique\History.IE5\MSHist012006012120060122\index.dat - deleted
    C:\Documents and Settings\MICKAEL\UserData\index.dat - deleted
    C:\Documents and Settings\Propriétaire\.limewire\fileurns.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\azureus.config.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\azureus.statistics.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\banips.config.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\downloads.config.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\tracker.config.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\08EA33FCC8EF181E2B42AE840868DD3D43A768E5.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\1B0A240B0CBAB86EA87562FC181718DC923DFA6D.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\1E67D4F143FDD98D3222544119F56FF7831A7525.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\56BFB75D654F390E28674BB602E3AA355ACA9D1C.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\70A9FAD9FC825A0004FECB8E1ED6363DEB352B17.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\8EC9AEC62635237E49FFC9560AA9BEE706753057.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\A0CEEACCABF60C2E316D63C7AC1731E9434ECF48.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\A5294A5F616AA203DAAC16911F45E58DF70D09CA.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\C0BC7F53BD5F12C135B200A101E0465F47177F23.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\active\D41D5B0404E80C444CE0FB108E8F8EB4A77463D7.dat.bak - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\torrents\AZU41410.tmp - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Azureus\torrents\AZU59855.tmp - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Address Book\Propriétaire.wab~ - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Address Book\Propriétaire.wa~ - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Fichiers récents\~DEST.lnk - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Fichiers récents\~e5.lnk - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
    C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Office\Récent\index.dat - deleted
    C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Incomplete\downloads.bak - deleted
    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\HP\Digital Imaging\db\ImageCatalog.mdb.bak - deleted
    C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\MSHist012006012220060123\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF83EF.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFCC90.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF83EF.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFCC90.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak - deleted
    C:\Documents and Settings\Propriétaire\UserData\index.dat - deleted
    C:\Documents and Settings\PropriÚtaire\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Program Files\Championship Manager 01-02\Data\index.dat - deleted
    C:\Program Files\eMule\eMule_Chicane.tmpl - deleted
    C:\Program Files\eMule\eMule.tmpl - deleted
    C:\Program Files\eMule\config\clients.met.BAK - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil4.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil5.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil55.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil6.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil7.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil75.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil76.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil77.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil8.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\fil9.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\filA.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\filB.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\filC.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\reg1.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\reg2.tmp - deleted
    C:\Program Files\ewido anti-malware\Quarantine\reg3.tmp - deleted
    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdc.ini.bak - deleted
    C:\Program Files\Fichiers communs\Symantec Shared\Firewall.BAK - deleted
    C:\Program Files\Fichiers communs\Symantec Shared\Persist.BAK - deleted
    C:\Program Files\HP\Digital Imaging\Migrate\hpqgends.tmp - deleted
    C:\Program Files\HP\Digital Imaging\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}\drivers\scanner\hpqgends.tmp - deleted
    C:\Program Files\InterActual\InterActual Player\itiBF.tmp - deleted
    C:\Program Files\Kodak\KODAK Software Updater\7288971\clasid.bak - deleted
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\1ea7\UserProf.bak - deleted
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\1ea7\Stats.tmp - deleted
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\6727\UserProf.bak - deleted
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\6727\Stats.tmp - deleted
    C:\Program Files\The Cleaner\cleaner4.cdb.bak - deleted
    C:\Program Files\The Cleaner\tcm.log.bak - deleted
    C:\RECYCLER\S-1-5-21-992659154-1999999487-2737529250-500\Dc1.IE5\MSHist012004112120041122\index.dat - deleted
    C:\WINDOWS\CREATOR\RCDCINI.bak - deleted
    C:\WINDOWS\Help\wmplayer.bak - deleted
    C:\WINDOWS\inf\mplayer2.bak - deleted
    C:\WINDOWS\PCHealth\HelpCtr\Config\Cache\Personal_32_1036.dat.bak - deleted
    C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat - deleted
    C:\WINDOWS\repair\system.bak - deleted
    C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
    C:\WINDOWS\system32\CatRoot2\edb.chk - deleted
    C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012004010120040102\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012005032220050323\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - deleted
    C:\WINDOWS\system32\NtmsData\NTMSDATA.BAK - deleted
    C:\WINDOWS\twain_32\hpqgends.tmp - deleted
    D:\I386\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.Manifest - deleted
    D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.Manifest - deleted
    D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest - deleted
    D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.Manifest - deleted
    D:\I386\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.Manifest - deleted
    Emptied Recycle Bin on drive C:
    'Run MRU' list - removed from the registry.
    WordPad Recent File List - removed from the registry.
    Telnet's MRU list - removed from the registry.
    WinZip Extract MRU list - removed from the registry.
    WinZip File MRU list - removed from the registry.
    CleanUp! 4.0 recovered 433.7 MB of disk space from 4658 files.
    CleanUp! finished on 01/22/06 16:04:08.
    0
  11. balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
     
    c etais pas la peine de mettre le ra^pport
    refait un scan defender pour voir si c est ok
    0
  12. ISA
     
    le rapport de bitdefender est toujours le même

    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm Suspects avec Trojan.Downloader.Small.WV

    Une autre idée ???
    0
  13. jean38 Messages postés 2534 Date d'inscription   Statut Contributeur Dernière intervention   47
     
    je ne sais si ball trap est là mais tu es sous la session AURORE et visiblement les temp malware se trouve dans la session Propriétaire.

    Mets toi sur cette session et relance Cleanup
    0
  14. ISA
     
    Je suis bien sous la session propriétaire, j'ai vérifiémalgré tout,
    J'ai relancé Cleanup,

    voilà son rapport

    CleanUp! started on 01/22/06 17:28:21.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
    C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    'Typed URLs' (Internet Explorer) - removed from the registry.
    C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\pcf1.tmp - deleted
    C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\temp.log - deleted
    C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
    C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
    C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
    C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
    C:\WINDOWS\temp\tmp000003b4\ - deleted
    C:\WINDOWS\temp\tmp00000761\tmp00000000 currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\locals~1\tempor~1\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
    C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\YVLZPURH\index[1].htm - not deleted (due to unexpected error)
    C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf - deleted
    C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\subC.tmp - deleted
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\xmlB.tmp - deleted
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DF982A.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\~DFC0CA.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
    'Run MRU' list - removed from the registry.
    WordPad Recent File List - removed from the registry.
    Telnet's MRU list - removed from the registry.
    WinZip Extract MRU list - removed from the registry.
    WinZip File MRU list - removed from the registry.
    CleanUp! 4.0 recovered 505.7 KB of disk space from 6 files.
    CleanUp! finished on 01/22/06 17:29:27.
    0
  15. balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
     
    repasse cleanup en mode sans echec
    0
  16. ISA
     
    Merci de votre aide à tous !

    ça marche, tout va bien !
    0
  17. balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
     
    oki
    a++
    0
  18. abcd
     
    Vous n'auriez pas installé la programe HOTBAR par hazard ?
    Ci oui c'est peut-etre pour ca car c'est un logiciel espion.
    0
    1. NAEGELEN
       
      pas du tout !!!
      0